Systematic and goal-oriented penetration testing always starts with the right methodology. The following diagram shows how web application…Continue reading on Medium » (https://medium.com/@arshiadev/web-application-hacking-methodology-4d147db32695?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Is it possible to turn a WiFi range extender into a wifi receiver?
OS: Linux 5.18 Device: Netgear Universal WiFi Range Extender Model: WN3000RPv2 Info: https://www.netgear.com/support/product/WN3000RPv2.aspx
This range extender is basically a powerline module with a wifi emitter.
One powerline module is plugged into a power outlet and connects directly to the wifi router via ethernet cable.
The netgear device is plugged into a different power outlet in the same house and receives the ethernet signal. You can either connect directly to it with an ethernet cable but it also acts as its own wifi router that you can connect to using a domain name (mywifiext.net)
I was curious if i could use this as a kind-of wifi adapter that connects to my laptop via ethernet instead of USB. It doesnt seem to be working without there being a second powerline device plugged directly into a modem
I was curious is there was anyway I could access the software on the device via ethernet and maybe mess around with its settings.
submitted by /u/dominic_l
[link] [comments]
Is it possible to turn a WiFi range extender into a wifi receiver?
OS: Linux 5.18 Device: Netgear Universal WiFi Range Extender Model: WN3000RPv2 Info: https://www.netgear.com/support/product/WN3000RPv2.aspx
This range extender is basically a powerline module with a wifi emitter.
One powerline module is plugged into a power outlet and connects directly to the wifi router via ethernet cable.
The netgear device is plugged into a different power outlet in the same house and receives the ethernet signal. You can either connect directly to it with an ethernet cable but it also acts as its own wifi router that you can connect to using a domain name (mywifiext.net)
I was curious if i could use this as a kind-of wifi adapter that connects to my laptop via ethernet instead of USB. It doesnt seem to be working without there being a second powerline device plugged directly into a modem
I was curious is there was anyway I could access the software on the device via ethernet and maybe mess around with its settings.
submitted by /u/dominic_l
[link] [comments]
hacking: security in practice
Why don’t hackers take down pornhub?
Is it difficult? Have people tried before? Is it illegal?
submitted by /u/SprinklesMcFlinkles
[link] [comments]
Why don’t hackers take down pornhub?
Is it difficult? Have people tried before? Is it illegal?
submitted by /u/SprinklesMcFlinkles
[link] [comments]
reddit
Why don’t hackers take down pornhub?
Is it difficult? Have people tried before? Is it illegal?
hacking: security in practice
I want to learn to trace an IP
For instance say that I was tired of hearing a racist kid in game chat. And I wanted to trace a gammer tag to an IP, and then find out where they are from and then maybe lead to like their Facebook. Just to get general information, name and hometown/address to scare the piss out of them.
What do I need to learn to do and tools I need to perform such actions. Thanks my fellow nerds. This will be my introduction into hacking.
Ps: where my marines at. Yutttttt and SFMF.
submitted by /u/OldDogRivers
[link] [comments]
I want to learn to trace an IP
For instance say that I was tired of hearing a racist kid in game chat. And I wanted to trace a gammer tag to an IP, and then find out where they are from and then maybe lead to like their Facebook. Just to get general information, name and hometown/address to scare the piss out of them.
What do I need to learn to do and tools I need to perform such actions. Thanks my fellow nerds. This will be my introduction into hacking.
Ps: where my marines at. Yutttttt and SFMF.
submitted by /u/OldDogRivers
[link] [comments]
reddit
I want to learn to trace an IP
For instance say that I was tired of hearing a racist kid in game chat. And I wanted to trace a gammer tag to an IP, and then find out where they...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Fight Against The Attackers Continues
https://cdn-images-1.medium.com/max/2048/1*FGMSZJZ6yJNPGC-foJf7UQ.jpeg
For those who haven’t read it before, I suggest you take a look at my part 1 article.
