Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Vimana is a modular security framework designed to audit Python web applications.The base of the Vimana is composed of crawlers focused on…Continue reading on Medium » (https://medium.com/@pentesterclubpvtltd/vimana-an-experimental-security-framework-that-aims-to-provide-resources-for-auditing-python-web-app-ad21f24a175c?source=rss------bug_bounty-5)
A CTF web challenge about making screenshots. It is inspired by a bug found in real life. The challenge was created by @LiveOverflow for…Continue reading on Medium » (https://medium.com/@pentesterclubpvtltd/ctf-screenshotter-a-ctf-web-challenge-about-making-screenshots-7ed0a5a5f29b?source=rss------bug_bounty-5)
hacking: security in practice
shocked to have found a password easily

Before when I took control of a person's computer thanks to my program that he downloaded via phishing

I remember one day, I came across a pc where I activated the webcam out of curiosity and I found a paper on the desk where it was written: Daisy108277189

I tested the password on the Gmail account and it worked the first time! It was the first time it had happened to me: finding the password the first time, WTF!

I was so shocked that I logged out and left him a text file that said I broke into his computer and he needs to change his password.

I went from black hat to gray hat in 2 seconds!

submitted by /u/Melodic-Heart-1172
[link] [comments]
hacking: security in practice
Is this malicious? Or legitimate

Get.misguided.com Windows activator txt.

I’m trying to active windows. I’m running it in a VM.

There are videos on YouTube. Idk if the the comments are legit.

It’s not malicious right?

Anyone fact check it

submitted by /u/Waltc222
[link] [comments]
hacking: security in practice
Looking to build a CTF from scratch for a school assignment. I have never done this before and only done two CTFs myself.

Like the title says, I need to build a CTF. The requirements are very relaxed: Can be on any platform and employ any measure of vulnerability. Just need a way to submit to my prof. I think if I could just get a rough idea of what I want to build I could troubleshoot my way through it, but am having a tough time getting a plan together. I am getting more comfortable with linux and would like to build a vulnerable linux box, but I just don’t have a place to start

submitted by /u/YungLawn0
[link] [comments]
hacking: security in practice
Looking to meet/talk with hackers on VC about how it's like and how to begin.

I am an intermediate programmer and I have been interested in this field for a while. I would love to have a conversation with people who live this life style and wouldn't mind sharing knowledge.

If anyone is interested I will send you my discord! :)

submitted by /u/Nimai_TV
[link] [comments]
hacking: security in practice
Hackers keep finding me on skribbl.io?

So I played skribbl.io while chilling and all of a sudden these guys just started talking about things I know. I have formatted my Windows PC a few times but they always come back. I don’t even feel mad or anything, I just want to find out how they did it so I can regain my privacy and move on. I don’t know if this is interesting enough for the rules. I hope it is. Basically long story short is I befriended a narcissist, I realise they are a narcissist, tried to get away, process of getting away was very messy, lot of people then chose sides between him and me, but worst of all, even though I’m not around him anymore, and I told him I don’t want to be around him anymore, he’s still leaching on me. He basically just checks on what I do on the cyber world, if they see I have friends or whatever on the cyber world they tell that person how bad of a person I am, I lose that friend, and this basically just keeps happening. So how do I regain my privacy?

submitted by /u/GoldenwithaG
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info

Attackers Spoof WhatsApp Voice-Message Alerts to Steal InfoPost Views: 45
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra

Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are spoofing voice message notifications from WhatsApp in a malicious phishing campaign that uses a legitimate domain to spread an info-stealing malware.
Researchers at cloud email security firm Armorblox discovered the malicious campaign targeting Office 365 and Google Workspace accounts using emails sent from domain associated with the Center for Road Safety, an entity believed to reside within the Moscow, Russia region. The site itself is legitimate, as it’s connected to the State Road Safety operations for Moscow and belongs to the Ministry of Internal Affairs of the Russian Federation, according to a blog post published Tuesday.

So far, attackers have reached about 27,660 mailboxes with the campaign, which spoofs WhatsApp by informing victims they have a “new private voicemail” from the chat app and includes a link purporting to allow them to play it, researchers said. Targeted organizations include healthcare, education and retail, researchers said.

The attack “employs a gamut of techniques to get past traditional email security filters and pass the eye tests of unsuspecting victims,” Armorblox Product Marketing Manager Lauryn Cash wrote in the post.

Those tactics include social engineering by eliciting trust and urgency in the emails sent to victims; brand impersonation by spoofing WhatsApp; the exploitation of a legitimate domain from which to send the emails; and the replication of existing workflows, i.e. getting an email notification of a voice message, Cash explained.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png How It WorksPotential victims of the campaign receive an email with the title “New Incoming Voice message” that includes a header in the email body reiterating this title. The email body spoofs a secure message from WhatsApp and tells the victim that he or she has received a new private voicemail, including a “Play” button so they allegedly can listen to the message.

The domain of the email sender was “mailman.cbddmo.ru,” which Amorblox researchers linked to the center for road safety of the Moscow region page–a legitimate site that allows the emails to slip past both Microsoft and Google’s authentication checks, they said. However, it’s possible that attackers exploited a deprecated or old version of this organization’s parent domain to send the malicious emails, they acknowledged.

If the recipient clicks the email’s “Play” link, he or she is redirected to a page that attempts to install a trojan horse JS/Kryptik–a malicious obfuscated JavaScript code embedded in HTML pages that redirects the browser to a malicious URL and implements a specific exploit, according to the post.

Once the target lands on the malicious page, a prompt asks for confirmation that the victim is not a robot. Then, if the victim clicks “allow” on the popup notification in the URL, a browser ad service can install the malicious payload as a Windows application, allowing it to bypass User Account Control.

“Once the malware was installed … it can steal sensitive information like credentials that are stored within the browser,” Cash wrote.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Targeting Unsuspecting ConsumersWhile the campaign appears to be focused on consumers rather than businesses[...]

___________________________
@hacking_Attack
@Hacking_Video