hacking: security in practice
Would a Solarwinds style hack be possible against APC?
So looking at APC's firmware update site they do not list hashes for their firmware updates.
https://www.apc.com/us/en/faqs/index?page=content&id=FA170679
They have all of their firmware on a Box.com account.
https://schneider-electric.box.com/s/jkigadv87yfv0oqu4d67fr7wp7s67mfo
This does not seem to be best practice.
submitted by /u/Boonaki
[link] [comments]
Would a Solarwinds style hack be possible against APC?
So looking at APC's firmware update site they do not list hashes for their firmware updates.
https://www.apc.com/us/en/faqs/index?page=content&id=FA170679
They have all of their firmware on a Box.com account.
https://schneider-electric.box.com/s/jkigadv87yfv0oqu4d67fr7wp7s67mfo
This does not seem to be best practice.
submitted by /u/Boonaki
[link] [comments]
reddit
r/hacking - Would a Solarwinds style hack be possible against APC?
0 votes and 0 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Critical Zoom vulnerability triggers remote code execution without user input
https://external-preview.redd.it/tCDgh0gw1dTa4Bhd7mnukLSec0WfBvZhOyg2a2UmDE8.jpg?width=640&crop=smart&auto=webp&s=ff415fda2c7915086968b344b67a9ef66108080f submitted by /u/_P4TR10T
[link] [comments]
Critical Zoom vulnerability triggers remote code execution without user input
https://external-preview.redd.it/tCDgh0gw1dTa4Bhd7mnukLSec0WfBvZhOyg2a2UmDE8.jpg?width=640&crop=smart&auto=webp&s=ff415fda2c7915086968b344b67a9ef66108080f submitted by /u/_P4TR10T
[link] [comments]
hacking: security in practice
Dscord video crashes client, is it harmful? tornadus net orange
Got to experience the strange gif/video that crashes your dscord client when viewed
I opened the website by accident which contained just a orange shaded word "Orange"
Does anyone know if that website didnt stole any personal information such as passwords?
submitted by /u/Ugh-Bot
[link] [comments]
Dscord video crashes client, is it harmful? tornadus net orange
Got to experience the strange gif/video that crashes your dscord client when viewed
I opened the website by accident which contained just a orange shaded word "Orange"
Does anyone know if that website didnt stole any personal information such as passwords?
submitted by /u/Ugh-Bot
[link] [comments]
reddit
Dscord video crashes client, is it harmful? tornadus net orange
Got to experience the strange gif/video that crashes your dscord client when viewed I opened the website by accident which contained just a...
hacking: security in practice
Android stalkers
I really need to track down stalkers in an android 10 system. Any leads I can follow?
submitted by /u/Adi026
[link] [comments]
Android stalkers
I really need to track down stalkers in an android 10 system. Any leads I can follow?
submitted by /u/Adi026
[link] [comments]
reddit
Android stalkers
I really need to track down stalkers in an android 10 system. Any leads I can follow?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Start
Im interested in coding or hacking but i dont know how or where to start. Any tips?
submitted by /u/MyOpnion
[link] [comments]
Start
Im interested in coding or hacking but i dont know how or where to start. Any tips?
submitted by /u/MyOpnion
[link] [comments]
reddit
Start
Im interested in coding or hacking but i dont know how or where to start. Any tips?
hacking: security in practice
Starting out
Im interested in coding or hacking but i dont know how or where to start. Any tips?
submitted by /u/MyOpnion
[link] [comments]
Starting out
Im interested in coding or hacking but i dont know how or where to start. Any tips?
submitted by /u/MyOpnion
[link] [comments]
reddit
Starting out
Im interested in coding or hacking but i dont know how or where to start. Any tips?
