Hacking on Medium
Deconstructing the ransomware kill chain
https://cdn-images-1.medium.com/max/1024/1*torJ6PlesCjsauXT2AG-Xw.jpeg
By design ransomware is a relatively “noisy” form of malware and its kill chain presents multiple opportunities for network defenders to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Deconstructing the ransomware kill chain
https://cdn-images-1.medium.com/max/1024/1*torJ6PlesCjsauXT2AG-Xw.jpeg
By design ransomware is a relatively “noisy” form of malware and its kill chain presents multiple opportunities for network defenders to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Deconstructing the ransomware kill chain
By design ransomware is a relatively “noisy” form of malware and its kill chain presents multiple opportunities for network defenders to…
Watch out the links : Account takeover
This is my second writeup here :), Hope you find enjoy it too!Continue reading on Medium »
Read more...
This is my second writeup here :), Hope you find enjoy it too!Continue reading on Medium »
Read more...
Very interested in landing a Pentester job to move on
https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/
I do hold a active good standing CISSP, will no doubt have OSCP on the 29th. 15 years experience as System Engineer and IDR. Kinda dumb question but I do have lock picking skills which is strictly a hobby and not resume worthy. If I did get some lockpicking certification is that any kind of additional edge over the competition to land a redteam job in the future? submitted by /u/newworldsamurai3030 (https://www.reddit.com/user/newworldsamurai3030)
[link] (https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/) [comments] (https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/
I do hold a active good standing CISSP, will no doubt have OSCP on the 29th. 15 years experience as System Engineer and IDR. Kinda dumb question but I do have lock picking skills which is strictly a hobby and not resume worthy. If I did get some lockpicking certification is that any kind of additional edge over the competition to land a redteam job in the future? submitted by /u/newworldsamurai3030 (https://www.reddit.com/user/newworldsamurai3030)
[link] (https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/) [comments] (https://www.reddit.com/r/redteamsec/comments/txbxfr/very_interested_in_landing_a_pentester_job_to/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Very interested in landing a Pentester job to move on
Posted by u/newworldsamurai3030 - No votes and 3 comments
hacking: security in practice
ADB exploit
I am curious, how i can exploit android which is on same network with me plus i have access to router page. I am researching about it for like weeks but can't find anything. Is it even possible ?
submitted by /u/YesDepresseddd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
ADB exploit
I am curious, how i can exploit android which is on same network with me plus i have access to router page. I am researching about it for like weeks but can't find anything. Is it even possible ?
submitted by /u/YesDepresseddd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
ADB exploit
I am curious, how i can exploit android which is on same network with me plus i have access to router page. I am researching about it for like...
Watch out the links : Account takeover
https://medium.com/@AkashHamal0x01/watch-out-the-links-account-takeover-32b9315390a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@AkashHamal0x01/watch-out-the-links-account-takeover-32b9315390a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Watch out the links : Account takeover!
This is my second writeup here :), Hope you find enjoy it too!
This is my second writeup here :), Hope you find enjoy it too!Continue reading on Medium » (https://medium.com/@AkashHamal0x01/watch-out-the-links-account-takeover-32b9315390a7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Watch out the links : Account takeover!
This is my second writeup here :), Hope you find enjoy it too!
Hacking on Medium
Man in the Middle and Denial of Service Attacks- Certified Ethical Hacking- Questionnaires Live
Man in the Middle and Denial of Service Attacks- Certified Ethical Hacking- Questionnaires Live
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Man in the Middle and Denial of Service Attacks- Certified Ethical Hacking- Questionnaires Live
Man in the Middle and Denial of Service Attacks- Certified Ethical Hacking- Questionnaires Live
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Man in the Middle and Denial of Service Attacks- Certified Ethical Hacking- Questionnaires Live
Hacking on Medium
Resources & Learning Paths collections (Part-1)
https://cdn-images-1.medium.com/max/1024/1*iigp3p9DtSN5HTcfMtzVuQ.png
I am starting a series of blogs where you find the collection of documents, presentations, videos, training materials, tools, services…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Resources & Learning Paths collections (Part-1)
https://cdn-images-1.medium.com/max/1024/1*iigp3p9DtSN5HTcfMtzVuQ.png
I am starting a series of blogs where you find the collection of documents, presentations, videos, training materials, tools, services…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Resources & Learning Paths collections (Part-1)
I am starting a series of blogs where you find the collection of documents, presentations, videos, training materials, tools, services, and…
Cyber Guardian Shirt for 3 min breach Survey
https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/
👋🏼 Hi everyone! I've read the FAQs so apologies if I may have misunderstood something! I'm conducting a 3 min confidential survey on breach preparedness for cyber security professionals and as a thanks, you get a free Cyber Guardian shirt! It's right here (https://www.surveymonkey.com/r/Social_Organic). Thank you for your time and have a great day :) Aviva submitted by /u/trojanrockinghorse (https://www.reddit.com/user/trojanrockinghorse)
[link] (https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/) [comments] (https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/
👋🏼 Hi everyone! I've read the FAQs so apologies if I may have misunderstood something! I'm conducting a 3 min confidential survey on breach preparedness for cyber security professionals and as a thanks, you get a free Cyber Guardian shirt! It's right here (https://www.surveymonkey.com/r/Social_Organic). Thank you for your time and have a great day :) Aviva submitted by /u/trojanrockinghorse (https://www.reddit.com/user/trojanrockinghorse)
[link] (https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/) [comments] (https://www.reddit.com/r/Pentesting/comments/txgkel/cyber_guardian_shirt_for_3_min_breach_survey/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cyber Guardian Shirt for 3 min breach Survey
👋🏼 Hi everyone! I've read the FAQs so apologies if I may have misunderstood something! I'm conducting a 3 min confidential survey on breach...
