Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Microsoft has addressed 71 security vulnerabilities in its scheduled March Patch Tuesday update – only three of which are rated critical in severity. The other 68 are all rated “important.”
Three of the bugs are listed as publicly known zero-days, but none of them are listed as having been exploited in the wild (thus far).
The issues affect the gamut of the computing giant’s portfolio, including Microsoft Windows and Windows Components, Azure Site Recovery, Microsoft Defender for Endpoint and IoT, Intune, Edge (Chromium-based), Windows HTML Platforms, Office and Office Components, Skype, .NET and Visual Studio, Windows RDP, SMB Server.
Notably, the tranche also contains the first-ever patch for the Xbox gaming console.
It’s worth noting that the update marks the second month in a row with a surprisingly low number of critical patches; in fact, February’s Patch Tuesday update didn’t list any.
“The number of critical-rated patches is again strangely low for this number of bugs,” Trend Micro Zero-Day Initiative researcher Dustin Childs noted in an email. “It’s unclear if this low percentage of bugs is just a coincidence, or if Microsoft might be evaluating the severity using different calculus than in the past.”
See Also: Complete Offensive Security and Ethical Hacking Course Critical-Rated Microsoft Security BugsThe three critical bugs, all of which could lead to remote code execution, are:
* CVE-2022-22006: HEVC Video Extensions (CVSS rating of 7.8)
* CVE-2022-24501: VP9 Video Extensions (CVSS rating of 7.8)
* CVE-2022-23277: Microsoft Exchange Server (CVSS rating of 8.8)
Both video extensions bugs, in HEVC and VP9, require social engineering; an attacker would need to convince a victim to download and open a specially crafted file, which could lead to a crash, according to Microsoft’s advisory.
The video extensions are coding standards for video compression that Windows is able to run so that users can watch high-fidelity videos. Paul Laudanski, head of threat intelligence at Tessian, noted that the likelihood of compromise is low, thanks to the user-interaction requirement.
That said, the VP9 bug is more crucial for patching, he said: “VP9 is supported by modern day browsers except for Internet Explorer, so it is critical for users to ensure they are updating them. While VP9 is open and royalty free, the other file code affected, HEVC, is one that users have to purchase a license for.”
The vulnerability in Exchange Server meanwhile would allow an authenticated attacker to target server accounts with the aim of executing code with elevated privileges, through a network call. Laudanski added that the vulnerability arises from the server not correctly handling objects in memory, which can lead to code execution.
Here, the attacker must be authenticated. Even so, “this is also listed as low complexity with exploitation more likely, so it wouldn’t surprise me to see this bug exploited in the wild soon,” Childs noted. “Test and deploy this to your Exchange servers quickly.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Kevin Breen, director of cyber-threat research at Immersive Labs, agreed. “While requiring authentication, this vul[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Microsoft has addressed 71 security vulnerabilities in its scheduled March Patch Tuesday update – only three of which are rated critical in severity. The other 68 are all rated “important.”
Three of the bugs are listed as publicly known zero-days, but none of them are listed as having been exploited in the wild (thus far).
The issues affect the gamut of the computing giant’s portfolio, including Microsoft Windows and Windows Components, Azure Site Recovery, Microsoft Defender for Endpoint and IoT, Intune, Edge (Chromium-based), Windows HTML Platforms, Office and Office Components, Skype, .NET and Visual Studio, Windows RDP, SMB Server.
Notably, the tranche also contains the first-ever patch for the Xbox gaming console.
It’s worth noting that the update marks the second month in a row with a surprisingly low number of critical patches; in fact, February’s Patch Tuesday update didn’t list any.
“The number of critical-rated patches is again strangely low for this number of bugs,” Trend Micro Zero-Day Initiative researcher Dustin Childs noted in an email. “It’s unclear if this low percentage of bugs is just a coincidence, or if Microsoft might be evaluating the severity using different calculus than in the past.”
See Also: Complete Offensive Security and Ethical Hacking Course Critical-Rated Microsoft Security BugsThe three critical bugs, all of which could lead to remote code execution, are:
* CVE-2022-22006: HEVC Video Extensions (CVSS rating of 7.8)
* CVE-2022-24501: VP9 Video Extensions (CVSS rating of 7.8)
* CVE-2022-23277: Microsoft Exchange Server (CVSS rating of 8.8)
Both video extensions bugs, in HEVC and VP9, require social engineering; an attacker would need to convince a victim to download and open a specially crafted file, which could lead to a crash, according to Microsoft’s advisory.
