Hacking on Medium
Self-XSS and they didn’t care
https://cdn-images-1.medium.com/max/2048/1*2e3WGwjpzi2q034rEDQ0Ig.png
A tale of Self-XSS getting no love.
Continue reading on Medium »
Self-XSS and they didn’t care
https://cdn-images-1.medium.com/max/2048/1*2e3WGwjpzi2q034rEDQ0Ig.png
A tale of Self-XSS getting no love.
Continue reading on Medium »
Medium
Self-XSS and they didn’t care
A tale of Self-XSS getting no love.
Hacking on Medium
Why Do You Need To Understand Your Enemy’s Tactics As An Ethical Hacker?
https://cdn-images-1.medium.com/max/1920/1*SOE_pHE-VD6ICUbxY-WPeA.png
It is interesting to see that both cyber-criminals and ethical hackers use the same tactics and techniques, but with a different objective…
Continue reading on Medium »
Why Do You Need To Understand Your Enemy’s Tactics As An Ethical Hacker?
https://cdn-images-1.medium.com/max/1920/1*SOE_pHE-VD6ICUbxY-WPeA.png
It is interesting to see that both cyber-criminals and ethical hackers use the same tactics and techniques, but with a different objective…
Continue reading on Medium »
Medium
Why Do You Need To Understand Your Enemy’s Tactics As An Ethical Hacker?
It is interesting to see that both cyber-criminals and ethical hackers use the same tactics and techniques, but with a different objective…
What is hacking ? How to hack ? Learn Hacking !!
A noob’s guide for hacking and understanding the computers.Continue reading on Medium »
Read more...
A noob’s guide for hacking and understanding the computers.Continue reading on Medium »
Read more...
What is hacking ? How to hack ? Learn Hacking !!
https://jahanviraycha.medium.com/what-is-hacking-how-to-hack-learn-hacking-6f228482381d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://jahanviraycha.medium.com/what-is-hacking-how-to-hack-learn-hacking-6f228482381d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is hacking ? How to hack ? Learn Hacking !!
A noob’s guide for hacking and understanding the computers.
A noob’s guide for hacking and understanding the computers.Continue reading on Medium » (https://jahanviraycha.medium.com/what-is-hacking-how-to-hack-learn-hacking-6f228482381d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is hacking ? How to hack ? Learn Hacking !!
A noob’s guide for hacking and understanding the computers.
What is hacking ? How to hack ? Learn Hacking !!
A noob’s guide for hacking and understanding the computers.Continue reading on Medium »
Read more...
A noob’s guide for hacking and understanding the computers.Continue reading on Medium »
Read more...
hacking: security in practice
I don't know who/ how to trust
0 I have had a few friends over the past say 10 years who were self-proclaimed hackers and yes they did know way more than I did as far as computer stuff goes cuz I missed a few days of that class I mean I used to know my computer s*** but now I don't. so basically I don't know whether someone's telling me the truth or not or whether they can really do what they say they can or not and because I've known a couple hackers who also turned out to be real scumbag junkies who are now back in my town and back trying to be in my life that I keep trying to avoid and block and not know them but they just keep calling and showing up basically because I have something they don't which is whatever they want-- or at least they assume I do more than they do--money, house, car, heart, their ex, a clean record, a clean IP, a clean computer, a clean phone, probably not bad credit, already-setup accounts, and some mutual friends who share a lot of the same ignorance, naiivity and vulnerability as I, but also share the same desperation as they (the hackers) do.
I need to talk to someone who knows these terms as i don't: ss7, cloning, remote, sms web page/previews, spying without phone ever in hand, locations of sent msgs, etc.
I need to know what they are capable of doing when they get fed up with me not giving into them and it's easier for them anyway to just hack me for their needs.
I'm kinda getting paranoid like, and I'm not a paranoid type. Cautious and street smart but like I said, I missed a day or two and have never caught up with today's tech.
submitted by /u/forevernever6824
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I don't know who/ how to trust
0 I have had a few friends over the past say 10 years who were self-proclaimed hackers and yes they did know way more than I did as far as computer stuff goes cuz I missed a few days of that class I mean I used to know my computer s*** but now I don't. so basically I don't know whether someone's telling me the truth or not or whether they can really do what they say they can or not and because I've known a couple hackers who also turned out to be real scumbag junkies who are now back in my town and back trying to be in my life that I keep trying to avoid and block and not know them but they just keep calling and showing up basically because I have something they don't which is whatever they want-- or at least they assume I do more than they do--money, house, car, heart, their ex, a clean record, a clean IP, a clean computer, a clean phone, probably not bad credit, already-setup accounts, and some mutual friends who share a lot of the same ignorance, naiivity and vulnerability as I, but also share the same desperation as they (the hackers) do.
