Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
It’s All About DMARC

Hello Everyone,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
GitHub: How stolen OAuth tokens helped breach dozens of orgs

GitHub: How stolen OAuth tokens helped breach dozens of orgsPost Views: 34
Premium Content

https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
GitHub has shared a timeline of this month’s security breach when a threat actor gained access to and stole private repositories belonging to dozens of organizations.
The attacker used stolen OAuth app tokens issued to Heroku and Travis-CI to breach GitHub.com customer accounts with authorized Heroku or Travis CI OAuth app integrations.

GitHub’s Chief Security Officer Mike Hanley says the company has yet to find evidence that its systems have been breached since the incident was first discovered on April 12th, 2022.

GitHub is still working on alerting all impacted users and organizations, with the company being in the process of sending the final notifications to affected GitHub.com users as of today.
See Also: Complete Offensive Security and Ethical Hacking Course
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png
An analysis of the attacker’s behavior, while he had access to compromised Github accounts, shows that the following activities were carried out on GitHub.com using the stolen OAuth app tokens:

1. The attacker authenticated to the GitHub API using the stolen OAuth tokens issued to Heroku and Travis CI.
2. For most people who had the affected Heroku or Travis CI OAuth apps authorized in their GitHub accounts, the attacker listed all the user’s organizations.
3. The attacker then selectively chose targets based on the listed organizations.
4. The attacker listed the private repositories for user accounts of interest.
5. The attacker then proceeded to clone some of those private repositories.

“This pattern of behavior suggests the attacker was only listing organizations in order to identify accounts to selectively target for listing and downloading private repositories,” GitHub said.

“GitHub believes these attacks were highly targeted based on the available information and our analysis of the attacker behavior using the compromised OAuth tokens issued to Travis CI and Heroku.”
See Also: Cisco vulnerability lets hackers craft their own login credentials Finding evidence of malicious activityGitHub disclosed the breach on the evening of April 15th, three days after discovering the attack, when the malicious actor accessed GitHub’s npm production infrastructure.

In the initial stage of the attack, the threat actor used a compromised AWS API key acquired after downloading multiple private npm repositories using stolen OAuth user tokens.

While GitHub, Travis CI, and Heroku have revoked all OAuth tokens to block further access after discovering the attack, affected organizations are advised to keep monitoring their audit logs and user account security logs for potentially malicious activity linked to this incident.

GitHub shared the following guidance with potentially impacted customers to help them investigate logs for evidence of data exfiltration or malicious activity:

* Review all your private repositories for secrets or credentials stored in them. There are several tools that can help with this task, such as GitHub secret scanning and trufflehog.
* Review the OAuth applications that you’ve authorized for your personal account or that are authorized to access your organization and remove anything that’s no longer needed.
* Follow GitHub’s guidelines for hardening the security posture of your GitHub organization.
* Review your account activit[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking GitHub: How stolen OAuth tokens helped breach dozens of orgs GitHub: How stolen OAuth tokens helped breach dozens of orgsPost Views: 34 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png…
y, personal access tokens, OAuth apps, and SSH keys for any activity or changes that may have come from the attacker.
* Additional questions should be directed to GitHub Support.

You can find more info on how GitHub responded to protect its customers and what organizations need to know in the initial security alert. See Also: Offensive Security Tool: KeeThief Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: How to schedule tasks the right way in Linux, using crontab
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Figure-6-Our-exploit-implemented-and-winning-the-TOCTOU-race-90x90.png New Nimbuspwn Linux vulnerability gives hackers root privileges1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-6-90x90.jpg Lapsus$ Hackers Target T-Mobile2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-5-90x90.jpg Log4Shell vulnerability in AWS allows full host takeover3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/New-Java-Framework-Vulnerability-and-Mitigations-90x90.jpg Java encryption implementation error made it trivial to forge credentials1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-3-90x90.jpg CISA warns of attackers now exploiting Windows Print Spooler bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-3-90x90.jpg Newly found zero-click iPhone exploit used in NSO spyware attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/2b93-article-220121-cisco-90x90.jpg Cisco vulnerability lets hackers craft their own login credentials1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/windows-patch-update-90x90.jpg Microsoft Zero-Days, Wormable Bugs Spark Concern2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-2-90x90.jpg Git security vulnerabilities prompt updates2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Amazon-EC2-90x90.jpg Internal AWS credentials swiped by researcher via SQL payload2 weeks ago
The post GitHub: How stolen OAuth tokens helped breach dozens of orgs first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Getting DNS tunnelling to work on Android 12

I had been tunnelling IPV4 over DNS for many many years.

Software used:

Server Side:

Iodine

Client side: AndIodine

With Android 12, the AndIodine app basically stopped working.

Can someone offer a way that works with Android 12, so I can continue using it? Thanks!

submitted by /u/BanglaV6
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Can someone explain this hack?

Scammer set up a cloned website of an official one 5 days ago. He entices people to get on it via whatsapp. They then have to enter some information about themselves on the site. Simple information like their name and email. He then proceeds to tell them to enter a code that he gives them. Once they enter the code, their bank account balance reduces as the attacker just transferred himself all the money from their account.

How on earth can this happen?

submitted by /u/abjedhowiz
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Any Red Team here has experience with getting code-signing certificates to sign their malware?

Hello!

more and more, we're running into issues when delivering malware (usually through social engineering) that it can not be started due to domain policy of not allowing unsigned applications to run. Does anyone here has some experience in how to deal with it?

I was trying to convince our company to just get us a legitimate code signing certificate, so we can sign the binaries which are getting used in legal engagements, so there is no risk in them being signed by us. But I've been told that is not going to work, because eventually every malware ends up in hands of a security researcher (even if it's Microsoft Defender submitting unknown binaries), and then we will end up having to explain why is our certificate signing malware, the certificate will get rewoked and in the worst case they will never give us another certificate again.

Which is a compelling argument, but I don't know whether it's actually happening in practice, which is why I'm asking for your experience if you've ever tried to legitimize your malware delivery in this way.

I feel like it should not be that easy, to get certificate that is accepted for malware (since prooving that you use it legitimately for legal red team engagements is really hard), but I also don't want to accept that there is not a way how to communicate it or get an exception, when we indeed are a legit security firm.

So, has anyone solved this issue, or is it really impossible?

Thank you!

submitted by /u/Mikina
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
We Rescued $4M from Rari Capital. But Was It Worth It?

On April 6th, we discovered a verified Fuse pool in Rari Capital used a weak price oracle prone to manipulation. Usually, exploiting a…Continue reading on Medium »
Read more...