Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CRYPTO RECOVERY
Cryptocurrencies like Bitcoin and Ethereum have dramatically increase in value, with even a single Bitcoin now worth tens of thousands ofβ¦
Continue reading on Medium Β»
CRYPTO RECOVERY
Cryptocurrencies like Bitcoin and Ethereum have dramatically increase in value, with even a single Bitcoin now worth tens of thousands ofβ¦
Continue reading on Medium Β»
Blockzero Labs Opens $10,000 Bug Bounty for Dropzero Protocol
https://medium.com/bombx/blockzero-labs-opens-10-000-bug-bounty-for-dropzero-protocol-b329fe5140a2?source=rss------bug_bounty-5
https://medium.com/bombx/blockzero-labs-opens-10-000-bug-bounty-for-dropzero-protocol-b329fe5140a2?source=rss------bug_bounty-5
Dropzero by Blockzero Labs is cryptoβs first permissionless protocol for one-stop airdrops distribution.Continue reading on Blockzero Labs Β» (https://medium.com/bombx/blockzero-labs-opens-10-000-bug-bounty-for-dropzero-protocol-b329fe5140a2?source=rss------bug_bounty-5)
KitPloit - PenTest Tools!
Cypheroth - Automated, Extensible Toolset That Runs Cypher Queries Against Bloodhound's Neo4j Backend And Saves Output To Spreadsheets
Cypheroth - Automated, Extensible Toolset That Runs Cypher Queries Against Bloodhound's Neo4j Backend And Saves Output To Spreadsheets
KitPloit - PenTest & Hacking Tools
Cypheroth - Automated, Extensible Toolset That Runs Cypher Queries Against Bloodhound's Neo4j Backend And Saves Output To Spreadsheets
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Domain Persistence: DSRM
In this post, we are going to discuss one more Mitre Attack Technique for Tactic ID TA0003 which is used by various of APTs & threat Actors for creating a permanent backdoor in the domain controller. We will check how to use Directory Services Restore Mode (DSRM) for conducting a
The post Domain Persistence: DSRM appeared first on Hacking Articles.
Domain Persistence: DSRM
In this post, we are going to discuss one more Mitre Attack Technique for Tactic ID TA0003 which is used by various of APTs & threat Actors for creating a permanent backdoor in the domain controller. We will check how to use Directory Services Restore Mode (DSRM) for conducting a
The post Domain Persistence: DSRM appeared first on Hacking Articles.
Deep Web
Deep Web Art
Does anyone know of any famous paintings or pieces of art that have gone missing and then have shown up on the deep web? Iβm very interested in art and I was watching a documentary about stealing paintings and was wondering where they go after they get stolen because itβs not like they can just sell the paintings on the open web... that would be way to much attention and they would obviously get caught.
So if anyone knows where they go please let me know Iβm very couriers!!
submitted by /u/Monkeyhank420
[link] [comments]
Deep Web Art
Does anyone know of any famous paintings or pieces of art that have gone missing and then have shown up on the deep web? Iβm very interested in art and I was watching a documentary about stealing paintings and was wondering where they go after they get stolen because itβs not like they can just sell the paintings on the open web... that would be way to much attention and they would obviously get caught.
So if anyone knows where they go please let me know Iβm very couriers!!
submitted by /u/Monkeyhank420
[link] [comments]
reddit
Deep Web Art
Does anyone know of any famous paintings or pieces of art that have gone missing and then have shown up on the deep web? Iβm very interested in...
Deep Web
Chinese 2015 OPM Leak
Referring to the Chinese hack of 2015 on the OPM, I heard it was leaked somewhere on the deep web. I am trying to get this information for a college project, this is not cheating as my professor said that we are allowed to use whatever open-source resources that we want. Does anyone know where I can find some info or the leak itself?
submitted by /u/Nalsooner12
[link] [comments]
Chinese 2015 OPM Leak
Referring to the Chinese hack of 2015 on the OPM, I heard it was leaked somewhere on the deep web. I am trying to get this information for a college project, this is not cheating as my professor said that we are allowed to use whatever open-source resources that we want. Does anyone know where I can find some info or the leak itself?
submitted by /u/Nalsooner12
[link] [comments]
reddit
Chinese 2015 OPM Leak
Referring to the Chinese hack of 2015 on the OPM, I heard it was leaked somewhere on the deep web. I am trying to get this information for a...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Bayrob.dtrg Insecure Permissions
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Trojan.Win32.Bayrob.dtrg malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Trojan.Win32.Bayrob.dtrg Insecure Permissions
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Trojan.Win32.Bayrob.dtrg malware suffers from an insecure permissions vulnerability.
