hacking: security in practice
I don’t understand the Russian hackers hype
I've always maintained that Russian hackers are good for the same reason that American, Chinese, Israeli, British, Australian, New Zealand, and Canadian hackers are: their nations can afford it and it's a priority for intelligence and defense. I've observed a thriving grey market for hacking services throughout the years, and I still benefit from it.
It's for sale if you can afford it. It's an acquired ability that takes years to master, and the pay isn't all that bad - $50k for a basic job, a little more for a particularly quiet or complex one. Larger governments, such as Russia, China, and the United States, can also afford to employ and train their own hackers.
Russian hackers gained more prominence as a result of the 2016 US presidential election. The geopolitical climate in Russia has also resulted in more prominent use of cyber assaults, such as those against Ukraine. Finally, due to the nature of Russian law enforcement, we tend to see more organized cyber crime from Russia than from America, China, or Western Europe.
submitted by /u/Communitybot1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I don’t understand the Russian hackers hype
I've always maintained that Russian hackers are good for the same reason that American, Chinese, Israeli, British, Australian, New Zealand, and Canadian hackers are: their nations can afford it and it's a priority for intelligence and defense. I've observed a thriving grey market for hacking services throughout the years, and I still benefit from it.
It's for sale if you can afford it. It's an acquired ability that takes years to master, and the pay isn't all that bad - $50k for a basic job, a little more for a particularly quiet or complex one. Larger governments, such as Russia, China, and the United States, can also afford to employ and train their own hackers.
Russian hackers gained more prominence as a result of the 2016 US presidential election. The geopolitical climate in Russia has also resulted in more prominent use of cyber assaults, such as those against Ukraine. Finally, due to the nature of Russian law enforcement, we tend to see more organized cyber crime from Russia than from America, China, or Western Europe.
submitted by /u/Communitybot1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I don’t understand the Russian hackers hype
I've always maintained that Russian hackers are good for the same reason that American, Chinese, Israeli, British, Australian, New Zealand, and...
Hacking on Medium
WHAT IS ETHICAL HACKING?
What is moral hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
WHAT IS ETHICAL HACKING?
What is moral hacking?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHAT IS ETHICAL HACKING?
What is moral hacking?
Hacking on Medium
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit ( Hack Bitcoin unconfirmed transaction )
https://cdn-images-1.medium.com/max/778/1*8C0F7QT3RHkDorunwHyINg.png
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit is a software which allows you to hack unconfirmed bitcoin transactions with the UTX…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit ( Hack Bitcoin unconfirmed transaction )
https://cdn-images-1.medium.com/max/778/1*8C0F7QT3RHkDorunwHyINg.png
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit is a software which allows you to hack unconfirmed bitcoin transactions with the UTX…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit ( Hack Bitcoin unconfirmed transaction )
Bitcoin Transaction Hijacker V 4.0.1 UTX Exploit is a software which allows you to hack unconfirmed bitcoin transactions with the UTX…
hacking: security in practice
Whats the best way to learn and understand how to write malware?
Hello all,
I already know most of the c++ language and i would like to know where i can go from here. I would like to learn to create malware so i can understand how it works because i wish to become a pentester. What are some good courses and tutorials to learn how to create malware?
submitted by /u/Astral_Parallax
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Whats the best way to learn and understand how to write malware?
Hello all,
I already know most of the c++ language and i would like to know where i can go from here. I would like to learn to create malware so i can understand how it works because i wish to become a pentester. What are some good courses and tutorials to learn how to create malware?
submitted by /u/Astral_Parallax
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Whats the best way to learn and understand how to write malware?
Hello all, I already know most of the c++ language and i would like to know where i can go from here. I would like to learn to create malware...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers getting faster at latching onto unpatched vulnerabilities
Hackers getting faster at latching onto unpatched vulnerabilitiesPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
Hackers are exploiting security vulnerabilities more quickly, often within a week of their public disclosure, according to a study by Rapid7.
The latest edition of Rapid7’s annual Vulnerability Intelligence Report, published today (March 28), finds that the average time to known exploitation of vulnerabilities is down to 12 days – markedly down from the 42 days recorded in last year’s edition of the same study.
