Pwning.eth has earned a Whitehat Hall of Fame NFT for his recent critical bug find in Aurora, forever securing his spot in hacking history…Continue reading on Immunefi » (https://medium.com/immunefi/pwning-eth-earns-whitehat-hall-of-fame-nft-for-aurora-find-fd4c52c4a025?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pwning.eth Earns Whitehat Hall Of Fame NFT For Aurora Find
Pwning.eth has earned a Whitehat Hall of Fame NFT for his recent critical bug find in Aurora, forever securing his spot in hacking history…
WEF - Wi-Fi Exploitation Framework
http://www.kitploit.com/2022/06/wef-wi-fi-exploitation-framework.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/wef-wi-fi-exploitation-framework.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
WEF - Wi-Fi Exploitation Framework
A fully offensive framework to the 802.11 networks and protocols with different types of attacks for WPA and WEP, automated (https://www.kitploit.com/search/label/Automated) hash cracking, bluetooth hacking and much more. I recommend you my alfa adapter: Alfa AWUS036ACM, which works really great with both, 2.4 and 5 Ghz Tested and supported in Kali Linux, Parrot OS, Arch Linux and Ubuntu *However it's not finished and may have issues, try it at your own risk.* If you have any issue please, contact me or create a issue
SUPPORTED ATTACKS: Deauthentication Attack Authentication Attack Beacon Flood Attack PKMID Attack EvilTwin Attack Passive/Stealthy Attack Pixie Dust Attack Null Pin Attack Chopchop Attack Replay Attack Michael Exploitation (https://www.kitploit.com/search/label/Exploitation) Attack Caffe-Latte Attack Jamming, Reading and Writing bluetooth connections GPS Spoofing with HackRF FEATURES: Log generatorWPA/WPA2, WPS and WEP AttacksAuto handshake crackingMultiple templates for EvilTwin attackCheck monitor mode and it status2Ghz and 5Ghz attacksCustom wordlist selectorAuto detect requirementsBluetooth (https://www.kitploit.com/search/label/Bluetooth) support (Jamming, Reading, Writing)USAGE: Common usage of the framework wef -i wlan0 # Your interface name might be different or wef --interface wlan0 Once the application is working, type 'help' to view more functions and useful info. If you don't want to scan APs with every attack you can do something like this: set name my-wifi # To especify the name to attack
set time 60 # To define the total duration of the attacks that ask for the time
set packets 15 # To define the amount of packets that some attacks will send REQUIREMENTS: Don't install them manually, WEF takes care of that if you don't already have them aircrack-ng
reaver
mdk4
macchanger
hashcat
xterm
hcxtools
pixiewps
python3
btlejack
crackle
php
hostadp
dnsmasq
INSTALLATION: Checkout the Wiki (https://github.com/D3Ext/WEF/wiki/Installation) DEMO: Demo on a Parrot OS with Kitty terminal
___________________________
@hacking_Attack
@Hacking_Video
SUPPORTED ATTACKS: Deauthentication Attack Authentication Attack Beacon Flood Attack PKMID Attack EvilTwin Attack Passive/Stealthy Attack Pixie Dust Attack Null Pin Attack Chopchop Attack Replay Attack Michael Exploitation (https://www.kitploit.com/search/label/Exploitation) Attack Caffe-Latte Attack Jamming, Reading and Writing bluetooth connections GPS Spoofing with HackRF FEATURES: Log generatorWPA/WPA2, WPS and WEP AttacksAuto handshake crackingMultiple templates for EvilTwin attackCheck monitor mode and it status2Ghz and 5Ghz attacksCustom wordlist selectorAuto detect requirementsBluetooth (https://www.kitploit.com/search/label/Bluetooth) support (Jamming, Reading, Writing)USAGE: Common usage of the framework wef -i wlan0 # Your interface name might be different or wef --interface wlan0 Once the application is working, type 'help' to view more functions and useful info. If you don't want to scan APs with every attack you can do something like this: set name my-wifi # To especify the name to attack
set time 60 # To define the total duration of the attacks that ask for the time
set packets 15 # To define the amount of packets that some attacks will send REQUIREMENTS: Don't install them manually, WEF takes care of that if you don't already have them aircrack-ng
reaver
mdk4
macchanger
hashcat
xterm
hcxtools
pixiewps
python3
btlejack
crackle
php
hostadp
dnsmasq
INSTALLATION: Checkout the Wiki (https://github.com/D3Ext/WEF/wiki/Installation) DEMO: Demo on a Parrot OS with Kitty terminal
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Created by D3Ext Extra If you are using bspwm, you can add this line to your bspwmrc for launching the xterm windows always beeing in floating mode (for a prettier design) bspc rule -a XTerm state=floating
Copyright © 2022, D3Ext
Download WEF (https://github.com/D3Ext/WEF)
___________________________
@hacking_Attack
@Hacking_Video
Copyright © 2022, D3Ext
Download WEF (https://github.com/D3Ext/WEF)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - D3Ext/WEF: Wi-Fi Exploitation Framework
Wi-Fi Exploitation Framework. Contribute to D3Ext/WEF development by creating an account on GitHub.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
C# - Vulnerability found in Newtonsoft Json - Upgrade package to 13.0.1
https://external-preview.redd.it/FS7Mx1ZQk9W4haSKp36dHjPnJrDaLopveIusgdNnwH4.jpg?width=216&crop=smart&auto=webp&s=2faf2ff72a5bb1755452a4496d421803b0c88183 submitted by /u/hlenyriao
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
C# - Vulnerability found in Newtonsoft Json - Upgrade package to 13.0.1
https://external-preview.redd.it/FS7Mx1ZQk9W4haSKp36dHjPnJrDaLopveIusgdNnwH4.jpg?width=216&crop=smart&auto=webp&s=2faf2ff72a5bb1755452a4496d421803b0c88183 submitted by /u/hlenyriao
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
C# - Vulnerability found in Newtonsoft Json - Upgrade package to...
