Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Do Black Hat Hackers Differ From White Hat Hackers?
https://cdn-images-1.medium.com/max/2600/0*jVFndLfeAykGp1UV
The difference between black hat and white hat is simple in their objectives. Black hat is a form of hacking which involves dishonest or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Do Black Hat Hackers Differ From White Hat Hackers?
https://cdn-images-1.medium.com/max/2600/0*jVFndLfeAykGp1UV
The difference between black hat and white hat is simple in their objectives. Black hat is a form of hacking which involves dishonest or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Do Black Hat Hackers Differ From White Hat Hackers?
The difference between black hat and white hat is simple in their objectives. Black hat is a form of hacking which involves dishonest or…
hacking: security in practice
Free WIFI?
despite the memes around it I was wondering if anyone knew of any way of accessing the internet and so on, in a free way, ideally mobile. is there a piece of hardware that can "jack" a signal without technically breaking in? or is my knowledge completely wrong? any help or ideas are appreciated!
submitted by /u/SpiritCreations
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Free WIFI?
despite the memes around it I was wondering if anyone knew of any way of accessing the internet and so on, in a free way, ideally mobile. is there a piece of hardware that can "jack" a signal without technically breaking in? or is my knowledge completely wrong? any help or ideas are appreciated!
submitted by /u/SpiritCreations
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Free WIFI?
despite the memes around it I was wondering if anyone knew of any way of accessing the internet and so on, in a free way, ideally mobile. is there...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers steal WhatsApp accounts using call forwarding trick
Hackers steal WhatsApp accounts using call forwarding trickPost Views: 4
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
There’s a trick that allows attackers to hijack a victim’s WhatsApp account and gain access to personal messages and contact list.
The method relies on the mobile carriers’ automated service to forward calls to a different phone number, and WhatsApp’s option to send a one-time password (OTP) verification code via voice call. The MMI code trickRahul Sasi, the founder and CEO of digital risk protection company CloudSEK, posted some details about the method saying that it is used to hack WhatsApp account.
BleepingComputer tested and found that the method works, albeit with some caveats that a sufficiently skilled attacker could overcome.
It takes just a few minutes for the attacker to take over the WhatsApp account of a victim, but they need to know the target’s phone number and be prepared do some social engineering.
Sasi says that an attacker first needs to convince the victim to make a call to a number that starts with a Man Machine Interface (MMI) code that the mobile carrier set up to enable call forwarding.
Depending on the carrier, a different MMI code can forward all calls to a terminal to a different number or just when the line is busy or there is no reception.
These codes start with a star (*) or a hash (#) symbol. They are easily found and from the research we did, all major mobile network operators support them.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png “First, you receive a call from the attacker who will convince you to make a call to the following number **67* or *405*. Within a few minutes, your WhatsApp would be logged out, and the attackers would get complete control of your account” – Rahul Sasi
The researcher explains that the 10 digit number belongs to the attacker and the MMI code in front of it tells the mobile carrier to forward all calls to the phone number specified after it when the victim’s line is busy.
Once they tricked the victim into forwarding calls to their number, the attacker starts the the WhatsApp registration process on their device, choosing the option to receive the OTP via voice call.
https://www.bleepstatic.com/images/news/u/1100723/2022/WhatsAppOTP.jpg
Some caveatsAlthough the method seems simple, getting it to work requires a little more effort, as BleepingComputer found during testing.
First off, the attacker needs to make sure that they use an MMI code that forwards all calls, regardless of the victim device’s state (unconditionally). For example, if the MMI only forwards calls when a line is busy, call waiting may cause the hijack to fail.
During testing, BleepingComputer noticed that the target device also received text messages informing that WhatsApp is being registered on another device.
Users may miss this warning if the attacker also turns to social engineering and engages the target in a phone call just long enough to receive the WhatsApp OTP code over voice.
If call forwarding has already been activated on[...]
___________________________
@hacking_Attack
@Hacking_Video
Hackers steal WhatsApp accounts using call forwarding trick
Hackers steal WhatsApp accounts using call forwarding trickPost Views: 4
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
There’s a trick that allows attackers to hijack a victim’s WhatsApp account and gain access to personal messages and contact list.
