Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
https://cdn-images-1.medium.com/max/1400/0*ZW2yzz4zKwlGE6o4
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
https://cdn-images-1.medium.com/max/1400/0*ZW2yzz4zKwlGE6o4
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Symbiote: un malware sigiloso de Linux dirigido al sector financiero latinoamericano.
PUBLICADO EN 9 JUNIO, 2022 EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Victim of Cyber Fraud Getting Money Back
Victims of Cyber Fraud Getting Money Back
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)
https://blogger.googleusercontent.com/img/a/AVvXsEhvJYSxBzvhziiqnNQMt1sVNIxlGDPxGaEDU73ligxfwzMzbXBi3yU8ypWCvQXp4yv7swHFon8H2aJCrn8HmJ8P_U1VRKcyPGulS3ckJLMWG9BozW5mcPC4jFdBmj9GCHuwx1YkvX_tI6PP7DHV1cHwoJnI1zhRwdnEHR4gHpUl8wsRJXX2MsN1_rv7=w640-h190
ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).
About the vulnerability
You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.
About the tool
ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.
Building & Running it
You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.
Testing and Issues
ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.
Follow us on Twitter --> @SI_FalconTeam <--
Download confluencePot
___________________________
@hacking_Attack
@Hacking_Video
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)
https://blogger.googleusercontent.com/img/a/AVvXsEhvJYSxBzvhziiqnNQMt1sVNIxlGDPxGaEDU73ligxfwzMzbXBi3yU8ypWCvQXp4yv7swHFon8H2aJCrn8HmJ8P_U1VRKcyPGulS3ckJLMWG9BozW5mcPC4jFdBmj9GCHuwx1YkvX_tI6PP7DHV1cHwoJnI1zhRwdnEHR4gHpUl8wsRJXX2MsN1_rv7=w640-h190
ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134).
About the vulnerability
You can find the official advisory by Atlassian to this vulerability here. For details about the inner workings and exploits in the wild you should refer to the reports by Rapid7 and Cloudflare. Affected but not yet patched systems should be deemed compromised until further investigation.
About the tool
ConfluencePot is written in Golang and implements its own HTTPS server to minimize the overall attack surface. To make it appear like a legit Confluence instance it returns a bare-bones version of a Confluence landing page. Log output is written to stdout and a log file on disk. ConfluencePot DOES NOT allow attackers to execute commands/code on your machine, it only logs requests and returns a bogus response.
Building & Running it
You need a recent version of Golang to run/build confluencePot and the appropriate privileges to bind to port 443. We recommend to execute it in a tmux session for easier handling. To run ConfluencePot you either need to create a self-signed TLS certificate with openssl or request one from e.g. Let's Encrypt.
go build confluencePot.go
./confluencePot
Testing and Issues
ConfluencePot was tested using the public exploit by Nwqda, which seems to be the most used variant in the wild at the time of writing. If you find anything wrong with confluencePot please feel free to open an issue or send us a pull request.
Follow us on Twitter --> @SI_FalconTeam <--
Download confluencePot
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
confluencePot - Simple Honeypot For Atlassian Confluence (CVE-2022-26134)
How I Hacked My Sister’s Netflix Profile and Messed Up With Her Account
https://medium.com/@prasanth.bodepu/how-i-hacked-my-sisters-netflix-profile-and-messed-up-with-her-account-5c54a157441e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@prasanth.bodepu/how-i-hacked-my-sisters-netflix-profile-and-messed-up-with-her-account-5c54a157441e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Hacked My Sister’s Netflix Profile and Messed Up With Her Account😈
Hello folks, I am Prashanth a security researcher and a part-time bug bounty hunter. You can reach out me at…
Hello folks, I am Prashanth a security researcher and a part-time bug bounty hunter. You can reach out me at…Continue reading on Medium » (https://medium.com/@prasanth.bodepu/how-i-hacked-my-sisters-netflix-profile-and-messed-up-with-her-account-5c54a157441e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Hacked My Sister’s Netflix Profile and Messed Up With Her Account😈
Hello folks, I am Prashanth a security researcher and a part-time bug bounty hunter. You can reach out me at…
Java Application WEB-INF Content Retrieved
https://medium.com/@Dhamuharker/java-application-web-inf-content-retrieved-e5271d4eb8be?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/java-application-web-inf-content-retrieved-e5271d4eb8be?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application WEB-INF Content Retrieved
Description:
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/java-application-web-inf-content-retrieved-e5271d4eb8be?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application WEB-INF Content Retrieved
Description:
hacking: security in practice
Experience with pre-installed Network-Keys for Zigbee-Devices?
