hacking: security in practice
Been PWNED. My journey through getting my info off of a leaked database.
I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities fell into my lap, and here I am a few years later after never getting back into it.
Nonetheless!
Some account information was leaked in a databreach. Here's the breach:
Warning: Porn Ads. Pop ups. Etc. Run of the mill stuff. https://www.freeaccounts.bi3.shop/p/all-free-account.html
I wont say where my info is on the site for obvious reasons.
Now I admit, ive been aware of that breach for some time now. I wasnt too concerned because the account was very old, and the password that was leaked I only used for random things when I was a student. But a few days ago, a got an email alerting me of a login through my ancient Grammarly account. Low and behold that account used the same login info. I finally got my wisdom teeth pulled, so im taking some time out of the office. I figured this would be a fun project to take on while I swallow Advil like tic tacs. Heres what i've found/done so far:
- Whois search
No luck. I personally dont know whats going on with this URL. But I couldnt find any info on this sucker on any conventional whois websites
- Reporting the website
I tried reporting the website to Google, just because i'd feel a little better if the info was viewable on the most used search engine. They determined it wasn't against their terms. Which...I mean. Yeah whatever.
- Following the yellow brick road
I joined the Discord/Telegram group. Now this was interesting. I found myself in a den of credit card info and all sorts of other scams. It was a bit odd seeing this type of thing outside of TOR, but I digress. I basically just asked the owner to take my stuff down, and he agreed! But heres the tricky part. THIS ISNT HIS WEBSITE. So this website is hosted and maintained (updated almost daily) by somoeone who literally just copies his websites content. So the owner of this Discord/Telegram deleted my info from HIS site, but of course wasnt able to do anything about the ones I was concerned about. What I also found interesting was that this page literally links you to the "legit" shop made by the real owner, where you can buy breached info. Even more interesting was that the "legit" website is brand new. The owners original one was taken down, and so he just published a new one as of 03/07? This guy is an active member.
Anyways, I then noticed this guy literally has his Facebook and Instagram on his website. Hm. They look legit. So I DMed him! (took the "honor among thieves" approach) Sent him a message on Facebook. And now im just waiting for him to see it. Looks like the accounts been dead for nearly a year. But the fact that he's so active with his updates makes me think he'll definitely see it. Whats interesting is that these accounts look personal. He has public accounts, and I believe im looking at this friends and family. I took the liberty of saving all those usernames in a .txt, as they may prove useful should things come down to...social engineering.
And thats where I am the journey now! In all honesty I think theres a solid 80% he just removes it. After all im pretty sure the only purpose for the site is to harvest ad revenue since he's not selling the information itself.
Any recommendations from you guys? Im really curious to see if this website is actually not showing up on any whois? Or if im just dumb? Maybe I just dont understand this part enough. What does a URL like this one indicate about the website? What would you guys have done differently, or in addition?
I also would like to kindly ask you all to please not contact this person or try to interfere with my attempts. I really d[...]
___________________________
@hacking_Attack
@Hacking_Video
Been PWNED. My journey through getting my info off of a leaked database.
I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities fell into my lap, and here I am a few years later after never getting back into it.
Nonetheless!
Some account information was leaked in a databreach. Here's the breach:
Warning: Porn Ads. Pop ups. Etc. Run of the mill stuff. https://www.freeaccounts.bi3.shop/p/all-free-account.html
I wont say where my info is on the site for obvious reasons.
Now I admit, ive been aware of that breach for some time now. I wasnt too concerned because the account was very old, and the password that was leaked I only used for random things when I was a student. But a few days ago, a got an email alerting me of a login through my ancient Grammarly account. Low and behold that account used the same login info. I finally got my wisdom teeth pulled, so im taking some time out of the office. I figured this would be a fun project to take on while I swallow Advil like tic tacs. Heres what i've found/done so far:
- Whois search
No luck. I personally dont know whats going on with this URL. But I couldnt find any info on this sucker on any conventional whois websites
- Reporting the website
I tried reporting the website to Google, just because i'd feel a little better if the info was viewable on the most used search engine. They determined it wasn't against their terms. Which...I mean. Yeah whatever.