Continue reading on Medium »
The Fight Against The Attackers Continues
https://cdn-images-1.medium.com/max/2048/1*FGMSZJZ6yJNPGC-foJf7UQ.jpeg
For those who haven’t read it before, I suggest you take a look at my part 1 article.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
EnemyBot malware adds exploits for critical VMware, F5 BIG-IP flaws expanding its reach by quickly adding exploits for recently disclosed critical vulnerabilities in web servers, content management systems, IoT, and Android devices.
https://external-preview.redd.it/gMcDeTAA7bdvruOFMuLW4Y8bxrGp-YeX8YW_jRv1c2s.jpg?width=640&crop=smart&auto=webp&s=6eb2465598d52f6a9b73d28a50b18906b6587b77 submitted by /u/Late_Ice_9288
[link] [comments]
EnemyBot malware adds exploits for critical VMware, F5 BIG-IP flaws expanding its reach by quickly adding exploits for recently disclosed critical vulnerabilities in web servers, content management systems, IoT, and Android devices.
https://external-preview.redd.it/gMcDeTAA7bdvruOFMuLW4Y8bxrGp-YeX8YW_jRv1c2s.jpg?width=640&crop=smart&auto=webp&s=6eb2465598d52f6a9b73d28a50b18906b6587b77 submitted by /u/Late_Ice_9288
[link] [comments]
hacking: security in practice
My card was stolen and used to purchase a Netflix subscription, how can u track their IP/location?
My car was broken into and countless things were stolen, my cards, shoes I only wore one time, a vintage pair of Versace sunglasses given to me by my grandmother, and other important items like my favorite concert hoodie and sweatpants, which hold no resale value whatsoever. Also, they took a photo of me and my friend and crumpled it up for no reason, and threw my neck pillow in a puddle of water. They already robbed me and then they have to act even more evil! The thieves are clearly poor seeing as they bought a Netflix subscription, things from CVS, Walmart, filled up their gas tank, and attempted to buy a $1000 bedroom set. At this point stop being so damn broke and lazy and get a job!!! I have a feeling they will keep all my items for personal use and hope to find them since the cops have already been notified, is there a way to track the IP of the Netflix account that was purchased with my credit card?
submitted by /u/pinksupremes
[link] [comments]
My card was stolen and used to purchase a Netflix subscription, how can u track their IP/location?
My car was broken into and countless things were stolen, my cards, shoes I only wore one time, a vintage pair of Versace sunglasses given to me by my grandmother, and other important items like my favorite concert hoodie and sweatpants, which hold no resale value whatsoever. Also, they took a photo of me and my friend and crumpled it up for no reason, and threw my neck pillow in a puddle of water. They already robbed me and then they have to act even more evil! The thieves are clearly poor seeing as they bought a Netflix subscription, things from CVS, Walmart, filled up their gas tank, and attempted to buy a $1000 bedroom set. At this point stop being so damn broke and lazy and get a job!!! I have a feeling they will keep all my items for personal use and hope to find them since the cops have already been notified, is there a way to track the IP of the Netflix account that was purchased with my credit card?
submitted by /u/pinksupremes
[link] [comments]
reddit
My card was stolen and used to purchase a Netflix subscription,...
My car was broken into and countless things were stolen, my cards, shoes I only wore one time, a vintage pair of Versace sunglasses given to me by...
Introducing Melos Bug Bounty Program
https://medium.com/@mycoinisbitcoin/introducing-melos-bug-bounty-program-101846336465?source=rss------bug_bounty-5
https://medium.com/@mycoinisbitcoin/introducing-melos-bug-bounty-program-101846336465?source=rss------bug_bounty-5
We’re happy to see how quickly Melos Studio has grown so far, but with that comes some concerns. We have seen many recent crises and fraud…Continue reading on Medium » (https://medium.com/@mycoinisbitcoin/introducing-melos-bug-bounty-program-101846336465?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Windows Subsystem for Linux malware steals browser auth cookies
New Windows Subsystem for Linux malware steals browser auth cookiesPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Hackers are showing an increased interest in the Windows Subsystem for Linux (WSL) as an attack surface as they build new malware, the more advanced samples being suitable for espionage and downloading additional malicious modules.
As the name of the feature implies, WSL allows running native Linux binaries to run on Windows in an environment that emulates the Linux kernel.
WSL-based malware samples discovered recently rely on open-source code that routes communication through the Telegram messaging service and gives the threat actor remote access to the compromised system. RATs and shellsMalicious Linux binaries for WSL were first discovered over a year ago, with researchers at Lumen Technologies’ Black Lotus Labs publishing a report on this new type of threat in September 2021.
Since then, their number has grown constantly, with all variants enjoying low detection rates, despite being based on publicly available code.
Black Lotus Labs researchers told BleepingComputer this week that they have tracked more than 100 samples of WSL-based malware since last fall.
