hacking: security in practice
How could I play a sound on my school intercom system.
I wanna hack my schools intercom system so I can play some pranks on the school for the end of the year. I know how to get into the school undetected (don't ask how) so I might be able to put a wireless bluetooth adapter into the system. Would that work or do I need to do something else.
submitted by /u/IAmABot123boi
[link] [comments]
How could I play a sound on my school intercom system.
I wanna hack my schools intercom system so I can play some pranks on the school for the end of the year. I know how to get into the school undetected (don't ask how) so I might be able to put a wireless bluetooth adapter into the system. Would that work or do I need to do something else.
submitted by /u/IAmABot123boi
[link] [comments]
reddit
How could I play a sound on my school intercom system.
I wanna hack my schools intercom system so I can play some pranks on the school for the end of the year. I know how to get into the school...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Announcing Reddit’s Public Bug Bounty Program Launch
submitted by /u/DrinkMoreCodeMore
[link] [comments]
Announcing Reddit’s Public Bug Bounty Program Launch
submitted by /u/DrinkMoreCodeMore
[link] [comments]
How I was able to find and exploit the Google Maps API key of a target and you can do it too
https://chirag0x22.medium.com/how-i-was-able-to-find-and-exploit-the-google-maps-api-key-of-a-target-and-you-can-do-it-too-8142ba0453cb?source=rss------bug_bounty-5
https://chirag0x22.medium.com/how-i-was-able-to-find-and-exploit-the-google-maps-api-key-of-a-target-and-you-can-do-it-too-8142ba0453cb?source=rss------bug_bounty-5
Hey, What’s Up Fellow Hackers & pro bug bounty hunters hope you are doing well and staying safe, hunting heavily and bunking online…Continue reading on Medium » (https://chirag0x22.medium.com/how-i-was-able-to-find-and-exploit-the-google-maps-api-key-of-a-target-and-you-can-do-it-too-8142ba0453cb?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
UAC : Unix-like Artifacts Collector
UAC is a Live Response collection tool for Incident Response that makes use of built-in tools to automate the collection of Unix-like systems artifacts. It respects the order of volatility and artifacts that are changed during the execution. It was created to facilitate and speed up data collection, and depend less on remote support during […]
The post UAC : Unix-like Artifacts Collector appeared first on Kali Linux Tutorials.
UAC : Unix-like Artifacts Collector
UAC is a Live Response collection tool for Incident Response that makes use of built-in tools to automate the collection of Unix-like systems artifacts. It respects the order of volatility and artifacts that are changed during the execution. It was created to facilitate and speed up data collection, and depend less on remote support during […]
The post UAC : Unix-like Artifacts Collector appeared first on Kali Linux Tutorials.
Pentesting toolset
https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/
<!-- SC_OFF -->Hi,
I've put up useful pentesting tools on https://forefy.com/
📝JWT resigner (that supports none,None,RS->HS downgrade vuln)
🔧 Useful oneliners and commands used in web and infra PT
🛰 HTTP request catcher to aid with blind XSS, XXE and more
💉 Chrome extension to passively look for secret keys and exposed buckets Please let me know what you think! <!-- SC_ON --> submitted by /u/forefy (https://www.reddit.com/user/forefy)
[link] (https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/) [comments] (https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/)
https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/
<!-- SC_OFF -->Hi,
I've put up useful pentesting tools on https://forefy.com/
📝JWT resigner (that supports none,None,RS->HS downgrade vuln)
🔧 Useful oneliners and commands used in web and infra PT
🛰 HTTP request catcher to aid with blind XSS, XXE and more
💉 Chrome extension to passively look for secret keys and exposed buckets Please let me know what you think! <!-- SC_ON --> submitted by /u/forefy (https://www.reddit.com/user/forefy)
[link] (https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/) [comments] (https://www.reddit.com/r/Pentesting/comments/mrb9sf/pentesting_toolset/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
New Saint Bot Malware Dropper Shared using Phishing Emails
