Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
I think I screwed up ….

Yesterday I was doing a few vulnhub ctf’s while I had some downtime at work.

I stepped a way to use the bathroom, and got side tracked with work stuff…

I came back and my ADD kicked in and I was messing about and found a scam website.

I got their ip and wrote it down.

I ran Whois and found out they were being hosted on go daddy.

And turned them in to go daddy’s abuse email….

Fast forward about an hour, I was going back to my vulnhub and was trying to reconnect via ssh, and put in the wrong IP address. I put in the one I wrote down earlier (again ADD).

I attempted to log in like 4 times wondering why I couldn’t get back in….

Fast forward about 20 minutes and my entire network loses all internet connectivity from the ISP, I’m afraid that my failed ssh attempts were picked up by my ISP and they shut it off.

In which case I could be facing charges and will most likely lose my job….

But it was an honest mistake and I don’t know how big I messed up just yet…

Any advice?

PS I was not using a VPN because I was just doing a CTF… my bad.

submitted by /u/H00L1GAN007
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
My First RCE from N/A to Triaged (CVE-2021–3064)

hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…Continue reading on Medium »
Read more...
"Linux Rootkits for Red-Blue Teams" Course of pentesterAcademy is a joke and scam..
https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/

I just wanted to share my thoughts on this "course".. Now even tho i pirated this course and didn't pay anything for it, i still feel like i was scammed for my time lol The entire course is just printing some info from the task_struct of a pid, and THAT'S IT! For example if you're from windows world, that's like someone making a course on how to print some info from a EPROCESS struct.. Literally that's it. I'm not even sure where the rootkit and red team in the course title comes from, that course should be name writing a hello world linux kernel module.. I saw that the title of their videos were really basic but thought for sure that there has be some useful stuff in it.. ​ So i just wanted to share this so no one falls for this trash of a course. submitted by /u/Ro0o0otkit (https://www.reddit.com/user/Ro0o0otkit)
[link] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/) [comments] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Iphone hacked after clicking on suspicious link

My wife got delivery sms and we didn't ordered anything so she clicked on link to see . After that her whatsapp wallpapers are changed and apps are crashing . I thought it can't happen in iPhone but need help from this community as to what should I do to fix it .

submitted by /u/nul_exception
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
is that any way to fake video call?

Everytime when I get someone message me through social app, I will try to video call them, to identify whether they are scammer, if they don't answer my video call, I know mostly they are scammer.

Now situation has change, I found an website called synthesia, it use deep fake AI to create human avatar.

My question is, is that possible someone can create a fake video call?

If one day you receive a video call which is fake video call, the person who call you is using deepfake technology, how will you identify it is a fake video call? How to avoid from getting cheat?

submitted by /u/Substantial_Gift_861
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple emergency update fixes zero-days used to hack iPhones, Macs

Apple emergency update fixes zero-days used to hack iPhones, MacsPost Views: 16
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Apple has released security updates on Thursday to address two zero-day vulnerabilities exploited by attackers to hack iPhones, iPads, and Macs.
Zero-day security bugs are flaws the software vendor is unaware of and hasn’t patched. In some cases, they also have publicly available proof-of-concept exploits or may be actively exploited in the wild.

In security advisories published today, Apple said that they’re aware of reports the issues “may have been actively exploited.”

The two flaws are an out-of-bounds write issue (CVE-2022-22674) in the Intel Graphics Driver that allows apps to read kernel memory and an out-of-bounds read issue (CVE-2022-22675) in the AppleAVD media decoder that will enable apps to execute arbitrary code with kernel privileges.

The bugs were reported by anonymous researchers and fixed by Apple in iOS 15.4.1, iPadOS 15.4.1, and macOS Monterey 12.3.1 with improved input validation and bounds checking, respectively.

The list of impacted devices includes:

* Macs running macOS Monterey
* iPhone 6s and later
* iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).

Apple disclosed active exploitation in the wild, however, it did not release any additional info regarding these attacks.

Withholding this information is likely designed to allow the security updates to reach as many iPhones, iPads, and Macs as possible before threat actors pick up on the details and start abusing the now-patched zero-days.

Even though these zero-days were likely only used in targeted attacks, it’s still strongly advised to install today’s security updates as soon as possible to block potential attack attempts.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Five zero-days patched by Apple this yearIn January, Apple patched two more actively exploited zero-days that can enable attackers to achieve arbitrary code execution with kernel privileges (CVE-2022-22587) and track web browsing activity and the users’ identities in real-time (CVE-2022-22594).

In February, Apple released security updates to fix a new zero-day bug exploited to hack iPhones, iPads, and Macs, leading to OS crashes and remote code execution on compromised devices after processing maliciously crafted web content.

These first three zero-days also impacted iPhones (iPhone 6s and up), Macs running macOS Monterey, and multiple iPad models.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH The company also had to deal with an almost unending stream of zero-days exploited in the wild to target iOS, iPadOS, and macOS devices throughout 2021.

That list includes multiple flaws used to deploy NSO’s Pegasus spyware on iPhones belonging to journalists, activists, and politicians. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple emergency update fixes zero-days used to hack iPhones, Macs Apple emergency update fixes zero-days used to hack iPhones, MacsPost Views: 16 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading…
-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day24 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
The post Apple emergency update fixes zero-days used to hack iPhones, Macs first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 2

Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…Continue reading on Medium »
Read more...