Some are more advanced than others, the researchers said, adding that threat actors “show continued interest” in the malware they are tracking.
Of the samples analyzed, two of them are more notable due to their capabilities to function as a remote access tool (RAT) or to establish a reverse shell on the infected host.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png The two samples were discovered after the Black Lotus Labs report in March that warned about WSL becoming a favored attack surface for adversaries of various technical skills levels.
One of the more recent samples relied on a Python-based open-source tool called RAT-via-Telegram Bot that allows control over Telegram and comes with functions for stealing authentication cookies from Google Chrome and Opera web browsers, running commands, or downloading files.
Black Lotus Labs researchers told BleepingComputer that the malware came with a live bot token and chat ID, indicating an active command and control mechanism.
https://www.bleepstatic.com/images/news/u/1100723/2022/WSL_new_sample.png
<figcaptionsource: Lumen Technologies Black Lotus Labs
Additional functions in this variant include taking screenshots and grabbing user and system information (username, IP address, OS version), which helps the attacker determine what malware or utilities they can use in the next phase of the compromise.
When Black Lotus Labs analyzed the sample, only two antivirus engines out of 57 on Virus Total flagged it as malicious, the researchers noted.
A second recently discovered WSL-based malware sample was built to set up a reverse TCP shell on the infected machine to communicate with the attacker.
Looking at the code, the researchers noticed that it used an IP address from Amazon Web Services that had been used previously by several entities.
One particularity that the researchers observed with this sample was that it displayed a pop-up message in Turkish, which translated to: “you’re screwed and there’s not much you can do.”
However, neither the pop-up message, which could indicate Turkish-speaking targets nor the code provided a clue about the author of the malware.
Both malware pieces could be used for espionage purposes and can downloa[...]
New Windows Subsystem for Linux malware steals browser auth cookies
New Windows Subsystem for Linux malware steals browser auth cookiesPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Hackers are showing an increased interest in the Windows Subsystem for Linux (WSL) as an attack surface as they build new malware, the more advanced samples being suitable for espionage and downloading additional malicious modules.
As the name of the feature implies, WSL allows running native Linux binaries to run on Windows in an environment that emulates the Linux kernel.
WSL-based malware samples discovered recently rely on open-source code that routes communication through the Telegram messaging service and gives the threat actor remote access to the compromised system. RATs and shellsMalicious Linux binaries for WSL were first discovered over a year ago, with researchers at Lumen Technologies’ Black Lotus Labs publishing a report on this new type of threat in September 2021.
Since then, their number has grown constantly, with all variants enjoying low detection rates, despite being based on publicly available code.
Black Lotus Labs researchers told BleepingComputer this week that they have tracked more than 100 samples of WSL-based malware since last fall.
Some are more advanced than others, the researchers said, adding that threat actors “show continued interest” in the malware they are tracking.
Of the samples analyzed, two of them are more notable due to their capabilities to function as a remote access tool (RAT) or to establish a reverse shell on the infected host.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png The two samples were discovered after the Black Lotus Labs report in March that warned about WSL becoming a favored attack surface for adversaries of various technical skills levels.
One of the more recent samples relied on a Python-based open-source tool called RAT-via-Telegram Bot that allows control over Telegram and comes with functions for stealing authentication cookies from Google Chrome and Opera web browsers, running commands, or downloading files.
Black Lotus Labs researchers told BleepingComputer that the malware came with a live bot token and chat ID, indicating an active command and control mechanism.
https://www.bleepstatic.com/images/news/u/1100723/2022/WSL_new_sample.png
<figcaptionsource: Lumen Technologies Black Lotus Labs
Additional functions in this variant include taking screenshots and grabbing user and system information (username, IP address, OS version), which helps the attacker determine what malware or utilities they can use in the next phase of the compromise.
When Black Lotus Labs analyzed the sample, only two antivirus engines out of 57 on Virus Total flagged it as malicious, the researchers noted.
A second recently discovered WSL-based malware sample was built to set up a reverse TCP shell on the infected machine to communicate with the attacker.
Looking at the code, the researchers noticed that it used an IP address from Amazon Web Services that had been used previously by several entities.
One particularity that the researchers observed with this sample was that it displayed a pop-up message in Turkish, which translated to: “you’re screwed and there’s not much you can do.”