Where is the safest place to store your data?
https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/
As for me all of my information can be divided by importance, like: system backups (1/10 importance); current working files (3); personal archives: photos, videos (6); copies of paper documents (8); secrets: keys, passwords, wallets (10/10). Losing files is always unpleasant. What can you do to protect them? submitted by /u/Derrick_Wallarm (https://www.reddit.com/user/Derrick_Wallarm)
[link] (https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/) [comments] (https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/
As for me all of my information can be divided by importance, like: system backups (1/10 importance); current working files (3); personal archives: photos, videos (6); copies of paper documents (8); secrets: keys, passwords, wallets (10/10). Losing files is always unpleasant. What can you do to protect them? submitted by /u/Derrick_Wallarm (https://www.reddit.com/user/Derrick_Wallarm)
[link] (https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/) [comments] (https://www.reddit.com/r/redteamsec/comments/txgjid/where_is_the_safest_place_to_store_your_data/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Where is the safest place to store your data?
Posted by u/Derrick_Wallarm - 2 votes and 2 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How German Cops took down Hydra. "It gave us all goosebumps" says Sebastian Zwiebel, as he describes the moment his team shut down Hydra, the world's largest darknet marketplace.
https://external-preview.redd.it/hCdy6gip-VLBDKhOa6bLpMXnE8urFlxpIajz3mBnGiA.jpg?width=640&crop=smart&auto=webp&s=1aacc6756a2f2ae0f4f281ee5aa59513543fafa8 submitted by /u/tides977
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How German Cops took down Hydra. "It gave us all goosebumps" says Sebastian Zwiebel, as he describes the moment his team shut down Hydra, the world's largest darknet marketplace.
https://external-preview.redd.it/hCdy6gip-VLBDKhOa6bLpMXnE8urFlxpIajz3mBnGiA.jpg?width=640&crop=smart&auto=webp&s=1aacc6756a2f2ae0f4f281ee5aa59513543fafa8 submitted by /u/tides977
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How German Cops took down Hydra. "It gave us all goosebumps" says...
Posted in r/hacking by u/tides977 • 2 points and 0 comments
hacking: security in practice
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
submitted by /u/pir8son
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
submitted by /u/pir8son
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
For educational purposes I was wondering how complex it is to set...
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point...
Top 5 Geeky Websites 2022
https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Geeky Websites Of 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium » (https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Geeky Websites Of 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…
Top 5 Geeky Websites 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium »
Read more...
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
No-Joke Borat RAT Propagates Ransomware, DDoS
No-Joke Borat RAT Propagates Ransomware, DDoSPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)
This fresh malware strain extends the functionality of typical trojans with advanced functionality and a series of modules for launching various types of threat activity.
Attackers are using a newly released remote access trojan (RAT) to spread ransomware and distributed denial of service (DDoS) — in addition to the traditional RAT function of backdooring victims’ systems.
Researchers at Cyble Research Labs discovered the RAT, which they dubbed Borat RAT because it uses a photo of Sacha Baron Cohen, the comedian who created and portrayed the fictional character Borat in a popular series of mockumentary films.
Borat RAT, however, is not “verrry nice” — contrary to one of the most popular catchphrases of the character for which it’s named. It provides a range of advanced features as well as a dashboard for threat actors to perform various malicious activities beyond what other RATs can do, “further expanding the malware capabilities,” researchers said in a blog post about the malware.
