hacking: security in practice
Are bug bounties still viable ?
At this point CMSs and frameworks used to create websites take the required security measures to keep a website safe (auto escaping and CSRF protection for example). And the hosting services provide firewalls by default in their servers. A web app would need the developers to mess up really bad somewhere in order for it to be vulnerable, which let's be honest, will not be done by a company offering a bug bounty program.
Your only shot is finding a vulnerability in the CMSs or frameworks used to build the website which are most of the time open source and reviewed by hundreds of people, or closed source and has been around for an eternity and has been patched against every single vulnerability a website can have.
That's why I don't think bug bounties are viable in 2022, let me know what you think.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are bug bounties still viable ?
At this point CMSs and frameworks used to create websites take the required security measures to keep a website safe (auto escaping and CSRF protection for example). And the hosting services provide firewalls by default in their servers. A web app would need the developers to mess up really bad somewhere in order for it to be vulnerable, which let's be honest, will not be done by a company offering a bug bounty program.
Your only shot is finding a vulnerability in the CMSs or frameworks used to build the website which are most of the time open source and reviewed by hundreds of people, or closed source and has been around for an eternity and has been patched against every single vulnerability a website can have.
That's why I don't think bug bounties are viable in 2022, let me know what you think.
submitted by /u/Iam_cool_asf
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are bug bounties still viable ?
At this point CMSs and frameworks used to create websites take the required security measures to keep a website safe (auto escaping and CSRF...
hacking: security in practice
How does the obfuscation of android code work?
I'm new to this sort of thing, any pointers on how to be able to read it?
submitted by /u/Skyfall642
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How does the obfuscation of android code work?
I'm new to this sort of thing, any pointers on how to be able to read it?
submitted by /u/Skyfall642
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How does the obfuscation of android code work?
I'm new to this sort of thing, any pointers on how to be able to read it?
An Out Of Scope domain Leads To a Critical Bug[$1500]
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).Continue reading on Medium »
Read more...
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
An Out Of Scope domain Leads To a Critical Bug[$1500]
https://cdn-images-1.medium.com/max/1550/1*BPZPk1cO77KkvQZJ2ISyxA.png
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
An Out Of Scope domain Leads To a Critical Bug[$1500]
https://cdn-images-1.medium.com/max/1550/1*BPZPk1cO77KkvQZJ2ISyxA.png
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
An Out Of Scope domain Leads To a Critical Bug[$1500]
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan). Hope all are having a good day. In this write-up, I will be sharing how I have found a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Sensitive Token Leakage from server side
https://cdn-images-1.medium.com/max/600/1*RyFGQUUCQYSl5C7PEYnPEw.png
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sensitive Token Leakage from server side
https://cdn-images-1.medium.com/max/600/1*RyFGQUUCQYSl5C7PEYnPEw.png
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sensitive Token Leakage from server side
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…
Sensitive Token Leakage from server side
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…Continue reading on Medium »
Read more...
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…Continue reading on Medium »
Read more...
An Out Of Scope domain Leads To a Critical Bug[$1500]
https://medium.com/@shakti.gtp/an-out-of-scope-domain-leads-to-a-critical-bug-1500-f228d2c7db4b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@shakti.gtp/an-out-of-scope-domain-leads-to-a-critical-bug-1500-f228d2c7db4b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
An Out Of Scope domain Leads To a Critical Bug[$1500]
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan). Hope all are having a good day. In this write-up, I will be sharing how I have found a…
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan).Continue reading on Medium » (https://medium.com/@shakti.gtp/an-out-of-scope-domain-leads-to-a-critical-bug-1500-f228d2c7db4b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
An Out Of Scope domain Leads To a Critical Bug[$1500]
Hello All, I am Shakti Ranjan Mohanty (3ncryptsaan). Hope all are having a good day. In this write-up, I will be sharing how I have found a…
Sensitive Token Leakage from server side
https://medium.com/@milanjain7906/sensitive-token-leakage-from-server-side-d9b7925f3651?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@milanjain7906/sensitive-token-leakage-from-server-side-d9b7925f3651?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sensitive Token Leakage from server side
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…Continue reading on Medium » (https://medium.com/@milanjain7906/sensitive-token-leakage-from-server-side-d9b7925f3651?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sensitive Token Leakage from server side
Hii all i have back with new Hacking story !!.so . One month Ago i was hunting on vdp program which is india’s one of the most successful…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click BugPost Views: 3
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Advanced persistent threat group Fancy Bear is behind a phishing campaign that uses the specter of nuclear war to exploit a known one-click Microsoft flaw.
The goal is to deliver malware that can steal credentials from the Chrome, Firefox and Edge browsers.
