Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Advice

I’m a senior in high school and wanting to have a career in the cybersecurity field. My plan is two years community college to get preliminary things out of the way. I’m then going to bridge to a different university where I’m going to finish my studies and get my bachelors. Any tips on things I can do to prepare myself for this career path I’m going down? Thanks

submitted by /u/SpicyLikeTakis
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Mac spoofing?

Surely, mac spoofing isn't the only thing that saves you from being located when hacking? Is there more ways to cover tracks?

Trying to creat a lab, so I can start pentesting and maybe trying my hand at bug bounties, but I want to be invisible first. DMs are welcome but please no links 😊.

Sure vpn can change location, but not fail proof and not safe regardless.

submitted by /u/IAmCrossLed
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Mastering CTFs as an intermediate.

I've been doing CTFs for a while now but i always run into a speed bump. The said speed bump is mostly a concept(like a service) that I've never studied and plus if I were to study it, it would take a long while to understand a concept deep enough to find loopholes. So what is the easiest way to counteract and penetrate new services? Or what should I be reading before I really get into CTFs

submitted by /u/h4cks1n
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
project ideas

I've been doing hackthebox and tryhackme but I'm getting tired of it. Any ideas on what i should do?

submitted by /u/void02241
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
VMware warns of critical vulnerabilities in multiple products

VMware warns of critical vulnerabilities in multiple productsPost Views: 27
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra

Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
VMware has warned customers to immediately patch critical vulnerabilities in multiple products that threat actors could use to launch remote code execution attacks.
“This critical vulnerability should be patched or mitigated immediately per the instructions in VMSA-2021-0011. The ramifications of this vulnerability are serious,” VMware warned on Wednesday.

“All environments are different, have different tolerance for risk, and have different security controls and defense-in-depth to mitigate risk, so customers must make their own decisions on how to proceed. However, given the severity of the vulnerability, we strongly recommend immediate action.” Patches for five critical vulnerabilitiesThe list of critical security flaws patched today includes a server-side template injection remote code execution vulnerability (CVE-2022-22954), two OAuth2 ACS authentication bypass vulnerabilities (CVE-2022-22955, CVE-2022-22956), and two JDBC injection remote code execution vulnerabilities (CVE-2022-22957, CVE-2022-22958).

VMware also patched high and medium severity bugs that could be exploited for Cross-Site Request Forgery (CSRF) attacks (CVE-2022-22959), escalate privileges (CVE-2022-22960), and gain access to information without authorization (CVE-2022-22961).
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
The complete list of VMware products impacted by these security vulnerabilities includes:

* VMware Workspace ONE Access (Access)
* VMware Identity Manager (vIDM)
* VMware vRealize Automation (vRA)
* VMware Cloud Foundation
* vRealize Suite Lifecycle Manager

The company added that it found no evidence of these bugs being exploited in the wild before today’s security advisory was published. VMware’s knowledgebase website also has a complete list of fixed versions and download links to hotfix installers.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Workaround also availableVMware also provides workarounds for those who cannot immediately patch their appliances as a temporary solution. The steps detailed here require admins to run a VMware-provided Python-based script on affected virtual appliances.

However, the company says that the only way to remove the vulnerabilities entirely is to apply the patches.

“Workarounds, while convenient, do not remove the vulnerabilities, and may introduce additional complexities that patching would not,” VMware added.

“While the decision to patch or use the workaround is yours, VMware always strongly recommends patching as the simplest and most reliable way to resolve this issue.”

A document with additional questions and answers regarding the critical vulnerabilities patched today is available here.

On Monday, VMware also released security updates to address the critical Spring4Shell RCE flaw in VMware Tanzu Application Service for VMs, VMware Tanzu Operations Manager, and VMware Tanzu Kubernetes Grid Integrated Edition (TKGI). See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking VMware warns of critical vulnerabilities in multiple products VMware warns of critical vulnerabilities in multiple productsPost Views: 27 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced…
us here for a quote: info@blackhatethicalhacking.com
See Also: Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/A-New-Borat-RAT-Capable-Of-Conducting-Ransomware-DDOS-Activities-90x90.png No-Joke Borat RAT Propagates Ransomware, DDoS1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ezgif.com-gif-maker-3-1-90x90.jpg DeadBolt Ransomware Resurfaces to Hit QNAP Again2 weeks ago
The post VMware warns of critical vulnerabilities in multiple products first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
This repo contains shell scripts that can be used to download and analyze differences between cloned and mirror Git repositories. For more information about the underlying quirk in Git behavior, please visit read our blog post (https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/).
What Do These Scripts (https://www.kitploit.com/search/label/Scripts) Do? These scripts will clone a copy of the given Git repository, both as regular clone and mirrored ("--mirror") option. It will then create a delta between the two, seeking to find the parts of the repository that are only available in mirror mode. Last, gitleaks (https://www.kitploit.com/search/label/Gitleaks) will be run to see if any secrets (https://www.kitploit.com/search/label/Secrets) are present in the delta portion, and "git log" will be used to create a single file containing the bodies of the commits so they can be analyzed easier. Please note that since this script creates three copies of the repository, it may consume a lot of disk space. Example repositories You can test these tools on the following two example repositories: gb_testrepo_delete (https://github.com/nightwatchcybersecurity/gb_testrepo_delete) - repository hiding secrets via deleted commits gb_testrepo_reset (https://github.com/nightwatchcybersecurity/gb_testrepo_reset) - repository hiding secrets via "git reset" Requirements You will need Git (https://git-scm.com/), Python 3 (https://www.python.org/). GitLeaks (https://github.com/zricethezav/gitleaks) and git-filter-repo (https://github.com/newren/git-filter-repo) to be installed. Here is an example of installing these on MacOS: brew install git python3 gitleaks git-filter-repo
How to Install and Run You can run this againt a repository as follows: git clone https://github.com/nightwatchcybersecurity/gitbleed_tools.git
cd gitbleed_tools
./gitbleed.sh https://github.com/nightwatchcybersecurity/gitbleed_tools.git example
There are also some helper scripts that can be used to scan GitHub and GitLab repositories (https://www.kitploit.com/search/label/Repositories) as follows: ./gitbleed_gh.sh nightwatchcybersecurity/gitbleed_tools
./gitbleed_gl.sh nwcs/junit_ui_bug
This will create an example folder containing three subfolders: clone - contains the cloned repository delta - contains the mirrrored repository minus all of the commits in the "clone" mirror - contains the mirrored repository cloned with the "--mirror" option There are also three files created: clone_hashes.done.txt - list of hashes (https://www.kitploit.com/search/label/Hashes) in the cloned repository gitleaks.json - results from running gitleaks gitlog.txt - all commits from the delta folder concatenated into a single file Development Information Reporting bugs and feature requests Please use the GitHub issue tracker to report issues or suggest features: https://github.com/nightwatchcybersecurity/gitbleed_tools You can also send emai to research /at/ nightwatchcybersecurity [dot] com Wishlist TBD

Download Gitbleed_Tools (https://github.com/nightwatchcybersecurity/gitbleed_tools)

___________________________
@hacking_Attack
@Hacking_Video