Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.InfecDoor.17.c MVID-2022-0614 Insecure Permissions
https://4.bp.blogspot.com/-mbNmyGHywr4/WWlve-suujI/AAAAAAAAIP4/9elXOC6IHOcW_3VzQDLCix2bjP9zh38ZgCLcBGAs/s1600/h83.png
Backdoor.Win32.InfecDoor.17.c malware suffers from an insecure permissions vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.InfecDoor.17.c MVID-2022-0614 Insecure Permissions
https://4.bp.blogspot.com/-mbNmyGHywr4/WWlve-suujI/AAAAAAAAIP4/9elXOC6IHOcW_3VzQDLCix2bjP9zh38ZgCLcBGAs/s1600/h83.png
Backdoor.Win32.InfecDoor.17.c malware suffers from an insecure permissions vulnerability.
SHA-256 |
3d83874665d92c5753ea0f979739fbb96e5a47c3ff77657f79b68a13a96e6218Download
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source: https://malvuln.com/advisory/1fd70e41918c3a75c634b1c234ec36fb.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.InfecDoor.17.c
Vulnerability: Insecure Permissions
Description: The malware writes a ".420" settings file type to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the file dropped by the malware to disable, change its settings or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: InfecDoor
Type: PE32
MD5: 1fd70e41918c3a75c634b1c234ec36fb
Vuln ID: MVID-2022-0614
Disclosure: 06/23/2022
Exploit/PoC:
C:\>cacls Infector.420
C:\Infector.420 BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
C:\>dir Infector.420
Volume in drive C has no label.
Directory of C:\
04/11/2022 03:29 AM 36 Infector.420
1 File(s) 36 bytes
0 Dir(s) 24,644,292,608 bytes free
C:\>type Infector.420
[My_OVER_ALL_SETTINGS]
FirsTime=0
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.InfecDoor.17.c MVID-2022-0614 Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Shark.btu MVID-2022-0615 Insecure Permissions
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
Backdoor.Win32.Shark.btu malware suffers from an insecure permissions vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Shark.btu MVID-2022-0615 Insecure Permissions
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
Backdoor.Win32.Shark.btu malware suffers from an insecure permissions vulnerability.
SHA-256 |
c655d4e022fcaf26fe0ab1bc5057626705455cfc787337ad8df95d9c1fca1f2fDownload
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source: https://malvuln.com/advisory/5a83f8b8c8a8b7a85b3ff632aa60e793.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Shark.btu
Vulnerability: Insecure Permissions
Description: The malware writes multiple PE files to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: Shark
Type: PE32
MD5: 5a83f8b8c8a8b7a85b3ff632aa60e793
Vuln ID: MVID-2022-0615
Disclosure: 06/23/2022
Exploit/PoC:
C:\Fraps BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir Fraps
Volume in drive C has no label.
Directory of C:\Fraps
01/14/2008 08:12 AM 12,988 changes.txt
01/14/2008 08:51 AM 172,032 fraps.dll
01/14/2008 08:53 AM 913,064 fraps.exe
01/14/2008 08:51 AM 1,683,968 fraps64.dat
01/14/2008 08:51 AM 111,616 fraps64.dll
01/14/2008 08:51 AM 135,168 frapslcd.dll
05/12/2022 02:02 AM DIR HELP
01/14/2008 08:07 AM 1,841 README.HTM
05/12/2022 02:02 AM 34,552 uninstall.exe
8 File(s) 3,065,229 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Shark.btu MVID-2022-0615 Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Mailfinder.Win32.VB.p MVID-2022-0616 Insecure Permissions
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png
Trojan-Mailfinder.Win32.VB.p malware suffers from an insecure permissions vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Trojan-Mailfinder.Win32.VB.p MVID-2022-0616 Insecure Permissions
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png
Trojan-Mailfinder.Win32.VB.p malware suffers from an insecure permissions vulnerability.
SHA-256 |
eccb9f610544b46bcdf27fabac4f1f936099cd8c6b21232d4171889d289f6dd4Download
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source: https://malvuln.com/advisory/20e438d84aa2828826d52540d80bf7f.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan-Mailfinder.Win32.VB.p
Vulnerability: Insecure Permissions
Description: The malware writes a dir with multiple PE files to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: VB
Type: PE32
MD5: 20e438d84aa2828826d52540d80bf7fa
Vuln ID: MVID-2022-0616
Disclosure: 06/23/2022
Exploit/PoC:
C:\>cacls IMB
C:\IMB BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir IMB
Volume in drive C has no label.
Directory of C:\IMB
09/12/2003 09:07 PM 140,288 comdlg32.ocx
06/16/2004 01:17 PM 282,624 IMB.exe
09/12/2003 09:07 PM 1,388,544 msvbvm60.dll
09/12/2003 09:07 PM 108,336 MSWINSCK.OCX
09/15/2003 05:16 PM 192 Readme.txt
10/04/2001 12:16 AM 147,483 scrrun.dll
10/04/2001 12:16 AM 17,920 stdole2.tlb
09/12/2003 09:07 PM 2,864 winsock.dll
8 File(s) 2,088,251 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Trojan-Mailfinder.Win32.VB.p MVID-2022-0616 Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Yashma Ransomware Builder 1.2 MVID-2022-0613 Insecure Permissions
https://4.bp.blogspot.com/-VWb4EvQ6bEo/WWlvWDArLMI/AAAAAAAAIOE/2pUCVP0uaRIPq11CtWtknt0n-yL_qFw9wCLcBGAs/s1600/h48.png
Yashma Ransomware Builder version 1.2 malware suffers from an insecure permissions vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Yashma Ransomware Builder 1.2 MVID-2022-0613 Insecure Permissions
https://4.bp.blogspot.com/-VWb4EvQ6bEo/WWlvWDArLMI/AAAAAAAAIOE/2pUCVP0uaRIPq11CtWtknt0n-yL_qFw9wCLcBGAs/s1600/h48.png
Yashma Ransomware Builder version 1.2 malware suffers from an insecure permissions vulnerability.
