Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet Malware. This is far from the first time the botnet operators have quickly added newly publicized flaws to their exploit toolset. last year, multiple botnets were uncovered leveraging the Log4Shell to breach susceptible servers.
https://external-preview.redd.it/WSF6aZTPaXiv_7pFWIPM8sc2tMEBJgsV4ENNbxTYelQ.jpg?width=640&crop=smart&auto=webp&s=484629d97d502b18c06a923b9c27b61251b98c45 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet Malware. This is far from the first time the botnet operators have quickly added newly publicized flaws to their exploit toolset. last year, multiple botnets were uncovered leveraging the Log4Shell to breach susceptible servers.
https://external-preview.redd.it/WSF6aZTPaXiv_7pFWIPM8sc2tMEBJgsV4ENNbxTYelQ.jpg?width=640&crop=smart&auto=webp&s=484629d97d502b18c06a923b9c27b61251b98c45 submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info
Attackers Spoof WhatsApp Voice-Message Alerts to Steal InfoPost Views: 45
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are spoofing voice message notifications from WhatsApp in a malicious phishing campaign that uses a legitimate domain to spread an info-stealing malware.
Researchers at cloud email security firm Armorblox discovered the malicious campaign targeting Office 365 and Google Workspace accounts using emails sent from domain associated with the Center for Road Safety, an entity believed to reside within the Moscow, Russia region. The site itself is legitimate, as it’s connected to the State Road Safety operations for Moscow and belongs to the Ministry of Internal Affairs of the Russian Federation, according to a blog post published Tuesday.
So far, attackers have reached about 27,660 mailboxes with the campaign, which spoofs WhatsApp by informing victims they have a “new private voicemail” from the chat app and includes a link purporting to allow them to play it, researchers said. Targeted organizations include healthcare, education and retail, researchers said.
The attack “employs a gamut of techniques to get past traditional email security filters and pass the eye tests of unsuspecting victims,” Armorblox Product Marketing Manager Lauryn Cash wrote in the post.
Those tactics include social engineering by eliciting trust and urgency in the emails sent to victims; brand impersonation by spoofing WhatsApp; the exploitation of a legitimate domain from which to send the emails; and the replication of existing workflows, i.e. getting an email notification of a voice message, Cash explained.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png How It WorksPotential victims of the campaign receive an email with the title “New Incoming Voice message” that includes a header in the email body reiterating this title. The email body spoofs a secure message from WhatsApp and tells the victim that he or she has received a new private voicemail, including a “Play” button so they allegedly can listen to the message.
The domain of the email sender was “mailman.cbddmo.ru,” which Amorblox researchers linked to the center for road safety of the Moscow region page–a legitimate site that allows the emails to slip past both Microsoft and Google’s authentication checks, they said. However, it’s possible that attackers exploited a deprecated or old version of this organization’s parent domain to send the malicious emails, they acknowledged.
If the recipient clicks the email’s “Play” link, he or she is redirected to a page that attempts to install a trojan horse JS/Kryptik–a malicious obfuscated JavaScript code embedded in HTML pages that redirects the browser to a malicious URL and implements a specific exploit, according to the post.
Once the target lands on the malicious page, a prompt asks for confirmation that the victim is not a robot. Then, if the victim clicks “allow” on the popup notification in the URL, a browser ad service can install the malicious payload as a Windows application, allowing it to bypass User Account Control.
“Once the malware was installed … it can steal sensitive information like credentials that are stored within the browser,” Cash wrote.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Targeting Unsuspecting ConsumersWhile the campaign appears to be focused on consumers rather than businesses[...]
___________________________
@hacking_Attack
@Hacking_Video
Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info
Attackers Spoof WhatsApp Voice-Message Alerts to Steal InfoPost Views: 45
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced Enumeration techniques with NMAP, Zenmap and Hydra
Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Attackers are spoofing voice message notifications from WhatsApp in a malicious phishing campaign that uses a legitimate domain to spread an info-stealing malware.
Researchers at cloud email security firm Armorblox discovered the malicious campaign targeting Office 365 and Google Workspace accounts using emails sent from domain associated with the Center for Road Safety, an entity believed to reside within the Moscow, Russia region. The site itself is legitimate, as it’s connected to the State Road Safety operations for Moscow and belongs to the Ministry of Internal Affairs of the Russian Federation, according to a blog post published Tuesday.
So far, attackers have reached about 27,660 mailboxes with the campaign, which spoofs WhatsApp by informing victims they have a “new private voicemail” from the chat app and includes a link purporting to allow them to play it, researchers said. Targeted organizations include healthcare, education and retail, researchers said.
The attack “employs a gamut of techniques to get past traditional email security filters and pass the eye tests of unsuspecting victims,” Armorblox Product Marketing Manager Lauryn Cash wrote in the post.
