Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Deep Web
Might be stupid

I really want someone to help me out with my court and DMV records, Don’t know really how to go about it. I need assistance to how to get to where I need to be(guidance) thanks man bunch 🫥💀👺🫶🏼

submitted by /u/PayMe2TheMoon
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Darkside hacker group, the group that provides ransomware as a service

Darkside hacker group, the group that provides ransomware as a servicePost Views: 29
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 6 Minutes
DarkSide hacker group provides ransomware as a service, and it is believed to be responsible for the Colonial Pipeline cyberattack, the biggest US gas pipeline, which was temporarily shut down its operations for several days due to the attack.
DarkSide is one of many increasingly professionalized groups of digital extortionists.
DarkSide group

DarkSide is a ransomware-as-a-service (RaaS) and offers its affiliates a percentage of the profits.

It presents an example of modern ransomware, operating with a more advanced business model. These modern ransomware attacks usually are done by several groups who collaborate and split the profits.

It is believed that the DarkSide group is based in Eastern Europe, likely Russia. Unlike other hacking groups responsible for high-profile cybercrimes, it is not believed to be state-sponsored.

Experts in the field who tracked DarkSide activities said it appears to be composed of veteran cyber criminals with a focus on making money from their targets.

“They’re very new but they’re very organized,” Lior Div, the chief executive of Boston-based security firm Cybereason said.

Their site on the dark web hints at their past crimes, claiming that they previously made millions from extortion. It also features a Hall of Shame-style gallery of leaked data from victims who haven’t paid up their ransom, disclosing stolen documents from more than 100 companies across the US and Europe.
See Also: Complete Offensive Security and Ethical Hacking Course
Targets
Based on the group’s Tor leak sites, the DarkSide group determines whether to pursue a target by looking at their financial records. The financial information gathered is also used to determine the amount of the ransom to demand, a typical ransom could be anywhere between 200K and 2 million US dollars.

According to Trend Micro reports, the most targeted country, with more than 500 detections was the US, followed by Belgium, France, and Canada. Also, according to McAfee, the most attacked countries In terms of the number of devices impacted per million devices are Israel with 1573.28, Malaysia with 130.99, Belgium with 106.93, etc., the list consists of 25 affected countries which also includes countries like Italy, Ukraine, and Peru.

Notably, the group avoids victimizing companies in a Commonwealth of Independent States (CIS) countries by using a part of their ransomware execution code that checks the geolocation of potential victims. This could be a clue to where DarkSide criminals are residing.  Additionally, they do not target schools, non-profit organizations, and healthcare centers Organizations.

As of June 2021, based on the leaked sites, there were at least 90 victims affected by the DarkSide attacks. In total, more than 2TB of stolen data are currently being hosted on DarkSide sites and 100% of victims’ stolen files are leaked. https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png See Also: Offensive Security Tool: KeeThief
History of Attacks
The Timeline of DarkSide activity is compiled from publicly available reports:

* August 2020: DarkSide introduces its ransomware.
* October 2020: DarkSide donates US$20,000 stolen from victims to charity.
* November 2020: DarkSide establishes its RaaS model. The group invites other criminals to use its service. A DarkSide data leak site is later discovered.
* November 2020: Da[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Socket: New tool uses a new, proactive defense against OSS supply chain attacks

Socket: New tool uses a new, proactive defense against OSS supply chain attacksPost Views: 22
Premium Content

https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-2.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A group of software package maintainers have created a tool for defending applications that depend on open source JavaScript libraries.
Called Socket, the tool uses a new, proactive defense against open source software OSS supply chain attacks. Supply chain attacks happen when a miscreant compromises a package and uses it to distribute malicious code to applications that depend on it. The tactic has become a growing threat, especially as more and more applications come to increasingly rely on open source software components. Traditional methods fall short“Everyone on the Socket team is an open source maintainer. Together, we have over 1 billion monthly downloads to our names,” Feross Aboukhadijeh, founder and CEO of Socket, told The Daily Swig. “We witnessed firsthand how supply chain attacks have swept across open source communities and damaged trust in open source.”