https://cdn-images-1.medium.com/max/1356/1*Hc4AnuD9l8_x0K3OjFG4Yg.jpeg
A new malware variant being referred to as Saint Bot malware is being shared using phishing emails that feature a Bitcoin-themed lure. As…
Continue reading on Medium »
New Saint Bot Malware Dropper Shared using Phishing Emails
https://cdn-images-1.medium.com/max/1356/1*Hc4AnuD9l8_x0K3OjFG4Yg.jpeg
A new malware variant being referred to as Saint Bot malware is being shared using phishing emails that feature a Bitcoin-themed lure. As…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Advent of Cyber 2 walkthrough part 2
https://cdn-images-1.medium.com/max/1920/1*B4NRDBmef0SCDsmT1EnNCQ.jpeg
Hi guys,
Our day two to start here. In our previous section, we learn more about cookies and authentication. In today’s section, we learn…
Continue reading on InfoSec Write-ups »
Advent of Cyber 2 walkthrough part 2
https://cdn-images-1.medium.com/max/1920/1*B4NRDBmef0SCDsmT1EnNCQ.jpeg
Hi guys,
Our day two to start here. In our previous section, we learn more about cookies and authentication. In today’s section, we learn…
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in totalPost Views: 94
Reading Time: 1 Minute
Microsoft had its hands full Tuesday snuffing out five zero-day vulnerabilities, a flaw under active attack and applying more patches to its problem-plagued Microsoft Exchange Server software.
In all, Microsoft released patches for 110 security holes, 19 classified critical in severity and 88 considered important. The most dire of those flaws disclosed is arguably a Win32k elevation of privilege vulnerability (CVE-2021-28310) actively being exploited in the wild by the cybercriminal group BITTER APT. Actively Exploited Zero-Day“We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access,” wrote Kaspersky in a Tuesday report detailing its find.
The bug is an out-of-bounds write vulnerability in Windows dwmcore.dll library, which is part of Desktop Window Manager (dwm.exe). “Due to the lack of bounds checking, attackers are able to create a situation that allows them to write controlled data at a controlled offset using DirectComposition API,” wrote Kaspersky researchers Boris Larin, Costin Raiu and Brian Bartholomew, co-authors of the report.
See Also: Chrome Zero-Day Exploit Posted on Twitter More Bugs Tied to Plagued ExchangeOf note, the U.S. National Security Agency released information on four critical Exchange Server vulnerabilities (CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483) impacting versions released between 2013 and 2019.
“These vulnerabilities have been rated ‘exploitation more likely’ using Microsoft’s Exploitability Index. Two of the four vulnerabilities (CVE-2021-28480, CVE-2021-28481) are pre-authentication, meaning an attacker does not need to authenticate to the vulnerable Exchange server to exploit the flaw. With the intense interest in Exchange Server since last month, it is crucial that organizations apply these Exchange Server patches immediately,” wrote Satnam Narang, staff research engineer with Tenable in commentary shared with Threatpost.
Microsoft notes that two of the four Exchange bugs reported by the NSA were also found internally by its own research team.
See Also: Offensive Security Tool: CVE Binary Tool by Intel https://media.threatpost.com/wp-content/uploads/sites/103/2020/09/25150114/Bug-Bounty-Code_small-300x198.jpg Bugs, Bugs and More BugsMicrosoft also included patches for its Chromium-based Edge web browser, Azure and Azure DevOps Server, Microsoft Office, SharePoint Server, Hyper-V, Team Foundation Server and Visual Studio.
“April’s Patch Tuesday yields… [are] the highest monthly total for 2021 (so far) and showing a return to the 100-plus totals we consistently saw in 2020,” wrote Justin Knapp, senior product marketing manager with Automox, in a prepared analysis shared with Threatpost. “This month’s haul includes 19 critical vulnerabilities and a high-severity zero-day that is actively being exploited in the wild.”
He added, “We’re also seeing multiple browser-related vulnerabilities this month that should be addressed immediately. This represents an overall upward trend that’s expected to continue throughout the year and draw greater urgency around patching velocity, to ensure organizations are not taking on unnecessary exposure — especially given the increased exploitation of[...]
Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in totalPost Views: 94
Reading Time: 1 Minute
Microsoft had its hands full Tuesday snuffing out five zero-day vulnerabilities, a flaw under active attack and applying more patches to its problem-plagued Microsoft Exchange Server software.
In all, Microsoft released patches for 110 security holes, 19 classified critical in severity and 88 considered important. The most dire of those flaws disclosed is arguably a Win32k elevation of privilege vulnerability (CVE-2021-28310) actively being exploited in the wild by the cybercriminal group BITTER APT. Actively Exploited Zero-Day“We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access,” wrote Kaspersky in a Tuesday report detailing its find.
The bug is an out-of-bounds write vulnerability in Windows dwmcore.dll library, which is part of Desktop Window Manager (dwm.exe). “Due to the lack of bounds checking, attackers are able to create a situation that allows them to write controlled data at a controlled offset using DirectComposition API,” wrote Kaspersky researchers Boris Larin, Costin Raiu and Brian Bartholomew, co-authors of the report.
See Also: Chrome Zero-Day Exploit Posted on Twitter More Bugs Tied to Plagued ExchangeOf note, the U.S. National Security Agency released information on four critical Exchange Server vulnerabilities (CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, CVE-2021-28483) impacting versions released between 2013 and 2019.
“These vulnerabilities have been rated ‘exploitation more likely’ using Microsoft’s Exploitability Index. Two of the four vulnerabilities (CVE-2021-28480, CVE-2021-28481) are pre-authentication, meaning an attacker does not need to authenticate to the vulnerable Exchange server to exploit the flaw. With the intense interest in Exchange Server since last month, it is crucial that organizations apply these Exchange Server patches immediately,” wrote Satnam Narang, staff research engineer with Tenable in commentary shared with Threatpost.
Microsoft notes that two of the four Exchange bugs reported by the NSA were also found internally by its own research team.
See Also: Offensive Security Tool: CVE Binary Tool by Intel https://media.threatpost.com/wp-content/uploads/sites/103/2020/09/25150114/Bug-Bounty-Code_small-300x198.jpg Bugs, Bugs and More BugsMicrosoft also included patches for its Chromium-based Edge web browser, Azure and Azure DevOps Server, Microsoft Office, SharePoint Server, Hyper-V, Team Foundation Server and Visual Studio.
“April’s Patch Tuesday yields… [are] the highest monthly total for 2021 (so far) and showing a return to the 100-plus totals we consistently saw in 2020,” wrote Justin Knapp, senior product marketing manager with Automox, in a prepared analysis shared with Threatpost. “This month’s haul includes 19 critical vulnerabilities and a high-severity zero-day that is actively being exploited in the wild.”
He added, “We’re also seeing multiple browser-related vulnerabilities this month that should be addressed immediately. This represents an overall upward trend that’s expected to continue throughout the year and draw greater urgency around patching velocity, to ensure organizations are not taking on unnecessary exposure — especially given the increased exploitation of[...]
Black Hat Ethical Hacking
Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total
Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total
2fa Bypass Using Response Manipulation
Hi Folks I am Vaibhav Gaikwad Bug Bounty Hunter from India and i recently found a 2fa bypass using Response Manipulation bug on Bugcrowd…Continue reading on Medium »
Read more...
Hi Folks I am Vaibhav Gaikwad Bug Bounty Hunter from India and i recently found a 2fa bypass using Response Manipulation bug on Bugcrowd…Continue reading on Medium »
Read more...
2fa Bypass Using Response Manipulation
https://vaibhavgaikwad1712.medium.com/2fa-bypass-using-response-manipulation-29d6c2583936?source=rss------bug_bounty-5
https://vaibhavgaikwad1712.medium.com/2fa-bypass-using-response-manipulation-29d6c2583936?source=rss------bug_bounty-5
Hi Folks I am Vaibhav Gaikwad Bug Bounty Hunter from India and i recently found a 2fa bypass using Response Manipulation bug on Bugcrowd…Continue reading on Medium » (https://vaibhavgaikwad1712.medium.com/2fa-bypass-using-response-manipulation-29d6c2583936?source=rss------bug_bounty-5)