hacking: security in practice
I received a message of someone claiming that infected me with njrat.
how should i proceed?
submitted by /u/JaponesBaiano
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I received a message of someone claiming that infected me with njrat.
how should i proceed?
submitted by /u/JaponesBaiano
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I received a message of someone claiming that infected me with njrat.
how should i proceed?
hacking: security in practice
Web Scraping a Google Contacts Directory
Not much "hacking" going on here, but I have a google organization directory for my school and it has about 20,000 contacts on it. I would like to get the email addresses that are on it to send a Rickroll email, but I am not able to select the emails all at once to copy them. So I would like to try web scraping and get the emails that way. However, I do not know much about how to web scrape. Another problem is that not all of the emails load at once. If the email is not currently on the screen, it will not load until I scroll down.Please tell me some services or methods that I can use to scrape the email addresses, or a way that I can get all of the email addresses to load at once.
submitted by /u/R4ndomP3rson69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Web Scraping a Google Contacts Directory
Not much "hacking" going on here, but I have a google organization directory for my school and it has about 20,000 contacts on it. I would like to get the email addresses that are on it to send a Rickroll email, but I am not able to select the emails all at once to copy them. So I would like to try web scraping and get the emails that way. However, I do not know much about how to web scrape. Another problem is that not all of the emails load at once. If the email is not currently on the screen, it will not load until I scroll down.Please tell me some services or methods that I can use to scrape the email addresses, or a way that I can get all of the email addresses to load at once.
submitted by /u/R4ndomP3rson69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Web Scraping a Google Contacts Directory
Not much "hacking" going on here, but I have a google organization directory for my school and it has about 20,000 contacts on it. I would like to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Atlassian has addressed a critical vulnerability in Jira software, tracked as CVE-2022-0540(CVSS score 9.9), that can be exploited by an unauthenticated attacker to bypass authentication. Threat actor could trigger the vulnerability by sending a specially crafted HTTP request to vulnerable software.
https://external-preview.redd.it/SwxCddYPLEy507Ufi7Zr4V5U_jUuK8sBVj0CrX6T268.jpg?width=216&crop=smart&auto=webp&s=27e65d503d5ff499a4e70b4f828d3c2e6d60c92e submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Atlassian has addressed a critical vulnerability in Jira software, tracked as CVE-2022-0540(CVSS score 9.9), that can be exploited by an unauthenticated attacker to bypass authentication. Threat actor could trigger the vulnerability by sending a specially crafted HTTP request to vulnerable software.
https://external-preview.redd.it/SwxCddYPLEy507Ufi7Zr4V5U_jUuK8sBVj0CrX6T268.jpg?width=216&crop=smart&auto=webp&s=27e65d503d5ff499a4e70b4f828d3c2e6d60c92e submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Atlassian has addressed a critical vulnerability in Jira software,...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
hacking: security in practice
How to target a computer outside local network?
I have an exploitable test machine running windows 7 and I know how to target it inside the local network with the local IP address to run metasploit exploits against it.
My question is, how do I target this same windows 7 machine outside the local network. If I use the public IP Address, isn't that just the IP address of my router that all the local machines use? How would I specify which machine in the network to target?
submitted by /u/Practical_Bathroom53
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to target a computer outside local network?
I have an exploitable test machine running windows 7 and I know how to target it inside the local network with the local IP address to run metasploit exploits against it.
My question is, how do I target this same windows 7 machine outside the local network. If I use the public IP Address, isn't that just the IP address of my router that all the local machines use? How would I specify which machine in the network to target?
submitted by /u/Practical_Bathroom53
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to target a computer outside local network?
I have an exploitable test machine running windows 7 and I know how to target it inside the local network with the local IP address to run...
help with crunch pelase!