Maintaining the security of open source software is becoming increasingly challenging, especially since every dependency can lead to dozens or hundreds of transitive dependencies.

The security industry is mostly focused on vulnerabilities that have already been discovered. There are many CVE scanners that monitor applications for known vulnerabilities.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png But vulnerabilities can take weeks or months to be discovered, and their emergence won’t stop supply chain attacks, Aboukhadijeh warns.

One study from 2020 shows that on average, a malicious package is available for 209 days before being publicly reported. Another states that 20% of malware “persist in package managers for over 400 days and have more than 1K downloads.”

“In today’s culture of fast development, a malicious dependency can be updated, merged, and running in production in days or even hours,” Aboukhadijeh said. “This isn’t enough time for a CVE to be created and make its way into the vuln scanning tools that teams use.” A proactive approachSocket has been designed with the assumption that all open source packages may be malicious. Instead of searching for known vulnerabilities, it tries to detect signs of compromised packages.

According to Aboukhadijeh, Socket uses “deep package inspection” to characterize the behavior of an open source package. It analyzes both the package code and maintainer behavior to detect the tell-tale signs of a supply chain attack.

Socket runs static analysis on a JavaScript package and all of its dependencies to look for risk markers such as install scripts, obfuscated code, high entropy strings, or usage of privileged APIs such as shell, network, filesystem, eval(), and environment variables.

“For example, if a new patch or minor version of a package adds an install script and new code to communicate with the network, that’s a huge red flag and something that every team should want to know about before they update to the new version,” Aboukhadijeh said. “Looking for just these two signals would have stopped a huge percentage of recent npm supply chain attacks.”

Socket has a total of 70 detection markers in five different categories: supply chain risk, quality, maintenance, known vulnerabilities, and license.

“We use eac[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Darkside hacker group, the group that provides ransomware as a service Darkside hacker group, the group that provides ransomware as a servicePost Views: 29 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploa…
rkSide launches its content delivery network (CDN) for storing and delivering compromised data.
* December 2020: A DarkSide actor invites media outlets and data recovery organizations to follow the group’s press center on the public leak site.
* March 2021: DarkSide releases version 2.0 of its ransomware with several updates.
* May 2021: DarkSide launches the Colonial Pipeline attack.
The attack on the Colonial Pipeline was unprecedented at the time as it caused the biggest US gas pipeline to be temporarily shut down its operations for several days. The Colonial Pipeline was the main pipeline supplying 45% of fuel to the East coast of the US.

DarkSide successfully extorted about 75 Bitcoin (around US$5 million at the time). After the attack, Darkside announces it is apolitical and will start vetting its targets (possibly to avoid raising attention to future attacks).
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-4.jpg

US Colonial pipeline
See Also: Write up: How to schedule tasks the right way in Linux, using crontab
Mechanism of attacks – ransomware

The group uses common, legitimate tools (Cobalt Strike, Mimikatz, Metasploit, etc.) throughout the attack process to remain undetected.
Initial Access

To gain initial access, the group uses various tactics such as phishing, remote desktop protocol abuse, and exploiting known vulnerabilities.

Throughout the reconnaissance and gaining entry phases multiple tools are used for specific purposes:

* PowerShell: for reconnaissance and persistence
* Metasploit Framework: for reconnaissance
* Mimikatz: for reconnaissance
* BloodHound: for reconnaissance
* Cobalt Strike: for installation
Lateral movement and privilege escalation

In general, this is a key discovery phase in the modern ransomware process where the goal is to identify all critical data (file targets, locations for the exfiltration, and encryption process) within the victims’ organization.

The goal of the DarkSide threat actors in the lateral movement is to gain access to Domain Controller (DC) or Active Directory, which will be used to steal credentials, escalate privileges, and any other valuable assets for the exfiltration.

