Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack

Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware AttackPost Views: 43
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A reported a “potentially dangerous piece of functionality” allows an attacker to launch an attack on cloud infrastructure and ransom files stored in SharePoint and OneDrive.
Researchers are warning attackers can abuse Microsoft Office 365 functionality to target files stored on SharePoint and OneDrive in ransomware attacks.

Those files, stored via “auto-save” and backed-up in the cloud, typically leave end users with the impression data is shielded from a ransomware attack. However, researchers say that is not always the case and files stored on SharePoint and OneDrive can be vulnerable to a ransomware attack.

The research comes from Proofpoint, which lays out what it say is “potentially dangerous piece of functionality” in a report released last week.

“Proofpoint has discovered a potentially dangerous piece of functionality in Office 365 or Microsoft 365 that allows ransomware to encrypt files stored on SharePoint and OneDrive in a way that makes them unrecoverable without dedicated backups or a decryption key from the attacker,” according to researchers. How the Attack Chain WorksThe attack chain assumes the worst and starts with an initial compromise of an Office 365 user’s account credentials. This leads to an account takeover, then discovery of data within the SharePoint and OneDrive environment and eventually a breach of data and ransomware attack.

Why this is a big deal, argues Proofpoint, is that tools such as cloud backups via Microsoft’s “auto-save” feature have been part of a best-practices for preventing a ransomware attack. Should data be locked-up on an endpoint, there would be a cloud backup to save the day. Configuring how many versions of a file is save in on OneDrive and SharePoint further reduces the damage an attack. The likelihood of and adversary encrypting previous versions of a file stored online reduces the likelihood of a successful ransomware attack.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png Proofpoint says these precautions can be sidestepped via an attacker modifying versioning limits, which allows an attacker to encrypt all known versions of a file.

“Most OneDrive accounts have a default version limit of 500 [version backups]. An attacker could edit files within a document library 501 times. Now, the original (pre-attacker) version of each file is 501 versions old, and therefore no longer restorable,” researchers wrote. “Encrypt the file(s) after each of the 501 edits. Now all 500 restorable versions are encrypted. Organizations cannot independently restore the original (pre-attacker) version of the files even if they attempt to increase version limits beyond the number of versions edited by the attacker. In this case, even if the version limit was increased to 501 or more, the file(s) saved 501 versions or older cannot be restored,” they wrote.

An adversary with access to compromised accounts can abuse the versioning mechanism found under the list settings and affects all the files in the document library. The versioning setting can be modified without requiring administrator privilege, an attacker can leverage this by creating too many versions of a file or encrypting the file more than the versioning limit. For instance, if the reduced version limit is[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware AttackPost Views: 43 Premium Content https://www.blackhatethicalhacking.com/wp…
set to 1 then the attacker encrypts the file twice. “In some cases, the attacker may exfiltrate the unencrypted files as part of a double extortion tactic, ” said researchers. Microsoft RespondsWhen asked, Microsoft commented “the configuration functionality for versioning settings within lists is working as intended,” according to Proofpoint. It added “older versions of files can be potentially recovered and restored for an additional 14 days with the assistance of Microsoft Support,” researchers quote Microsoft.

Researchers countered in a statement: “Proofpoint attempted to retrieve and restore old versions through this process (i.e., with Microsoft Support) and was not successful. Secondly, even if the versioning settings configuration workflow is as intended, Proofpoint has shown that it can be abused by attackers towards cloud ransomware aims.”
Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor Steps to Secure Microsoft Office 365Proofpoint recommends users fortify their Office 365 accounts by enforcing a strong password policy, enabling multi-factor authentication (MFA), and regularly maintaining the external backup of sensitive data.

The researcher also suggested the ‘response and investigation strategies’ that should be implemented if a change in configuration is triggered.

* Increase the restorable versions for the affected document libraries.
* Identify the high-risk configuration that is altered and previously compromised accounts.
* OAuth tokens for any suspicious third-party apps should be revoked immediately.
* Hunt for policy violation patterns across cloud, email, web, and endpoint by any user.
Trending: Offensive Security Tool: Mobile Security Framework (MobSF) Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
“Files stored in a hybrid state on both endpoint and cloud such as through cloud sync folders will reduce the impact of this novel risk as the attacker will not have access to the local/endpoint files,” the researchers said. “To perform a full ransom flow, the attacker will have to compromise the endpoint and the cloud account to access the endpoint and cloud-stored files.”
Trending: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/cyber-1-90x90.jpg Internet scans find 1.6 million secrets leaked by websites1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/malicious-chrome-extensions-feature-90x90.jpg Google Chrome extensions can be fingerprinted to track you online2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android_malware-700x394-1-90x90.jpg New MaliBot Android banking malware spreads as a crypto miner5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Cisco_Systems_Bug-90x90.jpg Cisco Secure Email bug can let attackers bypass authentication6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_m[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
set to 1 then the attacker encrypts the file twice. “In some cases, the attacker may exfiltrate the unencrypted files as part of a double extortion tactic, ” said researchers. Microsoft RespondsWhen asked, Microsoft commented “the configuration functionality…
ovie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches2 weeks ago
The post Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
bluetooth beacon tracking.

can anyone explain to me how nefarious one can be if they were to plant a bluetooth beacon in someones home to spy on them etc.?

The reason I ask my sister claims she is the victim of being hacked like crazy but its odd because it only happens in her house and no where else.

submitted by /u/malkierknight
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Forgotten passcode

I have some old apple devices which I’ve kept for a while. I have tried to backup the photos but I never get all of them. I’ll have 2500 new photos on my computer but my camera roll will have 2600 images. Instead of figuring out which photos didn’t transfer and getting them on my computer another way, I just kept them. Some of them have been sitting for years (they still turn on thankfully) but I have forgotten the passcodes, im logged into my Apple ID on those devices and by looking at the photos it’s quite obvious the phones aren’t stolen. Is there any way of unlocking the devices without losing all my photos?

submitted by /u/jamesec013
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Phone number lookup

Is there a way to find out who someone is from just a phone number? Name, social media. Anything? All I have is a phone number from WhatsApp and a picture.

submitted by /u/SpinachWeird5295
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Detect SIM swapping attack

You (should) probably know that SIM swapping can happen to you too,

and you probably disabled SMS recovery to your gmail, and you don't use gmail in the first place.

So my idea, is there an app that would monitor your SIM card and alert you if it's disconnected by the provider (not out of range)? There can't be 2 SIM cards with the same phone number on the network.

submitted by /u/zoenagy6865
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video