https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/
hello guys i hope you all good! i need help guys plz with crunch i have list for name and i want start with min 9 and max 15 and my list like this.. mohamed ahmed kareem sonia yassin samy abdulrahman badr abdelaziz ayman agnaden tedata vodafone etisalat orange zen ziad mahmoud elhadad awad rawan youssif mostafa ameen ali zico coco koki dido isso toto tata oraby islam hesham hussein hossam magdy mido becker salem ibrahim said ssadek habiba khattab ashour noga hegazy rima tito sadek hakem safwat fawry tomy anoosh pitbull hema abaas diab shaban nader tolba ammar lamia gego temo saso abdelhakim *@-_!0987654321 ok the list is much long ...,so this is my list I didn't want the letters to change I just want the words to change EXMPLE: ahmedmohamed**1234 EXMPLE2: ahmedkoki@01085643 like this guys only words change not letters and (only numbers and symbols change with each other) I hope you can help me with your kindness and generosity thank you guys i wish you all the best. submitted by /u/matrix-n (https://www.reddit.com/user/matrix-n)
[link] (https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/) [comments] (https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/
hello guys i hope you all good! i need help guys plz with crunch i have list for name and i want start with min 9 and max 15 and my list like this.. mohamed ahmed kareem sonia yassin samy abdulrahman badr abdelaziz ayman agnaden tedata vodafone etisalat orange zen ziad mahmoud elhadad awad rawan youssif mostafa ameen ali zico coco koki dido isso toto tata oraby islam hesham hussein hossam magdy mido becker salem ibrahim said ssadek habiba khattab ashour noga hegazy rima tito sadek hakem safwat fawry tomy anoosh pitbull hema abaas diab shaban nader tolba ammar lamia gego temo saso abdelhakim *@-_!0987654321 ok the list is much long ...,so this is my list I didn't want the letters to change I just want the words to change EXMPLE: ahmedmohamed**1234 EXMPLE2: ahmedkoki@01085643 like this guys only words change not letters and (only numbers and symbols change with each other) I hope you can help me with your kindness and generosity thank you guys i wish you all the best. submitted by /u/matrix-n (https://www.reddit.com/user/matrix-n)
[link] (https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/) [comments] (https://www.reddit.com/r/Pentesting/comments/uc1w0n/help_with_crunch_pelase/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
help with crunch pelase!
hello guys i hope you all good! i need help guys plz with crunch i have list for name and i want start with min 9 and max 15 and my list like...
hacking: security in practice
How to Decrypt a file without knowing the Algorithm, but knowing the key?
So I am trying to decrypt a file here. It is a .XMDX file that seems to be encrypted. I have the encryption key, but I don't know the algorithm used. How would I go about finding the algorithm?
I am using python. Should I just shuffle through all the know algorithms and see if any of them yield a legible result? can this file even be decrypted? Usually, this file is read by a program that only shows the user the contents when the password is entered.
Thanks in advance!
submitted by /u/scrubswithnosleeves
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to Decrypt a file without knowing the Algorithm, but knowing the key?
So I am trying to decrypt a file here. It is a .XMDX file that seems to be encrypted. I have the encryption key, but I don't know the algorithm used. How would I go about finding the algorithm?
I am using python. Should I just shuffle through all the know algorithms and see if any of them yield a legible result? can this file even be decrypted? Usually, this file is read by a program that only shows the user the contents when the password is entered.
Thanks in advance!
submitted by /u/scrubswithnosleeves
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to Decrypt a file without knowing the Algorithm, but knowing...
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
The omg cable by hak5
Are there headphones or and airpod version of the omg lighting cable that has the same or similar features? would be surprised if there is considering no one is just picking up random headphones and using them. But! Would it be possible to make one and if so who’s the guy that can make it happen ?
submitted by /u/theheadbanders
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The omg cable by hak5
Are there headphones or and airpod version of the omg lighting cable that has the same or similar features? would be surprised if there is considering no one is just picking up random headphones and using them. But! Would it be possible to make one and if so who’s the guy that can make it happen ?
submitted by /u/theheadbanders
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The omg cable by hak5
Are there headphones or and airpod version of the omg lighting cable that has the same or similar features? would be surprised if there is...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackme — Alfred(Exploit Jenkins Service Gain To Authority/System)
https://cdn-images-1.medium.com/max/600/1*LCrIBEvO-NKFN5IQWxjZYQ.png
Hi semua pada artikel ini saya akan membagikan write up mechine tryhackme yang bername alfred mechine ini berfokus pada teknologi jenkins…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackme — Alfred(Exploit Jenkins Service Gain To Authority/System)
https://cdn-images-1.medium.com/max/600/1*LCrIBEvO-NKFN5IQWxjZYQ.png
Hi semua pada artikel ini saya akan membagikan write up mechine tryhackme yang bername alfred mechine ini berfokus pada teknologi jenkins…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackme — Alfred(Exploit Jenkins Service Gain To Authority/System)
Hi semua pada artikel ini saya akan membagikan write up mechine tryhackme yang bername alfred mechine ini berfokus pada teknologi jenkins…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OWASP API Security (Offensive Prespective) : Excessive Data Exposure #3
https://cdn-images-1.medium.com/max/600/0*HpyszGZISX1YxXkD.png
Assalamualaikum Wr. Wb
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OWASP API Security (Offensive Prespective) : Excessive Data Exposure #3
https://cdn-images-1.medium.com/max/600/0*HpyszGZISX1YxXkD.png
Assalamualaikum Wr. Wb
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OWASP API Security (Offensive Prespective) : Excessive Data Exposure #3
Assalamualaikum Wr. Wb
My Pentest Log -16- (XS Size A Little Tip)
https://hcibo.medium.com/my-pentest-log-16-a-little-tip-ea55447443ae?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hcibo.medium.com/my-pentest-log-16-a-little-tip-ea55447443ae?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Pentest Log -16- (XS Size A Little Tip)
Greetings to all from a springtime Constantinople,
Greetings to all from a springtime Constantinople,Continue reading on Medium » (https://hcibo.medium.com/my-pentest-log-16-a-little-tip-ea55447443ae?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Pentest Log -16- (XS Size A Little Tip)
Greetings to all from a springtime Constantinople,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lapsus$ Hackers Target T-Mobile
Lapsus$ Hackers Target T-MobilePost Views: 38
Premium Content
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
T-Mobile confirmed that the extortion group Lapsus$ gains access to their system “several weeks ago”.