Rapid7 said that the trend meant that enterprises needed to be ready with “battle-tested emergency patching and incident response procedures” to have any hope of staying on top of the increasingly challenging security threat environment. Opportunistic breachesThe study put 50 vulnerabilities that posed a risk to businesses during 2021 under the microscope.
The vast majority – 43 of 50 vulnerabilities – were exploited in the wild.
Three in five (60%) of the widespread threats, defined by Rapid7 as those that have been exploited broadly and opportunistically by many attackers, were used in ransomware attacks. More than half of these widespread threats began with a zero-day exploit.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
Caitlin Condon, a manager at Rapid7’s vulnerability risk management engineering team, told The Daily Swig that ransomware exploitation was only one of several factors fueling the increase.
State-sponsored cyber-espionage groups (APTs) and opportunistic scammers attempting to enrich themselves through cryptojacking scams were also a problem.
Condon said: “For many of the vulnerabilities that became widespread threats, coin miners were the first wave of mass exploitation.
“We also saw instances where vulnerabilities in enterprise products were exploited by multiple APTs in addition to coin mining and ransomware groups, so it’s fair to say that a lot of the vulnerabilities in our ‘widespread’ threat category were quickly incorporated into both sophisticated and opportunistic campaigns.
She added: “The community and the security industry have benefited from sharing intelligence and expertise over the years – unfortunately, this is true of attackers, too.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Doubling down on zero-daysRapid7, the firm behind the Metasploit penetration testing tool, logged 20 CVEs that were exploited as zero-days during 2021 – more than double the number of exploits that figured in the previous edition of its study.
Condon commented: “We saw such a pronounced rise in zero-day attacks in 2021 that the most frequent value in our time to known exploitation data was zero. That drove all our statistics down.
“While a few of the zero-day vulnerabilities in the report were leveraged by ransomware groups from the start, most weren’t used in ransomware operations until after an initial wave of exploitation.”
In response to questions from The Daily Swig, Condon said there was no clear link or correlation between the more rapid exploitation of zero-day vulnerabilities and the growing threat posed by ransomware groups.
Condon explained: “In some cases, such as the ProxyLogon vulnerabilities in Microsoft Exchange Server, that ransomware wave began quickly. In others, it was weeks or months before we saw confirmation that fixed zero-day vulnerabilities had been incorporated into ransomware attacks.
“So there isn’t a clear correl[...]
___________________________
@hacking_Attack
@Hacking_Video
Hackers getting faster at latching onto unpatched vulnerabilities
Hackers getting faster at latching onto unpatched vulnerabilitiesPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
Hackers are exploiting security vulnerabilities more quickly, often within a week of their public disclosure, according to a study by Rapid7.
The latest edition of Rapid7’s annual Vulnerability Intelligence Report, published today (March 28), finds that the average time to known exploitation of vulnerabilities is down to 12 days – markedly down from the 42 days recorded in last year’s edition of the same study.
Rapid7 said that the trend meant that enterprises needed to be ready with “battle-tested emergency patching and incident response procedures” to have any hope of staying on top of the increasingly challenging security threat environment. Opportunistic breachesThe study put 50 vulnerabilities that posed a risk to businesses during 2021 under the microscope.
The vast majority – 43 of 50 vulnerabilities – were exploited in the wild.
Three in five (60%) of the widespread threats, defined by Rapid7 as those that have been exploited broadly and opportunistically by many attackers, were used in ransomware attacks. More than half of these widespread threats began with a zero-day exploit.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
Caitlin Condon, a manager at Rapid7’s vulnerability risk management engineering team, told The Daily Swig that ransomware exploitation was only one of several factors fueling the increase.
State-sponsored cyber-espionage groups (APTs) and opportunistic scammers attempting to enrich themselves through cryptojacking scams were also a problem.
Condon said: “For many of the vulnerabilities that became widespread threats, coin miners were the first wave of mass exploitation.
