hacking: security in practice
Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited in the Wild
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited in the Wild
submitted by /u/Late_Ice_9288
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cisco Issues Patch for New IOS XR Zero-Day Vulnerability Exploited...
Posted in r/hacking by u/Late_Ice_9288 • 1 point and 0 comments
what computer should i get?
https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/
Currently, I am selling my PC and am going to have a budget between 1k - 1.5k for a laptop. I really prefer a windows laptop so it would be also easier to switch between that and Kali Linux in the future. My question is... What computer should I get? I'm assuming something with 16 GB of Ram, 3.2+ GHz CPU, and possibly a decent GPU. submitted by /u/Psychological-Ad6935 (https://www.reddit.com/user/Psychological-Ad6935)
[link] (https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/
Currently, I am selling my PC and am going to have a budget between 1k - 1.5k for a laptop. I really prefer a windows laptop so it would be also easier to switch between that and Kali Linux in the future. My question is... What computer should I get? I'm assuming something with 16 GB of Ram, 3.2+ GHz CPU, and possibly a decent GPU. submitted by /u/Psychological-Ad6935 (https://www.reddit.com/user/Psychological-Ad6935)
[link] (https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/uwibvc/what_computer_should_i_get/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
what computer should i get?
Currently, I am selling my PC and am going to have a budget between 1k - 1.5k for a laptop. I really prefer a windows laptop so it would be also...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack WordPress Dengan Memanfaatkan Bug Dari Plugin FromCraft 2.0
https://cdn-images-1.medium.com/max/640/0*7GCgD-0uY92gFpVJ.jpg
Sesuai dengan judul postingan, kali ini saya akan memberikan tutorial untuk melakukan hacking atau deface sebuah website.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack WordPress Dengan Memanfaatkan Bug Dari Plugin FromCraft 2.0
https://cdn-images-1.medium.com/max/640/0*7GCgD-0uY92gFpVJ.jpg
Sesuai dengan judul postingan, kali ini saya akan memberikan tutorial untuk melakukan hacking atau deface sebuah website.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack WordPress Dengan Memanfaatkan Bug Dari Plugin FromCraft 2.0
Sesuai dengan judul postingan, kali ini saya akan memberikan tutorial untuk melakukan hacking atau deface sebuah website.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Intranet Asset Vulnerability Scanning Tool
https://cdn-images-1.medium.com/max/1000/1*aUKaerCp0UZYjARSkZgPhQ.jpeg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Intranet Asset Vulnerability Scanning Tool
https://cdn-images-1.medium.com/max/1000/1*aUKaerCp0UZYjARSkZgPhQ.jpeg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intranet Asset Vulnerability Scanning Tool
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Realistic Mission 8
https://cdn-images-1.medium.com/max/700/0*LTColOJ7VDJLP-kM.jpg
Alright this one is a doozy of a mission. I spent a lot of time on the website and finally got this one down, this page is riddled with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Realistic Mission 8
https://cdn-images-1.medium.com/max/700/0*LTColOJ7VDJLP-kM.jpg
Alright this one is a doozy of a mission. I spent a lot of time on the website and finally got this one down, this page is riddled with…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Realistic Mission 8
Alright this one is a doozy of a mission. I spent a lot of time on the website and finally got this one down, this page is riddled with…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
40 Unstoppable Productivity Hacks to Get You Back on Track
https://cdn-images-1.medium.com/max/2600/1*xdz67frDdRlGHRAkYpM1MA.jpeg
Do you wish to boost your efficiency? It’s simple like Mark Zuckerberg, Arianna Huffington, Jerry Seinfeld, and The Terminator. They’ve…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
40 Unstoppable Productivity Hacks to Get You Back on Track
https://cdn-images-1.medium.com/max/2600/1*xdz67frDdRlGHRAkYpM1MA.jpeg
