Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CEH Practical Notes
https://cdn-images-1.medium.com/max/600/0*PPmDHqgta93lecGL.png
1. Recon
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CEH Practical Notes
https://cdn-images-1.medium.com/max/600/0*PPmDHqgta93lecGL.png
1. Recon
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CEH Practical Notes
1. Recon
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Extended Basic Mission 3
https://cdn-images-1.medium.com/max/700/0*p-Rx7O3nkjY2-i6m.jpg
Imagine being such a king, that you decide to build your own language instead of using established languages worked on by teams of people…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Extended Basic Mission 3
https://cdn-images-1.medium.com/max/700/0*p-Rx7O3nkjY2-i6m.jpg
Imagine being such a king, that you decide to build your own language instead of using established languages worked on by teams of people…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Extended Basic Mission 3
Imagine being such a king, that you decide to build your own language instead of using established languages worked on by teams of people…
Newbie Question - TKINTER Python Penetration Testing / pyinstaller.exe
https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/
Hi Everyone, I've developed a calculation tool using TKINTER which I'd like to use for my work. I've been asked by internal IT about pen testing and security. There's not much documented regarding desktop applications made using python tools deployed by pyinstaller, I'm after a starting point in regards to tools? Would really appreciate your expertise! submitted by /u/Overall_Rhubarb_8679 (https://www.reddit.com/user/Overall_Rhubarb_8679)
[link] (https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/) [comments] (https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/
Hi Everyone, I've developed a calculation tool using TKINTER which I'd like to use for my work. I've been asked by internal IT about pen testing and security. There's not much documented regarding desktop applications made using python tools deployed by pyinstaller, I'm after a starting point in regards to tools? Would really appreciate your expertise! submitted by /u/Overall_Rhubarb_8679 (https://www.reddit.com/user/Overall_Rhubarb_8679)
[link] (https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/) [comments] (https://www.reddit.com/r/Pentesting/comments/vcke64/newbie_question_tkinter_python_penetration/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Newbie Question - TKINTER Python Penetration Testing / pyinstaller.exe
Hi Everyone, I've developed a calculation tool using TKINTER which I'd like to use for my work. I've been asked by internal IT about pen testing...
hacking: security in practice
Any brute force password cracking software?
Just wondering because mathematically it is doable in terms of combinations*time/combination = time .
submitted by /u/QuittingCauseBad
[link] [comments]
Any brute force password cracking software?
Just wondering because mathematically it is doable in terms of combinations*time/combination = time .
submitted by /u/QuittingCauseBad
[link] [comments]
reddit
Any brute force password cracking software?
Just wondering because mathematically it is doable in terms of combinations\*time/combination = time .
hacking: security in practice
Can someone put a key logger on my computer (Mac) by me clicking their link?
I know they can grab my IP but can they do this? Just wondering if this is possible.
Thanks.
submitted by /u/f-as-in-frank
[link] [comments]
Can someone put a key logger on my computer (Mac) by me clicking their link?
I know they can grab my IP but can they do this? Just wondering if this is possible.
Thanks.
submitted by /u/f-as-in-frank
[link] [comments]
reddit
Can someone put a key logger on my computer (Mac) by me clicking...
I know they can grab my IP but can they do this? Just wondering if this is possible. Thanks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The real story behind unknown Roblox hacker
Did two cousins really lie about being hacked?
Continue reading on Medium »
The real story behind unknown Roblox hacker
Did two cousins really lie about being hacked?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: OWASP Top 10 (Task 17–31) — Walkthrough
https://cdn-images-1.medium.com/max/600/1*3cI7eC0rZmP8QP0_AOrPgQ.png
Hi! I am making these walkthroughs to keep myself motivated to learn cyber security, and ensure that I remember the knowledge gained by…
Continue reading on Medium »
TryHackMe: OWASP Top 10 (Task 17–31) — Walkthrough
https://cdn-images-1.medium.com/max/600/1*3cI7eC0rZmP8QP0_AOrPgQ.png
Hi! I am making these walkthroughs to keep myself motivated to learn cyber security, and ensure that I remember the knowledge gained by…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Iranian hackers hijacked emails of high-level Israeli, US officials
https://cdn-images-1.medium.com/max/822/0*bSzmvOh5amCs-IsH
Iranian hackers targeted the emails of senior Israeli and American officials and executives, including former foreign minister Tzipi Livni…
Continue reading on Medium »
Iranian hackers hijacked emails of high-level Israeli, US officials
https://cdn-images-1.medium.com/max/822/0*bSzmvOh5amCs-IsH
Iranian hackers targeted the emails of senior Israeli and American officials and executives, including former foreign minister Tzipi Livni…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Android malware on the Google Play Store gets 2 million downloads
Android malware on the Google Play Store gets 2 million downloadsPost Views: 46
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Cybersecurity researchers have discovered adware and information-stealing malware on the Google Play Store last month, with at least five still available and having amassed over two million downloads.
