Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Kali Linux 2022.2 - Penetration Testing and Ethical Hacking Linux Distribution

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiTtZYI97lcNISgbv6KTnLdshFnFSINgQKZz4t-_pVsVzx0nu3jsDwgrMFpj_PI4qQzy-hB6MN13RyHlyU7Nxz0oWbOtOJjuwINGmxsaXLbf2-a-zvJEcU8omMaPzEwWWHW9Uz_5vuyngv36ADG843jjC2AsWp4CT7T6HrfkliCtjmyVRvdDmmM_MO/w640-h334/banner-2022.2-release.jpg
Time for another Kali Linux release! – Kali Linux 2022.2. This release has various impressive updates.
The summary of the changelog since the 2022.1 release from February 2022 is:

* GNOME 42 - Major release update of the popular desktop environment
* KDE Plasma 5.24 - Version bump with a more polished experience
* Multiple desktop enhancements - Disabled motherboard beep on Xfce, alternative panel layout for ARM, better support for VirtualBox shared folders, and lots more
* Tweaks for the terminal - Enhanced Zsh syntax-highlighting, inclusion of Python3-pipand Python3-virtualenvby default
* April fools - Hollywood mode - Awesome screensaver
* Kali Unkaputtbar - BTRFS snapshot support for Kali
* Win-KeX 3.1 - sudo support for GUI apps
* New tools - Various new tools added
* WPS attacks in Kali NetHunter - Added WPS attacks tab to the NetHunter app

More info here.
Download Kali Linux 2022.2

___________________________
@hacking_Attack
@Hacking_Video
Kali Linux 2022.2 - Penetration Testing and Ethical Hacking Linux Distribution

Time for another Kali Linux release! – Kali Linux 2022.2. This release has various impressive updates.The summary of the changelog since the 2022.1 release from February 2022 is:GNOME 42 - Major release update of the popular desktop environmentKDE Plasma 5.24 - Version bump with a more polished experienceMultiple desktop enhancements - Disabled motherboard beep on Xfce, alternative panel layout for ARM, better support for VirtualBox shared folders, and lots moreTweaks for the terminal - Enhanced Zsh syntax-highlighting, inclusion of Python3-pip and Python3-virtualenv by defaultApril fools - Hollywood mode - Awesome screensaverKali Unkaputtbar - BTRFS snapshot support for KaliWin-KeX 3.1 - sudo support for GUI appsNew tools - Various new tools addedWPS attacks in Kali NetHunter - Added WPS attacks tab to the NetHunter appMore info here.Download Kali Linux 2022.2
Read more...
Time for another Kali Linux release! – Kali Linux 2022.2. This release has various impressive updates.
The summary of the changelog (https://bugs.kali.org/changelog_page.php) since the 2022.1 release from February 2022 (https://www.kali.org/blog/kali-linux-2022-1-release/) is:GNOME 42 - Major release update of the popular desktop environmentKDE Plasma 5.24 - Version bump with a more polished experienceMultiple desktop enhancements - Disabled motherboard beep on Xfce, alternative panel layout for ARM, better support for VirtualBox shared folders, and lots moreTweaks for the terminal - Enhanced Zsh syntax-highlighting, inclusion of Python3-pip and Python3-virtualenv by defaultApril fools - Hollywood mode - Awesome screensaverKali Unkaputtbar - BTRFS snapshot support for KaliWin-KeX 3.1 - sudo support for GUI appsNew tools - Various new tools addedWPS attacks in Kali NetHunter - Added WPS attacks tab to the NetHunter app
More info here (https://www.kali.org/blog/kali-linux-2022-2-release/).


Download Kali Linux 2022.2 (https://www.kali.org/get-kali/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple emergency update fixes zero-day used to hack Macs, Watches

Apple emergency update fixes zero-day used to hack Macs, WatchesPost Views: 3
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Apple has released security updates to address a zero-day vulnerability that threat actors can exploit in attacks targeting Macs and Apple Watch devices.
Zero-days are security flaws that the software vendor is unaware of and hasn’t yet patched. In some cases, this type of vulnerability may also have publicly available proof-of-concept exploits before a patch arrives or may be actively exploited in the wild.

In security advisories issued on Monday, Apple revealed that they’re aware of reports this security bug “may have been actively exploited.”