The video extensions are coding standards for video compression that Windows is able to run so that users can watch high-fidelity videos. Paul Laudanski, head of threat intelligence at Tessian, noted that the likelihood of compromise is low, thanks to the user-interaction requirement.
That said, the VP9 bug is more crucial for patching, he said: “VP9 is supported by modern day browsers except for Internet Explorer, so it is critical for users to ensure they are updating them. While VP9 is open and royalty free, the other file code affected, HEVC, is one that users have to purchase a license for.”
The vulnerability in Exchange Server meanwhile would allow an authenticated attacker to target server accounts with the aim of executing code with elevated privileges, through a network call. Laudanski added that the vulnerability arises from the server not correctly handling objects in memory, which can lead to code execution.
Here, the attacker must be authenticated. Even so, “this is also listed as low complexity with exploitation more likely, so it wouldn’t surprise me to see this bug exploited in the wild soon,” Childs noted. “Test and deploy this to your Exchange servers quickly.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Kevin Breen, director of cyber-threat research at Immersive Labs, agreed. “While requiring authentication, this vul[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March | Black Hat Ethical Hacking
Microsoft patched 71 security vulnerabilities in an uncharacteristically light scheduled update, including its first Xbox bug.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for MarchPost Views: 29 htt…
nerability affecting on-prem Exchange servers could potentially be used during lateral movement into a part of the environment which presents the opportunity for business email compromise or data theft from email,” he said via email.
Claire Tillis, senior research engineer at Tenable, meanwhile told Threatpost: ” Given the prevalence of attacks against Microsoft Exchange flaws in the past, organizations should apply the available updates immediately.” Publicly Known BugsMeanwhile, the three zero-day issues are:
* CVE-2022-21990 – Remote Desktop Client (CVSS rating of 8.8, allows RCE)
* CVE-2022-24512 – .NET and Visual Studio (CVSS rating of 6.3, allows RCE)
* CVE-2022-24459 – Windows Fax and Scan Service (CVSS rating of 7.8, allows elevation of privilege)
The RDP client issue deserves to be treated as though it was designated critical, Childs said.
“This client-side bug doesn’t have the same punch as server-side-related RDP, but since it’s listed as publicly known, it makes sense to treat this as a critical-rated bug,” he said. “This isn’t as severe as BlueKeep or some of the other RDP server bugs, but it definitely shouldn’t be overlooked.”
With regards to attack vector, a threat actor would need to lure an affected RDP client to connect to a malicious RDP server, which would allow the person to trigger code execution on the targeted client, Childs explained.
Breen pointed out that the bug is one of three RCE bugs affecting RDP included in the advisory; the other two are CVE-2022-23285 (CVSS 8.8) and CVE-2022-24503 (CVSS 5.4).
“With the increase in remote working driving the expansion of the attack surface presented by RDP, a trio of RCE vulnerabilities affecting this protocol should be on security teams’ radar,” Breen said via email. “[They] are a potential concern especially as this infection vector is commonly used by ransomware actors. While exploitation is not trivial, requiring an attacker to set up bespoke infrastructure, it still presents enough of a risk to be a priority.”
The second known RCE bug is much less of a concern, according to Microsoft’s advisory.
“While we cannot rule out the impact to confidentiality, integrity and availability, the ability to exploit this vulnerability by itself is limited,” according to the company. “An attacker would need to combine this with other vulnerabilities to perform an attack.”
Plus, a targeted user would need to be lured to trigger a payload within the application.
Microsoft offered no technical details about the third publicly known bug. See Also: Offensive Security Tool: Scapy Other March Vulnerabilities of InterestResearchers flagged a handful of other issues to patch quickly, including CVE-2022-24508, which exists in the Windows SMBv3 client and server, and which could lead to RCE on Windows 10 version 2004 and newer systems.
“Authentication is required here, but since this affected both clients and servers, an attacker could use this for lateral movement within a network,” Childs explained. “This is another one I would treat as critical and mitigate quickly.”
Breen again agreed, and noted that Microsoft offered additional mitigations.
