Hi everyoneContinue reading on Medium » (https://aidilarf.medium.com/xss-blind-stored-at-asset-domain-android-apps-tiktok-ae2f4c2dbc07?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS Blind Stored at Asset Domain Android Apps TikTok
Hi everyone
hacking: security in practice
I got hacked by a malicious file, what's the best way to open it and learn about it?
Context: Here's how the hack went. I clicked it and immediately knew I messed up. It closed only one program (the account that got hacked) and then logged me out of it.
Basically I got a file from somebody I trusted which unfortunately hacked my account. Well, that's okay. I got the account back, and instead of deleting the file, I want to know exactly what it does. Is there a good program to use that'll isolate the file in maybe an environment that's safe to open it in or is there a good program that'll just tell me what it does or the scripts involved?
If it's a keylogger that's bad, but if it's just a one time dealio that's okay. Basically I want to find out if it's safe to simply delete the file.
Any recommendations otherwise? Should I completely wipe my hard drive? Should I set up a new drive for my system? Do malicious files usually download to all drives or just the system drives?
submitted by /u/Cryterionlol
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I got hacked by a malicious file, what's the best way to open it and learn about it?
Context: Here's how the hack went. I clicked it and immediately knew I messed up. It closed only one program (the account that got hacked) and then logged me out of it.
Basically I got a file from somebody I trusted which unfortunately hacked my account. Well, that's okay. I got the account back, and instead of deleting the file, I want to know exactly what it does. Is there a good program to use that'll isolate the file in maybe an environment that's safe to open it in or is there a good program that'll just tell me what it does or the scripts involved?
If it's a keylogger that's bad, but if it's just a one time dealio that's okay. Basically I want to find out if it's safe to simply delete the file.
Any recommendations otherwise? Should I completely wipe my hard drive? Should I set up a new drive for my system? Do malicious files usually download to all drives or just the system drives?
submitted by /u/Cryterionlol
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I got hacked by a malicious file, what's the best way to open it...
Context: Here's how the hack went. I clicked it and immediately knew I messed up. It closed only one program (the account that got hacked) and...
hacking: security in practice
Prevent transfer data to USB being monitored or tracked .
How can I transfer data to USB without being monitored or tracked ?
submitted by /u/Fresh_Ad_1688
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Prevent transfer data to USB being monitored or tracked .
How can I transfer data to USB without being monitored or tracked ?
submitted by /u/Fresh_Ad_1688
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Prevent transfer data to USB being monitored or tracked .
# How can I transfer data to USB without being monitored or tracked ?
How many VMs do you need for pentesting?
https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/
I have seen that you only beed a Linux vm and a Windows vm. This doubt is with purpose to know how much ram do I need in my PC. 16 gb ram 24 gb 32 gb?? And if I need let say 32gb ram for what purpose. Certain types of penetrations need more than two VM? Let me know your opinions. :) submitted by /u/PleasantBluejay7419 (https://www.reddit.com/user/PleasantBluejay7419)
[link] (https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/
I have seen that you only beed a Linux vm and a Windows vm. This doubt is with purpose to know how much ram do I need in my PC. 16 gb ram 24 gb 32 gb?? And if I need let say 32gb ram for what purpose. Certain types of penetrations need more than two VM? Let me know your opinions. :) submitted by /u/PleasantBluejay7419 (https://www.reddit.com/user/PleasantBluejay7419)
[link] (https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/vddmbo/how_many_vms_do_you_need_for_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How many VMs do you need for pentesting?
I have seen that you only beed a Linux vm and a Windows vm. This doubt is with purpose to know how much ram do I need in my PC. 16 gb ram 24...
What tools do you actually need to know in order to be a good at pentesting?
https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/
I’m going through THM rooms at a fast pace, and I started to wonder what tools do you actually need to know for real life action. I’m familiar with Burp, Nmap, Wireshark, Metasploit, Hashcat and some others. What else do you use and which ones do you use the most? submitted by /u/MrMeta3 (https://www.reddit.com/user/MrMeta3)
[link] (https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/) [comments] (https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/
I’m going through THM rooms at a fast pace, and I started to wonder what tools do you actually need to know for real life action. I’m familiar with Burp, Nmap, Wireshark, Metasploit, Hashcat and some others. What else do you use and which ones do you use the most? submitted by /u/MrMeta3 (https://www.reddit.com/user/MrMeta3)
[link] (https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/) [comments] (https://www.reddit.com/r/Pentesting/comments/vdejrc/what_tools_do_you_actually_need_to_know_in_order/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What tools do you actually need to know in order to be a good at...
