Hacking on Medium
PicoCTF 2022: Keygenme writeup (reverse engineering)
https://cdn-images-1.medium.com/max/1800/1*vL4gK6g-UQ1NisMeLZmuoQ.png
CHALLENGE
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PicoCTF 2022: Keygenme writeup (reverse engineering)
https://cdn-images-1.medium.com/max/1800/1*vL4gK6g-UQ1NisMeLZmuoQ.png
CHALLENGE
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PicoCTF 2022: Keygenme writeup (reverse engineering)
CHALLENGE
Hacking on Medium
가상자산 해킹 증가
https://cdn-images-1.medium.com/max/600/1*VMVhFsfGQkJmpeA8QzFfyg.png
해커들의 해킹 방법이 정교해지면서 중앙화된 거래소의 해킹 빈도는 증가하고 있다. 가상자산의 가치가 커지면서 보관 자산이 많고, 거래량이 많은 보관 업체는 해킹 위협에 더 취약할 수 있다.
Continue reading on cardo-official »
___________________________
@hacking_Attack
@Hacking_Video
가상자산 해킹 증가
https://cdn-images-1.medium.com/max/600/1*VMVhFsfGQkJmpeA8QzFfyg.png
해커들의 해킹 방법이 정교해지면서 중앙화된 거래소의 해킹 빈도는 증가하고 있다. 가상자산의 가치가 커지면서 보관 자산이 많고, 거래량이 많은 보관 업체는 해킹 위협에 더 취약할 수 있다.
Continue reading on cardo-official »
___________________________
@hacking_Attack
@Hacking_Video
Medium
가상자산 해킹 증가
해커들의 해킹 방법이 정교해지면서 중앙화된 거래소의 해킹 빈도는 증가하고 있다. 가상자산의 가치가 커지면서 보관 자산이 많고, 거래량이 많은 보관 업체는 해킹 위협에 더 취약할 수 있다.
Hacking on Medium
안전한 보관을 위한 다양한 가상자산 수탁 솔루션 소개
https://cdn-images-1.medium.com/max/600/1*4ZLEGRcsRhpLQNJRjE0vPw.png
현재 다양한 지갑 솔루션이 있고 장단점은 명확하다. 온라인 연결 유무에 따라 크게 3가지 유형으로 구분된다. 온라인에 연결되는 핫지갑과 오프라인이 유지되는 콜드지갑이 있다. 그리고 중간 지점의 웜지갑이 있다.
Continue reading on cardo-official »
___________________________
@hacking_Attack
@Hacking_Video
안전한 보관을 위한 다양한 가상자산 수탁 솔루션 소개
https://cdn-images-1.medium.com/max/600/1*4ZLEGRcsRhpLQNJRjE0vPw.png
현재 다양한 지갑 솔루션이 있고 장단점은 명확하다. 온라인 연결 유무에 따라 크게 3가지 유형으로 구분된다. 온라인에 연결되는 핫지갑과 오프라인이 유지되는 콜드지갑이 있다. 그리고 중간 지점의 웜지갑이 있다.
Continue reading on cardo-official »
___________________________
@hacking_Attack
@Hacking_Video
Medium
안전한 보관을 위한 다양한 가상자산 수탁 솔루션 소개
현재 다양한 지갑 솔루션이 있고 장단점은 명확하다. 온라인 연결 유무에 따라 크게 3가지 유형으로 구분된다. 온라인에 연결되는 핫지갑과 오프라인이 유지되는 콜드지갑이 있다. 그리고 중간 지점의 웜지갑이 있다.
Hacking on Medium
TryHackMe writeup: IDE
https://cdn-images-1.medium.com/max/1039/1*n1PnYOPn6hjnMxSuh3JIqA.png
Sometimes in hacking, the recon and enumeration phase is overlooked. Here, I hope to show that enumeration is just as important.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe writeup: IDE
https://cdn-images-1.medium.com/max/1039/1*n1PnYOPn6hjnMxSuh3JIqA.png
Sometimes in hacking, the recon and enumeration phase is overlooked. Here, I hope to show that enumeration is just as important.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe writeup: IDE
Sometimes in hacking, the recon and enumeration phase is overlooked. Here, I hope to show that enumeration is just as important.