“Another potential component of lateral movement, remotely executable CVE-2022-24508 in Windows SMB v3, seems to be one to watch out for,” he said. “While successful exploitation requires valid credentials, Microsoft provides advice on limiting SMB traffic in lateral and external connections. While this is a strong step in providing defense in depth, blocking such connections can also have an adverse effect on other tools using these connections, something to be considered in mitigation attempts.”
He also flagged three privilege-escalation vulnerabilities (CVE-2022-23286 in the Windows Cloud Files Mini Filter Driver; CVE-2022-24507 in the Windows Ancillary Function Driver for WinSock; and CVE-2022-23299 in Windows PDEV) as ones to prioritize, since they “c[...]
___________________________
@hacking_Attack
@Hacking_Video
Claire Tillis, senior research engineer at Tenable, meanwhile told Threatpost: ” Given the prevalence of attacks against Microsoft Exchange flaws in the past, organizations should apply the available updates immediately.” Publicly Known BugsMeanwhile, the three zero-day issues are:
* CVE-2022-21990 – Remote Desktop Client (CVSS rating of 8.8, allows RCE)
* CVE-2022-24512 – .NET and Visual Studio (CVSS rating of 6.3, allows RCE)
* CVE-2022-24459 – Windows Fax and Scan Service (CVSS rating of 7.8, allows elevation of privilege)
The RDP client issue deserves to be treated as though it was designated critical, Childs said.
“This client-side bug doesn’t have the same punch as server-side-related RDP, but since it’s listed as publicly known, it makes sense to treat this as a critical-rated bug,” he said. “This isn’t as severe as BlueKeep or some of the other RDP server bugs, but it definitely shouldn’t be overlooked.”
With regards to attack vector, a threat actor would need to lure an affected RDP client to connect to a malicious RDP server, which would allow the person to trigger code execution on the targeted client, Childs explained.
Breen pointed out that the bug is one of three RCE bugs affecting RDP included in the advisory; the other two are CVE-2022-23285 (CVSS 8.8) and CVE-2022-24503 (CVSS 5.4).
“With the increase in remote working driving the expansion of the attack surface presented by RDP, a trio of RCE vulnerabilities affecting this protocol should be on security teams’ radar,” Breen said via email. “[They] are a potential concern especially as this infection vector is commonly used by ransomware actors. While exploitation is not trivial, requiring an attacker to set up bespoke infrastructure, it still presents enough of a risk to be a priority.”
The second known RCE bug is much less of a concern, according to Microsoft’s advisory.
“While we cannot rule out the impact to confidentiality, integrity and availability, the ability to exploit this vulnerability by itself is limited,” according to the company. “An attacker would need to combine this with other vulnerabilities to perform an attack.”
Plus, a targeted user would need to be lured to trigger a payload within the application.
Microsoft offered no technical details about the third publicly known bug. See Also: Offensive Security Tool: Scapy Other March Vulnerabilities of InterestResearchers flagged a handful of other issues to patch quickly, including CVE-2022-24508, which exists in the Windows SMBv3 client and server, and which could lead to RCE on Windows 10 version 2004 and newer systems.
“Authentication is required here, but since this affected both clients and servers, an attacker could use this for lateral movement within a network,” Childs explained. “This is another one I would treat as critical and mitigate quickly.”
Breen again agreed, and noted that Microsoft offered additional mitigations.
“Another potential component of lateral movement, remotely executable CVE-2022-24508 in Windows SMB v3, seems to be one to watch out for,” he said. “While successful exploitation requires valid credentials, Microsoft provides advice on limiting SMB traffic in lateral and external connections. While this is a strong step in providing defense in depth, blocking such connections can also have an adverse effect on other tools using these connections, something to be considered in mitigation attempts.”
He also flagged three privilege-escalation vulnerabilities (CVE-2022-23286 in the Windows Cloud Files Mini Filter Driver; CVE-2022-24507 in the Windows Ancillary Function Driver for WinSock; and CVE-2022-23299 in Windows PDEV) as ones to prioritize, since they “c[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
nerability affecting on-prem Exchange servers could potentially be used during lateral movement into a part of the environment which presents the opportunity for business email compromise or data theft from email,” he said via email. Claire Tillis, senior…
ould form the connective tissue in any multi-stage attack, are marked as more likely to be exploited and also therefore warrant interest. Addressing these will stop a potentially limited incursion becoming more serious.”