I’m going through THM rooms at a fast pace, and I started to wonder what tools do you actually need to know for real life action. I’m familiar...
CSRF leads to account takeover in Yahoo!
https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-958321990740?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-958321990740?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF leads to account takeover in Yahoo!
How I managed to hack the accounts of arbitrary users of a yahoo! application in only 30 minutes.
How I managed to hack the accounts of arbitrary users of a yahoo! application in only 30 minutes.Continue reading on Medium » (https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-958321990740?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF leads to account takeover in Yahoo!
How I managed to hack the accounts of arbitrary users of a yahoo! application in only 30 minutes.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Save over $1,000 on your groceries with 1 line of code
https://cdn-images-1.medium.com/max/911/1*crBEZB_3wdVvGo8IEKXQ8Q.png
Rewards programs (AKA Loyalty Programs) are a fascinating, yet simple concept.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Save over $1,000 on your groceries with 1 line of code
https://cdn-images-1.medium.com/max/911/1*crBEZB_3wdVvGo8IEKXQ8Q.png
Rewards programs (AKA Loyalty Programs) are a fascinating, yet simple concept.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Save over $1,000 on your groceries with 1 line of code
Rewards programs (AKA Loyalty Programs) are a fascinating, yet simple concept. Companies will let you sign-up for free with an email, track…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Idea — Part One
https://cdn-images-1.medium.com/max/600/1*098td-ptnTkS0QtI8u3fqg.jpeg
Do not try to bypass antivirus just try to change your mindset as hacker.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking Idea — Part One
https://cdn-images-1.medium.com/max/600/1*098td-ptnTkS0QtI8u3fqg.jpeg
Do not try to bypass antivirus just try to change your mindset as hacker.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Idea — Part One
Do not try to bypass antivirus just try to change your mindset as hacker.
CSRF leads to account takeover in Yahoo!
https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-aa96c678d2aa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-aa96c678d2aa?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF leads to account takeover in Yahoo!
How I managed to hack the accounts of arbitrary users of a Yahoo! application in only 30 minutes.
How I managed to hack the accounts of arbitrary users of a Yahoo! application in only 30 minutes.Continue reading on Medium » (https://retr02332.medium.com/csrf-leads-to-account-takeover-in-yahoo-aa96c678d2aa?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF leads to account takeover in Yahoo!
How I managed to hack the accounts of arbitrary users of a Yahoo! application in only 30 minutes.
Aurora Stalls A Sizable DeFi Hack, Pays $6M Bug Bounty through Immunefi
https://smartcontractaudit.medium.com/aurora-stalls-a-sizable-defi-hack-pays-6m-bug-bounty-through-immunefi-a7f4173df3d2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://smartcontractaudit.medium.com/aurora-stalls-a-sizable-defi-hack-pays-6m-bug-bounty-through-immunefi-a7f4173df3d2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Aurora Stalls A Sizable DeFi Hack, Pays $6M Bug Bounty through Immunefi
It could have been the next market-moving DeFi hack, but thanks to bug bounty!
It could have been the next market-moving DeFi hack, but thanks to bug bounty!Continue reading on Medium » (https://smartcontractaudit.medium.com/aurora-stalls-a-sizable-defi-hack-pays-6m-bug-bounty-through-immunefi-a7f4173df3d2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Aurora Stalls A Sizable DeFi Hack, Pays $6M Bug Bounty through Immunefi
It could have been the next market-moving DeFi hack, but thanks to bug bounty!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco Secure Email bug can let attackers bypass authentication
Cisco Secure Email bug can let attackers bypass authenticationPost Views: 1
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Cisco notified customers this week to patch a critical vulnerability that could allow attackers to bypass authentication and login into the web management interface of Cisco email gateway appliances with non-default configurations.
The security flaw (tracked as CVE-2022-20798) was found in the external authentication functionality of virtual and hardware Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager appliances.