The method relies on the mobile carriers’ automated service to forward calls to a different phone number, and WhatsApp’s option to send a one-time password (OTP) verification code via voice call. The MMI code trickRahul Sasi, the founder and CEO of digital risk protection company CloudSEK, posted some details about the method saying that it is used to hack WhatsApp account.
BleepingComputer tested and found that the method works, albeit with some caveats that a sufficiently skilled attacker could overcome.
It takes just a few minutes for the attacker to take over the WhatsApp account of a victim, but they need to know the target’s phone number and be prepared do some social engineering.
Sasi says that an attacker first needs to convince the victim to make a call to a number that starts with a Man Machine Interface (MMI) code that the mobile carrier set up to enable call forwarding.
Depending on the carrier, a different MMI code can forward all calls to a terminal to a different number or just when the line is busy or there is no reception.
These codes start with a star (*) or a hash (#) symbol. They are easily found and from the research we did, all major mobile network operators support them.
See Also: Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png “First, you receive a call from the attacker who will convince you to make a call to the following number **67* or *405*. Within a few minutes, your WhatsApp would be logged out, and the attackers would get complete control of your account” – Rahul Sasi
The researcher explains that the 10 digit number belongs to the attacker and the MMI code in front of it tells the mobile carrier to forward all calls to the phone number specified after it when the victim’s line is busy.
Once they tricked the victim into forwarding calls to their number, the attacker starts the the WhatsApp registration process on their device, choosing the option to receive the OTP via voice call.
https://www.bleepstatic.com/images/news/u/1100723/2022/WhatsAppOTP.jpg
Some caveatsAlthough the method seems simple, getting it to work requires a little more effort, as BleepingComputer found during testing.
First off, the attacker needs to make sure that they use an MMI code that forwards all calls, regardless of the victim device’s state (unconditionally). For example, if the MMI only forwards calls when a line is busy, call waiting may cause the hijack to fail.
During testing, BleepingComputer noticed that the target device also received text messages informing that WhatsApp is being registered on another device.
Users may miss this warning if the attacker also turns to social engineering and engages the target in a phone call just long enough to receive the WhatsApp OTP code over voice.
If call forwarding has already been activated on[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Hackers steal WhatsApp accounts using call forwarding trick | Black Hat Ethical Hacking
There’s a trick that allows attackers to hijack a victim’s WhatsApp account and gain access to personal messages and contact list.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers steal WhatsApp accounts using call forwarding trick Hackers steal WhatsApp accounts using call forwarding trickPost Views: 4 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png…
the victim device, the attacker must use a different phone number than the one used for the redirection – a small inconvenience that might require more social engineering.
The most clear clue of suspicious activity for the target user occurs after the mobile operators turn on call forwarding for their device, since activation comes with a warning overlayed on the screen that doesn’t go away until the user confirms it.
https://www.bleepstatic.com/images/news/u/1100723/2022/CallFWOn.jpg
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/office-365-90x90.jpg Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/evilgnomes-linux-malware-steals-audios-spy-on-linux-users-1-1-1024x688-1-90x90.jpg New Windows Subsystem for Linux malware steals browser auth cookies2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethical[...]
___________________________
@hacking_Attack
@Hacking_Video
The most clear clue of suspicious activity for the target user occurs after the mobile operators turn on call forwarding for their device, since activation comes with a warning overlayed on the screen that doesn’t go away until the user confirms it.
https://www.bleepstatic.com/images/news/u/1100723/2022/CallFWOn.jpg
Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/office-365-90x90.jpg Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/evilgnomes-linux-malware-steals-audios-spy-on-linux-users-1-1-1024x688-1-90x90.jpg New Windows Subsystem for Linux malware steals browser auth cookies2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/3e41-article-210226-vmware-body-text-90x90.jpg April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell2 weeks ago
* https://www.blackhatethical[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
the victim device, the attacker must use a different phone number than the one used for the redirection – a small inconvenience that might require more social engineering. The most clear clue of suspicious activity for the target user occurs after the mobile…
hacking.com/wp-content/uploads/2022/05/iphone-low-power-hacking_068D000001681697-90x90.jpg iPhones Vulnerable to Attack Even When Turned Off2 weeks ago
The post Hackers steal WhatsApp accounts using call forwarding trick first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
The post Hackers steal WhatsApp accounts using call forwarding trick first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Cryptography a Foundation of Cyber Security.