Eventually, using the DC network share to deploy the ransomware to connected devices.
Data Exfiltration

It’s the last step before the ransomware is dropped on the system.

This is the riskier step in the process of ransomware execution. That’s why data exfiltration is more likely to alert the victim organization’s security department.

Tools used by DarkSide for the data exfiltration :

* 7-Zip: a utility used for archiving files in preparation for exfiltration
* Rclone and Mega client: tools used for exfiltrating files to cloud storage
* PuTTy: an alternative application used for network file transfer
The attackers then use various leak sites on the Tor network to host the stolen data.
Execution

The ransomware then gets executed and performs various actions. It checks that the victim is not located in a CIS country, stores the ransom note, and executes a PowerShell command to install and operate itself along with deleting the shadow copies from the network.

It uses two encryption techniques depending on the targets’ operating system (Linux or Windows), a ChaCha20 stream cipher with RSA-4096 for Linux and a Salsa20 with RSA-1024 for Windows machines.
A sample ransom note from DarkSide’s ransomware:
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-3-1.jpg
Aftermath
After the Colonial Pipeline attack, DarkSide released a statement on one of its leak sites clarifying that the group did not wish to create problems for society and that its goal was simply to make money.

After the attacks, the group went silent, presumably for all the attention it caused but likely reemerged as a group that called themselves BlackMatter around September 2021.

Since November 2021, the US State Department has offered a reward o[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Socket: New tool uses a new, proactive defense against OSS supply chain attacks Socket: New tool uses a new, proactive defense against OSS supply chain attacksPost Views: 22 Premium Content https://www.blackhatethicalhacking.com/wp…
h of these issues as signals into the supply chain risk formula that determines whether we will raise an alert,” Aboukhadijeh explained.
See Also: Cisco vulnerability lets hackers craft their own login credentials Socket to meThe tool is available as a paid app for GitHub and also has a free version with limited functionality. Aboukhadijeh says that in two months since its launch, it is already protecting hundreds of organizations and tens of thousands of repositories.

In the future, the team will be adding more risk detection techniques as well as advanced reporting features. They will also add support for more languages (Java, Go, Python) and integrations with other platforms (GitLab, Bitbucket).
See Also: Offensive Security Tool: KeeThief Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: How to schedule tasks the right way in Linux, using crontab
Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/github-90x90.jpg GitHub: How stolen OAuth tokens helped breach dozens of orgs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Figure-6-Our-exploit-implemented-and-winning-the-TOCTOU-race-90x90.png New Nimbuspwn Linux vulnerability gives hackers root privileges2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-6-90x90.jpg Lapsus$ Hackers Target T-Mobile3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-5-90x90.jpg Log4Shell vulnerability in AWS allows full host takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/New-Java-Framework-Vulnerability-and-Mitigations-90x90.jpg Java encryption implementation error made it trivial to forge credentials1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-3-90x90.jpg CISA warns of attackers now exploiting Windows Print Spooler bug1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-3-90x90.jpg Newly found zero-click iPhone exploit used in NSO spyware attacks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/2b93-article-220121-cisco-90x90.jpg Cisco vulnerability lets hackers craft their own login credentials2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/windows-patch-update-90x90.jpg Microsoft Zero-Days, Wormable Bugs Spark Concern2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-2-2-90x90.jpg Git security vulnerabilities prompt updates2 weeks ago
The post Socket: New tool uses a new, proactive defense against OSS supply chain attacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
rkSide launches its content delivery network (CDN) for storing and delivering compromised data. * December 2020: A DarkSide actor invites media outlets and data recovery organizations to follow the group’s press center on the public leak site. * March 2021:…
f up to 10 million dollars for anyone who has information that will help identify or locate the DarkSide members and a reward of up to 5 million dollars for information leading to the arrest or conviction of any party that attempted or participate in the DarkSide ransomware attacks.