“We also saw instances where vulnerabilities in enterprise products were exploited by multiple APTs in addition to coin mining and ransomware groups, so it’s fair to say that a lot of the vulnerabilities in our ‘widespread’ threat category were quickly incorporated into both sophisticated and opportunistic campaigns.
She added: “The community and the security industry have benefited from sharing intelligence and expertise over the years – unfortunately, this is true of attackers, too.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Doubling down on zero-daysRapid7, the firm behind the Metasploit penetration testing tool, logged 20 CVEs that were exploited as zero-days during 2021 – more than double the number of exploits that figured in the previous edition of its study.
Condon commented: “We saw such a pronounced rise in zero-day attacks in 2021 that the most frequent value in our time to known exploitation data was zero. That drove all our statistics down.
“While a few of the zero-day vulnerabilities in the report were leveraged by ransomware groups from the start, most weren’t used in ransomware operations until after an initial wave of exploitation.”
In response to questions from The Daily Swig, Condon said there was no clear link or correlation between the more rapid exploitation of zero-day vulnerabilities and the growing threat posed by ransomware groups.
Condon explained: “In some cases, such as the ProxyLogon vulnerabilities in Microsoft Exchange Server, that ransomware wave began quickly. In others, it was weeks or months before we saw confirmation that fixed zero-day vulnerabilities had been incorporated into ransomware attacks.
“So there isn’t a clear correl[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Hackers getting faster at latching onto unpatched vulnerabilities | Black Hat Ethical Hacking
Hackers are exploiting security vulnerabilities more quickly, often within a week of their public disclosure, according to a study by Rapid7.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers getting faster at latching onto unpatched vulnerabilities Hackers getting faster at latching onto unpatched vulnerabilitiesPost Views: 2 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading…
ation in our data between the decrease in time to known exploitation and ransomware, but it’s entirely reasonable to surmise that as ransomware groups continue to evolve and mature their operations, we will see additional increases in both the urgency and scale of attacks.” See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group2 weeks ago
The post Hackers getting faster at latching onto unpatched vulnerabilities first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/79ohvicqaKcVP9KT2mDdTH-90x90.jpg Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Lapsus-group-has-hacked-Ubisoft-as-well-90x90.jpg Ubisoft has confirmed it was hacked by Lapsus$ group2 weeks ago
The post Hackers getting faster at latching onto unpatched vulnerabilities first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
How I bypassed 403 forbidden domain using a simple trick
Hello hunters,Continue reading on Medium »
Read more...
Hello hunters,Continue reading on Medium »
Read more...
How I bypassed 403 forbidden domain using a simple trick
https://janmuhammadzaidi.medium.com/how-i-bypassed-403-forbidden-domain-using-a-simple-trick-c2d538de04b8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://janmuhammadzaidi.medium.com/how-i-bypassed-403-forbidden-domain-using-a-simple-trick-c2d538de04b8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypassed 403 forbidden domain using a simple trick
Hello hunters,
Hello hunters,Continue reading on Medium » (https://janmuhammadzaidi.medium.com/how-i-bypassed-403-forbidden-domain-using-a-simple-trick-c2d538de04b8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I bypassed 403 forbidden domain using a simple trick
Hello hunters,
Hacking on Medium
Cracking Passwords w/ John the Ripper
https://cdn-images-1.medium.com/max/1600/1*F6v-zWxXwKIFUaqtrqqXIQ.png
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Cracking Passwords w/ John the Ripper
https://cdn-images-1.medium.com/max/1600/1*F6v-zWxXwKIFUaqtrqqXIQ.png
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cracking Passwords w/ John the Ripper
Today we will be looking at a popular password cracking tool called “John the Ripper“ (JtR).
Hacking on Medium
abusing Living off the Land binaries (Lolbins) for data exfiltration
https://cdn-images-1.medium.com/max/611/1*Uu9YJ67tfxW66moYJ8RCMg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
abusing Living off the Land binaries (Lolbins) for data exfiltration
https://cdn-images-1.medium.com/max/611/1*Uu9YJ67tfxW66moYJ8RCMg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
abusing Living off the Land binaries (Lolbins) for data exfiltration
Introduction
hacking: security in practice
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any courses? If so, what do you recommend I get a degree on? Thanks
submitted by /u/CrispyClout
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any courses? If so, what do you recommend I get a degree on? Thanks
submitted by /u/CrispyClout
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where should I start?