Adware infections displaying unwanted advertisements that can be particularly intrusive, degrade the user experience, deplete the battery, generate heat, and even cause unauthorized charges.
This software generally tries to hide by masquerading as something else on the host device and makes money for remote operators by forcing the victim to perform views or clicks on affiliated advertisements.
However, information-stealing Trojans are far more nefarious, stealing login credentials for other sites you frequent, including your social media and online banking accounts. Infiltrating the Google Play StoreAnalysts at Dr. Web antivirus report that adware apps and data-stealing Trojans were among the most prominent Android threats in May 2022.
At the top of the report are spyware apps that can steal information from other apps’ notifications, primarily to snatch one-time 2FA passcodes (OTP) and take over accounts.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Among the many threats that managed to infiltrate the Google Play Store, the following five are still available:
* PIP Pic Camera Photo Editor – 1 million downloads, malware masquerading as image-editing software, but which steals the Facebook account credentials of its users.
* Wild & Exotic Animal Wallpaper – 500,000 downloads, an adware trojan that replaces its icon and name to ‘SIM Tool Kit’ and adds itself to the battery-saving exceptions list.
* ZodiHoroscope – Fortune Finder – 500,000 downloads, malware that steal Facebook account credentials by tricking users into entering them, supposedly to disable in-app ads.
* PIP Camera 2022 – 50,000 downloads, camera effects app that is also a Facebook account hijacker.
* Magnifier Flashlight – 10,000 downloads, adware app that serves videos and static banner ads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/applications.png
<figcaptionThree malicious applications still available on the Play Store
Bleeping Computer has contacted Google to inform them about the above applications and verify if the existing versions were cleaned and resubmitted or are still as dangerous as described in Dr. Web’s report.
However, judging from recent user reviews, these apps are still demonstrating malicious functionality and don’t deliver on their features promises.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/user-reviews.png
<figcaptionRecent user reviews for PIP Pic Camera Photo Editor (Play Store)
See Also: This new Linux malware is ‘almost impossible’ to detect Other applications spotted by Dr. Web’s antivirus team on the Play Store in May 2022 include a racing game, a deleted image recovery tool, a fake state compensation app targeting Russian users, and a “free access” app for the Only Fans platform.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/driving-real.png
<figcaptionFake game app that pushed advertisements (Dr. Web)
These apps have since been removed from the Play Store, but users who installed them on their devices need to remove them and also run a full AV[...]
Android malware on the Google Play Store gets 2 million downloads
Android malware on the Google Play Store gets 2 million downloadsPost Views: 46
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
Cybersecurity researchers have discovered adware and information-stealing malware on the Google Play Store last month, with at least five still available and having amassed over two million downloads.
Adware infections displaying unwanted advertisements that can be particularly intrusive, degrade the user experience, deplete the battery, generate heat, and even cause unauthorized charges.
This software generally tries to hide by masquerading as something else on the host device and makes money for remote operators by forcing the victim to perform views or clicks on affiliated advertisements.
However, information-stealing Trojans are far more nefarious, stealing login credentials for other sites you frequent, including your social media and online banking accounts. Infiltrating the Google Play StoreAnalysts at Dr. Web antivirus report that adware apps and data-stealing Trojans were among the most prominent Android threats in May 2022.
At the top of the report are spyware apps that can steal information from other apps’ notifications, primarily to snatch one-time 2FA passcodes (OTP) and take over accounts.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Among the many threats that managed to infiltrate the Google Play Store, the following five are still available:
* PIP Pic Camera Photo Editor – 1 million downloads, malware masquerading as image-editing software, but which steals the Facebook account credentials of its users.
* Wild & Exotic Animal Wallpaper – 500,000 downloads, an adware trojan that replaces its icon and name to ‘SIM Tool Kit’ and adds itself to the battery-saving exceptions list.
