Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box-Lame
https://cdn-images-1.medium.com/max/600/1*0jHirL8A8Tp_UuqS36CQ_g.png
This is my 14th write up and I will be discussing my experience with the machine “Lame” from Hack The Box. Htb is a great platform for…
Continue reading on Medium »
Hack The Box-Lame
https://cdn-images-1.medium.com/max/600/1*0jHirL8A8Tp_UuqS36CQ_g.png
This is my 14th write up and I will be discussing my experience with the machine “Lame” from Hack The Box. Htb is a great platform for…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Guide to Joining Hackathons as a Designer
https://cdn-images-1.medium.com/max/1500/0*InY99bFd5gxzm4h5
Ever feel intimidated joining hackathons as a designer? Then this guide is for you!
Continue reading on Medium »
A Guide to Joining Hackathons as a Designer
https://cdn-images-1.medium.com/max/1500/0*InY99bFd5gxzm4h5
Ever feel intimidated joining hackathons as a designer? Then this guide is for you!
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Is the CEH really “worth it”?
This question has been bouncing around in my head since I started really gobbling up certifications about 2 years ago. One of the first…
Continue reading on Medium »
Is the CEH really “worth it”?
This question has been bouncing around in my head since I started really gobbling up certifications about 2 years ago. One of the first…
Continue reading on Medium »
hacking: security in practice
Someone Doxxed Me
Is there a possible way to identify who made an Instagram account because someone created an account and revealed my friend and I’s home addresses. I want to find out who was responsible for this but I don’t know how to find out who created the account.
https://www.instagram.com/hsbsnzomamzmzhznsnsjwoamzkz here is the account link for anyone that wants to help me. If you find out who it is please tell me through private messages, Thanks a lot 🙏🏽
submitted by /u/Bennythebear25
[link] [comments]
Someone Doxxed Me
Is there a possible way to identify who made an Instagram account because someone created an account and revealed my friend and I’s home addresses. I want to find out who was responsible for this but I don’t know how to find out who created the account.
https://www.instagram.com/hsbsnzomamzmzhznsnsjwoamzkz here is the account link for anyone that wants to help me. If you find out who it is please tell me through private messages, Thanks a lot 🙏🏽
submitted by /u/Bennythebear25
[link] [comments]
reddit
Someone Doxxed Me
Is there a possible way to identify who made an Instagram account because someone created an account and revealed my friend and I’s home...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PC Optimization (Windows 10)
https://cdn-images-1.medium.com/max/1705/1*1eMHGZH7wSGGJJXX81C4cQ.png
We’ve all experienced our devices become painfully slow to the point we no longer want to use them. This can make for a very annoying…
Continue reading on Medium »
PC Optimization (Windows 10)
https://cdn-images-1.medium.com/max/1705/1*1eMHGZH7wSGGJJXX81C4cQ.png
We’ve all experienced our devices become painfully slow to the point we no longer want to use them. This can make for a very annoying…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Advanced Phishing Email — When Protective AI May Harm
One popular technique we hear a lot on corporate and college courses on phishing is that there are certain patterns with phishing emails…
Continue reading on Medium »
Advanced Phishing Email — When Protective AI May Harm
One popular technique we hear a lot on corporate and college courses on phishing is that there are certain patterns with phishing emails…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking a X-RAY Machine with WHIDelite & EvilCrowRF
https://cdn-images-1.medium.com/max/2048/1*c46yg5guDizVwsMTycVroA.jpeg
Recently I bought a X-RAY machine from China to have some ghetto-style desktop setup in order to inspect/reverse engineer some PCBs and…
Continue reading on Medium »
Hacking a X-RAY Machine with WHIDelite & EvilCrowRF
https://cdn-images-1.medium.com/max/2048/1*c46yg5guDizVwsMTycVroA.jpeg
Recently I bought a X-RAY machine from China to have some ghetto-style desktop setup in order to inspect/reverse engineer some PCBs and…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How does the Web work !!
https://cdn-images-1.medium.com/max/2600/0*jQVhe8ycKNHyS07N
To exploit a website, you must know how it works so that you can effectively take it down to the ground!
Continue reading on Secure You!! »
How does the Web work !!
https://cdn-images-1.medium.com/max/2600/0*jQVhe8ycKNHyS07N
To exploit a website, you must know how it works so that you can effectively take it down to the ground!
Continue reading on Secure You!! »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NitroRansomware Asks for Discord Gift Codes, Steals Access TokensPost Views: 60
Reading Time: 1 Minute
The NitroRansomware malware strain is shaking up the ransomware norm by demanding Discord Nitro gift codes from victims instead of actual money.
Discord is a VoIP, instant messaging and digital-distribution platform designed for creating communities. Users communicate with voice calls, video calls, text messaging, media and files in private chats or as part of communities called “servers.”
While it’s free, users can purchase an upgraded “Nitro” subscription for $9.99 that allows larger upload sizes, HD video streaming, better emoji options and the ability to “stand out” via promotions on servers.
The NitroRansomware operators are apparently extremely interested in Nitro subscriptions. Initially spotted by MalwareHunterTeam, other researchers looked into how the code works. It’s being distributed as a purported free gift-code generator for Nitro.