And finally, the Xbox bug (CVE-2022-21967) exists in the Xbox Live authentication manager for Windows, and can allow elevation of privilege. It’s notable for its uniqueness.
“This appears to be the first security patch impacting Xbox specifically,” Childs said. “There was an advisory for an inadvertently disclosed Xbox Live certificate back in 2015, but this seems to be the first security-specific update for the device itself.” Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/GettyImages-802535150-1-90x90.jpg Conti ransomware’s internal chats leaked after siding with Russia1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/6469-article-220223-ukraine-body-text-90x90.jpg Data wiper deployed in cyber-attacks targeting Ukrainian systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/T8F9rL5Ub6TRWHtQwsVCK6-1200-80-90x90.jpg Samsung Shattered Encryption on 100M Phones2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/4346-article-220222-airtags-body-text-90x90.jpg AirTag clone bypassed Apple’s tracking-protection features, claims researcher2 weeks ago
The post Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
And finally, the Xbox bug (CVE-2022-21967) exists in the Xbox Live authentication manager for Windows, and can allow elevation of privilege. It’s notable for its uniqueness.
“This appears to be the first security patch impacting Xbox specifically,” Childs said. “There was an advisory for an inadvertently disclosed Xbox Live certificate back in 2015, but this seems to be the first security-specific update for the device itself.” Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/GettyImages-802535150-1-90x90.jpg Conti ransomware’s internal chats leaked after siding with Russia1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/6469-article-220223-ukraine-body-text-90x90.jpg Data wiper deployed in cyber-attacks targeting Ukrainian systems2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/T8F9rL5Ub6TRWHtQwsVCK6-1200-80-90x90.jpg Samsung Shattered Encryption on 100M Phones2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/4346-article-220222-airtags-body-text-90x90.jpg AirTag clone bypassed Apple’s tracking-protection features, claims researcher2 weeks ago
The post Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
✳️ How to Recover Data From Corrupted OS ➖➖➖➖➖➖➖➖➖➖➖➖➖ ⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
How To Become a Good Hacker? The Fundamental Skills
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
How I Was Able To Wipe Any Registered Account
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
Hello, this is my first write up on medium, but I felt I had to share due to the unusualness of this vulnerability.Continue reading on Medium »
Read more...
✳️ How to Recover Data From Corrupted OS
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium »
Read more...
How To Become a Good Hacker? The Fundamental Skills
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium »
Read more...
Geowifi - Search WiFi Geolocation Data By BSSID And SSID On Different Public Databases
Search WiFi geolocation data by BSSID and SSID on different public databases. Databases: Wigle Apple OpenWifi Milnikov Prerequisites Python3. In order to display emojis on Windows, it is recommended to install the new Windows terminal. ⚠️ In order to use the Wigle service it is necessary to obtain an API and configure the utils/API.yaml file replacing the value of the "wigle_auth" parameter for the "Encoded for use" data provided by Wigle. This is necessary for searching by SSID. Installation Use the package manager pip to install requirements. python3 -m pip install -r requirements.txt Usage usage: geowifi.py -h (-s SSID | -b BSSID) -j -moptional arguments: -h, --help Show this help message and exit -s SSID, --ssid SSID Search by SSID -b BSSID, --bssid BSSID Search by BSSID -j, --json Json output -m, --map Map output Search by BSSID: python3 geowifi.py -b BSSID Search by SSID: python3 geowifi.py -s SSID It is possible to export the results in json format using the -j parameter and show the locations on html map using -m. ️ Map output example Json output example { "data":{ "bssid":"A0:XX:XX:XX:6F:90", "vendor":"TP-LINK TECHNOLOGIES CO.,LTD.", "mac_type":"MA-L", "wigle":{ "lat":00.000908922099, "lon":00.000945220028 }, "apple":{ "lat":"not_found", "lon":"not_found" }, "openwifi":{ "lat":00.000808900099, "lon":00.000845500028 }, "milnikov":{ "lat":"not_found", "lon":"not_found" } }} Mentions This project uses some of the research and code used at iSniff-GPS. Thanks to Micah Hoffman for his attention and answers to my questions. Thanks to kennbro for lending me his scrupulous eyes to give me feedback. Download Geowifi