The attacks by the Russia-linked APT are tied the Russian and Ukraine war, according to researchers at Malwarebytes Threat Intelligence. They report that Fancy Bear is pushing malicious documents weaponized with the exploit for Follina (CVE-2022-30190), a known Microsoft one-click flaw, according to a blog post published this week.
“This is the first time we’ve observed APT28 using Follina in its operations,” researchers wrote in the post. Fancy Bear is also known as APT28, Strontium and Sofacy.
On June 20, Malwarebytes researchers first observed the weaponized document, which downloads and executes a .Net stealer first reported by Google. Google’s Threat Analysis Group (TAG) said Fancy Bear already has used this stealer to target users in the Ukraine.
The Computer Emergency Response Team of Ukraine (CERT-UA) also independently discovered the malicious document used by Fancy Bear in the recent phishing campaign, according to Malwarebytes. Bear on the LooseCERT-UA previously identified Fancy Bear as one of the numerous APTs pummeling Ukraine with cyber-attacks in parallel with the invasion by Russian troops that began in late February. The group is believed to be operating on the behest of Russian intelligence to gather info that would be useful to the agency.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png In the past Fancy Bear has been linked in attacks targeting elections in the United States and Europe, as well as hacks against sporting and anti-doping agencies related to the 2020 Olympic Games.
Researchers first flagged Follina in April, but only in May was it officially identified as a zero-day, one-click exploit. Follina is associated with the Microsoft Support Diagnostic Tool (MSDT) and uses the ms-msdt protocol to load malicious code from Word or other Office documents when they’re opened.
The bug is dangerous for a number of reasons–not the least of which is its wide attack surface, as it basically affects anyone using Microsoft Office on all currently supported versions of Windows. If successfully exploited, attackers can gain user rights to effectively take over a system and install programs, view, change or delete data, or create new accounts.
Microsoft recently patched Follina in its June Patch Tuesday release but it remains under active exploit by threat actors, including known APTs.
Threat of Nuclear Attack
Fancy Bear’s Follina campaign targets users with emails carrying a malicious RTF file called “Nuclear Terrorism A Very Real Threat” in an attempt to prey on victims’ fears that the invasion of Ukraine will escalate into a nuclear conflict, researchers said in the post. The content of the document is an article from the international affairs group Atlantic Council that explores the possibility that Putin will use nuclear weapons in the war in Ukraine.
The malicious file uses a remote template embedded in the Document.xml.rels file to retrieve a remote HTML file from the URL http://kitten-268[.]frge[.]io/article[.]html. The HTML file then uses a JavaScript call to window.location.href to load and execute an e[...]
___________________________
@hacking_Attack
@Hacking_Video
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click BugPost Views: 3
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Advanced persistent threat group Fancy Bear is behind a phishing campaign that uses the specter of nuclear war to exploit a known one-click Microsoft flaw.
The goal is to deliver malware that can steal credentials from the Chrome, Firefox and Edge browsers.
The attacks by the Russia-linked APT are tied the Russian and Ukraine war, according to researchers at Malwarebytes Threat Intelligence. They report that Fancy Bear is pushing malicious documents weaponized with the exploit for Follina (CVE-2022-30190), a known Microsoft one-click flaw, according to a blog post published this week.
“This is the first time we’ve observed APT28 using Follina in its operations,” researchers wrote in the post. Fancy Bear is also known as APT28, Strontium and Sofacy.
On June 20, Malwarebytes researchers first observed the weaponized document, which downloads and executes a .Net stealer first reported by Google. Google’s Threat Analysis Group (TAG) said Fancy Bear already has used this stealer to target users in the Ukraine.
The Computer Emergency Response Team of Ukraine (CERT-UA) also independently discovered the malicious document used by Fancy Bear in the recent phishing campaign, according to Malwarebytes. Bear on the LooseCERT-UA previously identified Fancy Bear as one of the numerous APTs pummeling Ukraine with cyber-attacks in parallel with the invasion by Russian troops that began in late February. The group is believed to be operating on the behest of Russian intelligence to gather info that would be useful to the agency.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png In the past Fancy Bear has been linked in attacks targeting elections in the United States and Europe, as well as hacks against sporting and anti-doping agencies related to the 2020 Olympic Games.
Researchers first flagged Follina in April, but only in May was it officially identified as a zero-day, one-click exploit. Follina is associated with the Microsoft Support Diagnostic Tool (MSDT) and uses the ms-msdt protocol to load malicious code from Word or other Office documents when they’re opened.
The bug is dangerous for a number of reasons–not the least of which is its wide attack surface, as it basically affects anyone using Microsoft Office on all currently supported versions of Windows. If successfully exploited, attackers can gain user rights to effectively take over a system and install programs, view, change or delete data, or create new accounts.
