Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How German Cops took down Hydra. "It gave us all goosebumps" says Sebastian Zwiebel, as he describes the moment his team shut down Hydra, the world's largest darknet marketplace.
https://external-preview.redd.it/hCdy6gip-VLBDKhOa6bLpMXnE8urFlxpIajz3mBnGiA.jpg?width=640&crop=smart&auto=webp&s=1aacc6756a2f2ae0f4f281ee5aa59513543fafa8 submitted by /u/tides977
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How German Cops took down Hydra. "It gave us all goosebumps" says Sebastian Zwiebel, as he describes the moment his team shut down Hydra, the world's largest darknet marketplace.
https://external-preview.redd.it/hCdy6gip-VLBDKhOa6bLpMXnE8urFlxpIajz3mBnGiA.jpg?width=640&crop=smart&auto=webp&s=1aacc6756a2f2ae0f4f281ee5aa59513543fafa8 submitted by /u/tides977
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How German Cops took down Hydra. "It gave us all goosebumps" says...
Posted in r/hacking by u/tides977 • 2 points and 0 comments
hacking: security in practice
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
submitted by /u/pir8son
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point me in the direction of good educational resources, Thanks!
submitted by /u/pir8son
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
For educational purposes I was wondering how complex it is to set...
For educational purposes I was wondering how complex it is to set up a secure dark net market place, could anyone provide some knowledge or point...
Top 5 Geeky Websites 2022
https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Geeky Websites Of 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium » (https://medium.com/@mohitbajwa0/top-5-geeky-websites-2022-bdaaebc138e4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 5 Geeky Websites Of 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…
Top 5 Geeky Websites 2022
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium »
Read more...
Hi everyone, hope you doing great. So today I’ll introduce you to five amazing websites which can be very helpful for everyone and I…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
No-Joke Borat RAT Propagates Ransomware, DDoS
No-Joke Borat RAT Propagates Ransomware, DDoSPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)
This fresh malware strain extends the functionality of typical trojans with advanced functionality and a series of modules for launching various types of threat activity.
Attackers are using a newly released remote access trojan (RAT) to spread ransomware and distributed denial of service (DDoS) — in addition to the traditional RAT function of backdooring victims’ systems.
Researchers at Cyble Research Labs discovered the RAT, which they dubbed Borat RAT because it uses a photo of Sacha Baron Cohen, the comedian who created and portrayed the fictional character Borat in a popular series of mockumentary films.
Borat RAT, however, is not “verrry nice” — contrary to one of the most popular catchphrases of the character for which it’s named. It provides a range of advanced features as well as a dashboard for threat actors to perform various malicious activities beyond what other RATs can do, “further expanding the malware capabilities,” researchers said in a blog post about the malware.
“The Borat RAT is a potent and unique combination of remote-access trojan, spyware and ransomware, making it a triple threat to any machine compromised by it,” according to the post.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Attack LaunchpadAs described by Cyble Research Labs, the RAT acts like a framework from which threat actors can launch their cybercriminal activities, providing a dashboard to perform typical RAT activities as well as an option to compile the malware binary for performing DDoS and ransomware attacks on the victim’s machine.
“Interestingly, the RAT has an option to deliver a ransomware payload to the victim’s machine for encrypting users’ files as well as for demanding a ransom,” researchers said. “Like other ransomware, this RAT also has the capability to create a ransom note on the victim’s machine.”
Indeed, the RAT could have been crafted to appeal to fledgling malware operators, as cybercriminals “often don’t know the best way to monetize their victims until they have been in an environment awhile,” one security professional observed.
“Malware authors are increasingly developing feature sets and capabilities that allow flexibility on the part of the attacker,” John Bambenek, principal threat hunter at Netenrich, a digital IT and security operations company, wrote in an email to Threatpost.
The good news is, often these types of tools “tend to be used by less sophisticated criminals–or those pretending to be less sophisticated — who may find it difficult to succeed at ransomware at scale,” he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Specific Features and ModulesCyble researchers analyzed a number of modules of the Borat RAT and found that its functionality is varied. As mentioned, there is a ransomware module that can deliver a ransomware payload to the victim’s machine for encrypting users’ files and demand a ransom, as well as a module for performing a DDoS attack.
The RAT also includes the following functionality in a series of individual modules:
* A keylogger that can monitor and store the keystrokes in the victim’s machine;
* Audio recording that checks if a microphone is present [...]
___________________________
@hacking_Attack
@Hacking_Video
No-Joke Borat RAT Propagates Ransomware, DDoS
No-Joke Borat RAT Propagates Ransomware, DDoSPost Views: 2
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)
This fresh malware strain extends the functionality of typical trojans with advanced functionality and a series of modules for launching various types of threat activity.
