hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…Continue reading on Medium » (https://medium.com/@vivekkashyap0707/my-first-rce-from-n-a-to-triaged-cve-2021-3064-acdd0541c664?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My First RCE from N/A to Triaged (CVE-2021–3064)
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…
My First RCE from N/A to Triaged (CVE-2021–3064)
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…Continue reading on Medium »
Read more...
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…Continue reading on Medium »
Read more...
"Linux Rootkits for Red-Blue Teams" Course of pentesterAcademy is a joke and scam..
https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/
I just wanted to share my thoughts on this "course".. Now even tho i pirated this course and didn't pay anything for it, i still feel like i was scammed for my time lol The entire course is just printing some info from the task_struct of a pid, and THAT'S IT! For example if you're from windows world, that's like someone making a course on how to print some info from a EPROCESS struct.. Literally that's it. I'm not even sure where the rootkit and red team in the course title comes from, that course should be name writing a hello world linux kernel module.. I saw that the title of their videos were really basic but thought for sure that there has be some useful stuff in it.. So i just wanted to share this so no one falls for this trash of a course. submitted by /u/Ro0o0otkit (https://www.reddit.com/user/Ro0o0otkit)
[link] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/) [comments] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/
I just wanted to share my thoughts on this "course".. Now even tho i pirated this course and didn't pay anything for it, i still feel like i was scammed for my time lol The entire course is just printing some info from the task_struct of a pid, and THAT'S IT! For example if you're from windows world, that's like someone making a course on how to print some info from a EPROCESS struct.. Literally that's it. I'm not even sure where the rootkit and red team in the course title comes from, that course should be name writing a hello world linux kernel module.. I saw that the title of their videos were really basic but thought for sure that there has be some useful stuff in it.. So i just wanted to share this so no one falls for this trash of a course. submitted by /u/Ro0o0otkit (https://www.reddit.com/user/Ro0o0otkit)
[link] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/) [comments] (https://www.reddit.com/r/redteamsec/comments/ttl37t/linux_rootkits_for_redblue_teams_course_of/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
"Linux Rootkits for Red-Blue Teams" Course of pentesterAcademy is...
A subreddit dedicated to red and blue teaming content. Discussions @ https://discord.gg/mTvPzuT.
hacking: security in practice
Iphone hacked after clicking on suspicious link
My wife got delivery sms and we didn't ordered anything so she clicked on link to see . After that her whatsapp wallpapers are changed and apps are crashing . I thought it can't happen in iPhone but need help from this community as to what should I do to fix it .
submitted by /u/nul_exception
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Iphone hacked after clicking on suspicious link
My wife got delivery sms and we didn't ordered anything so she clicked on link to see . After that her whatsapp wallpapers are changed and apps are crashing . I thought it can't happen in iPhone but need help from this community as to what should I do to fix it .
submitted by /u/nul_exception
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Iphone hacked after clicking on suspicious link
My wife got delivery sms and we didn't ordered anything so she clicked on link to see . After that her whatsapp wallpapers are changed and apps...
hacking: security in practice
is that any way to fake video call?
Everytime when I get someone message me through social app, I will try to video call them, to identify whether they are scammer, if they don't answer my video call, I know mostly they are scammer.
Now situation has change, I found an website called synthesia, it use deep fake AI to create human avatar.
My question is, is that possible someone can create a fake video call?
If one day you receive a video call which is fake video call, the person who call you is using deepfake technology, how will you identify it is a fake video call? How to avoid from getting cheat?
submitted by /u/Substantial_Gift_861
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is that any way to fake video call?
Everytime when I get someone message me through social app, I will try to video call them, to identify whether they are scammer, if they don't answer my video call, I know mostly they are scammer.
Now situation has change, I found an website called synthesia, it use deep fake AI to create human avatar.
My question is, is that possible someone can create a fake video call?
If one day you receive a video call which is fake video call, the person who call you is using deepfake technology, how will you identify it is a fake video call? How to avoid from getting cheat?
submitted by /u/Substantial_Gift_861
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is that any way to fake video call?
Everytime when I get someone message me through social app, I will try to video call them, to identify whether they are scammer, if they don't...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple emergency update fixes zero-days used to hack iPhones, Macs
Apple emergency update fixes zero-days used to hack iPhones, MacsPost Views: 16
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Apple has released security updates on Thursday to address two zero-day vulnerabilities exploited by attackers to hack iPhones, iPads, and Macs.
