Send a Email to me and get kicked out of Google Groups !!
A Feature that almost broke Google Groups !!
Read more...
A Feature that almost broke Google Groups !!
Read more...
Reading and Writing into Process's Memory
https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/
Get the basic understanding on the remote process memory read and write all by windows 32 API and create your own game hacks. https://tbhaxor.com/reading-and-writing-into-processs-memory/ submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/) [comments] (https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/
Get the basic understanding on the remote process memory read and write all by windows 32 API and create your own game hacks. https://tbhaxor.com/reading-and-writing-into-processs-memory/ submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/) [comments] (https://www.reddit.com/r/redteamsec/comments/sxm8bn/reading_and_writing_into_processs_memory/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reading and Writing into Process's Memory
Get the basic understanding on the remote process memory read and write all by windows 32 API and create your own game...
Automating a Red Team lab with Packer, Terraform and Ansible
https://www.reddit.com/r/redteamsec/comments/sxnnd0/automating_a_red_team_lab_with_packer_terraform/
submitted by /u/nickonos (https://www.reddit.com/user/nickonos)
[link] (https://nickzero.co.uk/automating-a-red-team-lab/) [comments] (https://www.reddit.com/r/redteamsec/comments/sxnnd0/automating_a_red_team_lab_with_packer_terraform/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/sxnnd0/automating_a_red_team_lab_with_packer_terraform/
submitted by /u/nickonos (https://www.reddit.com/user/nickonos)
[link] (https://nickzero.co.uk/automating-a-red-team-lab/) [comments] (https://www.reddit.com/r/redteamsec/comments/sxnnd0/automating_a_red_team_lab_with_packer_terraform/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Automating a Red Team lab with Packer, Terraform and Ansible
Posted in r/redteamsec by u/nickonos • 1 point and 0 comments
Hacking on Medium
OpenSea Phishing
https://cdn-images-1.medium.com/max/1920/1*iA-6tStFqvJlIZ2_Vim9IA.jpeg
OpenSea has experienced a phishing scam. Such an attack hooked over 640 ETH in assets from 32 users with the label Fake_Phishing5169.
Continue reading on CryptoStars »
___________________________
@hacking_Attack
@Hacking_Video
OpenSea Phishing
https://cdn-images-1.medium.com/max/1920/1*iA-6tStFqvJlIZ2_Vim9IA.jpeg
OpenSea has experienced a phishing scam. Such an attack hooked over 640 ETH in assets from 32 users with the label Fake_Phishing5169.
Continue reading on CryptoStars »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OpenSea Phishing
OpenSea has experienced a phishing scam. Such an attack hooked over 640 ETH in assets from 32 users with the label Fake_Phishing5169.
Hacking on Medium
Thirteen ways to hack in the digital world
https://cdn-images-1.medium.com/max/824/1*jKleprC84vs5zkgKx1TVcQ.jpeg
1. Admin Key Compromise
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Thirteen ways to hack in the digital world
https://cdn-images-1.medium.com/max/824/1*jKleprC84vs5zkgKx1TVcQ.jpeg
1. Admin Key Compromise
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Thirteen ways to hack in the digital world
1. Admin Key Compromise
C0V3RT - An exploration of all things "Covert Entry" Watch "C0V3RT - Can0pen3r's Green Belt Submission "American Clone Picked, Gutted, & Reassembled" (Tutorial)" on YouTube
https://www.reddit.com/r/redteamsec/comments/sxpa0q/c0v3rt_an_exploration_of_all_things_covert_entry/
submitted by /u/Can0pen3r (https://www.reddit.com/user/Can0pen3r)
[link] (https://youtu.be/r1w7etG93Sg) [comments] (https://www.reddit.com/r/redteamsec/comments/sxpa0q/c0v3rt_an_exploration_of_all_things_covert_entry/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/sxpa0q/c0v3rt_an_exploration_of_all_things_covert_entry/
submitted by /u/Can0pen3r (https://www.reddit.com/user/Can0pen3r)
[link] (https://youtu.be/r1w7etG93Sg) [comments] (https://www.reddit.com/r/redteamsec/comments/sxpa0q/c0v3rt_an_exploration_of_all_things_covert_entry/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
C0V3RT - An exploration of all things "Covert Entry" Watch "C0V3RT...
