Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
How to install metasploitable 2 on UTM ?

I have an M1 mac and am learning kali. My research told me metasploitable 2 is a must for noobs like me but I am unable to run it on UTM. Any help will be appriciated.

(ik parallels is best but due to the pricing, it is way too expensive in my currency)

thanks

submitted by /u/DJ_Bhadwa
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any lists of Russian servers ?

We've at this point all seen the scripts that runs ddos on various russian servers. However those are all behind cloudflare.
The only efficient attack would be to hit the servers behind the cloudflare. Have anyone gotten any lists of them ? Or do I need to start doing detective work myself ?

submitted by /u/Kriss3d
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
How Did I Leak 5.2k Customer Data From a Large Company? (via Broken Access Control)

Hello everyone!
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Raccoon Stealer Crawls Into Telegram

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Raccoon Stealer Crawls Into TelegramPost Views: 51
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
A credential stealer, Raccoon Stealer,  the first to rose to popularity a couple of years ago is now abusing Telegram for command-and-control (C2).
A range of cybercriminals continue to widen its attack surface through creative distribution means like this, researchers have reported. Raccoon Stealer, which first appeared on the scene in April 2019, has added the ability to store and update its own actual C2 addresses on Telegram’s infrastructure, according to a blog post published by Avast Threat Labs this week. This gives them a “convenient and reliable” command center on the platform that they can update on the fly, researchers said.

The malware – believed to be developed and maintained by Russia-affiliated cybercriminals – is at its core a credential stealer but is capable of a range of nefarious activity. It can steal not only passwords but also cookies, saved logins and forms data from browsers, login credentials from email clients and messengers, files from crypto wallets, data from browser plugins and extensions, and arbitrary files, based on commands from its C2.

“In addition, it’s able to download and execute arbitrary files by command from its C2,” Avast Threat Labs researcher Vladimir Martyanov wrote in the post. This, in combination with active development and promotion on underground forums, makes Raccoon Stealer “prevalent and dangerous,” he said.

Upon its release in 2019, cybercriminals quickly adopted the malware because of its user-friendly malware-as-a-service (MaaS) model, which has given them a quick and easy way to make money by stealing sensitive data.
See Also: Complete Offensive Security and Ethical Hacking Course Creative DistributionEarly on, attackers were seen delivering Raccoon Stealer via an .IMG file hosted on a hacker-controlled Dropbox account in business email compromise (BEC) campaigns that targeted financial institutions and other organizations.

More recently, Avast Threat Labs researchers observed a number of new and creative ways attackers are distributing Raccoon Stealer, Martyanov said.

“Taking into account that Raccoon Stealer is for sale, its distribution techniques are limited only by the imagination of the end buyers,” he wrote.

In addition to being spread by two loaders – Buer Loader and GCleaner – attackers also are distributing Raccoon Stealer via fake game cheats, patches for cracked software – including hacks and mods for Fortnite, Valorant and NBA2K22 – or other software, Martyanov wrote.

Cybercriminals also are taking care to try to evade detection by packing the credential stealer, using Themida or malware packers, with some samples observed being packed more than five times in a row with the same packer, he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Abusing C2 in TelegramThe report detailed how the latest version of Raccoon Stealer communicates with C2 within Telegram: There are four “crucial” values for its C2 communication, which are hardcoded in every Raccoon Stealer sample, according to the post. They are:

* -MAIN_KEY, which has been changed four times during the year;
* -URLs of Telegram gates with a channel name;
* -BotID, a hexadecimal string, sent to the C2 every time; and
* -TELEGRAM_KEY, a key to decrypt the C2 address obtained from Telegram Gate.

To hijack Telegram for its C2, the malware first decrypts MAIN_KEY, which it uses to decrypt Tele[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Raccoon Stealer Crawls Into Telegram https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Raccoon Stealer Crawls Into TelegramPost Views: 51 https://www.blackhatethicalhacking.com/wp-content…
gram gates URLs and BotID. The stealer then uses Telegram gate to get to its real C2 using a string of queries that eventually allow it to use the Telegram infrastructure to store and update actual C2 addresses, Martyanov wrote.

By downloading and executing arbitrary files from a command from C2, the stealer also is able to distribute malware. Avast Threat Labs collected about 185 files, with a total size of 265 megabytes – including downloaders, clipboard crypto stealers and the WhiteBlackCrypt ransomware – that were being distributed by Raccoon Stealer. Avoiding Russian EntitiesOnce executed, Racoon Stealer starts checking for the default user locale set on the infected device and won’t work if it’s one of the following: Russian, Ukrainian, Belarusian, Kazakh, Kyrgyz, Armenian, Tajik or Uzbek. This is likely because the developers themselves are Russian, researchers believe.