Zero-day security bugs are flaws the software vendor is unaware of and hasn’t patched. In some cases, they also have publicly available proof-of-concept exploits or may be actively exploited in the wild.
In security advisories published today, Apple said that they’re aware of reports the issues “may have been actively exploited.”
The two flaws are an out-of-bounds write issue (CVE-2022-22674) in the Intel Graphics Driver that allows apps to read kernel memory and an out-of-bounds read issue (CVE-2022-22675) in the AppleAVD media decoder that will enable apps to execute arbitrary code with kernel privileges.
The bugs were reported by anonymous researchers and fixed by Apple in iOS 15.4.1, iPadOS 15.4.1, and macOS Monterey 12.3.1 with improved input validation and bounds checking, respectively.
The list of impacted devices includes:
* Macs running macOS Monterey
* iPhone 6s and later
* iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
Apple disclosed active exploitation in the wild, however, it did not release any additional info regarding these attacks.
Withholding this information is likely designed to allow the security updates to reach as many iPhones, iPads, and Macs as possible before threat actors pick up on the details and start abusing the now-patched zero-days.
Even though these zero-days were likely only used in targeted attacks, it’s still strongly advised to install today’s security updates as soon as possible to block potential attack attempts.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Five zero-days patched by Apple this yearIn January, Apple patched two more actively exploited zero-days that can enable attackers to achieve arbitrary code execution with kernel privileges (CVE-2022-22587) and track web browsing activity and the users’ identities in real-time (CVE-2022-22594).
In February, Apple released security updates to fix a new zero-day bug exploited to hack iPhones, iPads, and Macs, leading to OS crashes and remote code execution on compromised devices after processing maliciously crafted web content.
These first three zero-days also impacted iPhones (iPhone 6s and up), Macs running macOS Monterey, and multiple iPad models.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH The company also had to deal with an almost unending stream of zero-days exploited in the wild to target iOS, iPadOS, and macOS devices throughout 2021.
That list includes multiple flaws used to deploy NSO’s Pegasus spyware on iPhones belonging to journalists, activists, and politicians. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp[...]
___________________________
@hacking_Attack
@Hacking_Video
Apple emergency update fixes zero-days used to hack iPhones, Macs
Apple emergency update fixes zero-days used to hack iPhones, MacsPost Views: 16
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 2 Minutes
Apple has released security updates on Thursday to address two zero-day vulnerabilities exploited by attackers to hack iPhones, iPads, and Macs.
Zero-day security bugs are flaws the software vendor is unaware of and hasn’t patched. In some cases, they also have publicly available proof-of-concept exploits or may be actively exploited in the wild.
In security advisories published today, Apple said that they’re aware of reports the issues “may have been actively exploited.”
The two flaws are an out-of-bounds write issue (CVE-2022-22674) in the Intel Graphics Driver that allows apps to read kernel memory and an out-of-bounds read issue (CVE-2022-22675) in the AppleAVD media decoder that will enable apps to execute arbitrary code with kernel privileges.
The bugs were reported by anonymous researchers and fixed by Apple in iOS 15.4.1, iPadOS 15.4.1, and macOS Monterey 12.3.1 with improved input validation and bounds checking, respectively.
The list of impacted devices includes:
* Macs running macOS Monterey
* iPhone 6s and later
* iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
Apple disclosed active exploitation in the wild, however, it did not release any additional info regarding these attacks.
Withholding this information is likely designed to allow the security updates to reach as many iPhones, iPads, and Macs as possible before threat actors pick up on the details and start abusing the now-patched zero-days.
Even though these zero-days were likely only used in targeted attacks, it’s still strongly advised to install today’s security updates as soon as possible to block potential attack attempts.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Five zero-days patched by Apple this yearIn January, Apple patched two more actively exploited zero-days that can enable attackers to achieve arbitrary code execution with kernel privileges (CVE-2022-22587) and track web browsing activity and the users’ identities in real-time (CVE-2022-22594).
In February, Apple released security updates to fix a new zero-day bug exploited to hack iPhones, iPads, and Macs, leading to OS crashes and remote code execution on compromised devices after processing maliciously crafted web content.
These first three zero-days also impacted iPhones (iPhone 6s and up), Macs running macOS Monterey, and multiple iPad models.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH The company also had to deal with an almost unending stream of zero-days exploited in the wild to target iOS, iPadOS, and macOS devices throughout 2021.
