Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple paid out $36,000 bug bounty for HTTP request smuggling flaws

Apple paid out $36,000 bug bounty for HTTP request smuggling flawsPost Views: 79
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra

Subscribe to Patreon to watch this episode.
Reading Time: 1 Minute
A security researcher claims they netted $36,000 in bug bounties after uncovering critical HTTP request smuggling vulnerabilities affecting three of Apple’s core web applications.
The bug hunter, a 20-year-old hacker going by the online moniker ‘Stealthy’, said they deployed the same technique to achieve queue poisoning on the domains, paving the way to data disclosure and account takeover with no user interaction required.

The bugs supposedly affected servers for business.apple.com and school.apple.com, which businesses and schools respectively use to manage devices, apps, and accounts, as well as mapsconnect.apple.com, which organizations use to claim and manage business listings on Apple’s maps application.

The HTTP request smuggling flaws were CL.TE – or ‘Content-Length Transfer-Encoding’ – issues, whereby “the front-end server reads the Content-Length header in a request, and the backend server reads the Transfer-Encoding header”, Stealthy explained in a Medium blog post. Vulnerabilities arise because the servers disagree on where requests begin and end.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Redirecting live users“A transformation was needed in the Transfer-Encoding header on Apple’s websites using a newline character and then a space in the header name,” said Stealthy.

This change – Transfer-Encoding\n : chunked – “successfully slipped the header past the frontend server but [it] was still used by the backend”.

Based on this observation Stealthy crafted the first proof of concept.

“My smuggled path is /static/docs because a redirect occurs there, using the Host header value in the redirect,” continued the researcher. “Thus, I could redirect live users to my server to ensure that the request smuggling affects production users.”
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH This would enable attackers to redirect JavaScript imports and achieve stored cross-site scripting (XSS) on the host.

More impactful still was the servers’ vulnerability to queue poisoning, an attack technique that “smuggles a complete request and breaks the response queue, which will start sending random responses to unintended users”.

All response data, including Set-Cookie headers, could be disclosed by this technique, the researcher claims.

Apple responded to the bug report quickly, remediated the vulnerabilities, and paid Stealthy a $12,000 bug bounty reward for each domain. See Also: Offensive Security Tool: Scapy Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/3e41-article-210226-vmware-body-text-90x90.jpg VMware warns of critical vulnerabilities in multiple products1 day ago
* https://www.blackhatethical[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple paid out $36,000 bug bounty for HTTP request smuggling flaws Apple paid out $36,000 bug bounty for HTTP request smuggling flawsPost Views: 79 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png…
hacking.com/wp-content/uploads/2022/04/A-New-Borat-RAT-Capable-Of-Conducting-Ransomware-DDOS-Activities-90x90.png No-Joke Borat RAT Propagates Ransomware, DDoS2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/ee3dc49c79d14f20970cc8b20063f52e-90x90.jpg Flash loan attack on One Ring protocol nets crypto-thief $1.4 million2 weeks ago
The post Apple paid out $36,000 bug bounty for HTTP request smuggling flaws first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Broken Access Control Logic\`s

Access control enforces policy such that users cannot act outside of their intended permissions. Failures typically lead to unauthorized…Continue reading on Medium »
Read more...
Stripe checkout misconfiguration leads to an unlimited trial period

A quick check when doing recon on your target could lead to an unlimited trial period as I discovered this week while working on a bug…Continue reading on Medium »
Read more...
hacking: security in practice
Is ShopPay from Shopify secure?

I've tried googling but coming up empty. Does anyone know of any instances of ShopPay users getting sim swapped or user enumeration attacks against the service? It seems to be gaining in popularity but I just can't see how relying on SMS OTP as your only authentication (I'm fairly certain this is how it works) isn't getting obliterated by hackers. Theoretically, all you'd need is an email/phone number pair which shouldn't be hard to get and then sim swap (or whatever - I'm not a hacker, just interested in security) the phone number. Then you can authenticate as the user on a store that uses ShopPay.

Is it just that, to benefit from the hack, you'd be buying yourself products and would need to ship them somewhere you have access to which would be fairly easy for police to track down - is that what keeps people from getting hacked? Surely you could still use it to attack an individual who uses ShopPay - just buy a lot of things with their account and ship to random addresses.

Again - not a hacker here so I may not be thinking about this the right way. 🤔

submitted by /u/revscankof
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Notion (yes, the notetaking app) as a C2.
Wait, What? Yes. But Why? What started as a meme grew into a full project. Just roll with it. Read more! Here's our blog post about it: We Put A C2 In Your Notetaking App: OffensiveNotion (https://medium.com/@huskyhacks.mk/we-put-a-c2-in-your-notetaking-app-offensivenotion-3e933bace332)
Features A full-featured C2 platform built on the Notion notetaking app. Easy setup: set up your Notion developer API account, drop the Agent to the target, run and enjoy! Cross-platform agent built in Rust that compiles for Linux, Windows, and macOS with the same code base. Includes a Python setup/controller script to simplify the process. A range of capabilities including port-scanning, privilege (https://www.kitploit.com/search/label/Privilege) escalation, asynchronous command execution, file download, and shellcode injection, all controlled from the comfort of a Notion page! Document as you go! The agent identifies special syntax to run commands, so feel free to use the rest of the Notion page to document your operation. Collaborative by design! Notion allows for multiple people to edit and view your notes. Your listener (https://www.kitploit.com/search/label/Listener) page can handle multiple agents and you can invite your red team (https://www.kitploit.com/search/label/Red%20Team) friends to your page. Congratulations, that's a teamserver! Mobile C2! Use the Notion application from your mobile device to issue commands to your agents from anywhere in the world. Stealth! C2 comms ride over the Notion API natively. Your C2 traffic looks like someone is using Notion for its intended purpose. Quickstart See the Quickstart guide (https://github.com/mttaggart/OffensiveNotion/wiki/2.-Quickstart) on how to get going right away! Documentation Please see the Wiki (https://github.com/mttaggart/OffensiveNotion/wiki) for setup, usage, commands, and more! Thanks & Acknowledgements This project has been a blast for me! I learned a ton about Rust and how the mechanics of a C2 work. So thank you to my co-creator @mttaggart for helping me along the way. None of this would have been possible without your technical acumen and creativity. Thank you to Joe Helle (@joehelle) for the POC steps for the fodhelper UAC bypass. Thank you to all of the great red team devs who came before me, too numerous to list them all, who have created some of my favorite tools. I’m continually inspired by the red dev innovation in our field. -Husky As a fairly new security person, I had no idea I'd end up working with such a fantastically talented, kind, and reliable partner and hacker as @HuskyHacks. It's been a true privilege to build this alongside him. I want to thank the Taggart Tech (https://twitch.tv/mttaggart) community for supporting us along the way and always offering helpful feedback. This would not be possible without you all. -Taggart Disclaimer There is no way to make an offensive security relevant research (https://www.kitploit.com/search/label/Research) tool and release it open source without the possibility of it falling into the wrong hands. This tool is only to be used for legal, ethical purposes including, but not limited to, research, security assessment, education. The dev team is not responsible for the misuse of this tool by anyone if used for illegal/unethical purposes. No animals were harmed in the making of this code base (although Cosmo keeps climbing on my keyboard and I have to put him over on the couch, which I'm sure must feel like torture to him). See the LICENSE for more details.

Download OffensiveNotion (https://github.com/mttaggart/OffensiveNotion)

___________________________
@hacking_Attack
@Hacking_Video