Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click BugPost Views: 3 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe…
ncoded PowerShell script using the ms-msdt MSProtocol URI scheme, researchers said.
Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google in other Fancy Bear campaigns in the Ukraine. While the oldest variant of the stealer used a fake error message pop-up to distract users from what it was doing, the variant used in the nuclear-themed campaign does not, researchers said.
In other functionality, the recently seen variant is “almost identical” to the earlier one, “with just a few minor refactors and some additional sleep commands,” they added.
As with the previous variant, the stealer’s main pupose is to steal data—including website credentials such as username, password and URL–from several popular browsers, including Google Chrome, Microsoft Edge and Firefox. The malware then uses the IMAP email protocol to exfiltrate data to its command-and-control server in the same way the earlier variant did but this time to a different domain, researchers said.
“The old variant of this stealer connected to mail[.]sartoc.com (144.208.77.68) to exfiltrate data,” they wrote. “The new variant uses the same method but a different domain, www.specialityllc[.]com. Interestingly both are located in Dubai.”
Trending: Offensive Security Tool: Mobile Security Framework (MobSF) Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The owners of the websites most likely have nothing to do with APT28, with the group simply taking advantage of abandoned or vulnerable sites, researchers added.
Trending: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/intro_toddycat_apt-800x450-1-90x90.jpg Elusive ToddyCat APT Targets Microsoft Exchange Servers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/office-365-90x90.jpg Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/cyber-1-90x90.jpg Internet scans find 1.6 million secrets leaked by websites3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/malicious-chrome-extensions-feature-90x90.jpg Google Chrome extensions can be fingerprinted to track you online4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android_malware-700x394-1-90x90.jpg New MaliBot Android banking malware spreads as a crypto miner7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Cisco_Systems_Bug-90x90.jpg Cisco Secure Email bug can let attackers bypass authentication1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect2 weeks ago
The post Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug [...]
___________________________
@hacking_Attack
@Hacking_Video
Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google in other Fancy Bear campaigns in the Ukraine. While the oldest variant of the stealer used a fake error message pop-up to distract users from what it was doing, the variant used in the nuclear-themed campaign does not, researchers said.
In other functionality, the recently seen variant is “almost identical” to the earlier one, “with just a few minor refactors and some additional sleep commands,” they added.
As with the previous variant, the stealer’s main pupose is to steal data—including website credentials such as username, password and URL–from several popular browsers, including Google Chrome, Microsoft Edge and Firefox. The malware then uses the IMAP email protocol to exfiltrate data to its command-and-control server in the same way the earlier variant did but this time to a different domain, researchers said.
“The old variant of this stealer connected to mail[.]sartoc.com (144.208.77.68) to exfiltrate data,” they wrote. “The new variant uses the same method but a different domain, www.specialityllc[.]com. Interestingly both are located in Dubai.”
Trending: Offensive Security Tool: Mobile Security Framework (MobSF) Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The owners of the websites most likely have nothing to do with APT28, with the group simply taking advantage of abandoned or vulnerable sites, researchers added.
Trending: Write up: Find hidden and encrypted secrets from any website Source: threatpost.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/intro_toddycat_apt-800x450-1-90x90.jpg Elusive ToddyCat APT Targets Microsoft Exchange Servers1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/office-365-90x90.jpg Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/cyber-1-90x90.jpg Internet scans find 1.6 million secrets leaked by websites3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/malicious-chrome-extensions-feature-90x90.jpg Google Chrome extensions can be fingerprinted to track you online4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android_malware-700x394-1-90x90.jpg New MaliBot Android banking malware spreads as a crypto miner7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Cisco_Systems_Bug-90x90.jpg Cisco Secure Email bug can let attackers bypass authentication1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/android-malware-90x90.jpg Android malware on the Google Play Store gets 2 million downloads1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Linux-90x90.jpg New Linux rootkit, Syslogk uses magic packets to trigger backdoor1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect2 weeks ago
The post Fancy Bear Uses Nuke Threat Lure to Exploit 1-Click Bug [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ncoded PowerShell script using the ms-msdt MSProtocol URI scheme, researchers said. Trending: New Linux rootkit, Syslogk uses magic packets to trigger backdoor The PowerShell loads the final payload–a variant of the .Net stealer previously identified by Google…
first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Windows netsh grab username from wifi profile
I can grap the wifi password from the profile. Is there a way to show the username of that profile? I dont have admin rights.
hacking: security in practice
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?
submitted by /u/praisthesun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
VPS masscan
someone experienced to use masscan on a 10Gbits VPS? Witch VPS you used?
hacking: security in practice
Is IT blocking hotspot and router access through ethernet?