Posted in r/redteamsec by u/Can0pen3r • 1 point and 0 comments
Polygon Consensus Bypass Bugfix Review
https://medium.com/immunefi/polygon-consensus-bypass-bugfix-review-7076ce5047fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/polygon-consensus-bypass-bugfix-review-7076ce5047fe?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polygon Consensus Bypass Bugfix Review
Summary
SummaryContinue reading on Immunefi » (https://medium.com/immunefi/polygon-consensus-bypass-bugfix-review-7076ce5047fe?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polygon Consensus Bypass Bugfix Review
Summary
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on serversPost Views: 208 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Two vulnerabilities in open source monitoring platform Zabbix could allow an attacker to bypass authentication and execute arbitrary code on a targeted server.
The security flaws were found in Zabbix Web Frontend, a platform used to collect, centralize. and track metrics such as CPU load and network traffic across entire infrastructures.
Researchers from SonarSource, who discovered the bugs, noted that Zabbix is a high-profile target for threat actors due to its popularity, features, and its “privileged position in most company’s networks”. IssuesThe first vulnerability, tracked as CVE-2022-23131, which was given a severity of 9.1, is unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified.
A malicious unauthenticated actor could exploit this issue to escalate privileges and gain admin access to the Zabbix Frontend.
See Also: Complete Offensive Security and Ethical Hacking Course
A caveat to this is that to perform the attack, SAML authentication is required to be enabled, and the assailant has to know the username of Zabbix user (or use the guest account, which is disabled by default), a security advisory from Zabbix notes.
The second vulnerability found by SonarSource, tracked as CVE-2022-23134, is rated as medium severity and allows some steps of setup.php file to be reachable not only by super-administrators, but by unauthenticated users as well.
A malicious actor could pass step checks and potentially change the configuration of Zabbix Frontend, an advisory notes.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Patch nowIn a blog post from SonarSource, the researchers said that when writing and reviewing code related to important security features, “it is easy to make the same assumptions as the original developer who introduced the vulnerability”.
They wrote: “Here, there were no integration tests related to the client-side session storage that could have spotted this behavior.
“Always provide access to sensible services with extended internal accesses (e.g. orchestration, monitoring) over VPNs or a restricted set of IP addresses, harden filesystem permissions to prevent unintended changes, remove setup scripts, etc.”
Finally, the researchers recommended upgrading all instances running a Zabbix Web Frontend to 6.0.0beta2, 5.4.9, 5.0.19, or 4.0.37. See Also: Offensive Security Tool: Swaks – Swiss Army Knife for SMTP
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: portswigger.net Source Linkhttps://www.blackh[...]
___________________________
@hacking_Attack
@Hacking_Video
Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on serversPost Views: 208 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
Two vulnerabilities in open source monitoring platform Zabbix could allow an attacker to bypass authentication and execute arbitrary code on a targeted server.
The security flaws were found in Zabbix Web Frontend, a platform used to collect, centralize. and track metrics such as CPU load and network traffic across entire infrastructures.
Researchers from SonarSource, who discovered the bugs, noted that Zabbix is a high-profile target for threat actors due to its popularity, features, and its “privileged position in most company’s networks”. IssuesThe first vulnerability, tracked as CVE-2022-23131, which was given a severity of 9.1, is unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified.
A malicious unauthenticated actor could exploit this issue to escalate privileges and gain admin access to the Zabbix Frontend.
See Also: Complete Offensive Security and Ethical Hacking Course
A caveat to this is that to perform the attack, SAML authentication is required to be enabled, and the assailant has to know the username of Zabbix user (or use the guest account, which is disabled by default), a security advisory from Zabbix notes.
