Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
https://b.thumbs.redditmedia.com/CT6EX995fsxbNRmgyd7t-ab7ROmPuRx4uWDMaABsY1E.jpg Be careful if you operate Network printer ' The printer works automatically!' It's called printer hacking

To view the image file, lots of Network printer exposure outside.

Hacker can attack Network printer which returned DISPLAY="READY" status.



https://preview.redd.it/ka2kubgmbb391.png?width=1511&format=png&auto=webp&s=522140795098e6f2e9b8d4a6753aa1469b143afc

submitted by /u/kevin02561
[link] [comments]
hacking: security in practice
My old phone (got reciept)

I have an old Oneplus 6 that I have not used in a long time, and have therefor forgot the screen code. I contacted Oneplus but they said the only way to unlock it was to do a factort reset wich Kinda defeats the purpose.

Is there any way I can get in to the phone without deleting its data? As I said its mine and I got original reciept so nothing shady

submitted by /u/Drakenbror
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
2FA Bypass due to unauthorized 2FA disabling via X/CSRF

Product InfoContinue reading on Medium »
Read more...
hacking: security in practice
Trying to understand how webpages see IP addresses

I'm not. sure if this is the place to post but I'm desperate.

So my university has been insane this season and our we now have a fail rate of over 80%. It's a small uni in a tiny country so no ones been regulating the immense failure rate.

I'm on my last attempt for this subject and I don't really see an issue with cheesing this because

a. I still have to do the oral after this and

b. I've studied my ass off

Our university checks that we submit the page from their laptops (connected to a wifi that only they know the password to) and has caught students attempting from off campus.

But I was wondering if I start the exam on their laptop, leave the hall without submitting and finish the answers elsewhere ON CAMPUS (but a different wifi) can they see something fishy?

I'm desperate at this point

submitted by /u/Cuddle_Cloud
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical Atlassian Confluence zero-day actively used in attacks

Critical Atlassian Confluence zero-day actively used in attacksPost Views: 18
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Hackers are actively exploiting a new Atlassian Confluence zero-day vulnerability tracked as CVE-2022-26134 to install web shells, with no fix available at this time.
Today, Atlassian released a security advisory disclosing that CVE-2022-26134 is a critical unauthenticated, remote code execution vulnerability tracked in both Confluence Server and Data Center.

Atlassian says that they confirmed the vulnerability in Confluence Server 7.18.0 and believe that Confluence Server and Data Center 7.4.0 and higher are also vulnerable.

The advisory warns that threat actors are actively exploiting Confluence Server 7.18.0.

As there are no patches available, Atlassian is telling customers to make their servers inaccessible by one of these two methods:

*
Restricting Confluence Server and Data Center instances from the internet.

*
Disabling Confluence Server and Data Center instances.
There are no other ways to mitigate this vulnerability.

Organizations that use Atlassian Cloud (accessible via atlassian.net) are unaffected by this vulnerability.

Atlassian is actively working on a patch and will release further information in their advisory when it becomes available.

The Cybersecurity and Infrastructure Security Agency (CISA) has added this zero-day to its ‘Known Exploited Vulnerabilities Catalog‘  and is requiring federal agencies to block all internet traffic to Confluence servers by tomorrow, June 3rd.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Servers exploited for initial accessIn a coordinated disclosure, cybersecurity firm Volexity explained that the vulnerability was discovered over the Memorial Day weekend while performing incident response.

After conducting the investigation, Volexity could reproduce the exploit against the latest Confluence Server version and disclosed it to Atlassian on May 31st.

“After a thorough review of the collected data, Volexity was able to determine the server compromise stemmed from an attacker launching an exploit to achieve remote code execution,” explains a blog post by Volexity.

“Volexity was subsequently able to recreate that exploit and identify a zero-day vulnerability impacting fully up-to-date versions of Confluence Server.”

In the breach analyzed by Volexity, threat actors installed BEHINDER, a JSP web shell that allows threat actors to execute commands on the compromised server remotely.
See Also: Malicious PyPI package opens backdoors on Windows, Linux, and Macs See Also: Offensive Security Tool: Arjun The threat actors then used BEHINDER to install the China Chopper web shell and a simple file upload tool as backups.

From Volexity’s investigation, the threat actors dumped the user tables of the Confluence server, wrote additional webshells, and altered access logs to evade detection.

Volexity says that they believe the multiple threat actors from China are utilizing these exploits.

As there are no patches available, Volexity also recommends that Confluence admins disconnect their servers from the Internet until Atlassian releases a fix.

Volexity has released a list of IP addresses behind the attacks and Yara rules to identify web shell activity on Confluence servers. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security,[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical Atlassian Confluence zero-day actively used in attacks Critical Atlassian Confluence zero-day actively used in attacksPost Views: 18 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/3266-90x90.jpg Hackers steal WhatsApp accounts using call forwarding trick2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/office-365-90x90.jpg Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/evilgnomes-linux-malware-steals-audios-spy-on-linux-users-1-1-1024x688-1-90x90.jpg New Windows Subsystem for Linux malware steals browser auth cookies4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/shutterstock_176459972-90x90.jpg LinkedIn bug bounty program goes public with rewards of up to $18k7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/vmware-cloudnerve-90x90.jpg New ‘Cheers’ Linux ransomware targets VMware ESXi servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/mozilla-releases-fixes-for-firefox-thunderbird-vulnerabilities-exploited-during-pwn2own-vancouver-2022-hacking-contest-90x90.jpg Mozilla fixes Firefox, Thunderbird zero-days exploited at Pwn2Own1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/4x3_1600x1200_highres-Word_Snake_News-90x90.jpg Snake Keylogger Spreads Through Malicious PDFs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/FTYM512XsAArcFs-90x90.jpg Malicious PyPI package opens backdoors on Windows, Linux, and Macs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/WordPress_headpic-90x90.jpg Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover2 weeks ago
The post Critical Atlassian Confluence zero-day actively used in attacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty — Continue Penetration Testing

Continue reading on Medium »
Read more...