The flaw is an out-of-bounds write issue (CVE-2022-22675) in the AppleAVD (a kernel extension for audio and video decoding) that allows apps to execute arbitrary code with kernel privileges.

The bug was reported by anonymous researchers and fixed by Apple in macOS Big Sur 11.6., watchOS 8.6, and tvOS 15.5 with improved bounds checking.

The list of impacted devices includes Apple Watch Series 3 or late, Macs running macOS Big Sur, Apple TV 4K, Apple TV 4K (2nd generation), and Apple TV HD.

While Apple disclosed reports of active exploitation in the wild, it did not release any extra info regarding these attacks.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png By withholding information, the company is likely aiming to allow the security updates to reach as many Apple Watches and Macs as possible before attackers pick up on the zero-day’s details and start deploying exploits in other attacks.

Although this zero-day was most probably only used in targeted attacks, it’s still strongly advised to install today’s macOS and watchOS security updates as soon as possible to block attack attempts. Five zero-days patched in 2022In January, Apple patched two other zero-days exploited in the wild to let attackers gain arbitrary code execution with kernel privileges (CVE-2022-22587) and track web browsing activity and user identities in real-time (CVE-2022-22594).

One month later, Apple released security updates to patch a new zero-day bug (CVE-2022-22620) exploited to hack iPhones, iPads, and Macs, which leads to OS crashes and remote code execution on compromised Apple devices.
See Also: Attackers Use Event Logs to Hide Fileless Malware See Also: Offensive Security Tool: malicious-pdf In March, two more actively exploited zero-days in the Intel Graphics Driver (CVE-2022-22674) and the AppleAVD media decoder (CVE-2022-22675), the latter also backported today in older versions of macOS, in watchOS 8.6, and in tvOS 15.5.

These five zero-days impact iPhones (iPhone 6s and up), Macs running macOS Monterey, and multiple iPad models.

Throughout last year, the company also patched a long list of zero-days exploited in the wild to target iOS, iPadOS, and macOS devices. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackha[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple emergency update fixes zero-day used to hack Macs, Watches Apple emergency update fixes zero-day used to hack Macs, WatchesPost Views: 3 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
tethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more12 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20216 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-azure-cloud-90x90.jpg Microsoft releases fixes for Azure flaw allowing RCE attacks7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/f5-big-ip-hacking-90x90.jpg Exploits created for critical F5 BIG-IP flaw, install patch immediately1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Fileless-Malware-660x400-1-90x90.jpg Attackers Use Event Logs to Hide Fileless Malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/poison-1481596_1920-90x90.jpg Zero-day bug in uClibc library could leave IoT devices vulnerable to DNS poisoning attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/1ed10a11bb45c273cebc7b8cb492979249bcdcec-90x90.png Security bug in VMWare Workspace ONE could allow access to internal, cloud networks2 weeks ago
The post Apple emergency update fixes zero-day used to hack Macs, Watches first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
What hacking is and why it matters!

When people hear about hacking, there are different connotations to it! But the common interpretations of the term “hacking” in many…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Gitcolombo : Extract And Analyze Contributors Info From Git Repos

Git colombo is an OSINT tool to extract info about persons from git repositories: common names, emails, matches between different (as it may seems) accounts.

Using

* Install git
* Run:

from any git url
./gitcolombo.py -u https://github.com/Kalanchyovskaia16/newlps
from directory, recursively
./gitcolombo.py -d ./newlps -r
from all GitHub personal/org repos by nickname
./gitcolombo.py –nickname LubyRuffy

For batch cloning from Gitlab and Bitbucket group repos you can use ghorg.

Output:

* verbose persons info
* name
* email
* number of appearences as author/committer
* other persons that person can be

* emails used for the same name
* different names for the same person
* general statistics

What’s the difference between git author and committer?

TL;DR

* author wrote the code (make the patch)
* commiter commit it to the repo (rewrite history, make pull/merge requests…)

Nice explanation: https://stackoverflow.com/questions/18750808/difference-between-author-and-committer-in-git

Very often developers make inaccurate commits with the one name/email (e.g. work account), then change to the right (e.g. personal account) and make git commit --amend, but forget to change the author of the commit. This way we can use it for OSINT as match of names/emails from git history.
Download

___________________________
@hacking_Attack
@Hacking_Video