Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hire A Hacker To Change University Grades
Hire A Hacker To Change University Grades
Being a student can be really stressful, especially trying to draw a balance between academic…
Continue reading on Medium »
Hire A Hacker To Change University Grades
Hire A Hacker To Change University Grades
Being a student can be really stressful, especially trying to draw a balance between academic…
Continue reading on Medium »
Named Pipe Pass-the-Hash
https://www.reddit.com/r/redteamsec/comments/mu6tvw/named_pipe_passthehash/
submitted by /u/S3cur3Th1sSh1t (https://www.reddit.com/user/S3cur3Th1sSh1t)
[link] (https://s3cur3th1ssh1t.github.io/Named-Pipe-PTH/) [comments] (https://www.reddit.com/r/redteamsec/comments/mu6tvw/named_pipe_passthehash/)
https://www.reddit.com/r/redteamsec/comments/mu6tvw/named_pipe_passthehash/
submitted by /u/S3cur3Th1sSh1t (https://www.reddit.com/user/S3cur3Th1sSh1t)
[link] (https://s3cur3th1ssh1t.github.io/Named-Pipe-PTH/) [comments] (https://www.reddit.com/r/redteamsec/comments/mu6tvw/named_pipe_passthehash/)
https://b.thumbs.redditmedia.com/irOXcCW9120P3e0JnBFQ6ybEWs8IQ26nIRp96SYbu9Q.jpg the dogecoin army is great! let's go to the moon tomorrow!
https://preview.redd.it/4d87lpgv06u61.png?width=711&format=png&auto=webp&s=bd10cb53cc3227726fd3ab5a764344d3ecc148c1
submitted by /u/Trader_Kamikaze
[link] [comments]
https://preview.redd.it/4d87lpgv06u61.png?width=711&format=png&auto=webp&s=bd10cb53cc3227726fd3ab5a764344d3ecc148c1
submitted by /u/Trader_Kamikaze
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.Agent.hsm Insecure Permissions
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Trojan.Win32.Agent.hsm malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Trojan.Win32.Agent.hsm Insecure Permissions
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Trojan.Win32.Agent.hsm malware suffers from an insecure permissions vulnerability.
MD5 |
30fdf081c36736d3966de00b316db172Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/c58d5aecd223ac95ae5fab6dcd69e953.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan.Win32.Agent.hsm
Vulnerability: Insecure Permissions
Description: Agent.hsm creates an insecure dir named "LOL" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: c58d5aecd223ac95ae5fab6dcd69e953
Vuln ID: MVID-2021-0178
Dropped files: jah.exe
Disclosure: 04/18/2021
Exploit/PoC:
C:\>cacls LOL
C:\LOL BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir LOL
Volume in drive C has no label.
Directory of C:\LOL
12/30/2019 04:16 AM 45,056 jah.exe
1 File(s) 45,056 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Plantronics HUB 3.21 Privilege Escalation
https://4.bp.blogspot.com/-lQ2zJgiLTsU/WWlu34sMcWI/AAAAAAAAII4/mS7xceEZnmUYAvFeoaUiLc9JINHoDjNsACLcBGAs/s1600/h102.png
Plantronics HUB versions 3.21 and below are affected by a privilege escalation vulnerability allowing any local unprivileged user to acquire elevated access rights and take full control of the system.
MD5 |
Download
Source:packetstormsecurity.com
Plantronics HUB 3.21 Privilege Escalation
https://4.bp.blogspot.com/-lQ2zJgiLTsU/WWlu34sMcWI/AAAAAAAAII4/mS7xceEZnmUYAvFeoaUiLc9JINHoDjNsACLcBGAs/s1600/h102.png
Plantronics HUB versions 3.21 and below are affected by a privilege escalation vulnerability allowing any local unprivileged user to acquire elevated access rights and take full control of the system.
MD5 |
e621c3b1d19f270f4c0d773a88453820Download
https://www.redtimmy.com/when-a-denial-of-service-matters-fighting-with-risk-assessment-guys/
CVSS 3.0 score:
7.8 (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Description of the Vulnerable Product
Poly is a company with an annual revenue of 1,2 USD billion per year.
They are behind the Plantronics brand producing audio devices for the
segments business and consumer. Their software, Plantronics HUB, allows
end users to customize the settings and view the status of the audio
device plugged in the PC.
Product Homepage:
https://www.poly.com/us/en/support/downloads-apps/hub-desktop
Version(s) Affected:
3.21 (last available) and prior
Tested on
Windows 10 and Windows 8
Vulnerability Description
Plantronics HUB 3.21 (and previous versions) is affected by a privilege
escalation vulnerability allowing any local unprivileged user to acquire
elevated access rights and take full control of the system.
Additionally local attackers can delete arbitrary files from the
filesystem with the privileges of “NT_AUTHORITY\SYSTEM”.
More details can be found here:
https://www.redtimmy.com/when-a-denial-of-service-matters-fighting-with-risk-assessment-guys/
Source:packetstormsecurity.com
hacking: security in practice
Which RAT software to use?