I need to talk to someone who knows these terms as i don't: ss7, cloning, remote, sms web page/previews, spying without phone ever in hand, locations of sent msgs, etc.
I need to know what they are capable of doing when they get fed up with me not giving into them and it's easier for them anyway to just hack me for their needs.
I'm kinda getting paranoid like, and I'm not a paranoid type. Cautious and street smart but like I said, I missed a day or two and have never caught up with today's tech.
submitted by /u/forevernever6824
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I don't know who/ how to trust
0 I have had a few friends over the past say 10 years who were self-proclaimed hackers and yes they did know way more than I did as far as...
hacking: security in practice
Can anyone decode this thing?
Hey. I got this bin file somewhere in my PC, and I know it's not important, but I decided to test my decoding skills to decode it, and since it was only like ~20 hex characters it seemed very easy.
I ended up using ALL python encoders and all possible vscode's hex editor encoders and none seems to be working :(
here is the hex :
I think it's gotta be two strings? serialized in some c++ format . thats just a guess tho. but since the application that generated it was probably written in c++ (ExpressVPN), I'm assuming this is some serialized string, but not with any ordinary encoder?
anyways, if someone could help out, I'll be glad. and, well, if it turned out to be some confidential file, please be a good person and don't advertise it haha, (it's 99.99% not confidential tho)
submitted by /u/Ethical_John
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can anyone decode this thing?
Hey. I got this bin file somewhere in my PC, and I know it's not important, but I decided to test my decoding skills to decode it, and since it was only like ~20 hex characters it seemed very easy.
I ended up using ALL python encoders and all possible vscode's hex editor encoders and none seems to be working :(
here is the hex :
04 11 26 E3 F5 FC F5 F3 E4 F5 F4 CF E6 E0FE CF E0 E2 FF E4 FF F3 FF FC E3 5D 92 90I think it's gotta be two strings? serialized in some c++ format . thats just a guess tho. but since the application that generated it was probably written in c++ (ExpressVPN), I'm assuming this is some serialized string, but not with any ordinary encoder?
anyways, if someone could help out, I'll be glad. and, well, if it turned out to be some confidential file, please be a good person and don't advertise it haha, (it's 99.99% not confidential tho)
submitted by /u/Ethical_John
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can anyone decode this thing?
Hey. I got this bin file somewhere in my PC, and I know it's not important, but I decided to test my decoding skills to decode it, and since it...
Hacking on Medium
How Does Active Content Become Malicious?
https://cdn-images-1.medium.com/max/2600/1*NKK_tWw5CBJnHuaCrxGdRw.jpeg
Malicious Active Content target to vindictive code that is embedded into the system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Does Active Content Become Malicious?
https://cdn-images-1.medium.com/max/2600/1*NKK_tWw5CBJnHuaCrxGdRw.jpeg
Malicious Active Content target to vindictive code that is embedded into the system.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Does Active Content Become Malicious?
Malicious Active Content target to vindictive code that is embedded into the system.
Hacking on Medium
What is hacking ? How to hack ? Learn Hacking !!
https://cdn-images-1.medium.com/max/2600/0*egYjnSWPdc6vgrFX
A noob’s guide for hacking and understanding the computers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is hacking ? How to hack ? Learn Hacking !!
https://cdn-images-1.medium.com/max/2600/0*egYjnSWPdc6vgrFX
A noob’s guide for hacking and understanding the computers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is hacking ? How to hack ? Learn Hacking !!
A noob’s guide for hacking and understanding the computers.
Automating a Red Team Lab: Logging and Monitoring
https://www.reddit.com/r/redteamsec/comments/telonc/automating_a_red_team_lab_logging_and_monitoring/
submitted by /u/nickonos (https://www.reddit.com/user/nickonos)
[link] (https://nickzero.co.uk/automating-a-red-team-lab-part-2/) [comments] (https://www.reddit.com/r/redteamsec/comments/telonc/automating_a_red_team_lab_logging_and_monitoring/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/telonc/automating_a_red_team_lab_logging_and_monitoring/
submitted by /u/nickonos (https://www.reddit.com/user/nickonos)
[link] (https://nickzero.co.uk/automating-a-red-team-lab-part-2/) [comments] (https://www.reddit.com/r/redteamsec/comments/telonc/automating_a_red_team_lab_logging_and_monitoring/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Automating a Red Team Lab: Logging and Monitoring
Posted in r/redteamsec by u/nickonos • 27 points and 3 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Ubisoft has confirmed it was hacked by Lapsus$ group
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Ubisoft has confirmed it was hacked by Lapsus$ groupPost Views: 65
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
Video games developer and distributor Ubisoft has confirmed that it was hacked earlier this month, with the Lapsus$ group believed to be responsible.