https://medium.com/@cybertix/cryptography-a-foundation-of-cyber-security-38d5168be05?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@cybertix/cryptography-a-foundation-of-cyber-security-38d5168be05?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cryptography a Foundation of Cyber Security. (Part-1)
The word Cryptography, is very Common and well-known for the People who are in the Field of Cyber Security. But this Blog is for all the people who are new into this field, and who want to sharp…
Continue reading on Medium » (https://medium.com/@cybertix/cryptography-a-foundation-of-cyber-security-38d5168be05?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cryptography a Foundation of Cyber Security. (Part-1)
The word Cryptography, is very Common and well-known for the People who are in the Field of Cyber Security. But this Blog is for all the people who are new into this field, and who want to sharp…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Damn Vulnerable DeFi Wargame” Challenge #3 — Truster Contract Analysis
https://cdn-images-1.medium.com/max/1920/1*yqJl0wyEpSnRnMdup7CRFw.png
Challenge #3 — Truster
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Damn Vulnerable DeFi Wargame” Challenge #3 — Truster Contract Analysis
https://cdn-images-1.medium.com/max/1920/1*yqJl0wyEpSnRnMdup7CRFw.png
Challenge #3 — Truster
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Damn Vulnerable DeFi Wargame” Challenge #3 — Truster Contract Analysis🤔
Challenge #3 — Truster
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Damn Vulnerable DeFi Wargame” Challenge #2 — Naive receiver Contract Analysis
https://cdn-images-1.medium.com/max/1920/1*XDQ-wPAiHd1iA98DF-qVZA.png
Challenge #2 — Naive receiver
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
“Damn Vulnerable DeFi Wargame” Challenge #2 — Naive receiver Contract Analysis
https://cdn-images-1.medium.com/max/1920/1*XDQ-wPAiHd1iA98DF-qVZA.png
Challenge #2 — Naive receiver
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
“Damn Vulnerable DeFi Wargame” Challenge #2 — Naive receiver Contract Analysis
Challenge #2 — Naive receiver
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What are Dancing Pigs in Cybersecurity?
https://cdn-images-1.medium.com/max/2600/1*ojUOoQkfcsxDs4rz9kaaRA.jpeg
In computer security, “dancing pigs” is a term or problem that explains computer users’ attitudes towards computer security. Users will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What are Dancing Pigs in Cybersecurity?
https://cdn-images-1.medium.com/max/2600/1*ojUOoQkfcsxDs4rz9kaaRA.jpeg
In computer security, “dancing pigs” is a term or problem that explains computer users’ attitudes towards computer security. Users will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What are Dancing Pigs in Cybersecurity?
In computer security, “dancing pigs” is a term or problem that explains computer users’ attitudes towards computer security. Users will…
Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty
On 17.11.2021 I reported a critical security issue in Microsoft Dynamics Container Sandbox, that allows Microsoft Customers to setup a…Continue reading on Medium »
Read more...
On 17.11.2021 I reported a critical security issue in Microsoft Dynamics Container Sandbox, that allows Microsoft Customers to setup a…Continue reading on Medium »
Read more...
Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty
https://hencohen10.medium.com/microsoft-dynamics-container-sandbox-rce-via-unauthenticated-docker-remote-api-20-000-bounty-7f726340a93b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hencohen10.medium.com/microsoft-dynamics-container-sandbox-rce-via-unauthenticated-docker-remote-api-20-000-bounty-7f726340a93b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty
On 17.11.2021 I reported a critical security issue in Microsoft Dynamics Container Sandbox, that allows Microsoft Customers to setup a…
On 17.11.2021 I reported a critical security issue in Microsoft Dynamics Container Sandbox, that allows Microsoft Customers to setup a…Continue reading on Medium » (https://hencohen10.medium.com/microsoft-dynamics-container-sandbox-rce-via-unauthenticated-docker-remote-api-20-000-bounty-7f726340a93b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty
On 17.11.2021 I reported a critical security issue in Microsoft Dynamics Container Sandbox, that allows Microsoft Customers to setup a…