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Search WiFi geolocation data by BSSID and SSID on different public databases. Databases: Wigle Apple OpenWifi Milnikov Prerequisites Python3. In order to display emojis on Windows, it is recommended to install the new Windows terminal. ⚠️ In order to use the Wigle service it is necessary to obtain an API and configure the utils/API.yaml file replacing the value of the "wigle_auth" parameter for the "Encoded for use" data provided by Wigle. This is necessary for searching by SSID. Installation Use the package manager pip to install requirements. python3 -m pip install -r requirements.txt Usage usage: geowifi.py -h (-s SSID | -b BSSID) -j -moptional arguments: -h, --help Show this help message and exit -s SSID, --ssid SSID Search by SSID -b BSSID, --bssid BSSID Search by BSSID -j, --json Json output -m, --map Map output Search by BSSID: python3 geowifi.py -b BSSID Search by SSID: python3 geowifi.py -s SSID It is possible to export the results in json format using the -j parameter and show the locations on html map using -m. ️ Map output example Json output example { "data":{ "bssid":"A0:XX:XX:XX:6F:90", "vendor":"TP-LINK TECHNOLOGIES CO.,LTD.", "mac_type":"MA-L", "wigle":{ "lat":00.000908922099, "lon":00.000945220028 }, "apple":{ "lat":"not_found", "lon":"not_found" }, "openwifi":{ "lat":00.000808900099, "lon":00.000845500028 }, "milnikov":{ "lat":"not_found", "lon":"not_found" } }} Mentions This project uses some of the research and code used at iSniff-GPS. Thanks to Micah Hoffman for his attention and answers to my questions. Thanks to kennbro for lending me his scrupulous eyes to give me feedback. Download Geowifi
Read more...
___________________________
@hacking_Attack
@Hacking_Video
How To Become a Good Hacker? The Fundamental Skills
https://aravindnotes.medium.com/how-to-become-a-good-hacker-the-fundamental-skills-f5e0b8bbbfc?source=rss------bug_bounty-5
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium » (https://aravindnotes.medium.com/how-to-become-a-good-hacker-the-fundamental-skills-f5e0b8bbbfc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://aravindnotes.medium.com/how-to-become-a-good-hacker-the-fundamental-skills-f5e0b8bbbfc?source=rss------bug_bounty-5
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…Continue reading on Medium » (https://aravindnotes.medium.com/how-to-become-a-good-hacker-the-fundamental-skills-f5e0b8bbbfc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
🔰 How To Become a Good Hacker? 🔰 The Fundamental Skills
These are the basics that every hacker should know before even trying to hack. Once you have a good grasp on everything in this section…
✳️ How to Recover Data From Corrupted OS
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
https://aravindnotes.medium.com/%EF%B8%8F-how-to-recover-data-from-corrupted-os-we-are-going-to-use-easeus-data-dfd7883118ba?source=rss------bug_bounty-5
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium » (https://aravindnotes.medium.com/%EF%B8%8F-how-to-recover-data-from-corrupted-os-we-are-going-to-use-easeus-data-dfd7883118ba?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
➖➖➖➖➖➖➖➖➖➖➖➖➖
⚜ We are going to use EaseUS data recovery…
https://aravindnotes.medium.com/%EF%B8%8F-how-to-recover-data-from-corrupted-os-we-are-going-to-use-easeus-data-dfd7883118ba?source=rss------bug_bounty-5
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…Continue reading on Medium » (https://aravindnotes.medium.com/%EF%B8%8F-how-to-recover-data-from-corrupted-os-we-are-going-to-use-easeus-data-dfd7883118ba?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
✳️ How to Recover Data From Corrupted OS ➖➖➖➖➖➖➖➖➖➖➖➖➖ ⚜ We are going to use EaseUS data recovery…
🔹Step 1: First of all, launch EaseUS data recovery on a working computer. Select ‘USB Drive’ from the list and click on ‘Proceed’. Wait…
Geowifi - Search WiFi Geolocation Data By BSSID And SSID On Different Public Databases
http://www.kitploit.com/2022/03/geowifi-search-wifi-geolocation-data-by.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/geowifi-search-wifi-geolocation-data-by.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Search WiFi geolocation (https://www.kitploit.com/search/label/Geolocation) data by BSSID and SSID on different public databases.