SHA-256 |
2958cbdc74819764ad9679c607c3aa49b36ad14d86fb437d927a14ccf2c14229Download
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source: https://malvuln.com/advisory/13e878ed7e547523cffc5728f6ba4190.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Yashma Ransomware Builder v1.2
Vulnerability: Insecure Permissions
Description: The malware creates PE files with insecure permissions when writing to c:\ drive, granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: Yashma
Type: PE32
MD5: 13e878ed7e547523cffc5728f6ba4190
Vuln ID: MVID-2022-0613
Disclosure: 06/23/2022
Exploit/PoC:
C:\>cacls hate.exe
C:\hate.exe BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
C:\>dir hate.exe
Volume in drive C has no label.
Directory of C:\
05/14/2022 01:20 AM 54,784 hate.exe
1 File(s) 54,784 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Yashma Ransomware Builder 1.2 MVID-2022-0613 Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Are Botnets still a promising business? [Discussion]
No I don't own one or plan to, but after
"Cloudflare mitigates record-breaking HTTPS DDoS attack of 26 million https requests"
My question is the effort in creating a botnet, maintaining it, risking your career (by getting law enforcements behind you), is it all worth it?
That was insane 26 million requests which were neutralized. Considering the point that many businesses use cloud flare, and the cloud flare itself is constantly improving, the whole effort seems to be in vain. Right?
Bleeping computer article on this DDoS
Edit: After reading comments and some more research, I found it's still a valuable business.
Lezzz goooo boooyyyyzzz : )
submitted by /u/Blaack_Work
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are Botnets still a promising business? [Discussion]
No I don't own one or plan to, but after
"Cloudflare mitigates record-breaking HTTPS DDoS attack of 26 million https requests"
My question is the effort in creating a botnet, maintaining it, risking your career (by getting law enforcements behind you), is it all worth it?
That was insane 26 million requests which were neutralized. Considering the point that many businesses use cloud flare, and the cloud flare itself is constantly improving, the whole effort seems to be in vain. Right?
Bleeping computer article on this DDoS
Edit: After reading comments and some more research, I found it's still a valuable business.
Lezzz goooo boooyyyyzzz : )
submitted by /u/Blaack_Work
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are Botnets still a promising business? [Discussion]
No I don't own one or plan to, but after >"Cloudflare mitigates record-breaking HTTPS DDoS attack of 26 million https requests" My question is...
Cyber Security adalah suatu aktivitas yang dilakukan dengan tujuan untuk mengamankan serta mencegah…
https://medium.com/@frozzipies/cyber-security-adalah-suatu-aktivitas-yang-dilakukan-dengan-tujuan-untuk-mengamankan-serta-mencegah-38fa8b213c1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@frozzipies/cyber-security-adalah-suatu-aktivitas-yang-dilakukan-dengan-tujuan-untuk-mengamankan-serta-mencegah-38fa8b213c1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security adalah suatu aktivitas yang dilakukan dengan tujuan untuk mengamankan serta mencegah…
Dengan banyaknya kejadian cyber crime di seluruh dunia, ada baiknya kita harus menghasilkan dan mengumpulkan orang orang yang mahir dalam…
Dengan banyaknya kejadian cyber crime di seluruh dunia, ada baiknya kita harus menghasilkan dan mengumpulkan orang orang yang mahir dalam…Continue reading on Medium » (https://medium.com/@frozzipies/cyber-security-adalah-suatu-aktivitas-yang-dilakukan-dengan-tujuan-untuk-mengamankan-serta-mencegah-38fa8b213c1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security adalah suatu aktivitas yang dilakukan dengan tujuan untuk mengamankan serta mencegah…
Dengan banyaknya kejadian cyber crime di seluruh dunia, ada baiknya kita harus menghasilkan dan mengumpulkan orang orang yang mahir dalam…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Conti ransomware finalmente cierra la fuga de datos, los sitios de negociación
https://cdn-images-1.medium.com/max/1597/0*qPdqfOfHVV6VmIU0
PUBLICADO EN 24 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Conti ransomware finalmente cierra la fuga de datos, los sitios de negociación
https://cdn-images-1.medium.com/max/1597/0*qPdqfOfHVV6VmIU0
PUBLICADO EN 24 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Conti ransomware finalmente cierra la fuga de datos, los sitios de negociación
PUBLICADO EN 24 JUNIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Analyzing a macro enabled office file.
https://cdn-images-1.medium.com/max/1912/1*WdFFyNrzmiyomjQCb0Tp9Q.png
Hi! So if you’re using Microsoft Office and you been around for quite a while. You probably heard about Macros?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Analyzing a macro enabled office file.
https://cdn-images-1.medium.com/max/1912/1*WdFFyNrzmiyomjQCb0Tp9Q.png
Hi! So if you’re using Microsoft Office and you been around for quite a while. You probably heard about Macros?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Analyzing a macro enabled office file.
Hi! So if you’re using Microsoft Office and you been around for quite a while. You probably heard about Macros?
Alert(1)Continue reading on Medium » (https://thexssrat.medium.com/basic-xss-bypasses-c38226fb74bf?source=rss------bug_bounty-5)
Authcov - Web App Authorisation Coverage Scanning
http://www.kitploit.com/2022/06/authcov-web-app-authorisation-coverage.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/06/authcov-web-app-authorisation-coverage.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Authcov - Web App Authorisation Coverage Scanning