The second vulnerability found by SonarSource, tracked as CVE-2022-23134, is rated as medium severity and allows some steps of setup.php file to be reachable not only by super-administrators, but by unauthenticated users as well.
A malicious actor could pass step checks and potentially change the configuration of Zabbix Frontend, an advisory notes.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Patch nowIn a blog post from SonarSource, the researchers said that when writing and reviewing code related to important security features, “it is easy to make the same assumptions as the original developer who introduced the vulnerability”.
They wrote: “Here, there were no integration tests related to the client-side session storage that could have spotted this behavior.
“Always provide access to sensible services with extended internal accesses (e.g. orchestration, monitoring) over VPNs or a restricted set of IP addresses, harden filesystem permissions to prevent unintended changes, remove setup scripts, etc.”
Finally, the researchers recommended upgrading all instances running a Zabbix Web Frontend to 6.0.0beta2, 5.4.9, 5.0.19, or 4.0.37. See Also: Offensive Security Tool: Swaks – Swiss Army Knife for SMTP
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: portswigger.net Source Linkhttps://www.blackh[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers | Black Hat Ethical Hacking
Two vulnerabilities in open source monitoring platform Zabbix could allow an attacker to bypass authentication and execute arbitrary code on a targeted server.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Critical vulnerabilities in Zabbix Web…
atethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-1-90x90.jpg GitHub code scanning now finds more security vulnerabilities3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/012qzWe52HXVPxkc8nUrPyv-1.fit_lim.size_1200x630.v1617817629-90x90.jpg Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Unredacter-Pixelize-90x90.gif New tool can uncover redacted, pixelated text to reveal sensitive data5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-1-90x90.jpg Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/banner-2022.1-release-90x90.jpg Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/acastro_210104_1777_google_0001-90x90.jpg Google Project Zero: Vendors are now quicker at fixing zero-days1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Apple-Warning-90x90.jpg Apple patches new zero-day exploited to hack iPhones, iPads, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/f4bc-article-200611-wordpress-body-text-90x90.jpg PHP Everywhere RCE flaws threaten thousands of WordPress sites2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/178-706-450-android-patch-770x439_c-90x90.jpg Google fixes remote escalation of privileges bug on Android2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-90x90.jpg Qbot needs only 30 minutes to steal your credentials, emails2 weeks ago
The post Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/012qzWe52HXVPxkc8nUrPyv-1.fit_lim.size_1200x630.v1617817629-90x90.jpg Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Unredacter-Pixelize-90x90.gif New tool can uncover redacted, pixelated text to reveal sensitive data5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-1-90x90.jpg Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/banner-2022.1-release-90x90.jpg Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/acastro_210104_1777_google_0001-90x90.jpg Google Project Zero: Vendors are now quicker at fixing zero-days1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Apple-Warning-90x90.jpg Apple patches new zero-day exploited to hack iPhones, iPads, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/f4bc-article-200611-wordpress-body-text-90x90.jpg PHP Everywhere RCE flaws threaten thousands of WordPress sites2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/178-706-450-android-patch-770x439_c-90x90.jpg Google fixes remote escalation of privileges bug on Android2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-90x90.jpg Qbot needs only 30 minutes to steal your credentials, emails2 weeks ago
The post Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Attacking Kerberos | Kerberoasting | AS-REP Roasting | Active Directory | Windows |
https://systemweakness.com/attacking-kerberos-kerberoasting-as-rep-roasting-active-directory-windows-e1b770b95c4b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://systemweakness.com/attacking-kerberos-kerberoasting-as-rep-roasting-active-directory-windows-e1b770b95c4b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Attacking Kerberos | Kerberoasting | AS-REP Roasting | Active Directory | Windows |
This blog covers how to attack Kerberos with Kerberoasting and AS-REP Roasting attacks.
