Dark Reading: Attacks/Breaches
ChromeLoader Malware Hijacks Browsers With ISO Files
The malware’s abuse of PowerShell makes it more dangerous, allowing for more advanced attacks such as ransomware, fileless malware, and malicious code memory injections.
___________________________
@hacking_Attack
@Hacking_Video
ChromeLoader Malware Hijacks Browsers With ISO Files
The malware’s abuse of PowerShell makes it more dangerous, allowing for more advanced attacks such as ransomware, fileless malware, and malicious code memory injections.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
ChromeLoader Malware Hijacks Browsers With ISO Files
The malware's abuse of PowerShell makes it more dangerous, allowing for more advanced attacks such as ransomware, fileless malware, and malicious code memory injections.
Dark Reading: Attacks/Breaches
Scammer Behind $568M International Cybercrime Syndicate Gets 4 Years
The 14th defendant behind The Infraud Organization contraband marketplace has been sentenced, this time for one count of racketeering.
___________________________
@hacking_Attack
@Hacking_Video
Scammer Behind $568M International Cybercrime Syndicate Gets 4 Years
The 14th defendant behind The Infraud Organization contraband marketplace has been sentenced, this time for one count of racketeering.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Scammer Behind $568M International Cybercrime Syndicate Gets 4 Years
The 14th defendant behind The Infraud Organization contraband marketplace has been sentenced, this time for one count of racketeering.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Scanning using Nmap
I like nmap. Please don’t call it a port scanner. It’s more than this.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Scanning using Nmap
I like nmap. Please don’t call it a port scanner. It’s more than this.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Scanning using Nmap
I like nmap. Please don’t call it a port scanner. It’s more than this.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CAN DEVELOPERS MAKE SURE THAT AN ELEARNING APP DOES NOT GET HACKED?
https://cdn-images-1.medium.com/max/770/0*YO7SzVtjOFfddjEF.jpg
An elearning app is a major resource for businesses today when they have to ensure that the employee always keeps on grasping information…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CAN DEVELOPERS MAKE SURE THAT AN ELEARNING APP DOES NOT GET HACKED?
https://cdn-images-1.medium.com/max/770/0*YO7SzVtjOFfddjEF.jpg
An elearning app is a major resource for businesses today when they have to ensure that the employee always keeps on grasping information…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CAN DEVELOPERS MAKE SURE THAT AN ELEARNING APP DOES NOT GET HACKED?
An elearning app is a major resource for businesses today when they have to ensure that the employee always keeps on grasping information…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Expertos detallan una nueva vulnerabilidad de RCE que afecta al canal de desarrollo de Google…
https://cdn-images-1.medium.com/max/1457/0*5guHi9dRcfE9ambP
PUBLICADO EN 27 MAYO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Expertos detallan una nueva vulnerabilidad de RCE que afecta al canal de desarrollo de Google…
https://cdn-images-1.medium.com/max/1457/0*5guHi9dRcfE9ambP
PUBLICADO EN 27 MAYO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Expertos detallan una nueva vulnerabilidad de RCE que afecta al canal de desarrollo de Google Chrome
PUBLICADO EN 27 MAYO, 2022 EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Emotet sigue siendo uno de los malware más frecuentes
https://cdn-images-1.medium.com/max/1713/0*IamrXGE6HxX9wDQ4
PUBLICADO EN 27 MAYO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Emotet sigue siendo uno de los malware más frecuentes
https://cdn-images-1.medium.com/max/1713/0*IamrXGE6HxX9wDQ4
PUBLICADO EN 27 MAYO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Emotet sigue siendo uno de los malware más frecuentes
PUBLICADO EN 27 MAYO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How far can ‘good-faith’ hacking go? Experts question new DOJ guidance
https://cdn-images-1.medium.com/max/2500/1*SJiX_IoWGgjmr22SqLHjeQ.png
The U.S. Justice Department last week softened its stance on prosecuting hackers under a decades-old law. Will the updates thaw DOJ’s…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
How far can ‘good-faith’ hacking go? Experts question new DOJ guidance
https://cdn-images-1.medium.com/max/2500/1*SJiX_IoWGgjmr22SqLHjeQ.png
The U.S. Justice Department last week softened its stance on prosecuting hackers under a decades-old law. Will the updates thaw DOJ’s…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How far can ‘good-faith’ hacking go? Experts question new DOJ guidance
The U.S. Justice Department last week softened its stance on prosecuting hackers under a decades-old law. Will the updates thaw DOJ’s…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
God Mode For Windows 10 and 11 OS
https://cdn-images-1.medium.com/max/2600/0*WCv-BM-qJkEa_PBt
For users of the Microsoft Windows 10 there is a desktop trick that most code monkeys, gamers and hackers know. Old hat Windows users will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
God Mode For Windows 10 and 11 OS
https://cdn-images-1.medium.com/max/2600/0*WCv-BM-qJkEa_PBt
For users of the Microsoft Windows 10 there is a desktop trick that most code monkeys, gamers and hackers know. Old hat Windows users will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
God Mode For Windows 10 and 11 OS
For users of the Microsoft Windows 10 there is a desktop trick that most code monkeys, gamers and hackers know. Old hat Windows users will…
hacking: security in practice
What are some tools or methods people use to completely wipe memory.
