Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft releases fixes for Azure flaw allowing RCE attacks Microsoft releases fixes for Azure flaw allowing RCE attacksPost Views: 1 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/patreon-300x61.png…
the latest releases (Windows 11 and Windows Server 2022).

“For additional protection, Microsoft recommends configuring Synapse workspaces with a Managed Virtual Network which provides better compute and network isolation,” Redmond added.

“Customers using Azure Data Factory can enable Azure integration runtimes with a Managed Virtual Network.”

You can find further information on how to fully mitigate CVE-2022-299 in the “Customer Recommendations and Additional Support” section of MSRC’s blog post.

“Unfortunately, our research leads us to believe that the underlying architectural weakness is still present. There are areas in the service where a huge amount of Microsoft and 3rd party code, runs with SYSTEM permissions, processing customer controlled input,” Shua added.

“This runs on shared machines with access to Azure service keys and sensitive data of other customers. These areas of the service only have application-level separation and lack sandbox or hypervisor-level isolation. This is a major attack surface and not consistent with the level of security that public cloud customers expect.”
See Also: OSINT Tool: MOSINT Disclosure timeline:* January 4 – Orca reported the issue to Microsoft
* March 2 – Microsoft completed rollout of initial hotfix
* March 11 – Microsoft identified and notified the customer affected by the researcher’s activity
* March 30 – Orca notified Microsoft of an additional attack path to the same vulnerability
* April 13 – Orca notified Microsoft of a second attack path to the same vulnerability
* April 15 – Additional fixes deployed for the two newly reported attack paths as well as additional defense in depth measures applied

In March, Microsoft said it fixed another Azure security vulnerability in December (also reported by Orca Security) that enabled attackers to take complete control over other Azure customers’ data by abusing an Azure Automation service bug dubbed AutoWarp.

Last month, the company addressed a chain of critical bugs reported by cloud security firm Wiz in the Azure Database for PostgreSQL Flexible Server (known as ExtraReplica) that let malicious users gain access to other customers’ databases after bypassing authentication.

Other Microsoft Azure flaws fixed by Redmond during the last year also include ones Wiz researchers found in Azure Cosmos DB, the Open Management Infrastructure (OMI) software agent, and the Azure App Service.
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately24 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Fileless-Malware-660x400-1-90x90.jpg Attackers Use Event Logs to Hide Fileless Malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/poison-1481596_1920-90x90.jpg Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/1ed10a11bb45c273cebc7b8cb492979249bcdcec-90x90.png Security bug in VMWare Workspace ONE could allow access to internal, cloud networks6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-2-90x90.jpg New PyScript project lets you run Python programs in the browser7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
the latest releases (Windows 11 and Windows Server 2022). “For additional protection, Microsoft recommends configuring Synapse workspaces with a Managed Virtual Network which provides better compute and network isolation,” Redmond added. “Customers using…
1614322146_pexels-kevin-ku-577585-scaled-90x90.jpg Open source ‘Package Analysis’ tool finds malicious npm, PyPI packages1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/supply-chain-attack-90x90.jpg Socket: New tool uses a new, proactive defense against OSS supply chain attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/github-90x90.jpg GitHub: How stolen OAuth tokens helped breach dozens of orgs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Figure-6-Our-exploit-implemented-and-winning-the-TOCTOU-race-90x90.png New Nimbuspwn Linux vulnerability gives hackers root privileges2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/ezgif.com-gif-maker-6-90x90.jpg Lapsus$ Hackers Target T-Mobile2 weeks ago
The post Microsoft releases fixes for Azure flaw allowing RCE attacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
UniLend Finance moving towards Omnis Testnet with Completion of Bug Bounty

UniLend Omnis, the upcoming new version for Lending and Borrowing of every ERC20 asset, sets another milestone and moves very close to…Continue reading on Medium »
Read more...
hacking: security in practice
Looking for a valid ''source'' IP address scanner.

I have seen many network scanners and port scanners but for some reason very few if not just one valid ''source'' ip address scanner. The one I am talking about was created way back in the days when oxid.it was up and running. IRS was the name and how it worked, at least in theory, was you would setup a test network and on that network you would use a firewall that only allows one ip address to connect over a service like ssh lets say. IRS would first perform a mitm environment through arp poisoning and somehow fire off every ip on that subnet until it finds a match. I thought it was a nifty project but unfortunately never got the credit it deserved. So to you guys the community I ask is there something simmilar to IRS? Also I wanna point out that IRS does not attempt to connect to a service like http or ssh rather it simply tries to see how that service responds to various ip source addresses.

submitted by /u/SuperSoakerGuyx
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Good books on hacking?

Can someone recommend any good books on hacking that talks about different vulnerabilities and some history about them.. vulnerabilities in CVE, OWASP etc.. histories of malwares like wannacry , zeus, stuxnet etc...?

submitted by /u/resnetv2
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
password brute force tool?

I am looking for a basic password brute force tool, I wont go into what I am using it for but I can assure it is legal

the passwords are 6-8 caracters and all numbers and 4 characters with numbers and letters

submitted by /u/Adzey123
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video