This blog covers how to attack Kerberos with Kerberoasting and AS-REP Roasting attacks.Continue reading on System Weakness » (https://systemweakness.com/attacking-kerberos-kerberoasting-as-rep-roasting-active-directory-windows-e1b770b95c4b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Attacking Kerberos | Kerberoasting | AS-REP Roasting | Active Directory | Windows |
This blog covers how to attack Kerberos with Kerberoasting and AS-REP Roasting attacks.
hacking: security in practice
I'm kinda interested in all of this
What are common ways of dos-ing someone? Can someone give an example, and what do I have to learn. I'm new to all of this, I know java, that's all.
submitted by /u/KristerZX
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I'm kinda interested in all of this
What are common ways of dos-ing someone? Can someone give an example, and what do I have to learn. I'm new to all of this, I know java, that's all.
submitted by /u/KristerZX
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I'm kinda interested in all of this
What are common ways of dos-ing someone? Can someone give an example, and what do I have to learn. I'm new to all of this, I know java, that's all.
How can I secure my Android app’s code?
https://www.reddit.com/r/Pentesting/comments/sxqg9n/how_can_i_secure_my_android_apps_code/
submitted by /u/jeffreysan1996 (https://www.reddit.com/user/jeffreysan1996)
[link] (https://www.consealsecurity.com/blog/how-can-i-secure-android-app-code/) [comments] (https://www.reddit.com/r/Pentesting/comments/sxqg9n/how_can_i_secure_my_android_apps_code/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/sxqg9n/how_can_i_secure_my_android_apps_code/
submitted by /u/jeffreysan1996 (https://www.reddit.com/user/jeffreysan1996)
[link] (https://www.consealsecurity.com/blog/how-can-i-secure-android-app-code/) [comments] (https://www.reddit.com/r/Pentesting/comments/sxqg9n/how_can_i_secure_my_android_apps_code/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How can I secure my Android app’s code?
Posted in r/Pentesting by u/jeffreysan1996 • 1 point and 0 comments
Hacking on Medium
What is Kali Linux & An Introduction to the Linux Terminal and CLI.
This guide is smoothed out for complete fledglings in the Linux people group to stand up and begin with the terminal, utilize the Linux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Kali Linux & An Introduction to the Linux Terminal and CLI.
This guide is smoothed out for complete fledglings in the Linux people group to stand up and begin with the terminal, utilize the Linux…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Kali Linux & An Introduction to the Linux Terminal and CLI.
This guide is smoothed out for complete fledglings in the Linux people group to stand up and begin with the terminal, utilize the Linux…
Hacking on Medium
NFT Marketplace OpenSea Hacked, $1.7M in NFTs stolen
https://cdn-images-1.medium.com/max/1280/1*cbnzVwxCvC0LMljkOQmT6w.png
A new week, a new attack. Not a week has passed since the beginning of the year without an incident affecting a firm in the cryptosphere…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
NFT Marketplace OpenSea Hacked, $1.7M in NFTs stolen
https://cdn-images-1.medium.com/max/1280/1*cbnzVwxCvC0LMljkOQmT6w.png
A new week, a new attack. Not a week has passed since the beginning of the year without an incident affecting a firm in the cryptosphere…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
NFT Marketplace OpenSea Hacked, $1.7M in NFTs stolen
A new week, a new attack. Not a week has passed since the beginning of the year without an incident affecting a firm in the cryptosphere…
Hacking on Medium
Kernel Locking —Deep Dive into Spinlocks — Part 1
https://cdn-images-1.medium.com/max/600/1*3uhqV0ui4jOZMff1FxI5TQ.png
The Linux Kernel provides a variety of locking primitives. Each one of them behaves in a unique way that makes it more or less suitable to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Kernel Locking —Deep Dive into Spinlocks — Part 1
https://cdn-images-1.medium.com/max/600/1*3uhqV0ui4jOZMff1FxI5TQ.png
The Linux Kernel provides a variety of locking primitives. Each one of them behaves in a unique way that makes it more or less suitable to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Kernel Locking —Deep Dive into Spinlocks — Part 1
The Linux Kernel provides a variety of locking primitives. Each one of them behaves in a unique way that makes it more or less suitable to…