However, Avast Threat Labs found that in recent activity, “the country where we have blocked the most attempts is Russia, which is interesting because the actors behind the malware don’t want to infect computers in Russia or Central Asia,” Martyanov wrote.

This could be because “the attacks spray and pray, distributing the malware around the world,” he noted. The malware doesn’t check for the location of the user until it actually reaches a device; if it finds that the device is located in a region developers don’t want to target, it won’t run. See Also: Offensive Security Tool: Fibratus “This explains why we detected so many attack attempts in Russia; we block the malware before it can run, i.e. before it can even get to the stage where it checks for the device’s locale,” Martyanov wrote. “If an unprotected device that comes across the malware with its locale set to English or any other language that is not on the exception list but is in Russia, it would still become infected.”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/NINTCHDBPICT000622539771-90x90.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’2 weeks ago
* https://www.blackhatethicalhacking.com[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
gram gates URLs and BotID. The stealer then uses Telegram gate to get to its real C2 using a string of queries that eventually allow it to use the Telegram infrastructure to store and update actual C2 addresses, Martyanov wrote. By downloading and executing…
/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/download-90x90.jpg Cyber-attack on Nvidia linked to Lapsus$ ransomware gang2 weeks ago
The post Raccoon Stealer Crawls Into Telegram first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
CodeAnalysis - Static Code Analysis

Tencent Cloud Code Analysis (TCA for short, code-named CodeDog inside the company early) is a comprehensive platform for code analysis and issue tracking. TCA consist of three components, server, web and client. It also supports the integration of other code analysis tools. Code analysis is a technology, using lexical analysis, syntax analysis, control-flow analysis, data-flow analysis to make a comprehensive analysis of the code, so as to verify whether the code meets the requirements of normative, security, reliability, maintainability and other indicators. Using TCA can help team find normative, structural, security vulnerabilities and other issues in the code, continuously monitor the quality of the project code and issue alerts. At the same time, TCA opens up APIs to support connection with upstream and downstream systems, so as to integrate code analysis capabilities, ensure code quality, and be more conducive to inheriting an excellent team code culture. Experience Apply Link Key Features Language support: It supports Java/C++/Objective-C/C#/JavaScript/Python/Go/PHP and more, covering common programming languages. Code inspection: Discover code quality defects, code specification problems, code security vulnerabilities, invalid codes, etc. At present, many self-developed and well-known open source analysis tools have been integrated. The layered architecture can support rapid self-service management tools for teams. Code measurement: Support comprehensive measurement of code from the three dimensions of code cyclomatic complexity, code repetition rate and code statistics. DevOps integration: The client can be started via the command line. Standard APIs support connection to upstream and downstream systems, and various DevOps systems. Getting Started How to get start How to deploy server and web How to deploy server and web with docker-compose How to use client Deploy Q&A Community QQ Group: 361791391 Discussion Wiki White Paper Changelogs Check our Changelog Contributing Check out CONTRIBUTING to see how to develop with TCA. Tencent Open Source Incentive Program encourages the participation and contribution of developers. We look forward to your active participation. License TCA is MIT licensed Download CodeAnalysis
Read more...

___________________________
@hacking_Attack
@Hacking_Video
How I Made The BBC Hall Of Fame 3 Times

Happy Monday to anyone reading this write up. Today I am going to describe how I was able to make the BBC Hall Of Fame 3 times. My…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Mininode : A CLI Tool To Reduce The Attack Surface Of The Node.js Applications By Using Static Analysis

Mininode is a CLI tool to reduce the attack surface of the Node.js applications by using static analysis of source code. It supports two modes of reduction (1) coarse, (2) fine.

Mininode constructs the dependency graph (modules and functions used) of the application starting from main file, i.e. entry point of the application. Mininode initializes entry point to package.jsonfile’s mainfield if it exists. Otherwise default to index.js.

Example usage: node index.js . Below is the list of options that can be passed to Mininode.

Options

List of command line options that can be passed to mininode.