Do you wish to boost your efficiency? It’s simple like Mark Zuckerberg, Arianna Huffington, Jerry Seinfeld, and The Terminator. They’ve…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
40 Unstoppable Productivity Hacks to Get You Back on Track
Do you wish to boost your efficiency? It’s simple like Mark Zuckerberg, Arianna Huffington, Jerry Seinfeld, and The Terminator. They’ve…
Intranet Asset Vulnerability Scanning Tool
https://medium.com/@reconshell.com/intranet-asset-vulnerability-scanning-tool-b0ca800da71b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@reconshell.com/intranet-asset-vulnerability-scanning-tool-b0ca800da71b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intranet Asset Vulnerability Scanning Tool
Introduction
IntroductionContinue reading on Medium » (https://medium.com/@reconshell.com/intranet-asset-vulnerability-scanning-tool-b0ca800da71b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intranet Asset Vulnerability Scanning Tool
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Live Hacking With JBeers & The Million Dollar Hacker Tommy DeVoss
https://external-preview.redd.it/jOOWqLler-wKwi4UU3diP8HDnUbRFidZrwbkHa3el4c.jpg?width=216&crop=smart&auto=webp&s=77e0b46ee00ee2140ab3fdf8b7e88d2d35f4859a submitted by /u/Snoshberry
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Live Hacking With JBeers & The Million Dollar Hacker Tommy DeVoss
https://external-preview.redd.it/jOOWqLler-wKwi4UU3diP8HDnUbRFidZrwbkHa3el4c.jpg?width=216&crop=smart&auto=webp&s=77e0b46ee00ee2140ab3fdf8b7e88d2d35f4859a submitted by /u/Snoshberry
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Live Hacking With JBeers & The Million Dollar Hacker Tommy DeVoss
Posted in r/hacking by u/Snoshberry • 1 point and 0 comments
hacking: security in practice
Any advice for learning cyber security
I already received some hate like "we didn't have classes 10 years ago" or "just Google it" but I have learning disabilities and I struggle to learn from a page. I only do well doing thing hands on, hence why I'm really good at fixing things.. only way to learn is hands on. But I just want some suggestions on ways to learn or maybe if someone would be willing to help me get started.
I can't really afford to pay anything, I don't have more than 3 dollars in my account but I just wanna learn. Cause I doubt I'll go to college. My dad's saving for my sister to go, so I got put to the side, mom spent my college funds on pain pills.
Thanks for any advice. Sorry for being a bother.
submitted by /u/No_Positive_5235
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Any advice for learning cyber security
I already received some hate like "we didn't have classes 10 years ago" or "just Google it" but I have learning disabilities and I struggle to learn from a page. I only do well doing thing hands on, hence why I'm really good at fixing things.. only way to learn is hands on. But I just want some suggestions on ways to learn or maybe if someone would be willing to help me get started.
I can't really afford to pay anything, I don't have more than 3 dollars in my account but I just wanna learn. Cause I doubt I'll go to college. My dad's saving for my sister to go, so I got put to the side, mom spent my college funds on pain pills.
Thanks for any advice. Sorry for being a bother.
submitted by /u/No_Positive_5235
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Any advice for learning cyber security
I already received some hate like "we didn't have classes 10 years ago" or "just Google it" but I have learning disabilities and I struggle to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Snake Keylogger Spreads Through Malicious PDFs
Snake Keylogger Spreads Through Malicious PDFsPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
While most malicious e-mail campaigns use Word documents to hide and spread malware, a recently discovered campaign uses a malicious PDF file and a 22-year-old Office bug to propagate the Snake Keylogger malware, researchers have found.
The campaign—discovered by researchers at HP Wolf Security—aims to dupe victims with an attached PDF file purporting to have information about a remittance payment, according to a blog post published Friday. Instead, it loads the info-stealing malware, using some tricky evasion tactics to avoid detection.
