Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Il Business del Malware

https://cdn-images-1.medium.com/max/1024/1*ihktj0G0N_dpGF1H2CGrqw.png
Gli attacchi da parte dei più svariati tipi di malware si sono rivelati in costante crescita tanto nelle piccole aziende quanto nei…

Continue reading on Medium »
Immunefi、Armor.fi、DeFiSafetyと協力してプロトコルのセキュリティを強化します

C.R.E.A.M. FinanceはImmunefi、Armor.fi、DeFiSafetyと協力してC.R.E.A.M. Financeのプロトコルと様々なDeFiエコシステムに強固なセキュリティをもたらします。Continue reading on C.R.E.A.M. 日本公式 »
Read more...
Authentication bypass

Hello friends this is my first blog. so please ignore grammar mistakes. so let start with some basics of Authentication bypass…Continue reading on Medium »
Read more...
Authentication bypass
https://desaidhruvil1203.medium.com/authentication-bypass-b3a5bbf23ca4?source=rss------bug_bounty-5

Hello friends this is my first blog. so please ignore grammar mistakes. so let start with some basics of Authentication bypass…Continue reading on Medium » (https://desaidhruvil1203.medium.com/authentication-bypass-b3a5bbf23ca4?source=rss------bug_bounty-5)
hacking: security in practice
New here. Are SSH tunnels that valuable for hackers? Are they out-dated?

I've been trying to connect to my old PC but I was having a lot of issues, as I expected. Apparently I have to go into my target computer and turn on SSH server to allow another device to connect to it.

How would a hacker turn on my SSH Server, without having access to my computer in the first place?

submitted by /u/CaptnPilot
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser PadlockPost Views: 56
Reading Time: 1 Minute
The Mozilla Foundation fixed a flaw in its Firefox browser that allowed spoofing of the HTTPS secure communications icon, displayed as a padlock in the browser address window. Successful exploitation of the flaw could have allowed a rogue website to intercept browser communications.
The Mozilla Foundation releases Firefox 88, fixing 13 bugs ranging from high to low severity.
The patch was part of the non-profit’s Monday update to Firefox 88 and its corporate Firefox ESR 78.10 browser and its Thunderbird 78.10 email client. In total, Firefox 88 addresses 13 browser bugs, six of which are rated high-severity. Padlock Bug: False Sense of SecurityTracked as CVE-2021-23998, the secure-lock-icon bug effects both the consumer and corporate versions of Firefox browsers prior to the Monday releases. “Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page,” wrote Mozilla in its security advisory.
Credited for discovering the spoofed secure lock icon is independent researcher Jordi Chancel, who on December 10, 2020 tweeted “I discovered again a new SSL Spoofing Issue (and others variohttps://www.mozilla.org/en-US/security/advisories/mfsa2021-16/#CVE-2021-23998us security issues last 2 months)”. The vulnerability has a severity rating of moderate, Mozilla reported.
See Also: NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens The browser padlock icon, used by all major browsers, indicates a secure communication channel between the browser and the server hosting the website. It indicates the communication is encrypted using HTTPS and utilizes an SSL/TLS certificate. Six High-Severity BugsOther bugs, rated high-severity, are flaws ranging from memory corruption bugs to one that allowed a rogue website to render a malicious JavaScript outside a webpage’s visible content window.

“By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage’s viewport, resulting in a spoofing attack that could have been used for phishing or other attacks on a user,” Mozilla wrote of the bug tracked as CVE-2021-23996.

Bug hunter Irvan Kurniawan is credited for unearthing two of the high-severity bugs and one moderate flaw fixed in Firefox Monday. One is (CVE-2021-23995) is a bug described as a “use-after-free in responsive design mode”.
See Also: Offensive Security Tool: Hunt
“When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code,” wrote Mozilla. Responsive design is a term used to describe how websites automatically adapt to different sized screens

Kurniawan is also credited for finding a use-after-free bug (CVE-2021-23997) that can be triggered by the releasing of a web-based font from the browser’s cache. This bug, like Kurniawan’s previous vulnerability, could be uses by an adversary to target a specific browser and execute remote code.

“Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code,” Mozilla wrote. See Also: Hacking Stories: When two young hackers played war games with PentagonThe Mozilla security bulletin is light on t[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS…
he technical specifics of the bug and does not indicate if any of the 13 flaws outlined in its advisory are being exploited in the wild. The relatively mild collection of Firefox fixes stand in contrast to Google and its Chrome browser, which last week rushed patches addressing a zero-day remote code execution (RCE) vulnerability. Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Discord-Nitro-e1618858537976-90x90.png NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-10-90x90.png WordPress could treat Google FloC as a security issue2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Crypto_Mining_Bitcoin-90x90.jpg Attackers Target ProxyLogon Exploit to Install Cryptojacker5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/patchtues1-90x90.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-90x90.jpg Chrome Zero-Day Exploit Posted on Twitter1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Clubhouse2-e1618258606781-90x90.png 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/cisco-patch-90x90.png Zero-Day Bug Impacts Problem-Plagued Cisco SOHO Routers2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/google-play-90x90.jpg Fake Netflix App on Google Play Spreads Malware Via WhatsApp2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/vmware-patch-90x90.jpg Critical Cloud Bug in VMWare Carbon Black Allows Takeover2 weeks ago
The post Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock first appeared on Black Hat Ethical Hacking.
Overlord - Overlord - Red Teaming Infrastructure Automation
http://www.kitploit.com/2021/04/overlord-overlord-red-teaming.html
Overlord provides a python-based console CLI which is used to build Red Teaming infrastructure in an automated (https://www.kitploit.com/search/label/Automated) way. The user has to provide inputs by using the tool’s modules (e.g. C2, Email Server, HTTP web delivery server, Phishing (https://www.kitploit.com/search/label/Phishing) server etc.) and the full infra / modules and scripts will be generated automatically on a cloud provider of choice. Currently supports AWS and Digital Ocean. The tool is still under development and it was inspired and uses the Red-Baron (https://github.com/byt3bl33d3r/Red-Baron) Terraform (https://www.kitploit.com/search/label/Terraform) implementation found on Github. A demo infrastructure was set up in our blog post https://blog.qsecure.com.cy/posts/overlord/. For the full documentation of the tool visit the Wiki tab at https://github.com/qsecure-labs/overlord/wiki.
Installation
git clone https://github.com/qsecure-labs/overlord.git
cd overlord/config
chmod +x install.sh
sudo ./install.sh
Acknowledgments
This project could not be created without the awsome work for Marcello Salvati @byt3bl33d3r (https://twitter.com/byt3bl33d3r) with the RedBaron (https://github.com/byt3bl33d3r/Red-Baron) Project. That is the reason why we are referencing the name of RedBaron on our project as well. As Marcello stated on his acknowledgments, further thanks to: @_RastaMouse's (https://twitter.com/_RastaMouse) two serie's blogpost on 'Automated Red Team Infrastructure (https://www.kitploit.com/search/label/Infrastructure) Deployment with Terraform' Part 1 (https://rastamouse.me/2017/08/automated-red-team-infrastructure-deployment-with-terraform---part-1/) and 2 (https://rastamouse.me/2017/09/automated-red-team-infrastructure-deployment-with-terraform---part-2/) @bluscreenofjeff's (https://twitter.com/bluscreenofjeff) with his amazing Wiki on Read Team Infrastucture (https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki) @spotheplanet's (https://twitter.com/spotheplanet) blog post on Red team infrastructure (https://ired.team/offensive-security/red-team-infrastructure)
Disclaimer
Overlord comes without warranty and is meant to be used by penetration testers during approved red teaming assessments and/or social enigneering assessments. Overlord's developers and QSecure decline all responsibility in case the tool is used for malicious purposes or in any illegal context.

Download Overlord (https://github.com/qsecure-labs/overlord)
hacking: security in practice
Make a bot to look for exploits in exploit-db

So me and my friends have this small discord server. Its non-english and is designed to provide resources to people in my country who are trying to learn a bit more about cybersec. We have more than 100 links to tools, tutorials and much more. I want to add a discord bot that looks in exploit-db for a search termin, such as !exploitsearch Windows 10. Does anyone have experience with making such bots or similar bots ?

Edit: I am planning on using the Searchsploit app for linux on a small RPI4 as the bot. The only aivailible commands will obviously be thing ending with !exploitsearchwithout any "&" or "|" symbols as user input will be passed directly. I know that you shouldnt trust user input but that is the best I have.

submitted by /u/StillPackage4369
[link] [comments]
hacking: security in practice
Where can I find a good dictionary of people names?

I'm trying a fun project where I brute force a url that has a pattern with firstnamelastnamein it. Was wondering if there's a good dictionary of common people's names that I can use for the job

submitted by /u/nihilisticrock
[link] [comments]
Telegram bug bounties: XSS, privacy issues, official bot exploitation and more…

Insufficient verification over callback_data, XSS Telegram.org, Privacy of Profile Pictures, Sticker crash, issues on bugs.telegram.orgContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CPUFetch : Simplistic Yet Fancy CPU Architecture Fetching Tool

CPUFetch is a simple yet fancy CPU architecture fetching tool. Support cpufetch supports x86, x86_64 (Intel and AMD) and ARM. Platform x86_64 ARM Notes GNU/Linux ✔️ ✔️ Best support Windows ✔️ Some information may be missing.Colors will be used if supported Android ✔️ Some information may be missing.Not tested under x86_64 macOS ✔️ […]

The post CPUFetch : Simplistic Yet Fancy CPU Architecture Fetching Tool appeared first on Kali Linux Tutorials.