Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Live DevSecOps Training and Getting High paying Job in this domain.

So Lets talk about DevSecOps ,Continue reading on Medium »
Read more...
hacking: security in practice
How to hack into my late Father's computer?

Hey all,

My Dad recently passed away and we're locked out of his computer. Mom needs to get on to access a bunch of his business files, email, etc... 99% sure he's on Windows 10.

I once was able to hack into an older version of Windows on my laptop when I forgot the password, but can't remember how I did it.

Does anyone have a lny good resources about how to go about this?

Thanks!

submitted by /u/Igloooooooooo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
PyPI package ‘keep’ mistakenly included a password stealer

PyPI package ‘keep’ mistakenly included a password stealerPost Views: 54
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 4 Minutes
PyPI packages ‘keep,’ ‘pyanxdns,’ ‘api-res-py’ were found to be containing a backdoor due to the presence of malicious ‘request’ dependency within some versions.
For example, while most versions of ‘keep’ project use the legitimate Python module requests for making HTTP requests, ‘keep’ v.1.2 contains ‘request’ (without s) which is malware.

BleepingComputer reached out to the authors of each of these packages to understand if this was caused by a mere typographical error,  self-sabotage, or by maintainer accounts getting hijacked. PyPI package ‘keep’ uses malicious ‘request’Some versions of PyPI packages, ‘keep,’ ‘pyanxdns,’ and ‘api-res-py’ were caught using a malicious dependency, ‘request,’

Back in May, GitHub user duxinglin1 noticed the vulnerable versions contained the misspelled ‘request’ dependency, as opposed to the legitimate requests library.

As such, the following CVEs have been assigned this week with regards to the vulnerable versions:

* CVE-2022-30877 – ‘keep’ version 1.2 contains the backdoor ‘request’, contrary to what the advisory implies.
* CVE-2022-30882 – ‘pyanxdns’ version 0.2 impacted
* CVE-2022-31313 – ‘api-res-py’ version 0.1 impacted

Although ‘pyanxdns’ and ‘api-res-py’ might be small scale projects,  the ‘keep’ package, in particular, gets downloaded over 8,000 times in a week on average—with its version 1.2 using the malicious dependency:
https://www.bleepstatic.com/images/news/u/1164866/2022/jun-2022/pypi-request-keep-backdoor/pypi-keep-page.jpeg
___________________________
@hacking_Attack
@Hacking_Video