- Following the yellow brick road
I joined the Discord/Telegram group. Now this was interesting. I found myself in a den of credit card info and all sorts of other scams. It was a bit odd seeing this type of thing outside of TOR, but I digress. I basically just asked the owner to take my stuff down, and he agreed! But heres the tricky part. THIS ISNT HIS WEBSITE. So this website is hosted and maintained (updated almost daily) by somoeone who literally just copies his websites content. So the owner of this Discord/Telegram deleted my info from HIS site, but of course wasnt able to do anything about the ones I was concerned about. What I also found interesting was that this page literally links you to the "legit" shop made by the real owner, where you can buy breached info. Even more interesting was that the "legit" website is brand new. The owners original one was taken down, and so he just published a new one as of 03/07? This guy is an active member.
Anyways, I then noticed this guy literally has his Facebook and Instagram on his website. Hm. They look legit. So I DMed him! (took the "honor among thieves" approach) Sent him a message on Facebook. And now im just waiting for him to see it. Looks like the accounts been dead for nearly a year. But the fact that he's so active with his updates makes me think he'll definitely see it. Whats interesting is that these accounts look personal. He has public accounts, and I believe im looking at this friends and family. I took the liberty of saving all those usernames in a .txt, as they may prove useful should things come down to...social engineering.
And thats where I am the journey now! In all honesty I think theres a solid 80% he just removes it. After all im pretty sure the only purpose for the site is to harvest ad revenue since he's not selling the information itself.
Any recommendations from you guys? Im really curious to see if this website is actually not showing up on any whois? Or if im just dumb? Maybe I just dont understand this part enough. What does a URL like this one indicate about the website? What would you guys have done differently, or in addition?
I also would like to kindly ask you all to please not contact this person or try to interfere with my attempts. I really d[...]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Been PWNED. My journey through getting my info off of a leaked database. I would say im a novice to the hacking community. Ive tinkered with some Wireshark and started dipping my toes into Kali Linux before some other priorities…
ont want him having a change of heart because a few of you excellent fellows threaten to hackermans his life.
Thanks all!
submitted by /u/BangkokianFool [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Thanks all!
submitted by /u/BangkokianFool [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What are the protections placed by attackers to prevent tracking them? How would you mitigate such protection?
submitted by /u/Pranav__472
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What are the protections placed by attackers to prevent tracking them? How would you mitigate such protection?
submitted by /u/Pranav__472
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Tracing Back an Attack
If you hack into a system, or if your system is hacked, how would you track it back? Like what's the info that is used to trace the attacker? What...
Go Language pkg installation issue solved.
https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Go Language pkg installation issue solved.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.Continue reading on Medium » (https://medium.com/@anmolshah1707/go-language-pkg-installation-issue-solved-cfd195f9f5dc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Go Language pkg installation issue solved.
Hello Everyone, My name is Anmol Shah. I am a Penetration Tester and a Security Researcher.
How I Was Able To Wipe Any Registered Account
https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium » (https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium » (https://medium.com/@tobydavenn/how-i-was-able-to-wipe-any-registered-account-3b738afc389?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.
Hacking on Medium
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Cyber Security is hacked everyday. Why is no one talking about it?”
According to an article recently published by CNBC , Samsung data was breached was hacked. Yet, this is only one of the many other articles…
Hacking on Medium
Unique WAF Bypassing Methods…!!!
https://cdn-images-1.medium.com/max/1558/1*HH-0C5nU_MdD2Um-c6xO_g.png
What is WAF…???
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Unique WAF Bypassing Methods…!!!
https://cdn-images-1.medium.com/max/1558/1*HH-0C5nU_MdD2Um-c6xO_g.png
What is WAF…???