“While Office formats remain popular, this campaign shows how attackers are also using weaponized PDF documents to infect systems,” HP Wolf Security researcher Patrick Schlapfer wrote in the post, which opined in the headline that “PDF Malware Is Not Yet Dead.”
Indeed, attackers using malicious email campaigns have preferred to package malware in Microsoft Office file formats, particularly Word and Excel, for the past decade, Schlapfer said. In the first quarter of 2022 alone, nearly half (45 percent) of malware stopped by HP Wolf Security used Office formats, according to researchers.
“The reasons are clear: users are familiar with these file types, the applications used to open them are ubiquitous, and they are suited to social engineering lures,” he wrote.
Still, while the new campaign does use PDF in the file lure, it later employs Microsoft Word to deliver the ultimate payload—the Snake Keylogger, researchers found. Snake Keylogger is a malware developed using .NET that first appeared in late 2020 and is aimed at stealing sensitive information from a victim’s device, including saved credentials, the victim’s keystrokes, screenshots of the victim’s screen, and clipboard data, according to Fortinet. ‘Unusual’ CampaignThe HPW Wolf Security team noticed a new PDF-based threat campaign on March 23 with an “unusual infection chain,” involving not just a PDF but also “several tricks to evade detection, such as embedding malicious files, loading remotely-hosted exploits and shellcode encryption,” Schlapfer wrote.
Attackers target victims with emails that include a PDF document named “REMMITANCE INVOICE.pdf”—misspelling intended–as attachment. If someone opens the file, Adobe Reader prompts the user to open a .docx file with a rather curious name, researchers found.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png “The attackers sneakily named the Word document “has been verified. However PDF, Jpeg, xlsx, .docx” to make it look as though the file name was part of the Adobe Reader prompt,” according to the post.
The.docx file is stored as an EmbeddedFile object within the PDF, which opens Microsoft Word if clicked on, researchers found. If Protected View is disabled, Word downloads a Rich Text Format (.rtf) file from a web server, which then is run in the context of the open document.
Researchers unzipped the contents of the .rtf—which is an Office Open XML file—finding a URL hidden in the “document.xml.rels” file that is not a legitimate domain found in Office documents, they said. 17-Year-Old Bug ExploitedConnecting to this URL leads to a redirect and then downloads an RTF document called “f_document_shp.doc. This document contained two “not well-formed” OLE objects that revealed shellcode exploiting CVE-2017-11882, which researchers said is an “over four-years-old” remote code execution vulnerability (RCE) [...]
Snake Keylogger Spreads Through Malicious PDFs
Snake Keylogger Spreads Through Malicious PDFsPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
While most malicious e-mail campaigns use Word documents to hide and spread malware, a recently discovered campaign uses a malicious PDF file and a 22-year-old Office bug to propagate the Snake Keylogger malware, researchers have found.
The campaign—discovered by researchers at HP Wolf Security—aims to dupe victims with an attached PDF file purporting to have information about a remittance payment, according to a blog post published Friday. Instead, it loads the info-stealing malware, using some tricky evasion tactics to avoid detection.
“While Office formats remain popular, this campaign shows how attackers are also using weaponized PDF documents to infect systems,” HP Wolf Security researcher Patrick Schlapfer wrote in the post, which opined in the headline that “PDF Malware Is Not Yet Dead.”
Indeed, attackers using malicious email campaigns have preferred to package malware in Microsoft Office file formats, particularly Word and Excel, for the past decade, Schlapfer said. In the first quarter of 2022 alone, nearly half (45 percent) of malware stopped by HP Wolf Security used Office formats, according to researchers.
“The reasons are clear: users are familiar with these file types, the applications used to open them are ubiquitous, and they are suited to social engineering lures,” he wrote.