Those tactics include social engineering by eliciting trust and urgency in the emails sent to victims; brand impersonation by spoofing WhatsApp; the exploitation of a legitimate domain from which to send the emails; and the replication of existing workflows, i.e. getting an email notification of a voice message, Cash explained.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png How It WorksPotential victims of the campaign receive an email with the title “New Incoming Voice message” that includes a header in the email body reiterating this title. The email body spoofs a secure message from WhatsApp and tells the victim that he or she has received a new private voicemail, including a “Play” button so they allegedly can listen to the message.
The domain of the email sender was “mailman.cbddmo.ru,” which Amorblox researchers linked to the center for road safety of the Moscow region page–a legitimate site that allows the emails to slip past both Microsoft and Google’s authentication checks, they said. However, it’s possible that attackers exploited a deprecated or old version of this organization’s parent domain to send the malicious emails, they acknowledged.
If the recipient clicks the email’s “Play” link, he or she is redirected to a page that attempts to install a trojan horse JS/Kryptik–a malicious obfuscated JavaScript code embedded in HTML pages that redirects the browser to a malicious URL and implements a specific exploit, according to the post.
Once the target lands on the malicious page, a prompt asks for confirmation that the victim is not a robot. Then, if the victim clicks “allow” on the popup notification in the URL, a browser ad service can install the malicious payload as a Windows application, allowing it to bypass User Account Control.
“Once the malware was installed … it can steal sensitive information like credentials that are stored within the browser,” Cash wrote.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH Targeting Unsuspecting ConsumersWhile the campaign appears to be focused on consumers rather than businesses[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info | Black Hat Ethical Hacking
Attackers are spoofing voice message notifications from WhatsApp in a malicious phishing campaign that uses a legitimate domain to spread an info-stealing malware
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info Attackers Spoof WhatsApp Voice-Message Alerts to Steal InfoPost Views: 45 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png Advanced…
, it could be a threat to corporate networks if victims take the bait and the malware is installed, one security professional noted.
“The complexity and sophistication of the techniques make it very hard for the average consumer to detect a malicious attempt,” Purandar Das, CEO and co-founder at Sotero, an encryption-based data security solutions company, wrote in an email to Threatpost. “You could potentially see a path where they are able to collect business information once the malware is deployed and active.”
‘Targeting consumers is a successful path for cybercriminals, as people seem to let their guard down more with electronic communication than real-life communication, noted another security professional. The average person often falls for online scams if they are familiar with the social-media platform claiming to be the message sender,” James McQuiggan, security awareness advocate at security firm KnowBe4, wrote in an email to Threatpost.
“When they see it, most people will recognize someone trying to scam them in real life,” he said, citing an example of New York City street merchant trying to sell a passer-by a fake brand-name watch or handbag. “Most people will know they are fake and carry on walking. McQuiggan observed. See Also: Offensive Security Tool: Scapy
However, many people might not recognize an email claiming to have a voicemail from a popular messaging app or another social media platform is a scam and go along with it, he said.
“Users are too accepting of emails,” McQuiggan said. “There needs to be more education for everyone, not just within organizations, to spot electronic social engineering or scams, so it is apparent like someone who is trying to sell a fake watch or handbag on the street.”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/f956-article-211015-apple-body-text-90x90.jpg Apple paid out $36,000 bug bounty for HTTP request smuggling flaws3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/3e41-article-210226-vmware-body-text-90x90.jpg VMware warns of critical vulnerabilities in multiple products4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/A-New-Borat-RAT-Capable-Of-Conducting-Ransomware-DDOS-Activities-90x90.png No-Joke Borat RAT Propagates Ransomware, DDoS5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities2 weeks ago
* http[...]
___________________________
@hacking_Attack
@Hacking_Video
“The complexity and sophistication of the techniques make it very hard for the average consumer to detect a malicious attempt,” Purandar Das, CEO and co-founder at Sotero, an encryption-based data security solutions company, wrote in an email to Threatpost. “You could potentially see a path where they are able to collect business information once the malware is deployed and active.”
‘Targeting consumers is a successful path for cybercriminals, as people seem to let their guard down more with electronic communication than real-life communication, noted another security professional. The average person often falls for online scams if they are familiar with the social-media platform claiming to be the message sender,” James McQuiggan, security awareness advocate at security firm KnowBe4, wrote in an email to Threatpost.
“When they see it, most people will recognize someone trying to scam them in real life,” he said, citing an example of New York City street merchant trying to sell a passer-by a fake brand-name watch or handbag. “Most people will know they are fake and carry on walking. McQuiggan observed. See Also: Offensive Security Tool: Scapy
However, many people might not recognize an email claiming to have a voicemail from a popular messaging app or another social media platform is a scam and go along with it, he said.
“Users are too accepting of emails,” McQuiggan said. “There needs to be more education for everyone, not just within organizations, to spot electronic social engineering or scams, so it is apparent like someone who is trying to sell a fake watch or handbag on the street.”