Databases: Wigle (https://wigle.net/) Apple OpenWifi (https://openwifi.su/) Milnikov (https://www.mylnikov.org/)
Prerequisites Python3 (https://www.python.org/download/releases/3.0/). In order to display emojis on Windows, it is recommended to install the new (https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk701)Windows (https://www.kitploit.com/search/label/Windows) terminal. ⚠️ In order to use the Wigle service it is necessary to obtain an API (https://api.wigle.net/) and configure the utils/API.yaml file replacing the value of the "wigle_auth" parameter for the "Encoded for use" data provided by Wigle (https://wigle.net/account). This is necessary for searching by SSID.
Installation Use the package manager pip (https://pip.pypa.io/en/stable/) to install requirements. python3 -m pip install -r requirements.txt
Usage usage: geowifi.py [-h] (-s SSID | -b BSSID) [-j] [-m]
optional arguments:
-h, --help Show this help message and exit
-s SSID, --ssid SSID Search by SSID
-b BSSID, --bssid BSSID Search by BSSID
-j, --json Json output
-m, --map Map output
Search by BSSID: python3 geowifi.py -b BSSID
Search by SSID: python3 geowifi.py -s SSID
It is possible to export the results in json (https://www.kitploit.com/search/label/JSON) format using the -j parameter and show the locations on html map using -m. ️ Map output example
___________________________
@hacking_Attack
@Hacking_Video
Databases: Wigle (https://wigle.net/) Apple OpenWifi (https://openwifi.su/) Milnikov (https://www.mylnikov.org/)
Prerequisites Python3 (https://www.python.org/download/releases/3.0/). In order to display emojis on Windows, it is recommended to install the new (https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk701)Windows (https://www.kitploit.com/search/label/Windows) terminal. ⚠️ In order to use the Wigle service it is necessary to obtain an API (https://api.wigle.net/) and configure the utils/API.yaml file replacing the value of the "wigle_auth" parameter for the "Encoded for use" data provided by Wigle (https://wigle.net/account). This is necessary for searching by SSID.
Installation Use the package manager pip (https://pip.pypa.io/en/stable/) to install requirements. python3 -m pip install -r requirements.txt
Usage usage: geowifi.py [-h] (-s SSID | -b BSSID) [-j] [-m]
optional arguments:
-h, --help Show this help message and exit
-s SSID, --ssid SSID Search by SSID
-b BSSID, --bssid BSSID Search by BSSID
-j, --json Json output
-m, --map Map output
Search by BSSID: python3 geowifi.py -b BSSID
Search by SSID: python3 geowifi.py -s SSID
It is possible to export the results in json (https://www.kitploit.com/search/label/JSON) format using the -j parameter and show the locations on html map using -m. ️ Map output example
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Json output example {
"data":{
"bssid":"A0:XX:XX:XX:6F:90",
"vendor":"TP-LINK TECHNOLOGIES CO.,LTD.",
"mac_type":"MA-L",
"wigle":{
"lat":00.000908922099,
"lon":00.000945220028
},
"apple":{
"lat":"not_found",
"lon":"not_found"
},
"openwifi":{
"lat":00.000808900099,
"lon":00.000845500028
},
"milnikov":{
"lat":"not_found",
"lon":"not_found"
}
}
}
Mentions This project uses some of the research (https://www.kitploit.com/search/label/Research) and code used at iSniff-GPS (https://github.com/hubert3/iSniff-GPS). Thanks to Micah Hoffman (https://twitter.com/WebBreacher) for his attention and answers to my questions. Thanks to kennbro (https://twitter.com/kennbroorg) for lending me his scrupulous eyes to give me feedback.
Download Geowifi (https://github.com/GONZOsint/geowifi)
___________________________
@hacking_Attack
@Hacking_Video
"data":{
"bssid":"A0:XX:XX:XX:6F:90",
"vendor":"TP-LINK TECHNOLOGIES CO.,LTD.",
"mac_type":"MA-L",
"wigle":{
"lat":00.000908922099,
"lon":00.000945220028
},
"apple":{
"lat":"not_found",
"lon":"not_found"
},
"openwifi":{
"lat":00.000808900099,
"lon":00.000845500028
},
"milnikov":{
"lat":"not_found",
"lon":"not_found"
}
}
}
Mentions This project uses some of the research (https://www.kitploit.com/search/label/Research) and code used at iSniff-GPS (https://github.com/hubert3/iSniff-GPS). Thanks to Micah Hoffman (https://twitter.com/WebBreacher) for his attention and answers to my questions. Thanks to kennbro (https://twitter.com/kennbroorg) for lending me his scrupulous eyes to give me feedback.