That list includes multiple flaws used to deploy NSO’s Pegasus spyware on iPhones belonging to journalists, activists, and politicians. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees. Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Apple emergency update fixes zero-days used to hack iPhones, Macs | Black Hat Ethical Hacking
Apple has released security updates on Thursday to address two zero-day vulnerabilities exploited by attackers to hack iPhones, iPads, and Macs.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple emergency update fixes zero-days used to hack iPhones, Macs Apple emergency update fixes zero-days used to hack iPhones, MacsPost Views: 16 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png Reading…
-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day24 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
The post Apple emergency update fixes zero-days used to hack iPhones, Macs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Invisible-man-scaled-e1647906959971-90x90.jpg Browser-in-the-Browser Attack Makes Phishing Nearly Invisible1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/pdf-export-90x90.png Workaround offered for unpatched HTML-to-PDF rendering vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-2-scaled-90x90.jpg Caketap, a New Unix rootkit for stealing ATM banking data2 weeks ago
The post Apple emergency update fixes zero-days used to hack iPhones, Macs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 2
Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…Continue reading on Medium »
Read more...
Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…Continue reading on Medium »
Read more...
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 2
https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-2-57e8c0d5628f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-2-57e8c0d5628f?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 2
Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…
Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…Continue reading on Medium » (https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-2-57e8c0d5628f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 2
Hello Everyone, I hope you liked our previous article that was Cross-Site-Scripting (XSS) — Part 1, On that article, you learned about…
Hacking on Medium
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
https://cdn-images-1.medium.com/max/2600/1*dXmNy-KHRrDK79L7U7k7uQ.png
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Continue reading on Sentinel Protocol »
___________________________
@hacking_Attack
@Hacking_Video
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
https://cdn-images-1.medium.com/max/2600/1*dXmNy-KHRrDK79L7U7k7uQ.png
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Continue reading on Sentinel Protocol »
___________________________
@hacking_Attack
@Hacking_Video
Medium
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Hacking on Medium
HackMyVM: Blog writeup
https://cdn-images-1.medium.com/max/1027/1*KRJTTCWSpx3l42JxeEXJYg.png
RECON
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackMyVM: Blog writeup
https://cdn-images-1.medium.com/max/1027/1*KRJTTCWSpx3l42JxeEXJYg.png
RECON
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackMyVM: Blog writeup
RECON
Hacking on Medium
My First RCE from N/A to Triaged (CVE-2021–3064)
https://cdn-images-1.medium.com/max/623/1*QgHX7hXkkukt8W2ciO6urw.jpeg
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My First RCE from N/A to Triaged (CVE-2021–3064)
https://cdn-images-1.medium.com/max/623/1*QgHX7hXkkukt8W2ciO6urw.jpeg
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My First RCE from N/A to Triaged (CVE-2021–3064)
hello hackers, my name is Vivek Kumar & I started my bug bounty journey 8 months ago lets get back to the RCE its gonna very shot blog…
Slyther - AWS Security Tool
Slyther is AWS Security tool to check read/write/delete access for S3 buckets Requirements aws-cli Installation pip3 install -r requirements.txt Usage example python3 slyther.py -b flaws.cloud Release History 0.0.3 Added option to check if aws-cli is installed or not 0.0.2 Added option to check list of buckets 0.0.1 Initial release Created by – @iamavu Download Slyther
Read more...
Slyther is AWS Security tool to check read/write/delete access for S3 buckets Requirements aws-cli Installation pip3 install -r requirements.txt Usage example python3 slyther.py -b flaws.cloud Release History 0.0.3 Added option to check if aws-cli is installed or not 0.0.2 Added option to check list of buckets 0.0.1 Initial release Created by – @iamavu Download Slyther
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
LAPSUS$: Who Is Behind The Group
https://external-preview.redd.it/Wrv7pYotsvYNMb3RwtYTWYg_7dRK_lVJnSkg6Us1_jI.jpg?width=640&crop=smart&auto=webp&s=11a003d559bc57cd10b5a4d3d22030d844d83c01 submitted by /u/Kortings_codes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
LAPSUS$: Who Is Behind The Group
https://external-preview.redd.it/Wrv7pYotsvYNMb3RwtYTWYg_7dRK_lVJnSkg6Us1_jI.jpg?width=640&crop=smart&auto=webp&s=11a003d559bc57cd10b5a4d3d22030d844d83c01 submitted by /u/Kortings_codes
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
LAPSUS$: Who Is Behind The Group
Posted in r/hacking by u/Kortings_codes • 1 point and 0 comments
hacking: security in practice
beEF ilegal?