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Unique WAF Bypassing Methods…!!!
What is WAF…???
Hacking on Medium
How I created a Trojan Malware — Ethical Hacking
https://cdn-images-1.medium.com/max/700/0*lR2Byi6HLoyxpfln.png
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
How I created a Trojan Malware — Ethical Hacking
https://cdn-images-1.medium.com/max/700/0*lR2Byi6HLoyxpfln.png
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I created a Trojan Malware — Ethical Hacking
Trojan malware, when opened appears to be a legitimate file, but in the background, it will run some evil process like gaining access etc.
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Microsoft has addressed 71 security vulnerabilities in its scheduled March Patch Tuesday update – only three of which are rated critical in severity. The other 68 are all rated “important.”
Three of the bugs are listed as publicly known zero-days, but none of them are listed as having been exploited in the wild (thus far).
The issues affect the gamut of the computing giant’s portfolio, including Microsoft Windows and Windows Components, Azure Site Recovery, Microsoft Defender for Endpoint and IoT, Intune, Edge (Chromium-based), Windows HTML Platforms, Office and Office Components, Skype, .NET and Visual Studio, Windows RDP, SMB Server.
Notably, the tranche also contains the first-ever patch for the Xbox gaming console.
It’s worth noting that the update marks the second month in a row with a surprisingly low number of critical patches; in fact, February’s Patch Tuesday update didn’t list any.
“The number of critical-rated patches is again strangely low for this number of bugs,” Trend Micro Zero-Day Initiative researcher Dustin Childs noted in an email. “It’s unclear if this low percentage of bugs is just a coincidence, or if Microsoft might be evaluating the severity using different calculus than in the past.”
See Also: Complete Offensive Security and Ethical Hacking Course Critical-Rated Microsoft Security BugsThe three critical bugs, all of which could lead to remote code execution, are:
* CVE-2022-22006: HEVC Video Extensions (CVSS rating of 7.8)
* CVE-2022-24501: VP9 Video Extensions (CVSS rating of 7.8)
* CVE-2022-23277: Microsoft Exchange Server (CVSS rating of 8.8)
Both video extensions bugs, in HEVC and VP9, require social engineering; an attacker would need to convince a victim to download and open a specially crafted file, which could lead to a crash, according to Microsoft’s advisory.
The video extensions are coding standards for video compression that Windows is able to run so that users can watch high-fidelity videos. Paul Laudanski, head of threat intelligence at Tessian, noted that the likelihood of compromise is low, thanks to the user-interaction requirement.
That said, the VP9 bug is more crucial for patching, he said: “VP9 is supported by modern day browsers except for Internet Explorer, so it is critical for users to ensure they are updating them. While VP9 is open and royalty free, the other file code affected, HEVC, is one that users have to purchase a license for.”
The vulnerability in Exchange Server meanwhile would allow an authenticated attacker to target server accounts with the aim of executing code with elevated privileges, through a network call. Laudanski added that the vulnerability arises from the server not correctly handling objects in memory, which can lead to code execution.
Here, the attacker must be authenticated. Even so, “this is also listed as low complexity with exploitation more likely, so it wouldn’t surprise me to see this bug exploited in the wild soon,” Childs noted. “Test and deploy this to your Exchange servers quickly.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Kevin Breen, director of cyber-threat research at Immersive Labs, agreed. “While requiring authentication, this vul[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Microsoft has addressed 71 security vulnerabilities in its scheduled March Patch Tuesday update – only three of which are rated critical in severity. The other 68 are all rated “important.”
Three of the bugs are listed as publicly known zero-days, but none of them are listed as having been exploited in the wild (thus far).
The issues affect the gamut of the computing giant’s portfolio, including Microsoft Windows and Windows Components, Azure Site Recovery, Microsoft Defender for Endpoint and IoT, Intune, Edge (Chromium-based), Windows HTML Platforms, Office and Office Components, Skype, .NET and Visual Studio, Windows RDP, SMB Server.