“The Borat RAT is a potent and unique combination of remote-access trojan, spyware and ransomware, making it a triple threat to any machine compromised by it,” according to the post.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Attack LaunchpadAs described by Cyble Research Labs, the RAT acts like a framework from which threat actors can launch their cybercriminal activities, providing a dashboard to perform typical RAT activities as well as an option to compile the malware binary for performing DDoS and ransomware attacks on the victim’s machine.
“Interestingly, the RAT has an option to deliver a ransomware payload to the victim’s machine for encrypting users’ files as well as for demanding a ransom,” researchers said. “Like other ransomware, this RAT also has the capability to create a ransom note on the victim’s machine.”
Indeed, the RAT could have been crafted to appeal to fledgling malware operators, as cybercriminals “often don’t know the best way to monetize their victims until they have been in an environment awhile,” one security professional observed.
“Malware authors are increasingly developing feature sets and capabilities that allow flexibility on the part of the attacker,” John Bambenek, principal threat hunter at Netenrich, a digital IT and security operations company, wrote in an email to Threatpost.
The good news is, often these types of tools “tend to be used by less sophisticated criminals–or those pretending to be less sophisticated — who may find it difficult to succeed at ransomware at scale,” he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Specific Features and ModulesCyble researchers analyzed a number of modules of the Borat RAT and found that its functionality is varied. As mentioned, there is a ransomware module that can deliver a ransomware payload to the victim’s machine for encrypting users’ files and demand a ransom, as well as a module for performing a DDoS attack.
The RAT also includes the following functionality in a series of individual modules:
* A keylogger that can monitor and store the keystrokes in the victim’s machine;
* Audio recording that checks if a microphone is present [...]
___________________________
@hacking_Attack
@Hacking_Video
No-Joke Borat RAT Propagates Ransomware, DDoS
No-Joke Borat RAT Propagates Ransomware, DDoSPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)
This fresh malware strain extends the functionality of typical trojans with advanced functionality and a series of modules for launching various types of threat activity.
Attackers are using a newly released remote access trojan (RAT) to spread ransomware and distributed denial of service (DDoS) — in addition to the traditional RAT function of backdooring victims’ systems.
Researchers at Cyble Research Labs discovered the RAT, which they dubbed Borat RAT because it uses a photo of Sacha Baron Cohen, the comedian who created and portrayed the fictional character Borat in a popular series of mockumentary films.
Borat RAT, however, is not “verrry nice” — contrary to one of the most popular catchphrases of the character for which it’s named. It provides a range of advanced features as well as a dashboard for threat actors to perform various malicious activities beyond what other RATs can do, “further expanding the malware capabilities,” researchers said in a blog post about the malware.
“The Borat RAT is a potent and unique combination of remote-access trojan, spyware and ransomware, making it a triple threat to any machine compromised by it,” according to the post.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Attack LaunchpadAs described by Cyble Research Labs, the RAT acts like a framework from which threat actors can launch their cybercriminal activities, providing a dashboard to perform typical RAT activities as well as an option to compile the malware binary for performing DDoS and ransomware attacks on the victim’s machine.
“Interestingly, the RAT has an option to deliver a ransomware payload to the victim’s machine for encrypting users’ files as well as for demanding a ransom,” researchers said. “Like other ransomware, this RAT also has the capability to create a ransom note on the victim’s machine.”
Indeed, the RAT could have been crafted to appeal to fledgling malware operators, as cybercriminals “often don’t know the best way to monetize their victims until they have been in an environment awhile,” one security professional observed.
“Malware authors are increasingly developing feature sets and capabilities that allow flexibility on the part of the attacker,” John Bambenek, principal threat hunter at Netenrich, a digital IT and security operations company, wrote in an email to Threatpost.
The good news is, often these types of tools “tend to be used by less sophisticated criminals–or those pretending to be less sophisticated — who may find it difficult to succeed at ransomware at scale,” he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Specific Features and ModulesCyble researchers analyzed a number of modules of the Borat RAT and found that its functionality is varied. As mentioned, there is a ransomware module that can deliver a ransomware payload to the victim’s machine for encrypting users’ files and demand a ransom, as well as a module for performing a DDoS attack.
The RAT also includes the following functionality in a series of individual modules:
* A keylogger that can monitor and store the keystrokes in the victim’s machine;
* Audio recording that checks if a microphone is present [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
No-Joke Borat RAT Propagates Ransomware, DDoS | Black Hat Ethical Hacking
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)