Attackers are using a newly released remote access trojan (RAT) to spread ransomware and distributed denial of service (DDoS) — in addition to the traditional RAT function of backdooring victims’ systems.
Researchers at Cyble Research Labs discovered the RAT, which they dubbed Borat RAT because it uses a photo of Sacha Baron Cohen, the comedian who created and portrayed the fictional character Borat in a popular series of mockumentary films.
Borat RAT, however, is not “verrry nice” — contrary to one of the most popular catchphrases of the character for which it’s named. It provides a range of advanced features as well as a dashboard for threat actors to perform various malicious activities beyond what other RATs can do, “further expanding the malware capabilities,” researchers said in a blog post about the malware.
“The Borat RAT is a potent and unique combination of remote-access trojan, spyware and ransomware, making it a triple threat to any machine compromised by it,” according to the post.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Attack LaunchpadAs described by Cyble Research Labs, the RAT acts like a framework from which threat actors can launch their cybercriminal activities, providing a dashboard to perform typical RAT activities as well as an option to compile the malware binary for performing DDoS and ransomware attacks on the victim’s machine.
“Interestingly, the RAT has an option to deliver a ransomware payload to the victim’s machine for encrypting users’ files as well as for demanding a ransom,” researchers said. “Like other ransomware, this RAT also has the capability to create a ransom note on the victim’s machine.”
Indeed, the RAT could have been crafted to appeal to fledgling malware operators, as cybercriminals “often don’t know the best way to monetize their victims until they have been in an environment awhile,” one security professional observed.
“Malware authors are increasingly developing feature sets and capabilities that allow flexibility on the part of the attacker,” John Bambenek, principal threat hunter at Netenrich, a digital IT and security operations company, wrote in an email to Threatpost.
The good news is, often these types of tools “tend to be used by less sophisticated criminals–or those pretending to be less sophisticated — who may find it difficult to succeed at ransomware at scale,” he added.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Specific Features and ModulesCyble researchers analyzed a number of modules of the Borat RAT and found that its functionality is varied. As mentioned, there is a ransomware module that can deliver a ransomware payload to the victim’s machine for encrypting users’ files and demand a ransom, as well as a module for performing a DDoS attack.
The RAT also includes the following functionality in a series of individual modules:
* A keylogger that can monitor and store the keystrokes in the victim’s machine;
* Audio recording that checks if a microphone is present [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
No-Joke Borat RAT Propagates Ransomware, DDoS | Black Hat Ethical Hacking
Attackers are using a newly released remote access trojan (RAT), dubbed Borat RAT, to spread ransomware and distributed denial of service (DDoS)
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking No-Joke Borat RAT Propagates Ransomware, DDoS No-Joke Borat RAT Propagates Ransomware, DDoSPost Views: 2 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP…
and will record all audio and save it in a file named micaudio.wav;
* Webcam recording that records video is a webcam is present in the victim’s machine;
* Remote desktop sessions that can allow threat actors the necessary rights to control the victim’s machine, mouse, keyboard and screen capture;
* Code to enable reverse proxy for performing RAT activities anonymously;
* A module that collects information on a victim’s machine, including OS name/ version, system model, etc;
* Process hollowing that injects malicious code into the legitimate processes;
* Credential stealing that can steal cookies, history, bookmarks, and saved login credentials from chromium-based browsers like Google Chrome and Edge; and
* A module that steals Discord tokens and sends the stolen token information to the attacker.
Remote activities the RAT can perform to disturb victims include: play audio, swap mouse buttons, show/hide the desktop, show/hide the taskbar, and hold the mouse, among others. See Also: Offensive Security Tool: Scapy
The Cyble Research Team said it will continue to monitor the RAT’s actions and will update clients and the security community as the situation evolves.
In the meantime, organizations can mitigate risk by performing some common security precautions, such as avoiding the storage of important files in common locations such as the Desktop and My Documents; using strong passwords and enforcing multi-factor authentication wherever possible; and turning on the automatic software update feature on all connected devices wherever possible and pragmatic, researchers advised.
Individual users also should use a reputed antivirus and internet security software package on all connected devices, and should refrain from opening untrusted links and email attachments without verifying their authenticity, they said.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again2 weeks a[...]
___________________________
@hacking_Attack
@Hacking_Video
* Webcam recording that records video is a webcam is present in the victim’s machine;
* Remote desktop sessions that can allow threat actors the necessary rights to control the victim’s machine, mouse, keyboard and screen capture;
* Code to enable reverse proxy for performing RAT activities anonymously;
* A module that collects information on a victim’s machine, including OS name/ version, system model, etc;
* Process hollowing that injects malicious code into the legitimate processes;
* Credential stealing that can steal cookies, history, bookmarks, and saved login credentials from chromium-based browsers like Google Chrome and Edge; and
* A module that steals Discord tokens and sends the stolen token information to the attacker.