Posted in r/hacking by u/hlenyriao • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
SSOh-No : User Enumeration And Password Spraying Tool For Testing Azure AD
SSOh-No is designed to enumerate users, password spray and perform brute force attacks against any organisation that utilises Azure AD or O365.
Generally, this endpoint provides extremely verbose errors which can be leveraged to enumerate users and validate their passwords via brute force/spraying attacks, while also failing to log any failed authentication attempts.
This tool is a weaponised version of a PoC demonstrated in the arstechnica research article which discusses the techniques utilised to exploit the endpoint.
This endpoint is known to Microsoft however, in typical fashion it has been branded a feature, not a bug.
This endpoint does enforce “smart locking” which can be bypassed by rotating IP.
Why Is This Unique?
The SSO Autologon endpoint does not contain logging of any sort bar potentially updating the users “Last Logon” time.
The following have been tested and contain no logs:
* AzureAD
* Sentinel
* Defender for Identity (Formerly Advanced Thread Protection)
* Defender for Cloud Apps
Usage
$ ./SSOh-No -h
usage: SSOh-No [-h|–help] [-e|–email “”] [-p|–password “”]
[-U|–userlist “”] [-o|–outfile “”]
Enumerate and abuse a sub-par Azure SSO endpoint.
Arguments:
-h –help Print help information
-e –email Email address to query. Example: user@domain.com
-p –password Password to spray. Example: Password123!
-U –userlist Specify userlist to enumerate
-o –outfile Specify outfile. Example: validated.txt
Upcoming Features
* Proxy Implementation to bypass smart lock
* Password brute force from password lists (single user- No plans for password list brute force against a userlist)
Download
___________________________
@hacking_Attack
@Hacking_Video
SSOh-No : User Enumeration And Password Spraying Tool For Testing Azure AD
SSOh-No is designed to enumerate users, password spray and perform brute force attacks against any organisation that utilises Azure AD or O365.
Generally, this endpoint provides extremely verbose errors which can be leveraged to enumerate users and validate their passwords via brute force/spraying attacks, while also failing to log any failed authentication attempts.
This tool is a weaponised version of a PoC demonstrated in the arstechnica research article which discusses the techniques utilised to exploit the endpoint.
This endpoint is known to Microsoft however, in typical fashion it has been branded a feature, not a bug.
This endpoint does enforce “smart locking” which can be bypassed by rotating IP.
Why Is This Unique?
The SSO Autologon endpoint does not contain logging of any sort bar potentially updating the users “Last Logon” time.
The following have been tested and contain no logs:
* AzureAD
* Sentinel
* Defender for Identity (Formerly Advanced Thread Protection)
* Defender for Cloud Apps
Usage
$ ./SSOh-No -h
usage: SSOh-No [-h|–help] [-e|–email “”] [-p|–password “”]
[-U|–userlist “”] [-o|–outfile “”]
Enumerate and abuse a sub-par Azure SSO endpoint.
Arguments:
-h –help Print help information
-e –email Email address to query. Example: user@domain.com
-p –password Password to spray. Example: Password123!
-U –userlist Specify userlist to enumerate
-o –outfile Specify outfile. Example: validated.txt
Upcoming Features
* Proxy Implementation to bypass smart lock
* Password brute force from password lists (single user- No plans for password list brute force against a userlist)
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
SSOh-No : User Enumeration And Password Spraying Tool
SSOh-No is designed to enumerate users, password spray and perform brute force attacks against any organisation.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Kubeclarity : Tool For Detection And Management Of Software Bill Of Materials
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. It scans both runtime K8s clusters and CI/CD pipelines for enhanced software supply chain security. SBOM & vulnerability detection challenges* Effective vulnerability scanning requires an accurate Software Bill Of Materials (SBOM) detection:
* Various programming languages and package managers
* Various OS distributions
* Package dependency information is usually stripped upon build
* Which one is the best scanner/SBOM analyzer?