* ZodiHoroscope – Fortune Finder – 500,000 downloads, malware that steal Facebook account credentials by tricking users into entering them, supposedly to disable in-app ads.
* PIP Camera 2022 – 50,000 downloads, camera effects app that is also a Facebook account hijacker.
* Magnifier Flashlight – 10,000 downloads, adware app that serves videos and static banner ads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/applications.png
<figcaptionThree malicious applications still available on the Play Store
Bleeping Computer has contacted Google to inform them about the above applications and verify if the existing versions were cleaned and resubmitted or are still as dangerous as described in Dr. Web’s report.
However, judging from recent user reviews, these apps are still demonstrating malicious functionality and don’t deliver on their features promises.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/user-reviews.png
<figcaptionRecent user reviews for PIP Pic Camera Photo Editor (Play Store)
See Also: This new Linux malware is ‘almost impossible’ to detect Other applications spotted by Dr. Web’s antivirus team on the Play Store in May 2022 include a racing game, a deleted image recovery tool, a fake state compensation app targeting Russian users, and a “free access” app for the Only Fans platform.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/driving-real.png
<figcaptionFake game app that pushed advertisements (Dr. Web)
These apps have since been removed from the Play Store, but users who installed them on their devices need to remove them and also run a full AV[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Android malware on the Google Play Store gets 2 million downloads Android malware on the Google Play Store gets 2 million downloadsPost Views: 46 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
scan to uproot any remnants as well.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com Hydra malware infiltrationResearchers at Cyble have also spotted the Hydra banking trojan on the Google Play Store, recently observed targeting banking customers in Europe.
The malware masqueraded as a PDF document manager with text to PDF and QR code scanning features and amassed 10,000 downloads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/pdf-hydra.webp
<figcaptionHydra hiding in a PDF manager app on the Play Store (Cyble)
Cyble told Bleeping Computer that the malicious app was on the Play Store until June 9, 2022, but Google has since removed it.
However, the same PDF app is still available on third-party stores like APKAIO.com and APKCombo.com, so beware.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/3266-90x90.jpg Hackers steal WhatsApp accounts using call forwarding trick2 weeks ago
The post Android malware on the Google Play Store gets 2 million downloads first appeared on Black Hat Ethical Hacking.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com Hydra malware infiltrationResearchers at Cyble have also spotted the Hydra banking trojan on the Google Play Store, recently observed targeting banking customers in Europe.
The malware masqueraded as a PDF document manager with text to PDF and QR code scanning features and amassed 10,000 downloads.
https://www.bleepstatic.com/images/news/u/1220909/Android%20malware/pdf-hydra.webp
<figcaptionHydra hiding in a PDF manager app on the Play Store (Cyble)
Cyble told Bleeping Computer that the malicious app was on the Play Store until June 9, 2022, but Google has since removed it.
However, the same PDF app is still available on third-party stores like APKAIO.com and APKCombo.com, so beware.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/3266-90x90.jpg Hackers steal WhatsApp accounts using call forwarding trick2 weeks ago
The post Android malware on the Google Play Store gets 2 million downloads first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Callow
Is there anyway to use "Callow" to brute force a website with no username. The website im trying it on is for an internet mystery and the page only needs a password no username but the program requires one (to the best of my knowledge. GitHub for Callow (edit: grammar)
submitted by /u/_TheOneTrueBean_
[link] [comments]
Callow
Is there anyway to use "Callow" to brute force a website with no username. The website im trying it on is for an internet mystery and the page only needs a password no username but the program requires one (to the best of my knowledge. GitHub for Callow (edit: grammar)
submitted by /u/_TheOneTrueBean_
[link] [comments]
hacking: security in practice
How do I turn off tamper protection through powershell?
I'm trying to do a reverse shell attack on my windows computer from my linux vm, and the to run the powershell script on the client side, i need to disable real time protection manually, but i figured out a way to disable it by a powershell script, but to run the script and disable real time protection, first i need to disable tamper protection...So is there a way to disable tamper protection through a powershell command?
submitted by /u/Aryangsuktekar
[link] [comments]
How do I turn off tamper protection through powershell?
I'm trying to do a reverse shell attack on my windows computer from my linux vm, and the to run the powershell script on the client side, i need to disable real time protection manually, but i figured out a way to disable it by a powershell script, but to run the script and disable real time protection, first i need to disable tamper protection...So is there a way to disable tamper protection through a powershell command?
submitted by /u/Aryangsuktekar
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community