However, neither the pop-up message, which could indicate Turkish-speaking targets nor the code provided a clue about the author of the malware.
Both malware pieces could be used for espionage purposes and can downloa[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Windows Subsystem for Linux malware steals browser auth cookies New Windows Subsystem for Linux malware steals browser auth cookiesPost Views: 2 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
d files that would extend their functionality, the researchers said.
See Also: Malicious PyPI package opens backdoors on Windows, Linux, and Macs WSL-based malware taking offBlack Lotus Labs warned in the past that threat actors are exploring the WSL vector deeper, even if many of the samples analyzed “did not yet appear to be fully functional due to the use of internal or non-routable IPs.”
Nevertheless, malware authors are making progress and have already created variants that work on both Windows and Linux and can upload and download files, or execute attacker commands.
Unlike previous WSL-based malware, the latest samples that Black Lotus Labs analyzed “would prove effective with an active C2 [command and control] infrastructure in place given the low detection rates of AV providers.” See Also: Offensive Security Tool: Arjun Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The general recommendation for defending against WSL-based threats is to keep a close eye on the system activity (e.g. SysMon) to determine suspicious activity and investigate commands.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: www.bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more2 weeks ago
The post New Windows Subsystem for Linux malware steals browser auth cookies first appeared on Black Hat Ethical Hacking.
See Also: Malicious PyPI package opens backdoors on Windows, Linux, and Macs WSL-based malware taking offBlack Lotus Labs warned in the past that threat actors are exploring the WSL vector deeper, even if many of the samples analyzed “did not yet appear to be fully functional due to the use of internal or non-routable IPs.”
Nevertheless, malware authors are making progress and have already created variants that work on both Windows and Linux and can upload and download files, or execute attacker commands.
Unlike previous WSL-based malware, the latest samples that Black Lotus Labs analyzed “would prove effective with an active C2 [command and control] infrastructure in place given the low detection rates of AV providers.” See Also: Offensive Security Tool: Arjun Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The general recommendation for defending against WSL-based threats is to keep a close eye on the system activity (e.g. SysMon) to determine suspicious activity and investigate commands.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: www.bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/ezgif.com-gif-maker-90x90.jpg Apple emergency update fixes zero-day used to hack Macs, Watches2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/banner-2022.2-release-90x90.jpg Kali Linux 2022.2 released with new tools, terminal tweaks and more2 weeks ago
The post New Windows Subsystem for Linux malware steals browser auth cookies first appeared on Black Hat Ethical Hacking.
Introducing Melos Bug Bounty Program
We’re happy to see how quickly Melos Studio has grown so far, but with that comes some concerns. We have seen many recent crises and fraud…Continue reading on Medium »
Read more...
We’re happy to see how quickly Melos Studio has grown so far, but with that comes some concerns. We have seen many recent crises and fraud…Continue reading on Medium »
Read more...
How I found my first ever XSS on a website.
https://medium.com/@shellyshubh/how-i-found-my-first-ever-xss-on-a-website-e3a0d02e7649?source=rss------bug_bounty-5
So, I have been into web hacking lately. While into it, I have explored bug bounties but never found a bug in real website. I have tested…Continue reading on Medium » (https://medium.com/@shellyshubh/how-i-found-my-first-ever-xss-on-a-website-e3a0d02e7649?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@shellyshubh/how-i-found-my-first-ever-xss-on-a-website-e3a0d02e7649?source=rss------bug_bounty-5
So, I have been into web hacking lately. While into it, I have explored bug bounties but never found a bug in real website. I have tested…Continue reading on Medium » (https://medium.com/@shellyshubh/how-i-found-my-first-ever-xss-on-a-website-e3a0d02e7649?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I found my first ever XSS on a website.
So, I have been into web hacking lately. While into it, I have explored bug bounties but never found a bug in real website. I have tested…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Password Cracking
https://cdn-images-1.medium.com/max/863/0*VzcjBp_R1DAGmPnj.jpg
On hearing the term “password-cracking,” many will think this post will be about how to guess someone’s password or somewhat similar, but…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Password Cracking
https://cdn-images-1.medium.com/max/863/0*VzcjBp_R1DAGmPnj.jpg
On hearing the term “password-cracking,” many will think this post will be about how to guess someone’s password or somewhat similar, but…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Password Cracking
On hearing the term “password-cracking,” many will think this post will be about how to guess someone’s password or somewhat similar, but…