Bug Hunting 101: Nine Ways to Make Sure the Right People Read Your Bug Reports
https://joshpitts.medium.com/bug-hunting-101-nine-ways-to-make-sure-the-right-people-read-your-bug-reports-94ada471b894?source=rss------bug_bounty-5
https://joshpitts.medium.com/bug-hunting-101-nine-ways-to-make-sure-the-right-people-read-your-bug-reports-94ada471b894?source=rss------bug_bounty-5
Congrats you work in sales and marketing now.Continue reading on Medium » (https://joshpitts.medium.com/bug-hunting-101-nine-ways-to-make-sure-the-right-people-read-your-bug-reports-94ada471b894?source=rss------bug_bounty-5)
PoisonApple - macOS Persistence Tool
http://www.kitploit.com/2021/04/poisonapple-macos-persistence-tool.html
http://www.kitploit.com/2021/04/poisonapple-macos-persistence-tool.html
PoisonApple - macOS Persistence Tool
Command-line tool to perform various persistence mechanism techniques on macOS. This tool was designed to be used by threat hunters for cyber threat emulation purposes.Install Do it up: $ pip3 install poisonapple --user Note: PoisonApple was written & tested using Python 3.9, it should work using Python 3.6+ Important Notes! PoisonApple will make modifications to your macOS system, it's advised to only use PoisonApple on a virtual machine. Although any persistence mechanism technique added using this tool can also be easily removed (-r), please use with caution! Be advised: This tool will likely cause common AV / EDR / other macOS security products to generate alerts. To understand how any of these techniques work in-depth please see The Art of Mac Malware, Volume 1: Analysis - Chapter 0x2: Persistence by Patrick Wardle of Objective-See. It's a fantastic resource. Usage See PoisonApple switch options (--help): $ poisonapple --helpusage: poisonapple -h -l -t TECHNIQUE -n NAME -c COMMAND -rCommand-line tool to perform various persistence mechanism techniques on macOS.optional arguments: -h, --help show this help message and exit -l, --list list available persistence mechanism techniques -t TECHNIQUE, --technique TECHNIQUE persistence mechanism technique to use -n NAME, --name NAME name for the file or label used for persistence -c COMMAND, --command COMMAND command(s) to execute for persistence -r, --remove remove persistence mechanism List of available techniques: $ poisonapple --list , _ _ .-.:|.-. | _ .-----|_|-----.-----.-----..' '. |. | | | | |_ --| | | | |'-."~". .-' |. _|_|_|_|_|_|_| } ` } { |: | _ _ } } } { |::.| | _ .-----.-----| |-----. } ` } { `---' |. | | | | | | | -_|.-'"~" '-. |. _ | _| _|_|_|'. .' |: | |_| |_| '-_.._-' |::.|:. | `--- ---' v0.2.0+--------------------+| AtJob |+--------------------+| Bashrc |+--------------------+| Cron |+--------------------+| CronRoot |+--------------------+| Emond |+--------------------+| LaunchAgent |+--------------------+| LaunchAgentUser |+--------------------+| LaunchDaemon |+--- -----------------+| LoginHook |+--------------------+| LoginHookUser |+--------------------+| LoginItem |+--------------------+| LogoutHook |+--------------------+| LogoutHookUser |+--------------------+| Periodic |+--------------------+| Reopen |+--------------------+| Zshrc |+--------------------+ Apply a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing , _ _ .-.:|.-. | _ .-----|_|-----.-----.-----..' '. |. | | | | |_ --| | | | |'-."~". .-' |. _|_|_|_|_|_|_| } ` } { |: | _ _ } } } { |::.| | _ .-----.-----| |-----. } ` } { `---' |. | | | | | | | -_|.-'"~" '-. |. _ | _| _|_|_|'. .' |: | |_| |_| '-_.._-' |::.|:. | `--- ---' v0.2.0+ Success! The persistence mechanism action was successful: LaunchAgentUser If no command is specified (-c) a default trigger command will be used which writes to a file on the Desktop every time the persistence mechanism is triggered: $ cat ~/Desktop/PoisonApple-LaunchAgentUserTriggered @ Tue Mar 23 17:46:02 CDT 2021 Triggered @ Tue Mar 23 17:46:13 CDT 2021 Triggered @ Tue Mar 23 17:46:23 CDT 2021 Triggered @ Tue Mar 23 17:46:33 CDT 2021 Triggered @ Tue Mar 23 17:46:43 CDT 2021 Triggered @ Tue Mar 23 17:46:53 CDT 2021 Triggered @ Tue Mar 23 17:47:03 CDT 2021 Triggered @ Tue Mar 23 17:47:13 CDT 2021 Triggered @ Tue Mar 23 17:48:05 CDT 2021 Triggered @ Tue Mar 23 17:48:15 CDT 2021 Remove a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing -r... Use a custom command: $ poisonapple -t LaunchAgentUser -n foo -c "echo foo >> /Users/user/Desktop/foo"... Download PoisonApple
Read more...