* --destination, -d: the path where mininode will save the reduced Node.js application. The default value: mininode.
* --dry-run: just generates mininode.json without modifying the initial application.
* --mode, -m: reduction mode. The value can be either coarseor fine. In coarsemode mininode will perform only coarse-grained reduction. While in finemode mininode will perform fine-grained reduction. In general coarse-grained reduction is more reliable, because mininode will not try to reduce unused functions inside the module. Default value: coarse.
* --silent: console output is disabled. This will improve the performance of the mininode.
* --verbose: outputs additional information to the console. The default value: false
* --log: mininode will generate log file inside, which contains dependency graph of the application in json format. The default value: true.
* --log-output: the name of the log file generated by mininode. The default value: mininode.json.
* --compress-log: compresses the final log file. By default it will dump everything into log file. In production it is advised to pass the --compress-logflag to save space.
* --seeds: seed files from where mininode will start building dependency graph. You can provide many seed files by separating them with colon.
* --skip-stat: skips calculating the statistics
* --skip-reduction: if passed mininode will not reduce the JavaScript files. The default value: false.
* --skip-remove: if passed mininode will not remove unused JavaScript files. The default value: false.

Limitaions

* Mininode uses static analysis, which means it can not reduce the attack surface of the Node.js application which uses dynamic behaviour, such as eval. If Mininode detects dynamic behaviour in the application it exits with error DYNAMIC_BEHAVOUR_DETECTED.
Download

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CRT : CrowdStrike Reporting Tool for Azure

CRT is a tool to queries the following configurations in the Azure AD/O365 tenant which can shed light on hard-to-find permissions and configuration settings in order to assist organizations in securing these environments.

Exchange Online (O365):

* Federation Configuration
* Federation Trust
* Client Access Settings Configured on Mailboxes
* Mail Forwarding Rules for Remote Domains
* Mailbox SMTP Forwarding Rules
* Mail Transport Rules
* Delegates with ‘Full Access’ Permission Granted
* Delegates with Any Permissions Granted
* Delegates with ‘Send As’ or ‘SendOnBehalf’ Permissions
* Exchange Online PowerShell Enabled Users
* Users with ‘Audit Bypass’ Enabled
* Mailboxes Hidden from the Global Address List (GAL)
* Collect administrator audit logging configuration settings.

Azure AD:

* Service Principal Objects with KeyCredentials
* O365 Admin Groups Report
* Delegated Permissions & Application Permissions

Querying Tenant Partner Information: In order to view Tenant Partner Information, including roles assigned to your partners, you must log into the Microsoft 365 Admin Center as Global Admin:

https://admin.microsoft.com/AdminPortal/Home#/partners

Prerequisites

The following PowerShell modules are required and will be installed automatically:

* ExchangeOnlineManagement
* AzureAD

NOTE: To return the full extent of the configurations being queried, the following role is required:

* Global Admin

When Global Admin privileges are not available, the tool will notify you about what information won’t be available to you as a result.

Usage

No parameters specified: A folder named with date and time (YYYYDDMMTHHMM) will be created automatically in the directory the script is being run from. Default authentication method will prompt for each connection for compatibility with MFA.

.\Get-CRTReport.ps1

-BasicAuthParameter: [OPTIONAL] If MFA is not enforced for your user principal, you can use this parameter which will prompt only once for authentication and store credentials using Get-Credential. (Not Recommended)

.\Get-CRTReport.ps1 -BasicAuth

-JobNameParameter: [OPTIONAL] Use the JobName parameter to distinguish between different tenants. If no JobName is specified, a Date/Time formatted folder will be placed within the working directory.

.\Get-CRTReport.ps1 -JobName MyJobName

-CommandsParameter: [OPTIONAL] With this parameter, specify the specific commands you want to run in quotes, comma or space separated.

.\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Commands “Command1,Command2”

-AzureEnvironmentName & -ExchangeEnvironmentNameParameter: [OPTIONAL] With this parameter, specify the Azure or Exchange environment names. Using tab complete you can search the acceptable values.

.\Get-CRTReport.ps1 -ExchangeEnvironmentName O365USGovGCCHigh -AzureEnvironmentName AzureUSGovernment

Available Commands:

FedConfig
FedTrust
ClientAccess
RemoteDomains
SMTPForward
TransportRules
FullAccessGranted
AnyAccessGranted
SendAsGranted
EXOPowerShell
AuditBypassEnabled
HiddenMailboxes
KeyCredentials
O365AdminGroups
DelegateAppPerms
AdminAuditLogConfig

-InteractiveParameter: [OPTIONAL] Some commands may take a long time to process depending on the amount of data in the tenant. Using the Interactive parameter, you will have the option to skip any particular command prior to the module running.

.\Get-CRTReport.ps1 -JobName MyJobName -WorkingDirectory ‘C:\Path\to\Job\Folder’ -Interactive
Download

___________________________
@hacking_Attack
@Hacking_Video