Download Geowifi (https://github.com/GONZOsint/geowifi)
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Kali Linux Tutorials
Pip-Audit : Audits Python Environments And Dependency Trees For Known Vulnerabilities
___________________________
@hacking_Attack
@Hacking_Video
Pip-Audit : Audits Python Environments And Dependency Trees For Known Vulnerabilities
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Pip-Audit : Audits Python Environments And Dependency Trees
pip-audit is a tool for scanning Python environments for packages with known vulnerabilities. It uses the Python Packaging Advisory Database.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
goCabrito : Super Organized And Flexible Script For Sending Phishing Campaigns
goCabrito is a super organized and flexible script for sending phishing campaigns. Features
* Sends to a single email
* Sends to lists of emails (text)
* Sends to lists emails with first, last name (csv)
* Supports attachments
* Splits emails in groups
* Delays sending emails between each group
* Support Tags to be placed and replaced in the message’s body
* Add {{name}} tag into the HTML message to be replaced with name (used with –to CSV).
* Add {{track-click}} tag to URL in the HTML message.
* Add {{track-open}} tag into the HTML message.
* Add {{num}} tag to be replaced with a random phone number.
* Supports individual profiles for different campaigns to avoid mistakes and confusion.
* Supports creating database for sent emails, each email with its unique hash (useful with getCabrito)
* Supports dry test, to run the script against your profile without sending the email to test your campaign before the launch.
Prerequisites
Install gems’ dependencies
sudo apt-get install build-essential libsqlite3-dev
Install gems
gem install mail sqlite3
Usage
goCabrito.rb — A simple yet flexible email sender.
Help menu:
-s, –server HOST:PORT SMTP server and its port.
e.g. smtp.office365.com:587
-u, –user USER Username to authenticate.
e.g. user@domain.com
-p, –pass PASS Password to authenticate
-f, –from EMAIL Sender’s email (mostly the same as sender email)
e.g. user@domain.com
-t, –to EMAIL|LIST|CSV The receiver’s email or a file list of receivers.
e.g. user@domain.com or targets.lst or targets.csv
The csv expected to be in fname,lname,email format without header.
-c, –copy EMAIL|LIST|CSV The CC’ed receiver’s email or a file list of receivers.
-b, –bcopy EMAIL|LIST|CSV The BCC’ed receiver’s email or a file list of receivers.
-B, –body MSG|FILE The mail’s body string or a file contains the body (not attachements.)
For click and message opening and other trackings:
Add {{track-click}} tag to URL in the HTML message.
eg: http://phisher.com/file.exe/{{track-click}}
Add {{track-open}} tag into the HTML message.
eg:Hi{{track-open}}
Add {{name}} tag into the HTML message to be replaced with name (used with –to CSV).
eg:Dear {{name}},
Add {{num}} tag to be replaced with a random phone number.
-a, –attachments FILE1,FILE2 One or more files to be attached seperated by comma.
-S, –subject TITLE The mail subject/title.
–no-ssl Do NOT use SSL connect when connect to the server (default: false).
-g, –groups NUM Number of receivers to send mail to at once. (default all in one group)
-d, –delay NUM The delay, in seconds, to wait after sending each group.
-P, –profile FILE A json file contains all the the above settings in a file
-D, –db FILE Create a sqlite database file (contains emails & its tracking hashes) to be imported by ‘getCabrito’ server.
–dry Dry test, no actual email sending.
-h, –help Show this message.
Usage:
goCabrito.rb
Examples:
$goCabrito.rb -s smtp.office365.com:587 -u user1@domain.com -p P@ssword1 \
-f user1@domain.com -t targets1.csv -c targets2.lst -b targets3.lst \
-B msg.html -S “This’s title” -a file1.docx,file2.xlsx -g 3 -d 10
$goCabrito.rb –profile prf.json
How you really use it?