Hi, i am currently writing my Bachelors Thesis about Security in IoT-Systems. I got me a Sonoff Zigbee Bridge and a Sonoff Wireless Door-sensor to test my ideas in that system. It seems, that the used Network-Keys are pre-installed in a CC2530 F256 Microchip. I have read a lot about how easy IT should be to extract the Network-Key with physical access to the device, but i have absolutely no clue how. Is it possible to extract the Network-Key or does someone have other ideas how i could go on ? Note: The devices are property of my university and i have to pay them, if i break the devices.
Thx in advance
submitted by /u/BMGforever190
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Experience with pre-installed Network-Keys for Zigbee-Devices?
Hi, i am currently writing my Bachelors Thesis about Security in IoT-Systems. I got me a Sonoff Zigbee Bridge and a Sonoff Wireless Door-sensor to test my ideas in that system. It seems, that the used Network-Keys are pre-installed in a CC2530 F256 Microchip. I have read a lot about how easy IT should be to extract the Network-Key with physical access to the device, but i have absolutely no clue how. Is it possible to extract the Network-Key or does someone have other ideas how i could go on ? Note: The devices are property of my university and i have to pay them, if i break the devices.
Thx in advance
submitted by /u/BMGforever190
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Experience with pre-installed Network-Keys for Zigbee-Devices?
Hi, i am currently writing my Bachelors Thesis about Security in IoT-Systems. I got me a Sonoff Zigbee Bridge and a Sonoff Wireless Door-sensor to...
hacking: security in practice
is tails os a must?
So i have been using tor browser recently ( combining it with proxychains) and came across tails OS. Does it differ that much between using tails to conduct the reconnaissance phase ( passive or active) And using kali with tor+proxychains?
submitted by /u/__hiken__
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is tails os a must?
So i have been using tor browser recently ( combining it with proxychains) and came across tails OS. Does it differ that much between using tails to conduct the reconnaissance phase ( passive or active) And using kali with tor+proxychains?
submitted by /u/__hiken__
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is tails os a must?
So i have been using tor browser recently ( combining it with proxychains) and came across tails OS. Does it differ that much between using ...
The many lives of BlackCat ransomware
https://www.reddit.com/r/redteamsec/comments/vbgg6l/the_many_lives_of_blackcat_ransomware/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/BlackCatRansomware) [comments] (https://www.reddit.com/r/redteamsec/comments/vbgg6l/the_many_lives_of_blackcat_ransomware/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vbgg6l/the_many_lives_of_blackcat_ransomware/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/BlackCatRansomware) [comments] (https://www.reddit.com/r/redteamsec/comments/vbgg6l/the_many_lives_of_blackcat_ransomware/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
The many lives of BlackCat ransomware
Posted in r/redteamsec by u/SCI_Rusher • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Tony Jarvis on Shifting Security Gears as We Move to the Cloud
In this new episode of Tech Talks, Darktrace's Tony Jarvis and Dark Reading's Terry Sweeney discuss how to protect networks after the death of the perimeter.
___________________________
@hacking_Attack
@Hacking_Video
Tony Jarvis on Shifting Security Gears as We Move to the Cloud
In this new episode of Tech Talks, Darktrace's Tony Jarvis and Dark Reading's Terry Sweeney discuss how to protect networks after the death of the perimeter.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Darktrace's Tony Jarvis on Shifting Security Gears as We Move to the Cloud
In this new episode of Tech Talks, Darktrace's Tony Jarvis and Dark Reading's Terry Sweeney discuss how to protect networks after the death of the perimeter.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The terrifying world of Cross-Site Scripting (XSS) (Part 1) — StackZero
https://cdn-images-1.medium.com/max/1280/1*VBNq8etBYukZ00xkp9a4JQ.jpeg
Cross-site scripting (XSS) is a cyber-attack where the cybercriminal injects malicious code into an already trustworthy and valid…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The terrifying world of Cross-Site Scripting (XSS) (Part 1) — StackZero
https://cdn-images-1.medium.com/max/1280/1*VBNq8etBYukZ00xkp9a4JQ.jpeg
Cross-site scripting (XSS) is a cyber-attack where the cybercriminal injects malicious code into an already trustworthy and valid…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The terrifying world of Cross-Site Scripting (XSS) (Part 1) — StackZero
Cross-site scripting (XSS) is a cyber-attack where the cybercriminal injects malicious code into an already trustworthy and valid…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Inside The Mind of a Hacker (Part-3)
Cursed with knowledge
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Inside The Mind of a Hacker (Part-3)
Cursed with knowledge
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Inside The Mind of a Hacker (Part 3)
Cursed with knowledge