CVE-2022-20798 is due to improper authentication checks on affected devices using Lightweight Directory Access Protocol (LDAP) for external authentication.
“An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device,” Cisco explained.
“A successful exploit could allow the attacker to gain unauthorized access to the web-based management interface of the affected device.”
An advisory published on Wednesday says the bug was discovered during the resolution of a Cisco TAC (Technical Assistance Center) support case.
Cisco’s Product Security Incident Response Team (PSIRT) said it’s not aware of any publicly available exploits for this security bug or malicious use of the vulnerability in the wild.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Doesn’t affect default configurationsThis bug only affects appliances configured to use external authentication and LDAP as the authentication protocol.
Luckily, according to Cisco, the external authentication feature is disabled by default, meaning only devices with non-default configurations are impacted.
To check if external auth is enabled on your appliance, log into the web-based management interface, go to System Administration > Users, and look for a green check box next to “Enable External Authentication.”
See Also: This new Linux malware is ‘almost impossible’ to detect Cisco also says this vulnerability does not affect its Cisco Secure Web Appliance product, previously known as Cisco Web Security Appliance (WSA).
Admins who cannot immediately install CVE-2022-20798 security updates can also apply a workaround that requires disabling anonymous binds on the external authentication server.
Another Secure Email gateway flaw patched in February could allow remote attackers to crash unpatched appliances using maliciously crafted email messages.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Today, Cisco also announced it wouldn’t fix a critical zero-day bug affecting end-of-life RV110W, RV130, RV130W, and RV215W SMB routers, allowing attackers to execute arbitrary commands with root-level privileges.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 day [...]
___________________________
@hacking_Attack
@Hacking_Video
Cisco Secure Email bug can let attackers bypass authentication
Cisco Secure Email bug can let attackers bypass authenticationPost Views: 1
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Cisco notified customers this week to patch a critical vulnerability that could allow attackers to bypass authentication and login into the web management interface of Cisco email gateway appliances with non-default configurations.
The security flaw (tracked as CVE-2022-20798) was found in the external authentication functionality of virtual and hardware Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager appliances.
CVE-2022-20798 is due to improper authentication checks on affected devices using Lightweight Directory Access Protocol (LDAP) for external authentication.
“An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device,” Cisco explained.
“A successful exploit could allow the attacker to gain unauthorized access to the web-based management interface of the affected device.”
An advisory published on Wednesday says the bug was discovered during the resolution of a Cisco TAC (Technical Assistance Center) support case.
Cisco’s Product Security Incident Response Team (PSIRT) said it’s not aware of any publicly available exploits for this security bug or malicious use of the vulnerability in the wild.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Doesn’t affect default configurationsThis bug only affects appliances configured to use external authentication and LDAP as the authentication protocol.
Luckily, according to Cisco, the external authentication feature is disabled by default, meaning only devices with non-default configurations are impacted.
To check if external auth is enabled on your appliance, log into the web-based management interface, go to System Administration > Users, and look for a green check box next to “Enable External Authentication.”
See Also: This new Linux malware is ‘almost impossible’ to detect Cisco also says this vulnerability does not affect its Cisco Secure Web Appliance product, previously known as Cisco Web Security Appliance (WSA).
Admins who cannot immediately install CVE-2022-20798 security updates can also apply a workaround that requires disabling anonymous binds on the external authentication server.
Another Secure Email gateway flaw patched in February could allow remote attackers to crash unpatched appliances using maliciously crafted email messages.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Today, Cisco also announced it wouldn’t fix a critical zero-day bug affecting end-of-life RV110W, RV130, RV130W, and RV215W SMB routers, allowing attackers to execute arbitrary commands with root-level privileges.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 day [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Cisco Secure Email bug can let attackers bypass authentication | Black Hat Ethical Hacking
Cisco notified customers this week to patch a critical vulnerability that could allow attackers to bypass authentication and login into the web management interface of Cisco email gateway appliances with non-default configurations.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco Secure Email bug can let attackers bypass authentication Cisco Secure Email bug can let attackers bypass authenticationPost Views: 1 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
The post Cisco Secure Email bug can let attackers bypass authentication first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
The post Cisco Secure Email bug can let attackers bypass authentication first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video