The French-headquartered gaming company, known for leading titles including Assassin’s Creed, Far Cry, and Rainbow Six Siege, has around 117 million active users.
In a statement, Ubisoft says that the incident caused temporary disruption to some of its games, systems, and services.
“Our IT teams are working with leading external experts to investigate the issue. As a precautionary measure we initiated a company-wide password reset,” it says.
“Also, we can confirm that all our games and services are functioning normally and that at this time there is no evidence any player personal information was accessed or exposed as a by-product of this incident.”
See Also: Complete Offensive Security and Ethical Hacking Course Lapsus$ linksWhile it has not directly claimed responsibility, the South America-based Lapsus$ hacking group shared the news on Telegram with a smirking face emoji, suggesting that it may have been the culprit.
The group later commented in the same thread that it had not been targeting Ubisoft customer data.
Last month, Lapsus$ claimed it had leaked password hashes for employees of graphics chipmaker Nvidia, causing outages of its developer tools and email systems.
The group later threatened to leak files related to Nvidia’s GPUs unless the company open-sourced its graphics processing unit (GPU) drivers.
And just this month, the group claimed responsibility for hacking Samsung’s systems and dumping nearly 200 GB of stolen internal files online.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Last week, Lapsus$ posted on Telegram that it was recruiting insiders at potential targets – including ‘large software/gaming corporations’.
Responding to additional queries from The Daily Swig, a Ubisoft spokesperson said: “We don’t have additional information to share at the moment.” See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/NINTCHDBPICT[...]
___________________________
@hacking_Attack
@Hacking_Video
Ubisoft has confirmed it was hacked by Lapsus$ group
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Ubisoft has confirmed it was hacked by Lapsus$ groupPost Views: 65
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
Video games developer and distributor Ubisoft has confirmed that it was hacked earlier this month, with the Lapsus$ group believed to be responsible.
The French-headquartered gaming company, known for leading titles including Assassin’s Creed, Far Cry, and Rainbow Six Siege, has around 117 million active users.
In a statement, Ubisoft says that the incident caused temporary disruption to some of its games, systems, and services.
“Our IT teams are working with leading external experts to investigate the issue. As a precautionary measure we initiated a company-wide password reset,” it says.
“Also, we can confirm that all our games and services are functioning normally and that at this time there is no evidence any player personal information was accessed or exposed as a by-product of this incident.”
See Also: Complete Offensive Security and Ethical Hacking Course Lapsus$ linksWhile it has not directly claimed responsibility, the South America-based Lapsus$ hacking group shared the news on Telegram with a smirking face emoji, suggesting that it may have been the culprit.
The group later commented in the same thread that it had not been targeting Ubisoft customer data.
Last month, Lapsus$ claimed it had leaked password hashes for employees of graphics chipmaker Nvidia, causing outages of its developer tools and email systems.
The group later threatened to leak files related to Nvidia’s GPUs unless the company open-sourced its graphics processing unit (GPU) drivers.
And just this month, the group claimed responsibility for hacking Samsung’s systems and dumping nearly 200 GB of stolen internal files online.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Last week, Lapsus$ posted on Telegram that it was recruiting insiders at potential targets – including ‘large software/gaming corporations’.
Responding to additional queries from The Daily Swig, a Ubisoft spokesperson said: “We don’t have additional information to share at the moment.” See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/raccoon-stealer-90x90.jpg Raccoon Stealer Crawls Into Telegram1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/kali-bright-90x90.jpg Kali Unkaputtbar – a new feature on Kali Linux3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/wolf-in-sheps-clothing-2-scaled-e1646927438585-90x90.jpeg Malware Posing as Russia DDoS Tool Bites Ukraine Hackers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-90x90.jpg Agencies in Ukraine targeted with MicroBackdoor malware5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/NINTCHDBPICT[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Ubisoft has confirmed it was hacked by Lapsus$ group | Black Hat Ethical Hacking
Video games developer and distributor Ubisoft has confirmed that it was hacked earlier this month, with the Lapsus$ group believed to be responsible.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Write up: Steganography: Hide data in images and extract them
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Write up: Steganography: Hide data in images and extract themPost Views: 2 SteganographyIn the digital world, we can use images among other things to encode/decode information in them. Steganography is a hiding technique, which aims at delivering a hidden message where some other kind of information is already being delivered and is generally used in secret communication between acknowledged parties to establish a secured communication in an unnoticeable manner as well as to avoid drawing suspicion to the transmission of a hidden data. Many methods for hiding information in audio and images exist. More information about the steganography types, embedding techniques, and a more detailed article about how image steganography works can be found here. Choice of toolsThankfully, Linux users can choose from a variety of open-source tools such as Steghide, Exif, Stegosuite, Steg, Outguess, and many more. This tutorial uses Kali Linux as one of the many Debian-based Linux distros available that can be used to install and use the tools below.