MD5 |
54c14723e1fed89a332e168edb0e7669Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/2f3f0e9be7edb73e545fc49b5a78b4f0.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan.Win32.Bayrob.dtrg
Vulnerability: Insecure Permissions
Description: Bayrob.dtrg creates an insecure dir named "mnfqzckna0dkc" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 2f3f0e9be7edb73e545fc49b5a78b4f0
Vuln ID: MVID-2021-0175
Dropped files: fuwa2hvojto7lyc1nnmuov.exe, k2fyqvt.exe, pnhky9c.exe, stivbgcekgrl, oljlgxh, nxqdc3kf
Disclosure: 04/17/2021
Exploit/PoC:
C:\>cacls mnfqzckna0dkc
C:\mnfqzckna0dkc BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir /a mnfqzckna0dkc
Volume in drive C has no label.
Directory of C:\mnfqzckna0dkc
04/12/2021 08:27 PM 205,824 fuwa2hvojto7lyc1nnmuov.exe
04/12/2021 08:27 PM 205,824 k2fyqvt.exe
04/12/2021 08:27 PM 0 nxqdc3kf
04/12/2021 08:28 PM 4 oljlgxh
04/12/2021 08:27 PM 205,824 pnhky9c.exe
04/12/2021 08:27 PM 10 stivbgcekgrl
6 File(s) 617,486 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Agentb.iofv Insecure Permissions
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Trojan.Win32.Agentb.iofv malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Trojan.Win32.Agentb.iofv Insecure Permissions
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Trojan.Win32.Agentb.iofv malware suffers from an insecure permissions vulnerability.
MD5 |
f1d4908479b404b3600bb16933d6ba56Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/d4ac133a9df0c627f899bb6039d04215.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan.Win32.Agentb.iofv
Vulnerability: Insecure Permissions
Description: Agentb.iofv creates an insecure dir named "drivr" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges
Type: PE32
MD5: d4ac133a9df0c627f899bb6039d04215
Vuln ID: MVID-2021-0172
Dropped files: hostloader.exe
Disclosure: 04/17/2021
Exploit/PoC:
C:\>cacls drivr
C:\drivr BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir /a drivr
Volume in drive C has no label.
Directory of C:\drivr
06/14/2012 06:21 PM 293,376 hostloader.exe
1 File(s) 293,376 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.NanoBot.onh Insecure Permissions
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
Trojan.Win32.NanoBot.onh malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Trojan.Win32.NanoBot.onh Insecure Permissions
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
Trojan.Win32.NanoBot.onh malware suffers from an insecure permissions vulnerability.
MD5 |
547ee0ff71365297633d647614914aa7Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/9fff4c02274c0162880844f27ff91407.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan.Win32.NanoBot.onh
Vulnerability: Insecure Permissions
Description: NanoBot.onh creates an insecure dir named "AppData" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges. In this case the dropped file "amsiproxy.bat" is actually an PE32 executable as indicated by the presence of MZ header field and binary data.
Type: PE32
MD5: 9fff4c02274c0162880844f27ff91407
Vuln ID: MVID-2021-0173
Dropped files: amsiproxy.bat (PE32)
Disclosure: 04/17/2021
Exploit/PoC:
C:\>cacls AppData
C:\AppData BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\AppData\Register-CimProvider>dir
Volume in drive C has no label.
Directory of C:\AppData\Register-CimProvider
04/15/2021 10:50 PM 1,101,316 amsiproxy.bat
1 File(s) 1,101,316 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com