I’m curious on what programs or methods you guys use or are the best for completely formatting sd cards, usb sticks, hard drives, and operating systems so that no data can be recovered. This includes cookies, any metadata, files, etc. say if law enforcement seized these devices they would not find anything.
submitted by /u/shinygoldcollector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What are some tools or methods people use to completely wipe memory.
I’m curious on what programs or methods you guys use or are the best for completely formatting sd cards, usb sticks, hard drives, and operating systems so that no data can be recovered. This includes cookies, any metadata, files, etc. say if law enforcement seized these devices they would not find anything.
submitted by /u/shinygoldcollector
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What are some tools or methods people use to completely wipe memory.
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Offensive Security Tool: DeepSleep
Offensive Security Tool: DeepSleepPost Views: 104
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Offensive Security Tool: DeepSleep GitHub Link
DeepSleep by thefLink, is a variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC. Evasive techniques take time to produce, find and create. They are the most important steps for any attack scenario. Without evasion, you cannot perform attacks. DescriptionThis tool was created to better understand how to evade memory artifacts using a Gargoyle-like technique on x64. The idea is to set up a ROPChain calling VirtualProtect() ➡ Sleep() ➡ VirtualProtect() to mark my own page as N/A while Sleeping.
Unlike Gargoyle and other Gargoyle-like implementations, this tool relied on ROP and do not queue any APC. DeepSleep itself is implemented as fully PIC, which makes it easier to enumerate which memory pages have to be hidden from scanners.
While the thread is active, a MessageBox pops up and DeepSleep’s page is marked as executable. While Sleeping, the page is marked as N/A.
This effectively bypasses Moneta at the time of writing if DeepSleep is injected and the executing thread’s base address does not point to private commited memory.
It has been verified using the Earlybird injection technique to inject DeepSleep.bin into notepad.exe
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/MonetaFound.png
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/MonetaNotFound.png
See Also: Recon Tool: qsreplace UsageUsing Mingw:
Type make and a wild DeepSleep.bin appears.
Alternatively use the precompiled DeepSleep.bin LimitationsThis was tested on 10.0.19044 N/A Build 19044
The ROPgadgets that the tool relies on might not exist in ntdll.dll in other versions of Windows. It is probably a good idea to make use of smaller and more generic ROPgadgets and to enumerate the gadgets in more dlls than ntdll.dll. DetectionThe callstack to a thread in the DelayExecution state includes unknown/tampered memory regions and additionally includes addresses to VirtualProtect(). Hunt-Sleeping-Beacons detects this.