These kinds of attacks remind us those threat actors are always a step ahead regarding cybersecurity. Offensive security needs to be implemented now more than ever.

Offensive security solutions include testing your company against such attacks.

Testing your company’s infrastructure against ransomware attacks and setting up backup plans are essential tools to survive on the Internet “jungle”, where hackers are waiting to take advantage of every small opportunity for their profit.
References:

⦿ Who are DarkSide Hacker Group?

⦿ The US Puts a $10M Bounty on DarkSide Ransomware Hackers

⦿ Cyber attack on US fuel pipeline operator blamed on DarkSide, a ‘Robin Hood’ criminal gang ⦿ What We Know About the DarkSide Ransomware and the US Pipeline Attack – TrendMicro ⦿ DarkSide (hacker group) – Wikipedia Recent Articles* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/How-to-schedule-tasks-the-right-way-in-Linux-using-crontab-90x90.png Write up: How to schedule tasks the right way in Linux, using crontab6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Hacking-is-an-art-and-so-is-subdomain-enumeration-90x90.png Write up: Hacking is an art, and so is subdomain enumeration.3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Articles_Gallery-90x90.png Lizard Squad – the infamous hacking group that brought Xbox and PlayStation networks to their knees.1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Hide-data-in-images-and-extract-them-90x90.png Write up: Steganography: Hide data in images and extract them1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/MafiaBoy-the-hacker-who-took-down-the-Internet-90x90.png Hacking stories: MafiaBoy, the hacker who took down the Internet2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Detect-malicious-hacker-activities-on-endpoints-90x90.png Write up: Detect malicious hacker activities on endpoints2 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/Articles_Gallery-90x90.png How ILOVEYOU worm became the first global computer virus pandemic3 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Stuxnet-90x90.png Stuxnet – A weapon made out of code that almost started WW34 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Article-90x90.png Hacking stories – Rafael Núñez (aka RaFa), hacking NASA with the hacking group: World of Hell6 months ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/10/operation-troy-90x90.png Hacking stories – Operation Troy – How researchers linked the cyberattacks6 months ago
The post Darkside hacker group, the group that provides ransomware as a service first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Introduction to Smart Contract why it is so demanding in the IT world…

Started my research a month ago into Smart Contracts as a Security Analyst of Avalance Global Solutions and that’s why I want to share my…Continue reading on Medium »
Read more...
hacking: security in practice
red handed

Basically Im pretty sure my girl is cheating on me of course she Denis it an always has an aliby so I'm trying to catch her red handed any tips on hacking her microphone?

submitted by /u/sleppysmurf
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Locked out of my outlook account

I’ve been trying to get into my outlook account for about a week now but with no luck. I’ve forgotten the password and never set up a secondary email as backup. Could someone help me hack into it or hack into my discord to get the password or get back into my outlook so I can change my discord username plz?

submitted by /u/Most_Revolution_5330
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Proxy e-mail hacked?!

I hope this is the right place for this.

My facebook was hacked and I found out they hacked it by using the secondary email address. This email address was from a website my old band used to run over a decade ago. I see they logged into my Facebook using this email, likely someone bought the url and somehow gained access to the email it routed through?(a yahoo email account)

Looks like they added a phone number and login codes. They changed the profile picture and now I don't have access.

What to do? What to even research? I have no idea how email routing works or how I can disconnect my yahoo mail from this proxy account.

Thank you guys so much, this is frustrating and I have no idea what else they could access.

submitted by /u/64557175
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Possible for computer to monitor other display on the same monitor?

I’m currently working from home and I have both my personal PC and work PC sharing the same monitor. My work computer is obviously monitored - but wondering if they can see what I’m doing on my personal computer? My personal PC is connected via VGA and the work PC is connected via displayport.

Not necessarily worried about hackers. Just wondering if my work can see my monitor for what I’m doing on my personal PC?

submitted by /u/Capital-Context7041
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video