Command-line tool to perform various persistence mechanism techniques on macOS. This tool was designed to be used by threat hunters for cyber threat emulation purposes.Install Do it up: $ pip3 install poisonapple --user Note: PoisonApple was written & tested using Python 3.9, it should work using Python 3.6+ Important Notes! PoisonApple will make modifications to your macOS system, it's advised to only use PoisonApple on a virtual machine. Although any persistence mechanism technique added using this tool can also be easily removed (-r), please use with caution! Be advised: This tool will likely cause common AV / EDR / other macOS security products to generate alerts. To understand how any of these techniques work in-depth please see The Art of Mac Malware, Volume 1: Analysis - Chapter 0x2: Persistence by Patrick Wardle of Objective-See. It's a fantastic resource. Usage See PoisonApple switch options (--help): $ poisonapple --helpusage: poisonapple -h -l -t TECHNIQUE -n NAME -c COMMAND -rCommand-line tool to perform various persistence mechanism techniques on macOS.optional arguments: -h, --help show this help message and exit -l, --list list available persistence mechanism techniques -t TECHNIQUE, --technique TECHNIQUE persistence mechanism technique to use -n NAME, --name NAME name for the file or label used for persistence -c COMMAND, --command COMMAND command(s) to execute for persistence -r, --remove remove persistence mechanism List of available techniques: $ poisonapple --list , _ _ .-.:|.-. | _ .-----|_|-----.-----.-----..' '. |. | | | | |_ --| | | | |'-."~". .-' |. _|_|_|_|_|_|_| } ` } { |: | _ _ } } } { |::.| | _ .-----.-----| |-----. } ` } { `---' |. | | | | | | | -_|.-'"~" '-. |. _ | _| _|_|_|'. .' |: | |_| |_| '-_.._-' |::.|:. | `--- ---' v0.2.0+--------------------+| AtJob |+--------------------+| Bashrc |+--------------------+| Cron |+--------------------+| CronRoot |+--------------------+| Emond |+--------------------+| LaunchAgent |+--------------------+| LaunchAgentUser |+--------------------+| LaunchDaemon |+--- -----------------+| LoginHook |+--------------------+| LoginHookUser |+--------------------+| LoginItem |+--------------------+| LogoutHook |+--------------------+| LogoutHookUser |+--------------------+| Periodic |+--------------------+| Reopen |+--------------------+| Zshrc |+--------------------+ Apply a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing , _ _ .-.:|.-. | _ .-----|_|-----.-----.-----..' '. |. | | | | |_ --| | | | |'-."~". .-' |. _|_|_|_|_|_|_| } ` } { |: | _ _ } } } { |::.| | _ .-----.-----| |-----. } ` } { `---' |. | | | | | | | -_|.-'"~" '-. |. _ | _| _|_|_|'. .' |: | |_| |_| '-_.._-' |::.|:. | `--- ---' v0.2.0+ Success! The persistence mechanism action was successful: LaunchAgentUser If no command is specified (-c) a default trigger command will be used which writes to a file on the Desktop every time the persistence mechanism is triggered: $ cat ~/Desktop/PoisonApple-LaunchAgentUserTriggered @ Tue Mar 23 17:46:02 CDT 2021 Triggered @ Tue Mar 23 17:46:13 CDT 2021 Triggered @ Tue Mar 23 17:46:23 CDT 2021 Triggered @ Tue Mar 23 17:46:33 CDT 2021 Triggered @ Tue Mar 23 17:46:43 CDT 2021 Triggered @ Tue Mar 23 17:46:53 CDT 2021 Triggered @ Tue Mar 23 17:47:03 CDT 2021 Triggered @ Tue Mar 23 17:47:13 CDT 2021 Triggered @ Tue Mar 23 17:48:05 CDT 2021 Triggered @ Tue Mar 23 17:48:15 CDT 2021 Remove a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing -r... Use a custom command: $ poisonapple -t LaunchAgentUser -n foo -c "echo foo >> /Users/user/Desktop/foo"... Download PoisonApple
Read more...
Command-line tool to perform various persistence mechanism techniques on macOS. This tool was designed to be used by threat (https://www.kitploit.com/search/label/Threat) hunters for cyber threat emulation (https://www.kitploit.com/search/label/Emulation) purposes.
Install
Do it up: $ pip3 install poisonapple --user
Note: PoisonApple was written & tested using Python 3.9, it should work using Python 3.6+
Important Notes!
PoisonApple will make modifications to your macOS system, it's advised to only use PoisonApple on a virtual machine. Although any persistence mechanism technique added using this tool can also be easily removed (-r), please use with caution! Be advised: This tool will likely cause common AV / EDR / other macOS security products to generate alerts. To understand how any of these techniques work in-depth please see The Art of Mac Malware, Volume 1: (https://taomm.org/PDFs/vol1/CH%200x02%20Persistence.pdf)Analysis (https://www.kitploit.com/search/label/Analysis) - Chapter 0x2: Persistence by Patrick Wardle of Objective-See. It's a fantastic resource.