Still, while the new campaign does use PDF in the file lure, it later employs Microsoft Word to deliver the ultimate payload—the Snake Keylogger, researchers found. Snake Keylogger is a malware developed using .NET that first appeared in late 2020 and is aimed at stealing sensitive information from a victim’s device, including saved credentials, the victim’s keystrokes, screenshots of the victim’s screen, and clipboard data, according to Fortinet. ‘Unusual’ CampaignThe HPW Wolf Security team noticed a new PDF-based threat campaign on March 23 with an “unusual infection chain,” involving not just a PDF but also “several tricks to evade detection, such as embedding malicious files, loading remotely-hosted exploits and shellcode encryption,” Schlapfer wrote.
Attackers target victims with emails that include a PDF document named “REMMITANCE INVOICE.pdf”—misspelling intended–as attachment. If someone opens the file, Adobe Reader prompts the user to open a .docx file with a rather curious name, researchers found.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png “The attackers sneakily named the Word document “has been verified. However PDF, Jpeg, xlsx, .docx” to make it look as though the file name was part of the Adobe Reader prompt,” according to the post.
The.docx file is stored as an EmbeddedFile object within the PDF, which opens Microsoft Word if clicked on, researchers found. If Protected View is disabled, Word downloads a Rich Text Format (.rtf) file from a web server, which then is run in the context of the open document.
Researchers unzipped the contents of the .rtf—which is an Office Open XML file—finding a URL hidden in the “document.xml.rels” file that is not a legitimate domain found in Office documents, they said. 17-Year-Old Bug ExploitedConnecting to this URL leads to a redirect and then downloads an RTF document called “f_document_shp.doc. This document contained two “not well-formed” OLE objects that revealed shellcode exploiting CVE-2017-11882, which researchers said is an “over four-years-old” remote code execution vulnerability (RCE) [...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Snake Keylogger Spreads Through Malicious PDFs Snake Keylogger Spreads Through Malicious PDFsPost Views: 2 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch…
in Equation Editor.
Equation Editor is app installed by default with the Office suite that’s used to insert and edit complex equations as Object Linking and Embedding (OLE) items in Microsoft Word documents.
See Also: Kali Linux 2022.2 released with new tools, terminal tweaks and more
It turns out, however, that the bug that attackers leverage in the campaign is actually one that Microsoft patched more than four years ago–in 2017, to be exact—but actually had existed some 17 years before that, making it 22 years old now.
As the final act of the attack, researchers found shellcode stored in the “OLENativeStream” structure at the end of one of the OLE objects they examined. The code eventually decrypts a ciphertext that turns out to be more shellcode, which is then executed after to lead to an executable called fresh.exe that loads the Snake Keylogger, researchers found. See Also: Recon Tool: Dorks collections list Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20212 weeks ago
The post Snake Keylogger Spreads Through Malicious PDFs first appeared on Black Hat Ethical Hacking.
Equation Editor is app installed by default with the Office suite that’s used to insert and edit complex equations as Object Linking and Embedding (OLE) items in Microsoft Word documents.
See Also: Kali Linux 2022.2 released with new tools, terminal tweaks and more
It turns out, however, that the bug that attackers leverage in the campaign is actually one that Microsoft patched more than four years ago–in 2017, to be exact—but actually had existed some 17 years before that, making it 22 years old now.
As the final act of the attack, researchers found shellcode stored in the “OLENativeStream” structure at the end of one of the OLE objects they examined. The code eventually decrypts a ciphertext that turns out to be more shellcode, which is then executed after to lead to an executable called fresh.exe that loads the Snake Keylogger, researchers found. See Also: Recon Tool: Dorks collections list Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Discord-hack-90x90.png Malware Builder Leverages Discord Webhooks1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/backdoor-90x90.jpg BPFdoor: Stealthy Linux malware bypasses firewalls for remote access2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/microsoft-exploit-90x90.jpg Actively Exploited Zero-Day Bug Patched by Microsoft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/maxresdefault-90x90.jpg UK government blocked four times as many cyber-scams in 20212 weeks ago
The post Snake Keylogger Spreads Through Malicious PDFs first appeared on Black Hat Ethical Hacking.