Hacking on Medium
SmagGrotto Walkthrough
https://cdn-images-1.medium.com/max/1920/1*6fRC1OvfjdszLTvkeJe2KQ.png
This is the walkthrough of the SmagGrotto Machine in TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SmagGrotto Walkthrough
https://cdn-images-1.medium.com/max/1920/1*6fRC1OvfjdszLTvkeJe2KQ.png
This is the walkthrough of the SmagGrotto Machine in TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SmagGrotto Walkthrough
This is the walkthrough of the SmagGrotto Machine in TryHackMe.
My Pentest Log -12- (Out-Of-Band Sql Injection in MySQL)
https://hcibo.medium.com/my-pentest-log-12-out-of-band-sql-injection-in-mysql-a01ecf4e6555?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hcibo.medium.com/my-pentest-log-12-out-of-band-sql-injection-in-mysql-a01ecf4e6555?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Pentest Log -12- (Out-Of-Band Sql Injection in MySQL)
Greetings to everyone from Byzantion,
Greetings to everyone from Byzantion,Continue reading on Medium » (https://hcibo.medium.com/my-pentest-log-12-out-of-band-sql-injection-in-mysql-a01ecf4e6555?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Pentest Log -12- (Out-Of-Band Sql Injection in MySQL)
Greetings to everyone from Byzantion,
Black Hat Ethical Hacking
HTML parser bug triggers Chromium XSS security flaw
___________________________
@hacking_Attack
@Hacking_Video
HTML parser bug triggers Chromium XSS security flaw
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
HTML parser bug triggers Chromium XSS security flaw | Black Hat Ethical Hacking
A parser bug potentially leading to XSS exploits has been patched by Chromium developers.
Hacking on Medium
Infinity Hack
https://cdn-images-1.medium.com/max/800/0*Jj92_E181C2FdYuo.png
Crypto has been on a hot streak recently, with bulls having the best time of their lives.
Continue reading on invstr »
___________________________
@hacking_Attack
@Hacking_Video
Infinity Hack
https://cdn-images-1.medium.com/max/800/0*Jj92_E181C2FdYuo.png
Crypto has been on a hot streak recently, with bulls having the best time of their lives.
Continue reading on invstr »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Infinity Hack 🧑💻
Crypto has been on a hot streak recently, with bulls having the best time of their lives. After a long stand at the $30,000 region, Bitcoin…
Hacking on Medium
Hacking an IP security camera in a Bus for live streaming the video!
https://cdn-images-1.medium.com/max/600/0*r8jZeIHOOAKDTBFL
In this write up let’s learn how to hack the security camera in a bus or anywhere around you using RTSP Protocol
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking an IP security camera in a Bus for live streaming the video!
https://cdn-images-1.medium.com/max/600/0*r8jZeIHOOAKDTBFL
In this write up let’s learn how to hack the security camera in a bus or anywhere around you using RTSP Protocol
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking an IP security camera in a Bus for live streaming the video!
In this write up let’s learn how to hack the security camera in a bus or anywhere around you using RTSP Protocol
Hacking on Medium
КУПИВАЙТЕ ЯКІСНІ ПІДРОБЛЕЖНІ ГРОШІ WHATSAPP ME ЗА ТЕЛЕФОНОМ +27 67 252 9928 ЄВРО, ДОЛАРИ ТА ФУНТІ…
https://cdn-images-1.medium.com/max/1080/1*bOkIYpWuINVj4OBYLuwD0A.jpeg
Придбайте водійські права, паспорт, візу, іспити EITLS, підроблені банкноти WhatsApp: +27 67 252 9928
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
КУПИВАЙТЕ ЯКІСНІ ПІДРОБЛЕЖНІ ГРОШІ WHATSAPP ME ЗА ТЕЛЕФОНОМ +27 67 252 9928 ЄВРО, ДОЛАРИ ТА ФУНТІ…
https://cdn-images-1.medium.com/max/1080/1*bOkIYpWuINVj4OBYLuwD0A.jpeg
Придбайте водійські права, паспорт, візу, іспити EITLS, підроблені банкноти WhatsApp: +27 67 252 9928
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
КУПИВАЙТЕ ЯКІСНІ ПІДРОБЛЕЖНІ ГРОШІ WHATSAPP ME ЗА ТЕЛЕФОНОМ +27 67 252 9928 ЄВРО, ДОЛАРИ ТА ФУНТІ ТА ХІМІКАТИ S.S.D
Придбайте водійські права, паспорт, візу, іспити EITLS, підроблені банкноти WhatsApp: +27 67 252 9928
hacking: security in practice
How do “email hackers” send you an email from yourself?