The telecom giant responded to a report by a journalist Brian Krebs, who accessed the internal chats from the private Telegram channel of the core Lapsus$ gang members. The company added that it has mitigated the breach by terminating the hacker’s group access to its network and disabled the stolen credentials that were used in the breach.
Lapsus$ is a cybergang that came into prominence when it waged a ransomware attack against the Brazilian Ministry of Health in Feb 2021, compromising the data of COVID 19 vaccination data of millions. More recently, in March, the City of London Police arrested seven people suspected of being connected to the gang.
Private chats uncovered by Krebs revealed that the Lapsus$ hacking group get hold of the T-Mobile VPN credentials on illicit platforms like the Russian Market. Using these credentials Lapsus$ members can get access to the company’s internal tools like – Atlas an internal T-Mobile tool for managing customer accounts. It would help them to conduct a “Sim-Swapping” Attack – In this attack, the hacker hijacks the victim’s number by transferring it to the device owned by the attacker, this enables the hackers to obtain sensitive information such as phone number or any message sent for multi-factor authentication.
After gaining access to ATLAS, Lapsus$ hackers also attempted to compromise the T-Mobile accounts associated with the FBI and Department of Defense but were unsuccessful as an additional verification method was linked to those accounts.
“Several weeks ago, our monitoring tools detected a bad actor using stolen credentials to access internal systems that house operational tools software,” said a spokesperson from T-Mobile.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
T-Mobile said that despite the access attempts to the internal system ‘Atlas’ no sensitive information was leaked. “The systems accessed contained no customer or government information or other similarly sensitive information, and we have no evidence that the intruder was able to obtain anything of value,” T-Mobile added.
“Our systems and processes worked as designed, the intrusion was rapidly shut down and closed off, and the compromised credentials used were rendered obsolete.”
Recently Lapsus$ attack increased and they primarily target the source code of big technology companies like Microsoft, Samsung, Okta, and Nvidia.
The attacks carried out by Lapsus$ are not sophisticated, usually initiated by the stolen credentials from underground marketplaces, such as the Russian Market, and then an attempt to bypass the multi-factor authentication using social-engineering schemes.
“From a security pro who fought LAPSUS$: It forces us to shift thinking about insider access. Nation states want longer, strategic access; ransomware groups want lateral movement. LAPSUS$ asks: What can this account get me in the next 6 hours? We haven’t optimized to defend that.” said Brian Krebs in a tweet on Mar 24, 2022.
From a security pro who fought LAPSUS$: It forces us to shift thinking about insider access. Nation states want longer, strategic access; ransomware groups want lateral movement. LAPSUS$ asks: What can this account get me in the next 6 hours? We haven’t optimized to defend that.
— briankrebs (@briankrebs) Mar[...]
___________________________
@hacking_Attack
@Hacking_Video
Lapsus$ Hackers Target T-Mobile
Lapsus$ Hackers Target T-MobilePost Views: 38
Premium Content
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
T-Mobile confirmed that the extortion group Lapsus$ gains access to their system “several weeks ago”.
The telecom giant responded to a report by a journalist Brian Krebs, who accessed the internal chats from the private Telegram channel of the core Lapsus$ gang members. The company added that it has mitigated the breach by terminating the hacker’s group access to its network and disabled the stolen credentials that were used in the breach.
Lapsus$ is a cybergang that came into prominence when it waged a ransomware attack against the Brazilian Ministry of Health in Feb 2021, compromising the data of COVID 19 vaccination data of millions. More recently, in March, the City of London Police arrested seven people suspected of being connected to the gang.