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Hacking stories: MafiaBoy, the hacker who took down the Internet
Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/f956-article-211015-apple-body-text-90x90.jpg Apple paid out $36,000 bug bounty for HTTP request smuggling flaws3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/3e41-article-210226-vmware-body-text-90x90.jpg VMware warns of critical vulnerabilities in multiple products4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/A-New-Borat-RAT-Capable-Of-Conducting-Ransomware-DDOS-Activities-90x90.png No-Joke Borat RAT Propagates Ransomware, DDoS5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-pear-hacked-packages-malware-90x90.png Supply chain flaws in PHP package manager PEAR lay undiscovered for 15 years6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/php-hack-90x90.jpg PHP bug allows attackers to bypass domain filters, stage DoS attacks against servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/apple-iphone-hacking-90x90.jpg Apple emergency update fixes zero-days used to hack iPhones, Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Google-Campus-90x90.jpg Google Chrome Bug Actively Exploited as Zero-Day2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/685f-article-211221-chrome-site-isolation-body-text-90x90.jpg HTML parser bug triggers Chromium XSS security flaw2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Polygon-hacker-90x90.jpg Hackers getting faster at latching onto unpatched vulnerabilities2 weeks ago
* http[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
, it could be a threat to corporate networks if victims take the bait and the malware is installed, one security professional noted. “The complexity and sophistication of the techniques make it very hard for the average consumer to detect a malicious attempt…
s://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/mitmproxy-90x90.png HTTP request smuggling bug patched in mitmproxy2 weeks ago
The post Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
The post Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Process Injection using CreateRemoteThread API
https://www.reddit.com/r/redteamsec/comments/u13bx2/process_injection_using_createremotethread_api/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/createremotethread-process-injection/) [comments] (https://www.reddit.com/r/redteamsec/comments/u13bx2/process_injection_using_createremotethread_api/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/u13bx2/process_injection_using_createremotethread_api/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/createremotethread-process-injection/) [comments] (https://www.reddit.com/r/redteamsec/comments/u13bx2/process_injection_using_createremotethread_api/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Process Injection using CreateRemoteThread API
Posted in r/redteamsec by u/tbhaxor • 1 point and 0 comments
SVG SSRFs and saga of bypasses
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…Continue reading on InfoSec Write-ups »
Read more...
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…Continue reading on InfoSec Write-ups »
Read more...
SVG SSRFs and saga of bypasses
https://infosecwriteups.com/svg-ssrfs-and-saga-of-bypasses-777e035a17a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/svg-ssrfs-and-saga-of-bypasses-777e035a17a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
SVG SSRFs and saga of bypasses
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/svg-ssrfs-and-saga-of-bypasses-777e035a17a7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
SVG SSRFs and saga of bypasses
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…
SVG SSRFs and saga of bypasses
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…Continue reading on InfoSec Write-ups »
Read more...
Hi all, hope you are keeping well and staying safe. This blog is about my recent experiences with SVG, HTML to PDF SSRF, and bypasses for…Continue reading on InfoSec Write-ups »
Read more...
[1/3] Brute-Force Protection Bypass @ GitLab
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…Continue reading on Medium »
Read more...
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…Continue reading on Medium »
Read more...
Spring4Shell
Spring4Shell and Spring Cloud RCE vulnerability ScannerContinue reading on Medium »
Read more...
Spring4Shell and Spring Cloud RCE vulnerability ScannerContinue reading on Medium »
Read more...
[1/3] Brute-Force Protection Bypass @ GitLab
https://medium.com/@_ip_/1-3-brute-force-protection-bypass-gitlab-15a17909bb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@_ip_/1-3-brute-force-protection-bypass-gitlab-15a17909bb?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
[1/3] Brute-Force Protection Bypass @ GitLab
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…Continue reading on Medium » (https://medium.com/@_ip_/1-3-brute-force-protection-bypass-gitlab-15a17909bb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
[1/3] Brute-Force Protection Bypass @ GitLab
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…
Spring4Shell and Spring Cloud RCE vulnerability ScannerContinue reading on Medium » (https://medium.com/@reconshell.com/spring4shell-880e32ef71da?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Spring4Shell
Spring4Shell and Spring Cloud RCE vulnerability Scanner
Hacking on Medium
Software Reverse Engineering: Ripping Apart Bomb Binary
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Software Reverse Engineering: Ripping Apart Bomb Binary
https://cdn-images-1.medium.com/max/1229/1*c_XHLtRJNpWn39go6fwM5w.png
Baby, I hate little secrets you keep from me x_x
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Software Reverse Engineering: Ripping Apart Bomb Binary
Baby, I hate little secrets you keep from me x_x
Hacking on Medium
[1/3] Brute-Force Protection Bypass @ GitLab
https://cdn-images-1.medium.com/max/600/1*b5dtRAJ1Y-yZKvqGBQn8iQ.jpeg
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[1/3] Brute-Force Protection Bypass @ GitLab
https://cdn-images-1.medium.com/max/600/1*b5dtRAJ1Y-yZKvqGBQn8iQ.jpeg
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[1/3] Brute-Force Protection Bypass @ GitLab
This is the first of three reports describing my findings from a review I did of Gitlab around 6 months ago. I thought I’d start with the…