Usage
See PoisonApple switch options (--help): $ poisonapple --help
usage: poisonapple [-h] [-l] [-t TECHNIQUE] [-n NAME] [-c COMMAND] [-r]
Command-line tool to perform various persistence mechanism techniques on macOS.
optional arguments:
-h, --help show this help message and exit
-l, --list list available persistence mechanism techniques
-t TECHNIQUE, --technique TECHNIQUE
persistence mechanism technique to use
-n NAME, --name NAME name for the file or label used for persistence
-c COMMAND, --command COMMAND
command(s) to execute for persistence
-r, --remove remove persistence mechanism
List of available techniques: $ poisonapple --list
, _______ __
.-.:|.-. | _ .-----|__|-----.-----.-----.
.' '. |. | | | | |__ --| | | | |
'-."~". .-' |. ____|_____|__|_____|_____|__|__|
} ` } { |: | _______ __
} } } { |::.| | _ .-----.-----| |-----.
} ` } { `---' |. | | | | | | | -__|
.-'"~" '-. |. _ | __| __|__|_____|
'. .' |: | |__| |__|
'-_.._-' |::.|:. |
`--- ---' v0.2.0
+--------------------+
| AtJob |
+--------------------+
| Bashrc |
+--------------------+
| Cron |
+--------------------+
| CronRoot |
+--------------------+
| Emond |
+--------------------+
| LaunchAgent |
+--------------------+
| LaunchAgentUser |
+--------------------+
| LaunchDaemon |
+--- -----------------+
| LoginHook |
+--------------------+
| LoginHookUser |
+--------------------+
| LoginItem |
+--------------------+
| LogoutHook |
+--------------------+
| LogoutHookUser |
+--------------------+
| Periodic |
+--------------------+
| Reopen |
+--------------------+
| Zshrc |
+--------------------+
Apply a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing
, _______ __
.-.:|.-. | _ .-----|__|-----.-----.-----.
.' '. |. | | | | |__ --| | | | |
'-."~". .-' |. ____|_____|__|_____|_____|__|__|
} ` } { |: | _______ __
} } } { |::.| | _ .-----.-----| |-----.
} ` } { `---' |. | | | | | | | -__|
.-'"~" '-. |. _ | __| __|__|_____|
'. .' |: | |__| |__|
'-_.._-' |::.|:. |
`--- ---' v0.2.0
[+] Success! The persistence mechanism action was successful: LaunchAgentUser
If no command is specified (-c) a default trigger command will be used which writes to a file on the Desktop (https://www.kitploit.com/search/label/Desktop) every time the persistence mechanism is triggered: $ cat ~/Desktop/PoisonApple-LaunchAgentUser
Install
Do it up: $ pip3 install poisonapple --user
Note: PoisonApple was written & tested using Python 3.9, it should work using Python 3.6+
Important Notes!
PoisonApple will make modifications to your macOS system, it's advised to only use PoisonApple on a virtual machine. Although any persistence mechanism technique added using this tool can also be easily removed (-r), please use with caution! Be advised: This tool will likely cause common AV / EDR / other macOS security products to generate alerts. To understand how any of these techniques work in-depth please see The Art of Mac Malware, Volume 1: (https://taomm.org/PDFs/vol1/CH%200x02%20Persistence.pdf)Analysis (https://www.kitploit.com/search/label/Analysis) - Chapter 0x2: Persistence by Patrick Wardle of Objective-See. It's a fantastic resource.
Usage
See PoisonApple switch options (--help): $ poisonapple --help
usage: poisonapple [-h] [-l] [-t TECHNIQUE] [-n NAME] [-c COMMAND] [-r]
Command-line tool to perform various persistence mechanism techniques on macOS.
optional arguments:
-h, --help show this help message and exit
-l, --list list available persistence mechanism techniques
-t TECHNIQUE, --technique TECHNIQUE
persistence mechanism technique to use
-n NAME, --name NAME name for the file or label used for persistence
-c COMMAND, --command COMMAND
command(s) to execute for persistence
-r, --remove remove persistence mechanism
List of available techniques: $ poisonapple --list
, _______ __
.-.:|.-. | _ .-----|__|-----.-----.-----.
.' '. |. | | | | |__ --| | | | |
'-."~". .-' |. ____|_____|__|_____|_____|__|__|
} ` } { |: | _______ __
} } } { |::.| | _ .-----.-----| |-----.