I am wondering if I should learn at home, or go to university. I’m book smart, but I can really put my mind to work at home. Did you guys take any...
hacking: security in practice
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries"
So maybe, there is no problem using McDonald's trademarks without permission. In this regard, aren't there any ways to protect patent from Russia gov?
Blocking IP addresses of Russia will actually helpful for proactive action against Russia's patent theft?
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries"
So maybe, there is no problem using McDonald's trademarks without permission. In this regard, aren't there any ways to protect patent from Russia gov?
Blocking IP addresses of Russia will actually helpful for proactive action against Russia's patent theft?
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hey guys, aren't there any ways to protect patent from Russia gov?
By washington post, It says "Russia says its businesses can steal patents from anyone in ‘unfriendly’ countries" So maybe, there is no problem...
hacking: security in practice
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think.
This is the story of someone near and dear to me. When saying "I or me", it may be from their POV, just easier.
So, funds were transferred from my bank account to another bank account, but the other bank account was in my name and setup in another state - I never made this account, don't know of the bank, definitely not my account (still waiting to hear back about their investigation). Gmail had filters added to remove "transfer" emails. Gmail did say that my device had a suspicious app detected, which I could not/cannot find (device is my local computer - windows 10). Main bank account that was hacked, said that all activity, including the transfer came from my device (local computer). They didn't say if IP was exact match, but said that IP is same city and that Device ID was my local computer. Around that time, also, Facebooks, Twitter and another Gmail account (not me, but same house) said tried logging in from unrecognized device or what not, I still get these notifications a month later (but these attempts that are blocked, are from IP in my city - I tracert facebook or google, and these IP's are not hop points, they are other ISP owned IP's in the same city I live in - I'm with ATT). Passwords have been changed, 2FA added if it wasn't (it was not before). The initial bank and gmail hack happened a month ago, during span of 5 days. Bank found it odd that my device did it, and also that there is another bank account in my name, meaning my SSN is possibly taken, on top of them knowing security questions, passwords, etc.
I'm the one trying to figure this out with my barely above average IT/Networking experience, and how it was done. Seems like such a high-effort or targeted hack, with the other bank account being created in my name and definitely a person spending some time doing this.
Google account does have user/password logins saved.
I did not find any Firewall exceptions out of the ordinary on local device.
Tasks/Processes seemed normal.
Mbam scan did return PUP.Optional.WinYahoo.Generic located in appdata/../chrome when scanned.
How likely is it that my computer or network is compromised, being that they used my device ID, it seems less likely that they'd spoof my info, more likely that they used my actual device, I'm guessing. Thought has crossed my mind that someone sat outside my house and possibly did this, but that seems absurd. Thinking someone actually breached my computer and really did use it (remotely), invisibly in the background, with me not knowing a thing and me unable to find anything to do all of this and not trigger any alarms. If that's the case, they're probably still connected somehow.
Anyways, I'm looking for insight and thoughts on this, and maybe referrals to another subreddit or site if this is not the right place. I know you hackers are capable of incredible stuff. I'm thinking about setting up Wireshark on a clean PC (been a decade since I touched this stuff), still unable to find anything on that local device, so I could still be compromised after changing all of my passwords and stuff.
submitted by /u/MidiGong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think.
This is the story of someone near and dear to me. When saying "I or me", it may be from their POV, just easier.
So, funds were transferred from my bank account to another bank account, but the other bank account was in my name and setup in another state - I never made this account, don't know of the bank, definitely not my account (still waiting to hear back about their investigation). Gmail had filters added to remove "transfer" emails. Gmail did say that my device had a suspicious app detected, which I could not/cannot find (device is my local computer - windows 10). Main bank account that was hacked, said that all activity, including the transfer came from my device (local computer). They didn't say if IP was exact match, but said that IP is same city and that Device ID was my local computer. Around that time, also, Facebooks, Twitter and another Gmail account (not me, but same house) said tried logging in from unrecognized device or what not, I still get these notifications a month later (but these attempts that are blocked, are from IP in my city - I tracert facebook or google, and these IP's are not hop points, they are other ISP owned IP's in the same city I live in - I'm with ATT). Passwords have been changed, 2FA added if it wasn't (it was not before). The initial bank and gmail hack happened a month ago, during span of 5 days. Bank found it odd that my device did it, and also that there is another bank account in my name, meaning my SSN is possibly taken, on top of them knowing security questions, passwords, etc.