So the IT team at my university has started cracking down on students for using too much internet (even though it is unlimited) during class hours (streaming Netflix, torrenting MASSIVE files, etc).
They use MAC filtering for each student to limit how many devices can connect to the network. Luckily I have some Linux/basic hacking knowledge and used macchanger to change my MAC in order to bypass this.
Then they started manually blocking devices based on their usage. Eg if someone was using Netflix, connected to a VPN or proxy to bypass firewall restrictions, or had P2P (torrent) traffic on the network, they would block that device from connecting for 24 hours. Also, they started slowing the speed from gigabit to less than 10 Mbps, so now barely anything works.
We also have ethernet ports throughout the campus and in classes, which don't have any of these restrictions (other than MAC filtering), but the problem is they have somehow blocked the use of ethernet hotspot creation. I have a travel router and whenever I try to connect it with the ethernet, the router cannot give out internet access as an access point. My router has a setting to clone MAC addresses, so I have changed the MAC, but whenever I connect the port it shows up as having no internet through a connected laptop or phone.
I tried connecting my laptop directly to the ethernet port and see what happens, and somehow when I connect everything works just fine, but as soon as I open my mobile hotspot from the settings my internet gets disconnected and I have to reconnect.
First, I want to understand how they are even doing this. Also, I want to learn if there would be a way to bypass this so i can connect my router and create a hotspot.
submitted by /u/jackforfaltu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is IT blocking hotspot and router access through ethernet?
So the IT team at my university has started cracking down on students for using too much internet (even though it is unlimited) during class hours (streaming Netflix, torrenting MASSIVE files, etc).
They use MAC filtering for each student to limit how many devices can connect to the network. Luckily I have some Linux/basic hacking knowledge and used macchanger to change my MAC in order to bypass this.
Then they started manually blocking devices based on their usage. Eg if someone was using Netflix, connected to a VPN or proxy to bypass firewall restrictions, or had P2P (torrent) traffic on the network, they would block that device from connecting for 24 hours. Also, they started slowing the speed from gigabit to less than 10 Mbps, so now barely anything works.
We also have ethernet ports throughout the campus and in classes, which don't have any of these restrictions (other than MAC filtering), but the problem is they have somehow blocked the use of ethernet hotspot creation. I have a travel router and whenever I try to connect it with the ethernet, the router cannot give out internet access as an access point. My router has a setting to clone MAC addresses, so I have changed the MAC, but whenever I connect the port it shows up as having no internet through a connected laptop or phone.
I tried connecting my laptop directly to the ethernet port and see what happens, and somehow when I connect everything works just fine, but as soon as I open my mobile hotspot from the settings my internet gets disconnected and I have to reconnect.
First, I want to understand how they are even doing this. Also, I want to learn if there would be a way to bypass this so i can connect my router and create a hotspot.
submitted by /u/jackforfaltu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is IT blocking hotspot and router access through ethernet?
So the IT team at my university has started cracking down on students for using too much internet (even though it is unlimited) during class hours...
How I was able to delete any users’ OAUTH connections via IDOR
﷽Continue reading on Medium »
Read more...
﷽Continue reading on Medium »
Read more...