Microsoft recently patched Follina in its June Patch Tuesday release but it remains under active exploit by threat actors, including known APTs.
Threat of Nuclear Attack
Fancy Bear’s Follina campaign targets users with emails carrying a malicious RTF file called “Nuclear Terrorism A Very Real Threat” in an attempt to prey on victims’ fears that the invasion of Ukraine will escalate into a nuclear conflict, researchers said in the post. The content of the document is an article from the international affairs group Atlantic Council that explores the possibility that Putin will use nuclear weapons in the war in Ukraine.
The malicious file uses a remote template embedded in the Document.xml.rels file to retrieve a remote HTML file from the URL http://kitten-268[.]frge[.]io/article[.]html. The HTML file then uses a JavaScript call to window.location.href to load and execute an e[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug | Black Hat Ethical Hacking
Advanced persistent threat group Fancy Bear is behind a phishing campaign that uses the specter of nuclear war to exploit a known one-click Microsoft flaw.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click BugPost Views: 3 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe…
ncoded PowerShell script using the ms-msdt MSProtocol URI scheme, researchers said.
Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google in other Fancy Bear campaigns in the Ukraine. While the oldest variant of the stealer used a fake error message pop-up to distract users from what it was doing, the variant used in the nuclear-themed campaign does not, researchers said.
In other functionality, the recently seen variant is “almost identical” to the earlier one, “with just a few minor refactors and some additional sleep commands,” they added.
As with the previous variant, the stealer’s main pupose is to steal data—including website credentials such as username, password and URL–from several popular browsers, including Google Chrome, Microsoft Edge and Firefox. The malware then uses the IMAP email protocol to exfiltrate data to its command-and-control server in the same way the earlier variant did but this time to a different domain, researchers said.
“The old variant of this stealer connected to mail[.]sartoc.com (144.208.77.68) to exfiltrate data,” they wrote. “The new variant uses the same method but a different domain, www.specialityllc[.]com. Interestingly both are located in Dubai.”
Trending: Offensive Security Tool: Mobile Security Framework (MobSF) Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The owners of the websites most likely have nothing to do with APT28, with the group simply taking advantage of abandoned or vulnerable sites, researchers added.
Trending: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/intro_toddycat_apt-800x450-1-90x90.jpg Elusive ToddyCat APT Targets Microsoft Exchange Servers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/office-365-90x90.jpg Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/cyber-1-90x90.jpg Internet scans find 1.6 million secrets leaked by websites3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/malicious-chrome-extensions-feature-90x90.jpg Google Chrome extensions can be fingerprinted to track you online4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android_malware-700x394-1-90x90.jpg New MaliBot Android banking malware spreads as a crypto miner7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Cisco_Systems_Bug-90x90.jpg Cisco Secure Email bug can let attackers bypass authentication1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect2 weeks ago
The post Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug [...]
___________________________
@hacking_Attack
@Hacking_Video
Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google in other Fancy Bear campaigns in the Ukraine. While the oldest variant of the stealer used a fake error message pop-up to distract users from what it was doing, the variant used in the nuclear-themed campaign does not, researchers said.
In other functionality, the recently seen variant is “almost identical” to the earlier one, “with just a few minor refactors and some additional sleep commands,” they added.
As with the previous variant, the stealer’s main pupose is to steal data—including website credentials such as username, password and URL–from several popular browsers, including Google Chrome, Microsoft Edge and Firefox. The malware then uses the IMAP email protocol to exfiltrate data to its command-and-control server in the same way the earlier variant did but this time to a different domain, researchers said.
“The old variant of this stealer connected to mail[.]sartoc.com (144.208.77.68) to exfiltrate data,” they wrote. “The new variant uses the same method but a different domain, www.specialityllc[.]com. Interestingly both are located in Dubai.”
Trending: Offensive Security Tool: Mobile Security Framework (MobSF) Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The owners of the websites most likely have nothing to do with APT28, with the group simply taking advantage of abandoned or vulnerable sites, researchers added.
Trending: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/intro_toddycat_apt-800x450-1-90x90.jpg Elusive ToddyCat APT Targets Microsoft Exchange Servers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/office-365-90x90.jpg Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/cyber-1-90x90.jpg Internet scans find 1.6 million secrets leaked by websites3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/malicious-chrome-extensions-feature-90x90.jpg Google Chrome extensions can be fingerprinted to track you online4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android_malware-700x394-1-90x90.jpg New MaliBot Android banking malware spreads as a crypto miner7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Cisco_Systems_Bug-90x90.jpg Cisco Secure Email bug can let attackers bypass authentication1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect2 weeks ago
The post Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ncoded PowerShell script using the ms-msdt MSProtocol URI scheme, researchers said. Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google…
first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
hacking: security in practice
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?