Remote activities the RAT can perform to disturb victims include: play audio, swap mouse buttons, show/hide the desktop, show/hide the taskbar, and hold the mouse, among others. See Also: Offensive Security Tool: Scapy
The Cyble Research Team said it will continue to monitor the RAT’s actions and will update clients and the security community as the situation evolves.
In the meantime, organizations can mitigate risk by performing some common security precautions, such as avoiding the storage of important files in common locations such as the Desktop and My Documents; using strong passwords and enforcing multi-factor authentication wherever possible; and turning on the automatic software update feature on all connected devices wherever possible and pragmatic, researchers advised.
Individual users also should use a reputed antivirus and internet security software package on all connected devices, and should refrain from opening untrusted links and email attachments without verifying their authenticity, they said.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again2 weeks a[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
and will record all audio and save it in a file named micaudio.wav; * Webcam recording that records video is a webcam is present in the victim’s machine; * Remote desktop sessions that can allow threat actors the necessary rights to control the victim’s machine…
go
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta2 weeks ago
The post No-Joke Borat RAT Propagates Ransomware, DDoS first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/hackers-90x90.jpg Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta2 weeks ago
The post No-Joke Borat RAT Propagates Ransomware, DDoS first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
[NEW EVENT] BUG HUNTING BOUNTY IN STMAN TESTNET
Dear Stickmen, you must be all very excited to experience the Testnet version to be released today. To celebrate this event and create the…Continue reading on Medium »
Read more...
Dear Stickmen, you must be all very excited to experience the Testnet version to be released today. To celebrate this event and create the…Continue reading on Medium »
Read more...
API Security Checklist
https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/
APIs come in many flavors, including REST, SOAP, graphQL, gRPC, and WebSockets, and each has its own use cases and common vulnerabilities. The issues covered in this checklist can occur in any kind of API. Regardless of which technology you have used to implement your API, read on to find out what you can do today to address the biggest potential risks associated with it. https://www.wallarm.com/resources/api-security-checklist submitted by /u/Derrick_Wallarm (https://www.reddit.com/user/Derrick_Wallarm)
[link] (https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/) [comments] (https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/
APIs come in many flavors, including REST, SOAP, graphQL, gRPC, and WebSockets, and each has its own use cases and common vulnerabilities. The issues covered in this checklist can occur in any kind of API. Regardless of which technology you have used to implement your API, read on to find out what you can do today to address the biggest potential risks associated with it. https://www.wallarm.com/resources/api-security-checklist submitted by /u/Derrick_Wallarm (https://www.reddit.com/user/Derrick_Wallarm)
[link] (https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/) [comments] (https://www.reddit.com/r/redteamsec/comments/txi13i/api_security_checklist/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
API Security Checklist
APIs come in many flavors, including REST, SOAP, graphQL, gRPC, and WebSockets, and each has its own use cases and common vulnerabilities. The...
[NEW EVENT] BUG HUNTING BOUNTY IN STMAN TESTNET
https://medium.com/@stickman_battleground/new-event-bug-hunting-bounty-in-stman-testnet-7e98010ed8bd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@stickman_battleground/new-event-bug-hunting-bounty-in-stman-testnet-7e98010ed8bd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
[NEW EVENT] 🔥BUG HUNTING BOUNTY IN STMAN TESTNET🔥
Dear Stickmen, you must be all very excited to experience the Testnet version to be released today. To celebrate this event and create the…
Dear Stickmen, you must be all very excited to experience the Testnet version to be released today. To celebrate this event and create the…Continue reading on Medium » (https://medium.com/@stickman_battleground/new-event-bug-hunting-bounty-in-stman-testnet-7e98010ed8bd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
[NEW EVENT] 🔥BUG HUNTING BOUNTY IN STMAN TESTNET🔥
Dear Stickmen, you must be all very excited to experience the Testnet version to be released today. To celebrate this event and create the…
Hacking on Medium
CSRF in ICEHRM 31.0.0.0S in Delete User Endpoint
AbICEHRM
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CSRF in ICEHRM 31.0.0.0S in Delete User Endpoint
AbICEHRM
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF in ICEHRM 31.0.0.0S in Delete User Endpoint
AbICEHRM
Hacking on Medium
Russia-China Alliance Extends to Youtube: Artist Criticizes Little Pinks, A Bear Responds
Political satire is an ancient tradition. It is an art form that has always existed, regardless of centuries, countries or cultures. And…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Russia-China Alliance Extends to Youtube: Artist Criticizes Little Pinks, A Bear Responds
Political satire is an ancient tradition. It is an art form that has always existed, regardless of centuries, countries or cultures. And…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Russia-China Alliance Extends to Youtube: Artist Criticizes Little Pinks, A Bear Responds
