Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
What is it actually like to be a hacker?

So I'm curious as to what it's actually like to be a hacker. As someone with very little knowledge on this but having an interest in it for years and considering getting into it I want to make sure it's for me. Obviously the media overhypes stuff and makes it seem completely different than it is so would it happen to irl be anything like the media portrays or it just another desk job/life?

submitted by /u/MoonMeta
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How will Russia attack?

Can you predict what Russia will do or is doing? They said they are going to attack “sensitive” assets, and I’m guessing cyber is part or most of their plan, but no idea what area or how. Thoughts?

PS: Maybe like this, four years ago only and against Ukraine

submitted by /u/sukarsono
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Could the cyber world defend Ukraine?

Trying to find a sub that can answer this.. seems reasonable from someone that knows nothing about the cyber world, so… is it reasonable? Could hackers come together an protect Ukraine from Russian cyber attacks?

submitted by /u/Johnny1America
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
$$$ Bank Verification Bypass(Broken Object Level Authorisation)

Hey Readers 👋, Hope you are doing great,Continue reading on InfoSec Write-ups »
Read more...
$$$ Bank Verification Bypass(Broken Object Level Authorisation)

Hey Readers 👋, Hope you are doing great,Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Samsung Shattered Encryption on 100M Phones

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Samsung Shattered Encryption on 100M PhonesPost Views: 185
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 3 Minutes
Samsung shipped an estimated 100 million smartphones with botched encryption, including models ranging from the 2017 Galaxy S8 on up to last year’s Galaxy S21.
One cryptography expert said that ‘serious flaws’ in the way Samsung phones encrypt sensitive material, as revealed by academics, are ’embarrassingly bad.’

Researchers at Tel Aviv University found what they called “severe” cryptographic design flaws that could have let attackers siphon the devices’ hardware-based cryptographic keys: keys that unlock the treasure trove of security-critical data that’s found in smartphones.

What’s more, cyber attackers could even exploit Samsung’s cryptographic missteps – since addressed in multiple CVEs – to downgrade a device’s security protocols. That would set up a phone to be vulnerable to future attacks: a practice known as IV (initialization vector) reuse attacks. IV reuse attacks screw with the encryption randomization that ensures that even if multiple messages with identical plaintext are encrypted, the generated corresponding ciphertexts will each be distinct.
See Also: Complete Offensive Security and Ethical Hacking Course Untrustworthy Implementation of TrustZoneIn a paper (PDF) entitled “Trust Dies in Darkness: Shedding Light on Samsung’s TrustZone Keymaster Design” – written by by Alon Shakevsky, Eyal Ronen and Avishai Wool – the academics explain that nowadays, smartphones control data that includes sensitive messages, images and files; cryptographic key management; FIDO2 web authentication; digital rights management (DRM) data; data for mobile payment services such as Samsung Pay; and enterprise identity management.

The authors are due to give a detailed presentation of the vulnerabilities at the upcoming USENIX Security, 2022 symposium in August.

The design flaws primarily affect devices that use ARM’s TrustZone technology: the hardware support provided by ARM-based Android smartphones (which are the majority) for a Trusted Execution Environment (TEE) to implement security-sensitive functions.

TrustZone splits a phone into two portions, known as the Normal world (for running regular tasks, such as the Android OS) and the Secure world, which handles the security subsystem and where all sensitive resources reside. The Secure world is only accessible to trusted applications used for security-sensitive functions, including encryption.

Matthew Green, associate professor of computer science at the Johns Hopkins Information Security Institute, explained on Twitter that Samsung incorporated “serious flaws” in the way its phones encrypt key material in TrustZone, calling it “embarrassingly bad.”

“They used a single key and allowed IV re-use,” Green said.

“So they could have derived a different key-wrapping key for each key they protect,” he continued. “But instead Samsung basically doesn’t. Then they allow the app-layer code to pick encryption IVs.” The design decision allows for “trivial decryption,” he said.
Ugh god. Serious flaws in the way Samsung phones encrypt key material in TrustZone and it’s embarrassingly bad. They used a single key and allowed IV re-use. https://t.co/XteB3kc8cH pic.twitter.com/4wxA6XBuN2

— Matthew Green (@matthew_d_green) February 22, 2022
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Flaws Enable Security Standards BypassThe security flaws not only allow cybercriminals to steal crypto[...]

___________________________
@hacking_Attack
@Hacking_Video