We will use one graphical and one command line steganography tool for this tutorial.
1. Steghide: Is an open-source, command-line software that can encode and decode data into image files.
Current Version: 0.5.1
Features:
* compression of embedded data
* encryption of embedded data
* embedding of a checksum to verify the integrity of the extracted data
* support for JPEG, BMP, WAV and AU files
Installation: Steghide is already available in the Kali Linux repo.
Creating an image with a secret message in it.
* Create a folder with the name of your choice:
* Download or use an image of your choice to hide the secret message.
For this example we used his test image that you can download it using wget steghide embed -cf Patern_test.jpg -ef message.txt -sf secret.jpg* Embed: embed data
* -cf: cover file
* -ef: embed file
* -sf: output file – stego file
You can also choose between different encryption algorithms and compression levels.
See the user manual of steghide with:
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/passphrase.png
* Enter a passphrase and re-enter it for confirmation – be sure to remember it because you will not be able to decode the secret message from the stego file.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/encoding_done.png
Now, the stego file (secret.jpg) is ready.
* View info or the embedded data
You can get some information before extracting the stego file. To view the encryption algorithm, file size, and the embedded filename[...]
___________________________
@hacking_Attack
@Hacking_Video
Write up: Steganography: Hide data in images and extract them
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Write up: Steganography: Hide data in images and extract themPost Views: 2 SteganographyIn the digital world, we can use images among other things to encode/decode information in them. Steganography is a hiding technique, which aims at delivering a hidden message where some other kind of information is already being delivered and is generally used in secret communication between acknowledged parties to establish a secured communication in an unnoticeable manner as well as to avoid drawing suspicion to the transmission of a hidden data. Many methods for hiding information in audio and images exist. More information about the steganography types, embedding techniques, and a more detailed article about how image steganography works can be found here. Choice of toolsThankfully, Linux users can choose from a variety of open-source tools such as Steghide, Exif, Stegosuite, Steg, Outguess, and many more. This tutorial uses Kali Linux as one of the many Debian-based Linux distros available that can be used to install and use the tools below.
We will use one graphical and one command line steganography tool for this tutorial.
1. Steghide: Is an open-source, command-line software that can encode and decode data into image files.
Current Version: 0.5.1
Features:
* compression of embedded data
* encryption of embedded data
* embedding of a checksum to verify the integrity of the extracted data
* support for JPEG, BMP, WAV and AU files
Installation: Steghide is already available in the Kali Linux repo.
apt-get install steghidehttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/steghide_installation-1.png Creating an image with a secret message in it.
* Create a folder with the name of your choice:
mkdir steghide* Create a new text files with some text. – This will be the secret that we want to embed in the image of our choice. cd steghideecho "the secret message" > message.txthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/create_folder_and_secret_message.png * Download or use an image of your choice to hide the secret message.
For this example we used his test image that you can download it using wget steghide embed -cf Patern_test.jpg -ef message.txt -sf secret.jpg* Embed: embed data
* -cf: cover file
* -ef: embed file
* -sf: output file – stego file
You can also choose between different encryption algorithms and compression levels.
See the user manual of steghide with:
man steghide* It will prompt you to enter a passphrase needed to then later extract the message.txt from the secret.jpg image.https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/passphrase.png
* Enter a passphrase and re-enter it for confirmation – be sure to remember it because you will not be able to decode the secret message from the stego file.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/encoding_done.png
Now, the stego file (secret.jpg) is ready.
* View info or the embedded data
You can get some information before extracting the stego file. To view the encryption algorithm, file size, and the embedded filename[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Write up: Steganography: Hide data in images and extract them | Black Hat Ethical Hacking
Steganography is a hiding technique, which aims at delivering a hidden message where some other kind of information is already being delivered...