“Upon executing the ransomware, it will encrypt the victim’s file and will give three hours to them to provide a valid Discord Nitro [code],” explained Heimdal Security researcher Cezarina Chirica, in a Monday posting. “The malware appends the ‘.givemenitro’ extension to the filenames of the encrypted files. At the end of an encryption process, NitroRansomware will change the user’s wallpaper to an evil or angry Discord logo.”
See Also: WordPress could treat Google FloC as a security issue
According to an analysis by Bleeping Computer, the ransomware verifies that the provided Discord gift codes are valid, and decrypts the files using an embedded static decryption key. However, the three-hour limit appears to be a scareware tactic. If the timer ticks down to zero, no files are actually deleted.
The outlet’s analysis also pointed out that because the decryption keys are static, it’s possible to extract a decryption key from the executable itself, so there’s no real need to pay the $9.99. Follow-On Attacks PossibleMalwareHunterTeam also noted that the malware steals Discord tokens from victims as well, which would allow attackers to hack Discord servers.
See Also: Offensive Security Tool: Hunt
And, “NitroRansomware also implements backdoor capabilities, allowing the hackers to remotely execute commands and then have the output sent through their webhook to the attacker’s Discord channel,” said Heimdal’s Chirica.
Chirica recommended that users infected with the ransomware immediately change their Discord password and perform an antivirus scan to detect other malicious programs added to the computer. And, also, users should check for new user accounts in Windows that they did not create and remove them if found. Gift Cards: A Cybercrime GoldmineWhy gift codes? They can be resold, and also can be used for money laundering, researcher Kevin Beaumont pointed out.
Lolol, ransomware which uses Discord gift cards as payment. https://t.co/dWWOLqiQqQ
— Kevin Beaumont (@GossiTheDog) April 18, 2021 See Also: Hacking Stories: When two young hackers played war games with PentagonStolen gift and loyalty codes and cards can be big business on the cyber-underground. In February for instance, gift cards from 3,010 companies showed up on a Russian-speaking illicit forum, according to Gemini Advisors. These included cards from Airbnb, Amazon, American Airlines, Chipotle, Dunkin Donuts, Marriott, Nike, Subway, Target and Walmart.
These were worth around $38,000, Gemini noted – but they netted a bit less for[...]
NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg NitroRansomware Asks for Discord Gift Codes, Steals Access TokensPost Views: 60
Reading Time: 1 Minute
The NitroRansomware malware strain is shaking up the ransomware norm by demanding Discord Nitro gift codes from victims instead of actual money.
Discord is a VoIP, instant messaging and digital-distribution platform designed for creating communities. Users communicate with voice calls, video calls, text messaging, media and files in private chats or as part of communities called “servers.”
While it’s free, users can purchase an upgraded “Nitro” subscription for $9.99 that allows larger upload sizes, HD video streaming, better emoji options and the ability to “stand out” via promotions on servers.
The NitroRansomware operators are apparently extremely interested in Nitro subscriptions. Initially spotted by MalwareHunterTeam, other researchers looked into how the code works. It’s being distributed as a purported free gift-code generator for Nitro.
“Upon executing the ransomware, it will encrypt the victim’s file and will give three hours to them to provide a valid Discord Nitro [code],” explained Heimdal Security researcher Cezarina Chirica, in a Monday posting. “The malware appends the ‘.givemenitro’ extension to the filenames of the encrypted files. At the end of an encryption process, NitroRansomware will change the user’s wallpaper to an evil or angry Discord logo.”
See Also: WordPress could treat Google FloC as a security issue
According to an analysis by Bleeping Computer, the ransomware verifies that the provided Discord gift codes are valid, and decrypts the files using an embedded static decryption key. However, the three-hour limit appears to be a scareware tactic. If the timer ticks down to zero, no files are actually deleted.
The outlet’s analysis also pointed out that because the decryption keys are static, it’s possible to extract a decryption key from the executable itself, so there’s no real need to pay the $9.99. Follow-On Attacks PossibleMalwareHunterTeam also noted that the malware steals Discord tokens from victims as well, which would allow attackers to hack Discord servers.
See Also: Offensive Security Tool: Hunt
And, “NitroRansomware also implements backdoor capabilities, allowing the hackers to remotely execute commands and then have the output sent through their webhook to the attacker’s Discord channel,” said Heimdal’s Chirica.
Chirica recommended that users infected with the ransomware immediately change their Discord password and perform an antivirus scan to detect other malicious programs added to the computer. And, also, users should check for new user accounts in Windows that they did not create and remove them if found. Gift Cards: A Cybercrime GoldmineWhy gift codes? They can be resold, and also can be used for money laundering, researcher Kevin Beaumont pointed out.
Lolol, ransomware which uses Discord gift cards as payment. https://t.co/dWWOLqiQqQ
— Kevin Beaumont (@GossiTheDog) April 18, 2021 See Also: Hacking Stories: When two young hackers played war games with PentagonStolen gift and loyalty codes and cards can be big business on the cyber-underground. In February for instance, gift cards from 3,010 companies showed up on a Russian-speaking illicit forum, according to Gemini Advisors. These included cards from Airbnb, Amazon, American Airlines, Chipotle, Dunkin Donuts, Marriott, Nike, Subway, Target and Walmart.
These were worth around $38,000, Gemini noted – but they netted a bit less for[...]