* What should we scan: Git repos, builds, container images or runtime?
* Each scanner/analyzer has its own format – how to compare the results?
* How to manage the discovered SBOM and vulnerabilities?
* How are my applications affected by a newly discovered vulnerability? Solution* Separate vulnerability scanning into 2 phases:
* Content analysis to generate SBOM
* Scan the SBOM for vulnerabilities
* Create a pluggable infrastructure to:
* Run several content analyzers in parallel
* Run several vulnerability scanners in parallel
* Scan and merge results between different CI stages using KubeClarity CLI
* Runtime K8s scan to detect vulnerabilities discovered post-deployment
* Group scanned resources (images/directories) under defined applications to navigate the object tree dependencies (applications, resources, packages, vulnerabilities) Features* Dashboard
* Fixable vulnerabilities per severity
* Top 5 vulnerable elements (applications, resources, packages)
* New vulnerabilities trends
* Package count per license type
* Package count per programming language
* General counters
* Applications
* Automatic application detection in K8s runtime
* Create/edit/delete applications
* Per application, navigation to related:
* Resources (images/directories)
* Packages
* Vulnerabilities
* Licenses in use by the resources
* Application Resources (images/directories)
* Per resource, navigation to related:
* Applications
* Packages
* Vulnerabilities
* Packages
* Per package, navigation to related:
* Applications
* Linkable list of resources and the detecting SBOM analyzers
* Vulnerabilities
* Vulnerabilities
* Per vulnerability, navigation to related:
* Applications
* Resources
* List of detecting scanners
* K8s Runtime scan
* On-demand or scheduled scanning
* Automatic detection of target namespaces
* Scan progress and result navigation per affected element (applications, resources, packages, vulnerabilities)
* CIS Docker benchmark
* CLI (CI/CD)
* SBOM generation using multiple integrated content analyzers (Syft, cyclonedx-gomod)
* SBOM/image/directory vulnerability scanning using multiple integrated scanners (Grype, Dependency-track)
* Merging of SBOM and vulnerabilities across different CI/CD stages
* Export results to KubeClarity backend
* API
* The API for KubeClarity can be found here High level architecturehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji-NTlmT6zLPs4dGThLdXp7CZ2qYF07FZZGn3ouvvfBR8Yc5DgIrV_LGUXiHtcLf7WXJHnZ4_v6AM9hvaY-rp2JU-i5o_PATm6SbteWFt_-JZXVUHttTfEFyvvzeXgazuZZLiO_qkBYW5WT3h9McBqDqVJa2v0NYMTT_9VDauNdaJ0rwrbm8n8xfLH/s2850/architecture.png Getting startedIntegration with SBOM generators and vulnerability scannersKubeClarity content analyzer integrates with the following SBOM generators:
* Syft
* Cyclonedx-gomod
KubeClarity vulnerability scanner integrates with the following scanners:
* Grype
* Dependency-Track
The integrations with the SBOM generators can be found here, and the integrations with the vulnerability scanners can be found here here. To enable and configure the supported SBOM generators and vulnerability scanners, please check the “analyzer” and “scanner” config under the “vulnerability[...]
___________________________
@hacking_Attack
@Hacking_Video
Kubeclarity : Tool For Detection And Management Of Software Bill Of Materials
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems. It scans both runtime K8s clusters and CI/CD pipelines for enhanced software supply chain security. SBOM & vulnerability detection challenges* Effective vulnerability scanning requires an accurate Software Bill Of Materials (SBOM) detection:
* Various programming languages and package managers
* Various OS distributions
* Package dependency information is usually stripped upon build
* Which one is the best scanner/SBOM analyzer?
* What should we scan: Git repos, builds, container images or runtime?
* Each scanner/analyzer has its own format – how to compare the results?
* How to manage the discovered SBOM and vulnerabilities?