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Ubisoft has confirmed it was hacked by Lapsus$ group https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Ubisoft has confirmed it was hacked by Lapsus$ groupPost Views: 65 https://www.black…
000622539771-90x90.png Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!2 weeks ago
The post Ubisoft has confirmed it was hacked by Lapsus$ group first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/linux-kernel-double-free-vulnerability-90x90.png New Linux bug gives root on all major distros, exploit released1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/firefox-90x90.jpg Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/small-business-internet-security-90x90.jpg Google WAF bypassed via oversized POST requests2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-4-90x90.jpg Ukraine invasion: WordPress-hosted university websites hacked in ‘targeted attacks’2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-90x90.jpg RCE Bugs in WhatsApp, Other Hugely Popular VoIP Apps: Patch Now!2 weeks ago
The post Ubisoft has confirmed it was hacked by Lapsus$ group first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Write up: Steganography: Hide data in images and extract them https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Write up: Steganography: Hide data in images and extract themPost Views: 2 SteganographyIn…
/secret message filename using the command below:
(You must then enter the passphrase to continue)
* Retrieve information of the embedded file (stego file)
The way to decode and reveal the secret message embed in the stego file. Make sure to rename or remove the original message.txt from the working folder when performing this command.
* Now the extracted message can be read and found in the working folder.
Use cat to read and confirm the embedded message.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/read_file.png
See Also: Write up: Detect malicious hacker activities on endpoints
2. Stegosuite: Is a graphical interface steganographic tool written in Python for hiding data/extracting data them from images and more features.
Modules:
* Error Level analysis
* Threshold analysis of the image
* Edge Detection
* Metadata analysis
Version: 0.8
Installation: Stegosuite is also available in the Kali Linux repo.
Creating an image with a secret message in it.
It’s a way easier method since no prior knowledge of bash scripting or terminal is required.
* Run the tool from the terminal by typing stegosuite in the terminal and then click enter or you can find it from the navigation menu.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/stegosuite_.png
* Click file from the menu bar and choose the image to hide the secret message
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/file_selected.png
* You then just type the secret message, add the secret message.txt file
(right click on the embedded files and add it) that you want to embed, enter a password and click Embed.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/enter_message.png
* The stego file will be created on the same directory where the image was saved with the name _embed on the end.
e.g. original filename: test.jpg will be test_embed.jpg
* To extract the message just add the stego file from the file option on the header menu, type the password and click Extract.
* The secret message file will be saved also in the same directory where the stego file was saved with the same name that was embedded.
Thanks for checking out this write up, it was written by Black Hat Ethical Hacking members. The purpose is to make it easy for you choosing the guidelines and tips that we shared so you can enhance your experience and understand it, giving you more knowledge about Steganography.
If you think we have helped you, you can support us on Patreon.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to Information Security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote:
info (at) blackhatethicalhacking (dot) com https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic1 month ago
* https://www.blackhatethicalhac[...]
___________________________
@hacking_Attack
@Hacking_Video
(You must then enter the passphrase to continue)
steghide info secret.jpghttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/info-1.png * Retrieve information of the embedded file (stego file)
The way to decode and reveal the secret message embed in the stego file. Make sure to rename or remove the original message.txt from the working folder when performing this command.
steghide extract -sf secret.jpghttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/extract.png * Now the extracted message can be read and found in the working folder.
Use cat to read and confirm the embedded message.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/read_file.png
See Also: Write up: Detect malicious hacker activities on endpoints
2. Stegosuite: Is a graphical interface steganographic tool written in Python for hiding data/extracting data them from images and more features.
Modules:
* Error Level analysis
* Threshold analysis of the image
* Edge Detection
* Metadata analysis
Version: 0.8
Installation: Stegosuite is also available in the Kali Linux repo.
sudo apt-get install steghidehttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/stegosuite_installation.png Creating an image with a secret message in it.
It’s a way easier method since no prior knowledge of bash scripting or terminal is required.
* Run the tool from the terminal by typing stegosuite in the terminal and then click enter or you can find it from the navigation menu.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/stegosuite_.png
* Click file from the menu bar and choose the image to hide the secret message
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/file_selected.png
* You then just type the secret message, add the secret message.txt file
(right click on the embedded files and add it) that you want to embed, enter a password and click Embed.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/enter_message.png
* The stego file will be created on the same directory where the image was saved with the name _embed on the end.
e.g. original filename: test.jpg will be test_embed.jpg
* To extract the message just add the stego file from the file option on the header menu, type the password and click Extract.