Private chats uncovered by Krebs revealed that the Lapsus$ hacking group get hold of the T-Mobile VPN credentials on illicit platforms like the Russian Market. Using these credentials Lapsus$ members can get access to the company’s internal tools like – Atlas an internal T-Mobile tool for managing customer accounts. It would help them to conduct a “Sim-Swapping” Attack – In this attack, the hacker hijacks the victim’s number by transferring it to the device owned by the attacker, this enables the hackers to obtain sensitive information such as phone number or any message sent for multi-factor authentication.
After gaining access to ATLAS, Lapsus$ hackers also attempted to compromise the T-Mobile accounts associated with the FBI and Department of Defense but were unsuccessful as an additional verification method was linked to those accounts.
“Several weeks ago, our monitoring tools detected a bad actor using stolen credentials to access internal systems that house operational tools software,” said a spokesperson from T-Mobile.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
T-Mobile said that despite the access attempts to the internal system ‘Atlas’ no sensitive information was leaked. “The systems accessed contained no customer or government information or other similarly sensitive information, and we have no evidence that the intruder was able to obtain anything of value,” T-Mobile added.
“Our systems and processes worked as designed, the intrusion was rapidly shut down and closed off, and the compromised credentials used were rendered obsolete.”
Recently Lapsus$ attack increased and they primarily target the source code of big technology companies like Microsoft, Samsung, Okta, and Nvidia.
The attacks carried out by Lapsus$ are not sophisticated, usually initiated by the stolen credentials from underground marketplaces, such as the Russian Market, and then an attempt to bypass the multi-factor authentication using social-engineering schemes.
“From a security pro who fought LAPSUS$: It forces us to shift thinking about insider access. Nation states want longer, strategic access; ransomware groups want lateral movement. LAPSUS$ asks: What can this account get me in the next 6 hours? We haven’t optimized to defend that.” said Brian Krebs in a tweet on Mar 24, 2022.
From a security pro who fought LAPSUS$: It forces us to shift thinking about insider access. Nation states want longer, strategic access; ransomware groups want lateral movement. LAPSUS$ asks: What can this account get me in the next 6 hours? We haven’t optimized to defend that.
— briankrebs (@briankrebs) Mar[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Lapsus$ Hackers Target T-Mobile | Black Hat Ethical Hacking
T-Mobile confirmed that the extortion group Lapsus$ gains access to their system “several weeks ago”.
Black Hat Ethical Hacking
Lapsus$ Hackers Target T-Mobile
___________________________
@hacking_Attack
@Hacking_Video
Lapsus$ Hackers Target T-Mobile
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Lapsus$ Hackers Target T-Mobile | Black Hat Ethical Hacking
T-Mobile confirmed that the extortion group Lapsus$ gains access to their system “several weeks ago”.
hacking: security in practice
Should I start with HacktheBox or TryHackMe?
Hello,
I've got some understanding of cybersecurity and concepts but next to no actual hands on. I'd like to run some of the modules from either of these websites while I am studying for my Sec+. Which one should I do first?
submitted by /u/jungle_dave
[link] [comments]
Should I start with HacktheBox or TryHackMe?
Hello,
I've got some understanding of cybersecurity and concepts but next to no actual hands on. I'd like to run some of the modules from either of these websites while I am studying for my Sec+. Which one should I do first?
submitted by /u/jungle_dave
[link] [comments]
reddit
Should I start with HacktheBox or TryHackMe?
Hello, I've got some understanding of cybersecurity and concepts but next to no actual hands on. I'd like to run some of the modules from either...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Quantum ransomware seen deployed in rapid network attacks. The threat actors are using the IcedID malware as one of their initial access vectors, which deploys Cobalt Strike for remote access and leads to data theft and encryption using Quantum Locker.
https://external-preview.redd.it/kxUPaf4zLZwpqfmNDzou8dwLWcpZvg99gPz_ET9paPU.jpg?width=640&crop=smart&auto=webp&s=3b286ebb2596c93e5c80e6d8c6d268d74d86fea9 submitted by /u/Late_Ice_9288
[link] [comments]
Quantum ransomware seen deployed in rapid network attacks. The threat actors are using the IcedID malware as one of their initial access vectors, which deploys Cobalt Strike for remote access and leads to data theft and encryption using Quantum Locker.
https://external-preview.redd.it/kxUPaf4zLZwpqfmNDzou8dwLWcpZvg99gPz_ET9paPU.jpg?width=640&crop=smart&auto=webp&s=3b286ebb2596c93e5c80e6d8c6d268d74d86fea9 submitted by /u/Late_Ice_9288
[link] [comments]