Title
submitted by /u/oprimeolt
[link] [comments]
Which RAT software to use?
Title
submitted by /u/oprimeolt
[link] [comments]
reddit
Which RAT software to use?
Title
hacking: security in practice
Iceland and Norway registered websites tied to scam tokens?
Me and some friends have been rug pulled by a $hitcoin project and we notice a lot of the websites are registered in Norway or Iceland. Can anybody advise why this may be the case? We are pretty clueless at the moment and just starting out our hunt. Thanks for any ideas!
submitted by /u/PersonRetto
[link] [comments]
Iceland and Norway registered websites tied to scam tokens?
Me and some friends have been rug pulled by a $hitcoin project and we notice a lot of the websites are registered in Norway or Iceland. Can anybody advise why this may be the case? We are pretty clueless at the moment and just starting out our hunt. Thanks for any ideas!
submitted by /u/PersonRetto
[link] [comments]
reddit
Iceland and Norway registered websites tied to scam tokens?
Me and some friends have been rug pulled by a $hitcoin project and we notice a lot of the websites are registered in Norway or Iceland. Can...
hacking: security in practice
Can I be hacked through my WiFi?
This may be a violation of rule 4 but please lemme ask.
So a random number is messaging me. They just sent me photos from my gallery they shouldn't have access to. I blocked and reported the number. Thing is, my cousin has already tried something like this on me. When he did it, I didn't recieve photos from my gallery but this time I did get sent some private photos.
Chances of him being able to obtain my pin and/or fingerprints are highly unlikely. The only link left is our common wifi. Could I have been hacked through my wifi? Is there a way to protect myself from this? Is there any other sub I could be recommended if this isn't the right one?
submitted by /u/gediwer
[link] [comments]
Can I be hacked through my WiFi?
This may be a violation of rule 4 but please lemme ask.
So a random number is messaging me. They just sent me photos from my gallery they shouldn't have access to. I blocked and reported the number. Thing is, my cousin has already tried something like this on me. When he did it, I didn't recieve photos from my gallery but this time I did get sent some private photos.
Chances of him being able to obtain my pin and/or fingerprints are highly unlikely. The only link left is our common wifi. Could I have been hacked through my wifi? Is there a way to protect myself from this? Is there any other sub I could be recommended if this isn't the right one?
submitted by /u/gediwer
[link] [comments]
reddit
Can I be hacked through my WiFi?
This may be a violation of rule 4 but please lemme ask. So a random number is messaging me. They just sent me photos from my gallery they...
red team interview
https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/
<!-- SC_OFF -->hi all, i’ve got an interview tomorrow for a dream job red team role. anyone got any advice for the interview to stand out as a candidate? <!-- SC_ON --> submitted by /u/kama_aina (https://www.reddit.com/user/kama_aina)
[link] (https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/) [comments] (https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/)
https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/
<!-- SC_OFF -->hi all, i’ve got an interview tomorrow for a dream job red team role. anyone got any advice for the interview to stand out as a candidate? <!-- SC_ON --> submitted by /u/kama_aina (https://www.reddit.com/user/kama_aina)
[link] (https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/) [comments] (https://www.reddit.com/r/redteamsec/comments/mu9dru/red_team_interview/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
STEALING COOKIES
https://cdn-images-1.medium.com/max/1024/1*GFl9p-BTi1d8DwBHJ2N0Lw.png
Hello freaks! This is Hackfreaks. In this article we will talk about Cookies so let’s :) taste this virtual cookies.
Continue reading on Medium »
STEALING COOKIES
https://cdn-images-1.medium.com/max/1024/1*GFl9p-BTi1d8DwBHJ2N0Lw.png
Hello freaks! This is Hackfreaks. In this article we will talk about Cookies so let’s :) taste this virtual cookies.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top Injector APK New v5.3.1 Download Free For Android
Top Injector APK is newly developed for your Mobile Legend account, PUBG. t also gives you all of the game’s accessories, skins, unlock…
Continue reading on Medium »
Top Injector APK New v5.3.1 Download Free For Android
Top Injector APK is newly developed for your Mobile Legend account, PUBG. t also gives you all of the game’s accessories, skins, unlock…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DMCA.COM , Full Disclosure Publication (With Proof-of-Concept)
https://cdn-images-1.medium.com/max/600/1*0x9xSs9psff7Foq-RCeokA.jpeg
What is DMCA.COM
First of all, for those who don’t know what DMCA is: DMCA stands for the ‘Digital Millennium Copyright Act’ which is a…
Continue reading on Medium »
DMCA.COM , Full Disclosure Publication (With Proof-of-Concept)
https://cdn-images-1.medium.com/max/600/1*0x9xSs9psff7Foq-RCeokA.jpeg
What is DMCA.COM
First of all, for those who don’t know what DMCA is: DMCA stands for the ‘Digital Millennium Copyright Act’ which is a…
Continue reading on Medium »