* The secret message file will be saved also in the same directory where the stego file was saved with the same name that was embedded.
Thanks for checking out this write up, it was written by Black Hat Ethical Hacking members. The purpose is to make it easy for you choosing the guidelines and tips that we shared so you can enhance your experience and understand it, giving you more knowledge about Steganography.
If you think we have helped you, you can support us on Patreon.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to Information Security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote:
info (at) blackhatethicalhacking (dot) com https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic1 month ago
* https://www.blackhatethicalhac[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
/secret message filename using the command below: (You must then enter the passphrase to continue) steghide info secret.jpghttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/info-1.png * Retrieve information of the embedded file (stego file)…
king.com/wp-content/uploads/2021/12/Stuxnet-90x90.png Stuxnet – A weapon made out of code that almost started WW32 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Article-90x90.png Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/operation-troy-90x90.png Hacking stories – Operation Troy – How researchers linked the cyberattacks5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90.png Hacking stories – Operation Aurora: When China hacked Google6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/The-first-botnet-hijacker-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-4-90x90.png Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker9 months ago
The post Write up: Steganography: Hide data in images and extract them first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Article-90x90.png Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell4 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/operation-troy-90x90.png Hacking stories – Operation Troy – How researchers linked the cyberattacks5 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/09/Operation-Aurora-90x90.png Hacking stories – Operation Aurora: When China hacked Google6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/The-first-botnet-hijacker-90x90.png Hacking stories – The first botnet hijacker aka the Zombie King7 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/07/featured_image_jonathan_james_hacker-90x90.png Hacking Stories: Jonathan James – The teenager who hacked NASA for fun8 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-4-90x90.png Hacking Stories: Andrian Lamo – The ‘homeless’ Hacker9 months ago
The post Write up: Steganography: Hide data in images and extract them first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
RecoverPy : Interactively Find And Recover Deleted Or Overwritten Files From Your Terminal
RecoverPy searches through every block of your partition to find your request. You can already find plenty of solutions to recover deleted files, but it can be a hassle to recover overwritten files.
Installation
RecoverPy is currently only available on Linux systems.
Dependancies
Mandatory: To list and search through your partitions, recoverpy uses
Optional: To display real time grep progress, you can install
To install all dependencies:
* Debian-like:
* Arch:
* Fedora:
Installation from pip
Usage
python3 -m recoverpy
If you are not logged as root use
Select the system partition in which your file was. If you are out of luck, you can alternatively search in your home partition, maybe your IDE, text editor, etc. made a backup at some point.
Type a text string to search. See tips below for better results.
Note that searching a string in a whole partition may take a while. (see euphemism)
Default save path is
Start search, Results will appear in the left-hand box.
Select a result to display the corresponding partition block content in the right-hand box.
Once you have found your precious, select
You can now either save this block individually or explore neighboring blocks for the remaining parts of the file. You could then save it all in one file.
Download
___________________________
@hacking_Attack
@Hacking_Video
RecoverPy : Interactively Find And Recover Deleted Or Overwritten Files From Your Terminal
RecoverPy searches through every block of your partition to find your request. You can already find plenty of solutions to recover deleted files, but it can be a hassle to recover overwritten files.
Installation
RecoverPy is currently only available on Linux systems.
Dependancies
Mandatory: To list and search through your partitions, recoverpy uses
grep, dd, and lsblkcommands.Optional: To display real time grep progress, you can install
progress.To install all dependencies:
* Debian-like:
apt install grep coreutils util-linux progress* Arch:
pacman -S grep coreutils util-linux progress* Fedora:
dnf install grep coreutils util-linux progressInstallation from pip
python3 -m pip install recoverpyUsage
python3 -m recoverpy
If you are not logged as root use
sudo recoverpyor log in with su -before execution.Select the system partition in which your file was. If you are out of luck, you can alternatively search in your home partition, maybe your IDE, text editor, etc. made a backup at some point.
Type a text string to search. See tips below for better results.
Note that searching a string in a whole partition may take a while. (see euphemism)
Default save path is
/tmp/, click on Settings to edit configuration.Start search, Results will appear in the left-hand box.
Select a result to display the corresponding partition block content in the right-hand box.
Once you have found your precious, select
Save.You can now either save this block individually or explore neighboring blocks for the remaining parts of the file. You could then save it all in one file.
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
RecoverPy : Interactively Find And Recover Deleted Or Overwritten Files
RecoverPy searches through every block of your partition to find your request. You can already find plenty of solutions to recover.