If you warn the user in the term of service that beef is penetrating testing them. is it still ilegal?
submitted by /u/Lucaspapper
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
beEF ilegal?
If you warn the user in the term of service that beef is penetrating testing them. is it still ilegal?
submitted by /u/Lucaspapper
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
beEF ilegal?
If you warn the user in the term of service that beef is penetrating testing them. is it still ilegal?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
News-Draft-Patreon image removed, Patreon link instead
News-Draft-Patreon image removed, Patreon link insteadPost Views: 7 Advanced Enumeration techniques with NMAP, Zenmap and Hydra https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Digital-Patreon-Logo_FieryCoral-150x150.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Mozilla has released Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0 to fix two critical zero-day vulnerabilities actively exploited in attacks.
Both zero-day vulnerabilities are “Use-after-free” bugs, which is when a program tries to use memory that has been previously cleared. When threat actors exploit this type of bug, it can cause the program to crash while at the same time allowing commands to be executed on the device without permission.
These bugs are critical because they could allow a remote attacker to execute almost any command, including the downloading of malware to provide further access to the device.
The zero-day vulnerabilities fixed by Mozilla are:
* CVE-2022-26485: Use-after-free in XSLT parameter processing – Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.
* CVE-2022-26486: Use-after-free in WebGPU IPC Framework – An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
As Mozilla’s security advisory explains, the Firefox developers are aware of “reports of attacks in the wild” actively exploiting these vulnerabilities.
While Mozilla has not shared how threat actors use these zero-day vulnerabilities in attacks, it was likely done by redirecting Firefox users to maliciously crafted web pages.
These vulnerabilities were discovered and disclosed to Mozilla by Chinese cybersecurity company Qihoo 360 ATA.
Due to the critical nature of these bugs, and they are being actively exploited, it is strongly recommended that all Firefox users update their browsers immediately.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH You can also download the latest version of Mozilla Firefox for Windows, macOS, and Linux from the following links:
* Firefox 97.0.2 for Windows 64-bit
* Firefox 97.0.2 for Windows 32-bit
* Firefox 97.0.2 for macOS
* Firefox 97.0.2 for Linux 64-bit
* Firefox 97.0.2 for Linux 32-bit
Users can manually check for new updates by going to the Firefox menu > Help > About Firefox. Firefox will then automatically check for and install the latest update and prompt you to restart your browser. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs5 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day1 day ago
* https://www.blackhatet[...]
___________________________
@hacking_Attack
@Hacking_Video
News-Draft-Patreon image removed, Patreon link instead
News-Draft-Patreon image removed, Patreon link insteadPost Views: 7 Advanced Enumeration techniques with NMAP, Zenmap and Hydra https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Digital-Patreon-Logo_FieryCoral-150x150.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Mozilla has released Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0 to fix two critical zero-day vulnerabilities actively exploited in attacks.
Both zero-day vulnerabilities are “Use-after-free” bugs, which is when a program tries to use memory that has been previously cleared. When threat actors exploit this type of bug, it can cause the program to crash while at the same time allowing commands to be executed on the device without permission.
These bugs are critical because they could allow a remote attacker to execute almost any command, including the downloading of malware to provide further access to the device.
The zero-day vulnerabilities fixed by Mozilla are:
* CVE-2022-26485: Use-after-free in XSLT parameter processing – Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.
* CVE-2022-26486: Use-after-free in WebGPU IPC Framework – An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
As Mozilla’s security advisory explains, the Firefox developers are aware of “reports of attacks in the wild” actively exploiting these vulnerabilities.
While Mozilla has not shared how threat actors use these zero-day vulnerabilities in attacks, it was likely done by redirecting Firefox users to maliciously crafted web pages.
These vulnerabilities were discovered and disclosed to Mozilla by Chinese cybersecurity company Qihoo 360 ATA.
Due to the critical nature of these bugs, and they are being actively exploited, it is strongly recommended that all Firefox users update their browsers immediately.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH You can also download the latest version of Mozilla Firefox for Windows, macOS, and Linux from the following links:
* Firefox 97.0.2 for Windows 64-bit
* Firefox 97.0.2 for Windows 32-bit
* Firefox 97.0.2 for macOS
* Firefox 97.0.2 for Linux 64-bit
* Firefox 97.0.2 for Linux 32-bit
Users can manually check for new updates by going to the Firefox menu > Help > About Firefox. Firefox will then automatically check for and install the latest update and prompt you to restart your browser. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs5 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day1 day ago
* https://www.blackhatet[...]
___________________________
@hacking_Attack
@Hacking_Video