} ` } { `---' |. | | | | | | | -__|
.-'"~" '-. |. _ | __| __|__|_____|
'. .' |: | |__| |__|
'-_.._-' |::.|:. |
`--- ---' v0.2.0
+--------------------+
| AtJob |
+--------------------+
| Bashrc |
+--------------------+
| Cron |
+--------------------+
| CronRoot |
+--------------------+
| Emond |
+--------------------+
| LaunchAgent |
+--------------------+
| LaunchAgentUser |
+--------------------+
| LaunchDaemon |
+--- -----------------+
| LoginHook |
+--------------------+
| LoginHookUser |
+--------------------+
| LoginItem |
+--------------------+
| LogoutHook |
+--------------------+
| LogoutHookUser |
+--------------------+
| Periodic |
+--------------------+
| Reopen |
+--------------------+
| Zshrc |
+--------------------+
Apply a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing
, _______ __
.-.:|.-. | _ .-----|__|-----.-----.-----.
.' '. |. | | | | |__ --| | | | |
'-."~". .-' |. ____|_____|__|_____|_____|__|__|
} ` } { |: | _______ __
} } } { |::.| | _ .-----.-----| |-----.
} ` } { `---' |. | | | | | | | -__|
.-'"~" '-. |. _ | __| __|__|_____|
'. .' |: | |__| |__|
'-_.._-' |::.|:. |
`--- ---' v0.2.0
[+] Success! The persistence mechanism action was successful: LaunchAgentUser
If no command is specified (-c) a default trigger command will be used which writes to a file on the Desktop (https://www.kitploit.com/search/label/Desktop) every time the persistence mechanism is triggered: $ cat ~/Desktop/PoisonApple-LaunchAgentUser
Triggered @ Tue Mar 23 17:46:02 CDT 2021
Triggered @ Tue Mar 23 17:46:13 CDT 2021
Triggered @ Tue Mar 23 17:46:23 CDT 2021
Triggered @ Tue Mar 23 17:46:33 CDT 2021
Triggered @ Tue Mar 23 17:46:43 CDT 2021
Triggered @ Tue Mar 23 17:46:53 CDT 2021
Triggered @ Tue Mar 23 17:47:03 CDT 2021
Triggered @ Tue Mar 23 17:47:13 CDT 2021
Triggered @ Tue Mar 23 17:48:05 CDT 2021
Triggered @ Tue Mar 23 17:48:15 CDT 2021
Remove a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing (https://www.kitploit.com/search/label/Testing) -r
...
Use a custom command: $ poisonapple -t LaunchAgentUser -n foo -c "echo foo >> /Users/user/Desktop/foo"
...
Download PoisonApple (https://github.com/CyborgSecurity/PoisonApple)
Triggered @ Tue Mar 23 17:46:13 CDT 2021
Triggered @ Tue Mar 23 17:46:23 CDT 2021
Triggered @ Tue Mar 23 17:46:33 CDT 2021
Triggered @ Tue Mar 23 17:46:43 CDT 2021
Triggered @ Tue Mar 23 17:46:53 CDT 2021
Triggered @ Tue Mar 23 17:47:03 CDT 2021
Triggered @ Tue Mar 23 17:47:13 CDT 2021
Triggered @ Tue Mar 23 17:48:05 CDT 2021
Triggered @ Tue Mar 23 17:48:15 CDT 2021
Remove a persistence mechanism: $ poisonapple -t LaunchAgentUser -n testing (https://www.kitploit.com/search/label/Testing) -r
...
Use a custom command: $ poisonapple -t LaunchAgentUser -n foo -c "echo foo >> /Users/user/Desktop/foo"
...
Download PoisonApple (https://github.com/CyborgSecurity/PoisonApple)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Tabby: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*Quvs4ttzF5hJvWFFZx04Wg.png
Hack The Box — Tabby: Walkthrough (without Metasploit) | Road to OSCP | Linux Medium Level | tomcat | fcrackzip | lxd | Sandbox Escape
Continue reading on Medium »
Hack The Box — Tabby: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*Quvs4ttzF5hJvWFFZx04Wg.png
Hack The Box — Tabby: Walkthrough (without Metasploit) | Road to OSCP | Linux Medium Level | tomcat | fcrackzip | lxd | Sandbox Escape
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Los piratas informáticos aprovechan las VPN sin parches para instalar ransomware en objetivos…
https://cdn-images-1.medium.com/max/600/0*LJtwyXFRBhSYUj4B
PUBLICADO EN 9 ABRIL, 2021 POR EHACKING
Continue reading on Medium »
Los piratas informáticos aprovechan las VPN sin parches para instalar ransomware en objetivos…
https://cdn-images-1.medium.com/max/600/0*LJtwyXFRBhSYUj4B
PUBLICADO EN 9 ABRIL, 2021 POR EHACKING
Continue reading on Medium »