I'm the one trying to figure this out with my barely above average IT/Networking experience, and how it was done. Seems like such a high-effort or targeted hack, with the other bank account being created in my name and definitely a person spending some time doing this.
Google account does have user/password logins saved.
I did not find any Firewall exceptions out of the ordinary on local device.
Tasks/Processes seemed normal.
Mbam scan did return PUP.Optional.WinYahoo.Generic located in appdata/../chrome when scanned.
How likely is it that my computer or network is compromised, being that they used my device ID, it seems less likely that they'd spoof my info, more likely that they used my actual device, I'm guessing. Thought has crossed my mind that someone sat outside my house and possibly did this, but that seems absurd. Thinking someone actually breached my computer and really did use it (remotely), invisibly in the background, with me not knowing a thing and me unable to find anything to do all of this and not trigger any alarms. If that's the case, they're probably still connected somehow.
Anyways, I'm looking for insight and thoughts on this, and maybe referrals to another subreddit or site if this is not the right place. I know you hackers are capable of incredible stuff. I'm thinking about setting up Wireshark on a clean PC (been a decade since I touched this stuff), still unable to find anything on that local device, so I could still be compromised after changing all of my passwords and stuff.
submitted by /u/MidiGong
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is this normal? Ongoing investigation regarding hack.
I am not a hacker, but here is something maybe interesting. Seems like such a high-effort/targeted hack, I'm curious what you hackers think. This...
Dummy DeHashed data for testing API?
https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/
I'm putting together a desktop app for consuming data from different API's like hunter.io (https://hunter.io/) and DeHashed.
It kinda / sorta works but I've run out of DeHashed credits at the moment and I'm looking for some dummy JSON output in the same format as DeHashed's output so that I can test it. There isn't a complete example in their docs, has anyone found an online resource that can be used for testing the API for free? The alpha version is at https://github.com/cyberfilth/nergal submitted by /u/PascalGeek (https://www.reddit.com/user/PascalGeek)
[link] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/
I'm putting together a desktop app for consuming data from different API's like hunter.io (https://hunter.io/) and DeHashed.
It kinda / sorta works but I've run out of DeHashed credits at the moment and I'm looking for some dummy JSON output in the same format as DeHashed's output so that I can test it. There isn't a complete example in their docs, has anyone found an online resource that can be used for testing the API for free? The alpha version is at https://github.com/cyberfilth/nergal submitted by /u/PascalGeek (https://www.reddit.com/user/PascalGeek)
[link] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/) [comments] (https://www.reddit.com/r/Pentesting/comments/tqwswb/dummy_dehashed_data_for_testing_api/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dummy DeHashed data for testing API?
I'm putting together a desktop app for consuming data from different API's like [hunter.io](https://hunter.io) and DeHashed. It kinda / sorta...
Analyzing Docker Image for Retrieving Secrets
https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/analyzing-docker-image-for-hunting-secrets/) [comments] (https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/analyzing-docker-image-for-hunting-secrets/) [comments] (https://www.reddit.com/r/redteamsec/comments/tqvwe6/analyzing_docker_image_for_retrieving_secrets/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Analyzing Docker Image for Retrieving Secrets
Posted in r/redteamsec by u/tbhaxor • 4 points and 0 comments
Socid-Extractor - Extract Accounts Info From Personal Pages On Various Sites For OSINT Purpose
http://www.kitploit.com/2022/03/socid-extractor-extract-accounts-info.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/socid-extractor-extract-accounts-info.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Socid-Extractor - Extract Accounts Info From Personal Pages On Various Sites For OSINT Purpose