I’ve recently gotten one of those classic “I’m hacked you and stolen you information” emails, and it’s clearly a scam that relies on the fear factor. The only thing that concerns me is that the email was seemingly sent from my own account and that the hacker knows the password. I haven’t gotten any “new login” notifications, and read somewhere that such a thing can be easily spoofed by even inexperienced hackers. My question: How? Did they actually log into my email? I’m almost certain they didn’t as it was my school email account and the head of it would instantly get notified. I’m just wondering how it happened.
submitted by /u/_the_redditor__
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do “email hackers” send you an email from yourself?
I’ve recently gotten one of those classic “I’m hacked you and stolen you information” emails, and it’s clearly a scam that relies on the fear factor. The only thing that concerns me is that the email was seemingly sent from my own account and that the hacker knows the password. I haven’t gotten any “new login” notifications, and read somewhere that such a thing can be easily spoofed by even inexperienced hackers. My question: How? Did they actually log into my email? I’m almost certain they didn’t as it was my school email account and the head of it would instantly get notified. I’m just wondering how it happened.
submitted by /u/_the_redditor__
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do “email hackers” send you an email from yourself?
I’ve recently gotten one of those classic “I’m hacked you and stolen you information” emails, and it’s clearly a scam that relies on the fear...
Casper-Fs - A Custom Hidden Linux Kernel Module Generator. Each Module Works In The File System To Protect And Hide Secret Files
http://www.kitploit.com/2022/03/casper-fs-custom-hidden-linux-kernel.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/casper-fs-custom-hidden-linux-kernel.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Enter the folder and install python3 modules: $ cd casper-fs/module_generator
$ sudo python3 -m pip install -r requirements.txt
Edit your file rules in directory (https://www.kitploit.com/search/label/Directory) module_generator/rules/fs-rules.yaml, the python scripts, use that file to generate a new casper-fs custom module. $ cat module_generator/rules/fs-rules.yaml
binary_name: casperfs
module_name: Casperfs
unhide_module_key: AbraKadabra
hide_module_key: Shazam
fake_device_name: usb15
unhide-hide-file-key: Alakazam
unprotect-protect-file-key: Sesame
fs-rules:
- hidden:
1: secret.txt
2: my_vault.db
- protect:
1: backup_httpd.log
The array is hidden and array protected. You can insert a lot of the elements of another file on context, for example: - protect:
1: backup_httpd.log
2: secret_img.iso
3: secret_file.img
4: secret_file2.img
5: secret_file3.img
If you want to study the static code to generate, look at the directory "templates" content. The second step, generate your module. If you want to generate a kernel module following your YAML file of rules, follow that command: $ python3 casper-fs-gen.py --rules rules/fs-rules.yaml
This action can generate a generic module with the fs-rules.yaml. The third step, install your module. If you use Fedora Linux, install kernel packages for the developer: # dnf update
# dnf install kernel-headers.x86_64 kernel-modules.x86_64 kernel.x86_64 kernel-devel kmod
On Ubuntu Linux: apt install linux-headers-generic gcc make
To test module: # cd output; make clean; make