Notably, the tranche also contains the first-ever patch for the Xbox gaming console.
It’s worth noting that the update marks the second month in a row with a surprisingly low number of critical patches; in fact, February’s Patch Tuesday update didn’t list any.
“The number of critical-rated patches is again strangely low for this number of bugs,” Trend Micro Zero-Day Initiative researcher Dustin Childs noted in an email. “It’s unclear if this low percentage of bugs is just a coincidence, or if Microsoft might be evaluating the severity using different calculus than in the past.”
See Also: Complete Offensive Security and Ethical Hacking Course Critical-Rated Microsoft Security BugsThe three critical bugs, all of which could lead to remote code execution, are:
* CVE-2022-22006: HEVC Video Extensions (CVSS rating of 7.8)
* CVE-2022-24501: VP9 Video Extensions (CVSS rating of 7.8)
* CVE-2022-23277: Microsoft Exchange Server (CVSS rating of 8.8)
Both video extensions bugs, in HEVC and VP9, require social engineering; an attacker would need to convince a victim to download and open a specially crafted file, which could lead to a crash, according to Microsoft’s advisory.
The video extensions are coding standards for video compression that Windows is able to run so that users can watch high-fidelity videos. Paul Laudanski, head of threat intelligence at Tessian, noted that the likelihood of compromise is low, thanks to the user-interaction requirement.
That said, the VP9 bug is more crucial for patching, he said: “VP9 is supported by modern day browsers except for Internet Explorer, so it is critical for users to ensure they are updating them. While VP9 is open and royalty free, the other file code affected, HEVC, is one that users have to purchase a license for.”
The vulnerability in Exchange Server meanwhile would allow an authenticated attacker to target server accounts with the aim of executing code with elevated privileges, through a network call. Laudanski added that the vulnerability arises from the server not correctly handling objects in memory, which can lead to code execution.
Here, the attacker must be authenticated. Even so, “this is also listed as low complexity with exploitation more likely, so it wouldn’t surprise me to see this bug exploited in the wild soon,” Childs noted. “Test and deploy this to your Exchange servers quickly.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Kevin Breen, director of cyber-threat research at Immersive Labs, agreed. “While requiring authentication, this vul[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March | Black Hat Ethical Hacking
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29 htt…
nerability affecting on-prem Exchange servers could potentially be used during lateral movement into a part of the environment which presents the opportunity for business email compromise or data theft from email,” he said via email.
Claire Tillis, senior research engineer at Tenable, meanwhile told Threatpost: ” Given the prevalence of attacks against Microsoft Exchange flaws in the past, organizations should apply the available updates immediately.” Publicly Known BugsMeanwhile, the three zero-day issues are:
* CVE-2022-21990 – Remote Desktop Client (CVSS rating of 8.8, allows RCE)
* CVE-2022-24512 – .NET and Visual Studio (CVSS rating of 6.3, allows RCE)
* CVE-2022-24459 – Windows Fax and Scan Service (CVSS rating of 7.8, allows elevation of privilege)
The RDP client issue deserves to be treated as though it was designated critical, Childs said.
“This client-side bug doesn’t have the same punch as server-side-related RDP, but since it’s listed as publicly known, it makes sense to treat this as a critical-rated bug,” he said. “This isn’t as severe as BlueKeep or some of the other RDP server bugs, but it definitely shouldn’t be overlooked.”
With regards to attack vector, a threat actor would need to lure an affected RDP client to connect to a malicious RDP server, which would allow the person to trigger code execution on the targeted client, Childs explained.
Breen pointed out that the bug is one of three RCE bugs affecting RDP included in the advisory; the other two are CVE-2022-23285 (CVSS 8.8) and CVE-2022-24503 (CVSS 5.4).