How I was able to delete any users’ OAUTH connections via IDOR
https://medium.com/@webresearcher007/how-i-was-able-to-delete-any-users-oauth-connections-via-idor-bf3a8e8e2269?source=rss------bug_bounty-5
﷽Continue reading on Medium » (https://medium.com/@webresearcher007/how-i-was-able-to-delete-any-users-oauth-connections-via-idor-bf3a8e8e2269?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@webresearcher007/how-i-was-able-to-delete-any-users-oauth-connections-via-idor-bf3a8e8e2269?source=rss------bug_bounty-5
﷽Continue reading on Medium » (https://medium.com/@webresearcher007/how-i-was-able-to-delete-any-users-oauth-connections-via-idor-bf3a8e8e2269?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to delete any users’ OAUTH connections via IDOR
﷽
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CITRIX got a Problem with Unauthorized Users for Application Delivery Management
https://cdn-images-1.medium.com/max/640/0*icS7OKZ3ia7Yz5l0.jpg
Citrix is a cloud computing company that holds a lot of data to become an incharge of. That’s why this latest issue became a problem for…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CITRIX got a Problem with Unauthorized Users for Application Delivery Management
https://cdn-images-1.medium.com/max/640/0*icS7OKZ3ia7Yz5l0.jpg
Citrix is a cloud computing company that holds a lot of data to become an incharge of. That’s why this latest issue became a problem for…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CITRIX got a Problem with Unauthorized Users for Application Delivery Management
Citrix is a cloud computing company that holds a lot of data to become an incharge of. That’s why this latest issue became a problem for…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
People Are Getting Hacked By The Cyber Criminals In Order To Get There Internet Connection Fast.
People Are Getting Hacked By The Cyber Criminals In Order To Get Their Internet Connection Fast.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
People Are Getting Hacked By The Cyber Criminals In Order To Get There Internet Connection Fast.
People Are Getting Hacked By The Cyber Criminals In Order To Get Their Internet Connection Fast.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
People Are Getting Hacked By The Cyber Criminals In Order To Get There Internet Connection Fast.
People Are Getting Hacked By The Cyber Criminals In Order To Get Their Internet Connection Fast.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PINNACLE IS THE BEST
I had three evictions late last year which deprived me from purchasing an apartment for my family, and my other apartment was not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PINNACLE IS THE BEST
I had three evictions late last year which deprived me from purchasing an apartment for my family, and my other apartment was not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PINNACLE IS THE BEST
I had three evictions late last year which deprived me from purchasing an apartment for my family, and my other apartment was not conducive…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is growth hacking?
https://cdn-images-1.medium.com/max/1200/1*4JD5zMrkapBTHYD0wpQxOw.jpeg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is growth hacking?
https://cdn-images-1.medium.com/max/1200/1*4JD5zMrkapBTHYD0wpQxOw.jpeg
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is growth hacking?
When you are starting a new company, the first main thing that you need is “GROWTH”. Not someone to build a marketing team or manage it, not just a marketing strategy to achieve marketing objectives…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
WordPress WP HTML Mail plugin Vulnerable to XSS
https://cdn-images-1.medium.com/max/640/0*9qepydqvFV4MjP8H.png
The XSS vulnerability in the WordPress WP HTML Mail plugin for personalized emails makes it vulnerable to code injection and phishing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
WordPress WP HTML Mail plugin Vulnerable to XSS
https://cdn-images-1.medium.com/max/640/0*9qepydqvFV4MjP8H.png
The XSS vulnerability in the WordPress WP HTML Mail plugin for personalized emails makes it vulnerable to code injection and phishing…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
WordPress WP HTML Mail plugin Vulnerable to XSS
The XSS vulnerability in the WordPress WP HTML Mail plugin for personalized emails makes it vulnerable to code injection and phishing…
Black Hat Ethical Hacking
Offensive Security Tool: HTTPLoot
___________________________
@hacking_Attack
@Hacking_Video
Offensive Security Tool: HTTPLoot
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Offensive Security Tool: HTTPLoot | Black Hat Ethical Hacking
An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.
Norimaci - Simple And Lightweight Malware Analysis Sandbox For macOS
http://www.kitploit.com/2022/06/norimaci-simple-and-lightweight-malware.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/norimaci-simple-and-lightweight-malware.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Norimaci - Simple And Lightweight Malware Analysis Sandbox For macOS