# insmod casperfs.ko
The fourth step runs your custom module. The password to turn casper-fs module visible for lsmod is the key "Shazam". The password to turn the casper-fs invisible is "AbraKadabra". The password to turn the secret files in hidden is "Alakazam", the same to turn to unhidden. The password to protect files or unprotect is "Sesame". You need to send the password for your fake device, "usb15" for example, to test hidden and unhidden resources on the file system: /dev/usb15 $ ls secret.txt $ echo "Alakazam" > /dev/usb15 $ ls -- no results--'>$ touch secret.txt
$ ls
-- no results--
$ echo "Alakazam" > /dev/usb15
$ ls
secret.txt
$ echo "Alakazam" > /dev/usb15
$ ls
-- no results--
So this is an example of trying to remove a protected file by Casper-fs: /dev/usb15 // to remove protection # rm backup_httpd.log # ls test.txt log.txt # echo "Sesame" > /dev/usb15 // to active protection (https://www.kitploit.com/search/label/Protection) again'># ls
test.txt log.txt backup_httpd.log
# rm backup_httpd.log
# ls
test.txt log.txt backup_httpd.log
# echo "Sesame" > /dev/usb15 // to remove protection
# rm backup_httpd.log
# ls
test.txt log.txt
# echo "Sesame" > /dev/usb15 // to active protection again
Note You need to turn casperfs visible at the "lsmod" command. Need this action before removing module /dev/usb15 # lsmod | grep casper casperfs # rmmod casperfs"># rmmod casperfs
rmmod: ERROR: ../libkmod/libkmod-module.c:799 kmod_module_remove_module() could not remove 'casperfs': No such file or directory
rmmod: ERROR: could not remove module casperfs: No such file or directory
# lsmod | grep casper
# echo "Shazam" > /dev/usb15
# lsmod | grep casper
casperfs
# rmmod casperfs
Random notes Tested on ubuntu 16 and fedora 29 at kernels "3.x","4.x" and "5.x". Point of attention This tool aims to use in the hardening system context. Pay attention if you have proper authorization (https://www.kitploit.com/search/label/Authorization) before using that. I do not have responsibility for your actions. You can use a hammer to construct a house or destroy it, choose the law path, don't be a bad guy, remember. References Wikipedia Netfilter https://en.wikipedia.org/wiki/Netfilter Linux Device Drivers http://lwn.net/Kernel/LDD3/ M0nad's Diamorphine https://github.com/m0nad/Diamorphine/
___________________________
@hacking_Attack
@Hacking_Video
$ sudo python3 -m pip install -r requirements.txt
Edit your file rules in directory (https://www.kitploit.com/search/label/Directory) module_generator/rules/fs-rules.yaml, the python scripts, use that file to generate a new casper-fs custom module. $ cat module_generator/rules/fs-rules.yaml
binary_name: casperfs
module_name: Casperfs
unhide_module_key: AbraKadabra
hide_module_key: Shazam
fake_device_name: usb15
unhide-hide-file-key: Alakazam
unprotect-protect-file-key: Sesame
fs-rules:
- hidden:
1: secret.txt
2: my_vault.db
- protect:
1: backup_httpd.log
The array is hidden and array protected. You can insert a lot of the elements of another file on context, for example: - protect:
1: backup_httpd.log
2: secret_img.iso
3: secret_file.img
4: secret_file2.img
5: secret_file3.img
If you want to study the static code to generate, look at the directory "templates" content. The second step, generate your module. If you want to generate a kernel module following your YAML file of rules, follow that command: $ python3 casper-fs-gen.py --rules rules/fs-rules.yaml
This action can generate a generic module with the fs-rules.yaml. The third step, install your module. If you use Fedora Linux, install kernel packages for the developer: # dnf update
# dnf install kernel-headers.x86_64 kernel-modules.x86_64 kernel.x86_64 kernel-devel kmod
On Ubuntu Linux: apt install linux-headers-generic gcc make
To test module: # cd output; make clean; make