It may be possible to apply that metric to other C2 using a different technique to wait between callbacks.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WeirdTrace.png
See Also: The Difference between Vulnerability Assessment and Pentesting https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/qsreplace-90x90.png Recon Tool: qsreplace1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Arjun-90x90.png Offensive Security Tool: Arjun1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Dorks-collections-list-90x90.png Recon Tool: Dorks collections list1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/malicious-pdf-90x90.png Offensive Security Tool: malicious-pdf2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/scanmycode-90x90.png Static Code Analysis Tool: scanmycode-ce3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/MOSINT-1-90x90.png OSINT Tool: MOSINT4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/findomain-90x90.png Recon Tool: Findomain4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/keethief-90x90.png Offensive Security Tool: KeeThief1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/reconftw-90x90.png Recon Tool: ReconFTW1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/smap-demo-90x90.png Recon Tool: Smap1 month ago
The post Offensive Security Tool: DeepSleep first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Offensive Security Tool: DeepSleep
Offensive Security Tool: DeepSleepPost Views: 104
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Offensive Security Tool: DeepSleep GitHub Link
DeepSleep by thefLink, is a variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC. Evasive techniques take time to produce, find and create. They are the most important steps for any attack scenario. Without evasion, you cannot perform attacks. DescriptionThis tool was created to better understand how to evade memory artifacts using a Gargoyle-like technique on x64. The idea is to set up a ROPChain calling VirtualProtect() ➡ Sleep() ➡ VirtualProtect() to mark my own page as N/A while Sleeping.
Unlike Gargoyle and other Gargoyle-like implementations, this tool relied on ROP and do not queue any APC. DeepSleep itself is implemented as fully PIC, which makes it easier to enumerate which memory pages have to be hidden from scanners.
While the thread is active, a MessageBox pops up and DeepSleep’s page is marked as executable. While Sleeping, the page is marked as N/A.
This effectively bypasses Moneta at the time of writing if DeepSleep is injected and the executing thread’s base address does not point to private commited memory.
It has been verified using the Earlybird injection technique to inject DeepSleep.bin into notepad.exe
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/MonetaFound.png
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/MonetaNotFound.png
See Also: Recon Tool: qsreplace UsageUsing Mingw:
Type make and a wild DeepSleep.bin appears.
Alternatively use the precompiled DeepSleep.bin LimitationsThis was tested on 10.0.19044 N/A Build 19044
The ROPgadgets that the tool relies on might not exist in ntdll.dll in other versions of Windows. It is probably a good idea to make use of smaller and more generic ROPgadgets and to enumerate the gadgets in more dlls than ntdll.dll. DetectionThe callstack to a thread in the DelayExecution state includes unknown/tampered memory regions and additionally includes addresses to VirtualProtect(). Hunt-Sleeping-Beacons detects this.
It may be possible to apply that metric to other C2 using a different technique to wait between callbacks.
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WeirdTrace.png
See Also: The Difference between Vulnerability Assessment and Pentesting https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/qsreplace-90x90.png Recon Tool: qsreplace1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Arjun-90x90.png Offensive Security Tool: Arjun1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Dorks-collections-list-90x90.png Recon Tool: Dorks collections list1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/malicious-pdf-90x90.png Offensive Security Tool: malicious-pdf2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/scanmycode-90x90.png Static Code Analysis Tool: scanmycode-ce3 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/MOSINT-1-90x90.png OSINT Tool: MOSINT4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/findomain-90x90.png Recon Tool: Findomain4 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/keethief-90x90.png Offensive Security Tool: KeeThief1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/reconftw-90x90.png Recon Tool: ReconFTW1 month ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/smap-demo-90x90.png Recon Tool: Smap1 month ago
The post Offensive Security Tool: DeepSleep first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Offensive Security Tool: DeepSleep | Black Hat Ethical Hacking
DeepSleep is a variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC. Evasive techniques take time to produce. They are the most important steps for any attack scenario.
Dark Reading: Attacks/Breaches
Space Force Expands Cyber Defense Operations
Space Force's Delta 6 cyber-defense group adds squadrons, updates legacy Satellite Control Network.
___________________________
@hacking_Attack
@Hacking_Video
Space Force Expands Cyber Defense Operations
Space Force's Delta 6 cyber-defense group adds squadrons, updates legacy Satellite Control Network.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Space Force Expands Cyber Defense Operations
Space Force's Delta 6 cyber-defense group adds squadrons, updates legacy Satellite Control Network.