“With the increase in remote working driving the expansion of the attack surface presented by RDP, a trio of RCE vulnerabilities affecting this protocol should be on security teams’ radar,” Breen said via email. “[They] are a potential concern especially as this infection vector is commonly used by ransomware actors. While exploitation is not trivial, requiring an attacker to set up bespoke infrastructure, it still presents enough of a risk to be a priority.”
The second known RCE bug is much less of a concern, according to Microsoft’s advisory.
“While we cannot rule out the impact to confidentiality, integrity and availability, the ability to exploit this vulnerability by itself is limited,” according to the company. “An attacker would need to combine this with other vulnerabilities to perform an attack.”
Plus, a targeted user would need to be lured to trigger a payload within the application.
Microsoft offered no technical details about the third publicly known bug. See Also: Offensive Security Tool: Scapy Other March Vulnerabilities of InterestResearchers flagged a handful of other issues to patch quickly, including CVE-2022-24508, which exists in the Windows SMBv3 client and server, and which could lead to RCE on Windows 10 version 2004 and newer systems.
“Authentication is required here, but since this affected both clients and servers, an attacker could use this for lateral movement within a network,” Childs explained. “This is another one I would treat as critical and mitigate quickly.”
Breen again agreed, and noted that Microsoft offered additional mitigations.
“Another potential component of lateral movement, remotely executable CVE-2022-24508 in Windows SMB v3, seems to be one to watch out for,” he said. “While successful exploitation requires valid credentials, Microsoft provides advice on limiting SMB traffic in lateral and external connections. While this is a strong step in providing defense in depth, blocking such connections can also have an adverse effect on other tools using these connections, something to be considered in mitigation attempts.”
He also flagged three privilege-escalation vulnerabilities (CVE-2022-23286 in the Windows Cloud Files Mini Filter Driver; CVE-2022-24507 in the Windows Ancillary Function Driver for WinSock; and CVE-2022-23299 in Windows PDEV) as ones to prioritize, since they “c[...]
___________________________
@hacking_Attack
@Hacking_Video
Claire Tillis, senior research engineer at Tenable, meanwhile told Threatpost: ” Given the prevalence of attacks against Microsoft Exchange flaws in the past, organizations should apply the available updates immediately.” Publicly Known BugsMeanwhile, the three zero-day issues are:
* CVE-2022-21990 – Remote Desktop Client (CVSS rating of 8.8, allows RCE)
* CVE-2022-24512 – .NET and Visual Studio (CVSS rating of 6.3, allows RCE)
* CVE-2022-24459 – Windows Fax and Scan Service (CVSS rating of 7.8, allows elevation of privilege)
The RDP client issue deserves to be treated as though it was designated critical, Childs said.
“This client-side bug doesn’t have the same punch as server-side-related RDP, but since it’s listed as publicly known, it makes sense to treat this as a critical-rated bug,” he said. “This isn’t as severe as BlueKeep or some of the other RDP server bugs, but it definitely shouldn’t be overlooked.”
With regards to attack vector, a threat actor would need to lure an affected RDP client to connect to a malicious RDP server, which would allow the person to trigger code execution on the targeted client, Childs explained.
Breen pointed out that the bug is one of three RCE bugs affecting RDP included in the advisory; the other two are CVE-2022-23285 (CVSS 8.8) and CVE-2022-24503 (CVSS 5.4).
“With the increase in remote working driving the expansion of the attack surface presented by RDP, a trio of RCE vulnerabilities affecting this protocol should be on security teams’ radar,” Breen said via email. “[They] are a potential concern especially as this infection vector is commonly used by ransomware actors. While exploitation is not trivial, requiring an attacker to set up bespoke infrastructure, it still presents enough of a risk to be a priority.”
The second known RCE bug is much less of a concern, according to Microsoft’s advisory.
“While we cannot rule out the impact to confidentiality, integrity and availability, the ability to exploit this vulnerability by itself is limited,” according to the company. “An attacker would need to combine this with other vulnerabilities to perform an attack.”