Political satire is an ancient tradition. It is an art form that has always existed, regardless of centuries, countries or cultures. And…
Hacking on Medium
TryHackMe: [Day 8] Special by John Hammond Santa’s Bag of Toys
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Read the premise above, start the attached Windows analysis machine and find the transcription logs in the SantasLaptopLogs folder on the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: [Day 8] Special by John Hammond Santa’s Bag of Toys
https://cdn-images-1.medium.com/max/1920/1*psaTaSfd9sQyajFeYTLO-w.png
Read the premise above, start the attached Windows analysis machine and find the transcription logs in the SantasLaptopLogs folder on the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: [Day 8] Special by John Hammond Santa’s Bag of Toys
Read the premise above, start the attached Windows analysis machine and find the transcription logs in the SantasLaptopLogs folder on the…
Hacking on Medium
My CRTP Bootcamp Experience
https://cdn-images-1.medium.com/max/2000/0*KWLPydUzdgLPC1Tp.png
A little Background
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My CRTP Bootcamp Experience
https://cdn-images-1.medium.com/max/2000/0*KWLPydUzdgLPC1Tp.png
A little Background
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My CRTP Bootcamp Experience
A little Background
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Persistence: COM Hijacking (MITRE: T1546.015)
IntroductionAccording to MITRE, “Adversaries can use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence.” To hijack a COM object, an attacker needs to make certain changes in registry hives and replace the reference to a legitimate system component with a malicious one. When that application is run and the COM object called, the malware is run instead, hence, giving persistence.Background· Attack Methodology· Discover Hijackable Keys· InProcServer32: CacheTask (Physical Access to Machine)· InProcServer32: CacheTask (Remote Access to Machine)· InProcServer32: Internet Explorer (Remote Access)· LocalServer32: Remote Access to Machine· ConclusionAccording to Microsoft, “The Microsoft Component Object Model (COM) is a platform-independent, distributed, object-oriented system for creating binary software components that can interact. COM is the foundation technology for Microsoft’s OLE (compound documents), ActiveX (Internet-enabled components), as well as others.Registries: The registry is a system-defined database in which applications and system components store and retrieve configuration data. The data stored in the registry varies according to the version of Microsoft Windows. Applications use the registry API to retrieve, modify, or delete registry data. More info here.CLSID: The CLSID or Class Identifier is a string of alphanumeric (both numbers and alphabet characters) symbols that are used to represent a specific instance of a Component Object Model or COM-based program. It allows operating systems and software, particularly for Windows, to detect and access software components without identifying them by their names. More info here.Attack MethodologyBasically, any application which is triggering an EXE/DLL or some other library, first reads the HKCU (HKEY_CURRENT_USER) value and then HKLM (HKEY_LOCAL_MACHINE). So[...]
___________________________
@hacking_Attack
@Hacking_Video
Windows Persistence: COM Hijacking (MITRE: T1546.015)
IntroductionAccording to MITRE, “Adversaries can use the COM system to insert malicious code that can be executed in place of legitimate software through hijacking the COM references and relationships as a means for persistence.” To hijack a COM object, an attacker needs to make certain changes in registry hives and replace the reference to a legitimate system component with a malicious one. When that application is run and the COM object called, the malware is run instead, hence, giving persistence.Background· Attack Methodology· Discover Hijackable Keys· InProcServer32: CacheTask (Physical Access to Machine)· InProcServer32: CacheTask (Remote Access to Machine)· InProcServer32: Internet Explorer (Remote Access)· LocalServer32: Remote Access to Machine· ConclusionAccording to Microsoft, “The Microsoft Component Object Model (COM) is a platform-independent, distributed, object-oriented system for creating binary software components that can interact. COM is the foundation technology for Microsoft’s OLE (compound documents), ActiveX (Internet-enabled components), as well as others.Registries: The registry is a system-defined database in which applications and system components store and retrieve configuration data. The data stored in the registry varies according to the version of Microsoft Windows. Applications use the registry API to retrieve, modify, or delete registry data. More info here.CLSID: The CLSID or Class Identifier is a string of alphanumeric (both numbers and alphabet characters) symbols that are used to represent a specific instance of a Component Object Model or COM-based program. It allows operating systems and software, particularly for Windows, to detect and access software components without identifying them by their names. More info here.Attack MethodologyBasically, any application which is triggering an EXE/DLL or some other library, first reads the HKCU (HKEY_CURRENT_USER) value and then HKLM (HKEY_LOCAL_MACHINE). So[...]
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Windows Persistence: COM Hijacking (MITRE: T1546.015)
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.