# insmod casperfs.ko
The fourth step runs your custom module. The password to turn casper-fs module visible for lsmod is the key "Shazam". The password to turn the casper-fs invisible is "AbraKadabra". The password to turn the secret files in hidden is "Alakazam", the same to turn to unhidden. The password to protect files or unprotect is "Sesame". You need to send the password for your fake device, "usb15" for example, to test hidden and unhidden resources on the file system: /dev/usb15 $ ls secret.txt $ echo "Alakazam" > /dev/usb15 $ ls -- no results--'>$ touch secret.txt
$ ls
-- no results--
$ echo "Alakazam" > /dev/usb15
$ ls
secret.txt
$ echo "Alakazam" > /dev/usb15
$ ls
-- no results--
So this is an example of trying to remove a protected file by Casper-fs: /dev/usb15 // to remove protection # rm backup_httpd.log # ls test.txt log.txt # echo "Sesame" > /dev/usb15 // to active protection (https://www.kitploit.com/search/label/Protection) again'># ls
test.txt log.txt backup_httpd.log
# rm backup_httpd.log
# ls
test.txt log.txt backup_httpd.log
# echo "Sesame" > /dev/usb15 // to remove protection
# rm backup_httpd.log
# ls
test.txt log.txt
# echo "Sesame" > /dev/usb15 // to active protection again
Note You need to turn casperfs visible at the "lsmod" command. Need this action before removing module /dev/usb15 # lsmod | grep casper casperfs # rmmod casperfs"># rmmod casperfs
rmmod: ERROR: ../libkmod/libkmod-module.c:799 kmod_module_remove_module() could not remove 'casperfs': No such file or directory
rmmod: ERROR: could not remove module casperfs: No such file or directory
# lsmod | grep casper
# echo "Shazam" > /dev/usb15
# lsmod | grep casper
casperfs
# rmmod casperfs
Random notes Tested on ubuntu 16 and fedora 29 at kernels "3.x","4.x" and "5.x". Point of attention This tool aims to use in the hardening system context. Pay attention if you have proper authorization (https://www.kitploit.com/search/label/Authorization) before using that. I do not have responsibility for your actions. You can use a hammer to construct a house or destroy it, choose the law path, don't be a bad guy, remember. References Wikipedia Netfilter https://en.wikipedia.org/wiki/Netfilter Linux Device Drivers http://lwn.net/Kernel/LDD3/ M0nad's Diamorphine https://github.com/m0nad/Diamorphine/
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Download Casper-Fs (https://github.com/CoolerVoid/casper-fs)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Notion as a platform for offensive operations
https://www.reddit.com/r/redteamsec/comments/ts5se7/notion_as_a_platform_for_offensive_operations/
submitted by /u/soupcreamychicken (https://www.reddit.com/user/soupcreamychicken)
[link] (https://github.com/mttaggart/OffensiveNotion) [comments] (https://www.reddit.com/r/redteamsec/comments/ts5se7/notion_as_a_platform_for_offensive_operations/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ts5se7/notion_as_a_platform_for_offensive_operations/
submitted by /u/soupcreamychicken (https://www.reddit.com/user/soupcreamychicken)
[link] (https://github.com/mttaggart/OffensiveNotion) [comments] (https://www.reddit.com/r/redteamsec/comments/ts5se7/notion_as_a_platform_for_offensive_operations/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
r/redteamsec - Notion as a platform for offensive operations
0 votes and 0 comments so far on Reddit
Hacking on Medium
Αύξηση κυβερνοεπιθέσεων κατά την σύγκρουση Ρωσίας-Ουκρανίας
https://cdn-images-1.medium.com/max/1000/0*QYR7W5c7engKdAhU.jpg
Continue reading on iGuRu.gr »
___________________________
@hacking_Attack
@Hacking_Video
Αύξηση κυβερνοεπιθέσεων κατά την σύγκρουση Ρωσίας-Ουκρανίας
https://cdn-images-1.medium.com/max/1000/0*QYR7W5c7engKdAhU.jpg
Continue reading on iGuRu.gr »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Αύξηση κυβερνοεπιθέσεων κατά την σύγκρουση Ρωσίας-Ουκρανίας
Αύξηση κυβερνοεπιθέσεων κατά την σύγκρουση Ρωσίας-Ουκρανίας