Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Is hacking getting easier or harder?

Literally everything I’ve learned on Udemy, YouTube and tryhackme (so far) is blocked by standard security features like cloud flare or windows defender.

They say that the demand for cyber security is going to increase by 33% in the next few years.

My professor said that ~93% of hacking is done by script kiddies. If standard script kiddy tools are blocked by default windows defender configurations, where is this increasing threat coming from? Nation state actors and the elite criminal organizations who have access to zero days?

submitted by /u/Practical_Bathroom53
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Uncommon/Unique malware evasion techniques?

I’m in the final stages of developing a Crypter at the moment. It’s sitting at 0/38 Scantime and 1/22 Runtime.

I have anti-VM features implemented which do standard checks on storage, ram, and CPU queries.

What other AV evasion techniques / anti debug features have you heard of?

The current list of features are as follows:

Polymorphic Encrypted Strings

Strings that would be constant within the stub are encrypted with a polymorphic encryption scheme so that the injected strings are different upon each build.

No decryption key in the “Stub”

The decryption key is not passed to the stub. Instead, a charset and length is passed along to be brute-forced at run. (Bypass some runtime AV; harder for reversing)

Randomized Code Blocks

Code Blocks / Subs&Functions are randomized in their placement when the assembly is crypted.

Legitimate Workstation Checks

At run, the program utilizes 3 check points to verify it is being run on a legitimate machine and not a virtualized environment.

Memory Execution

The crypted file is run directly in memory via a background thread.

Service Startup

The crypted file runs as a windows service until the injected bytes are run into memory.

Compression

The payload is compressed before being Injected into the stub, this sometimes provides outputs smaller than the stub+original payload.

Obfuscation

Using Mono.cecil, the assembly is lightly obfuscated using renaming techniques paired with invalid whitespace characters.

Only one static variable

Entire integer,string,array is dynamically changed each build with exception to one integer that is a divisor for bytes. A common number that would not be marked as malicious.

Small Stub

Only 12kb total size.

submitted by /u/MysticalTeamMember
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Whatsapp does not require OTP

NOTE: This finding was declared as feature by Facebook team so i would like to share this new feature with everyone.Continue reading on Medium »
Read more...
How I got my first HOF in United Nations | 0xshahriar

This is the story about getting my first Hall Of Fame. And I got it in United Nations. 🎉🎊Continue reading on Medium »
Read more...
Moving from Web application to Mobile pentesting.
https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/

Hello, I've been moving from web app pentesting to mobile soon and have no clue what to do. Can you guys share any materials or tips? So far I've found the OWASP-MSTG. Somewhere I've read that I should use some proxies and wireshark and stuff but can't paint the large picture. Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/tvuuac/moving_from_web_application_to_mobile_pentesting/)

___________________________
@hacking_Attack
@Hacking_Video
2FA… To Bypass

Learn various ways to bypass 2FAContinue reading on Medium »
Read more...