* How are my applications affected by a newly discovered vulnerability? Solution* Separate vulnerability scanning into 2 phases:
* Content analysis to generate SBOM
* Scan the SBOM for vulnerabilities
* Create a pluggable infrastructure to:
* Run several content analyzers in parallel
* Run several vulnerability scanners in parallel
* Scan and merge results between different CI stages using KubeClarity CLI
* Runtime K8s scan to detect vulnerabilities discovered post-deployment
* Group scanned resources (images/directories) under defined applications to navigate the object tree dependencies (applications, resources, packages, vulnerabilities) Features* Dashboard
* Fixable vulnerabilities per severity
* Top 5 vulnerable elements (applications, resources, packages)
* New vulnerabilities trends
* Package count per license type
* Package count per programming language
* General counters
* Applications
* Automatic application detection in K8s runtime
* Create/edit/delete applications
* Per application, navigation to related:
* Resources (images/directories)
* Packages
* Vulnerabilities
* Licenses in use by the resources
* Application Resources (images/directories)
* Per resource, navigation to related:
* Applications
* Packages
* Vulnerabilities
* Packages
* Per package, navigation to related:
* Applications
* Linkable list of resources and the detecting SBOM analyzers
* Vulnerabilities
* Vulnerabilities
* Per vulnerability, navigation to related:
* Applications
* Resources
* List of detecting scanners
* K8s Runtime scan
* On-demand or scheduled scanning
* Automatic detection of target namespaces
* Scan progress and result navigation per affected element (applications, resources, packages, vulnerabilities)
* CIS Docker benchmark
* CLI (CI/CD)
* SBOM generation using multiple integrated content analyzers (Syft, cyclonedx-gomod)
* SBOM/image/directory vulnerability scanning using multiple integrated scanners (Grype, Dependency-track)
* Merging of SBOM and vulnerabilities across different CI/CD stages
* Export results to KubeClarity backend
* API
* The API for KubeClarity can be found here High level architecturehttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji-NTlmT6zLPs4dGThLdXp7CZ2qYF07FZZGn3ouvvfBR8Yc5DgIrV_LGUXiHtcLf7WXJHnZ4_v6AM9hvaY-rp2JU-i5o_PATm6SbteWFt_-JZXVUHttTfEFyvvzeXgazuZZLiO_qkBYW5WT3h9McBqDqVJa2v0NYMTT_9VDauNdaJ0rwrbm8n8xfLH/s2850/architecture.png Getting startedIntegration with SBOM generators and vulnerability scannersKubeClarity content analyzer integrates with the following SBOM generators:
* Syft
* Cyclonedx-gomod
KubeClarity vulnerability scanner integrates with the following scanners:
* Grype
* Dependency-Track
The integrations with the SBOM generators can be found here, and the integrations with the vulnerability scanners can be found here here. To enable and configure the supported SBOM generators and vulnerability scanners, please check the “analyzer” and “scanner” config under the “vulnerability[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Kubeclarity : Tool For Detection And Management Of Software
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images.
Kali Linux Tutorials
Kubeclarity : Tool For Detection And Management Of Software Bill Of Materials
___________________________
@hacking_Attack
@Hacking_Video
Kubeclarity : Tool For Detection And Management Of Software Bill Of Materials
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Kubeclarity : Tool For Detection And Management Of Software
KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images.
Dark Reading: Attacks/Breaches
Organizations Battling Phishing Malware, Viruses the Most
Organizations may not encounter malware targeting cloud systems or networking equipment frequently, but the array of malware they encounter just occasionally are no less disruptive or damaging. That is where the focus needs to be.
Organizations Battling Phishing Malware, Viruses the Most
Organizations may not encounter malware targeting cloud systems or networking equipment frequently, but the array of malware they encounter just occasionally are no less disruptive or damaging. That is where the focus needs to be.
Dark Reading: Attacks/Breaches
80% of Legacy MSSP Users Planning MDR Upgrade
False positives and staff shortages are inspiring a massive managed detection and response (MDR) services migration, research finds.
___________________________
@hacking_Attack
@Hacking_Video
80% of Legacy MSSP Users Planning MDR Upgrade
False positives and staff shortages are inspiring a massive managed detection and response (MDR) services migration, research finds.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
80% of Legacy MSSP Users Planning MDR Upgrade
False positives and staff shortages are inspiring a massive managed detection and response (MDR) services migration, research finds.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pwning.eth Earns Whitehat Hall Of Fame NFT For Aurora Find
https://cdn-images-1.medium.com/max/1200/1*9sX1DCuQX1guyg1FG_mJ-g.png
Pwning.eth has earned a Whitehat Hall of Fame NFT for his recent critical bug find in Aurora, forever securing his spot in hacking history…
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Pwning.eth Earns Whitehat Hall Of Fame NFT For Aurora Find
https://cdn-images-1.medium.com/max/1200/1*9sX1DCuQX1guyg1FG_mJ-g.png
Pwning.eth has earned a Whitehat Hall of Fame NFT for his recent critical bug find in Aurora, forever securing his spot in hacking history…
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pwning.eth Earns Whitehat Hall Of Fame NFT For Aurora Find
Pwning.eth has earned a Whitehat Hall of Fame NFT for his recent critical bug find in Aurora, forever securing his spot in hacking history…