* I create directory for each customer
* Under the customer’s directory, I create a directory for each campaign. This sub directory contains
* The profile
* The To, CC & BCC lists in CSV format
* The message body in HTML format
* I configure the profile and prepare my HTML
* Execute the campaign profile in
ruby goCabrito.rb -P CUSTOMER/3/camp3.json –dry
* I remove the
* Send to a test email
* Send to t[...]
___________________________
@hacking_Attack
@Hacking_Video
goCabrito : Super Organized And Flexible Script For Sending Phishing Campaigns
goCabrito is a super organized and flexible script for sending phishing campaigns. Features
* Sends to a single email
* Sends to lists of emails (text)
* Sends to lists emails with first, last name (csv)
* Supports attachments
* Splits emails in groups
* Delays sending emails between each group
* Support Tags to be placed and replaced in the message’s body
* Add {{name}} tag into the HTML message to be replaced with name (used with –to CSV).
* Add {{track-click}} tag to URL in the HTML message.
* Add {{track-open}} tag into the HTML message.
* Add {{num}} tag to be replaced with a random phone number.
* Supports individual profiles for different campaigns to avoid mistakes and confusion.
* Supports creating database for sent emails, each email with its unique hash (useful with getCabrito)
* Supports dry test, to run the script against your profile without sending the email to test your campaign before the launch.
Prerequisites
Install gems’ dependencies
sudo apt-get install build-essential libsqlite3-dev
Install gems
gem install mail sqlite3
Usage
goCabrito.rb — A simple yet flexible email sender.
Help menu:
-s, –server HOST:PORT SMTP server and its port.
e.g. smtp.office365.com:587
-u, –user USER Username to authenticate.
e.g. user@domain.com
-p, –pass PASS Password to authenticate
-f, –from EMAIL Sender’s email (mostly the same as sender email)
e.g. user@domain.com
-t, –to EMAIL|LIST|CSV The receiver’s email or a file list of receivers.
e.g. user@domain.com or targets.lst or targets.csv
The csv expected to be in fname,lname,email format without header.
-c, –copy EMAIL|LIST|CSV The CC’ed receiver’s email or a file list of receivers.
-b, –bcopy EMAIL|LIST|CSV The BCC’ed receiver’s email or a file list of receivers.
-B, –body MSG|FILE The mail’s body string or a file contains the body (not attachements.)
For click and message opening and other trackings:
Add {{track-click}} tag to URL in the HTML message.
eg: http://phisher.com/file.exe/{{track-click}}
Add {{track-open}} tag into the HTML message.
eg:Hi{{track-open}}
Add {{name}} tag into the HTML message to be replaced with name (used with –to CSV).
eg:Dear {{name}},
Add {{num}} tag to be replaced with a random phone number.
-a, –attachments FILE1,FILE2 One or more files to be attached seperated by comma.
-S, –subject TITLE The mail subject/title.
–no-ssl Do NOT use SSL connect when connect to the server (default: false).
-g, –groups NUM Number of receivers to send mail to at once. (default all in one group)
-d, –delay NUM The delay, in seconds, to wait after sending each group.
-P, –profile FILE A json file contains all the the above settings in a file
-D, –db FILE Create a sqlite database file (contains emails & its tracking hashes) to be imported by ‘getCabrito’ server.
–dry Dry test, no actual email sending.
-h, –help Show this message.
Usage:
goCabrito.rb
Examples:
$goCabrito.rb -s smtp.office365.com:587 -u user1@domain.com -p P@ssword1 \
-f user1@domain.com -t targets1.csv -c targets2.lst -b targets3.lst \
-B msg.html -S “This’s title” -a file1.docx,file2.xlsx -g 3 -d 10
$goCabrito.rb –profile prf.json
How you really use it?
* I create directory for each customer
* Under the customer’s directory, I create a directory for each campaign. This sub directory contains
* The profile
* The To, CC & BCC lists in CSV format
* The message body in HTML format
* I configure the profile and prepare my HTML
* Execute the campaign profile in
drymode first (check the profile file dryvalue)ruby goCabrito.rb -P CUSTOMER/3/camp3.json –dry
* I remove the
--dryswitch and make sure the dryvalue is falsein the config file* Send to a test email
* Send to t[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
goCabrito : Super Organized And Flexible Script For Sending Phishing
goCabrito is a super organized and flexible script for sending phishing campaigns. Sends to a single email.