Plus, a targeted user would need to be lured to trigger a payload within the application.
Microsoft offered no technical details about the third publicly known bug. See Also: Offensive Security Tool: Scapy Other March Vulnerabilities of InterestResearchers flagged a handful of other issues to patch quickly, including CVE-2022-24508, which exists in the Windows SMBv3 client and server, and which could lead to RCE on Windows 10 version 2004 and newer systems.
“Authentication is required here, but since this affected both clients and servers, an attacker could use this for lateral movement within a network,” Childs explained. “This is another one I would treat as critical and mitigate quickly.”
Breen again agreed, and noted that Microsoft offered additional mitigations.
“Another potential component of lateral movement, remotely executable CVE-2022-24508 in Windows SMB v3, seems to be one to watch out for,” he said. “While successful exploitation requires valid credentials, Microsoft provides advice on limiting SMB traffic in lateral and external connections. While this is a strong step in providing defense in depth, blocking such connections can also have an adverse effect on other tools using these connections, something to be considered in mitigation attempts.”
He also flagged three privilege-escalation vulnerabilities (CVE-2022-23286 in the Windows Cloud Files Mini Filter Driver; CVE-2022-24507 in the Windows Ancillary Function Driver for WinSock; and CVE-2022-23299 in Windows PDEV) as ones to prioritize, since they “c[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
nerability affecting on-prem Exchange servers could potentially be used during lateral movement into a part of the environment which presents the opportunity for business email compromise or data theft from email,” he said via email. Claire Tillis, senior…
ould form the connective tissue in any multi-stage attack, are marked as more likely to be exploited and also therefore warrant interest. Addressing these will stop a potentially limited incursion becoming more serious.”
And finally, the Xbox bug (CVE-2022-21967) exists in the Xbox Live authentication manager for Windows, and can allow elevation of privilege. It’s notable for its uniqueness.
“This appears to be the first security patch impacting Xbox specifically,” Childs said. “There was an advisory for an inadvertently disclosed Xbox Live certificate back in 2015, but this seems to be the first security-specific update for the device itself.” Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/GettyImages-802535150-1-90x90.jpg Conti ransomware’s internal chats leaked after siding with Russia1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/6469-article-220223-ukraine-body-text-90x90.jpg Data wiper deployed in cyber-attacks targeting Ukrainian systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/T8F9rL5Ub6TRWHtQwsVCK6-1200-80-90x90.jpg Samsung Shattered Encryption on 100M Phones2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/4346-article-220222-airtags-body-text-90x90.jpg AirTag clone bypassed Apple’s tracking-protection features, claims researcher2 weeks ago
The post Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
And finally, the Xbox bug (CVE-2022-21967) exists in the Xbox Live authentication manager for Windows, and can allow elevation of privilege. It’s notable for its uniqueness.
“This appears to be the first security patch impacting Xbox specifically,” Childs said. “There was an advisory for an inadvertently disclosed Xbox Live certificate back in 2015, but this seems to be the first security-specific update for the device itself.” Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/GettyImages-802535150-1-90x90.jpg Conti ransomware’s internal chats leaked after siding with Russia1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/6469-article-220223-ukraine-body-text-90x90.jpg Data wiper deployed in cyber-attacks targeting Ukrainian systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/T8F9rL5Ub6TRWHtQwsVCK6-1200-80-90x90.jpg Samsung Shattered Encryption on 100M Phones2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/4346-article-220222-airtags-body-text-90x90.jpg AirTag clone bypassed Apple’s tracking-protection features, claims researcher2 weeks ago
The post Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
✳️ How to Recover Data From Corrupted OS ➖➖➖➖➖➖➖➖➖➖➖➖➖ ⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
How To Become a Good Hacker? The Fundamental Skills
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
✳️ How to Recover Data From Corrupted OS
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
How To Become a Good Hacker? The Fundamental Skills
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...