Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How I Earned $200 in 5 Minutes | Open Redirection

Hello Researchers,Continue reading on Medium »
Read more...
Livepeer (Non Smart Contract) Security Disclosure Program

Program OverviewContinue reading on Livepeer Blog »
Read more...
HTML and Hyperlink Injection via Share Option In Microsoft Onenote Application

Hyperlink Injection it’s when attacker injecting a malicious link when sending an email invitation.Continue reading on InfoSec Write-ups »
Read more...
hacking: security in practice
How profitable is cryptojacking?

Been reading up and doing research lately on blockchain and came across cryptojacking. I am brand new to hacking so I don’t know how this works. Let’s say a black hat were able to get into 800 computers, would he be able to make 800 or more a day through this? Or is this an unrealistic scenario and is way less profitable and I don’t know what I’m talking about. If it isn’t this profitable how much would he be able to get a day to day basis through 800 computers and is 800 even realistic feat to get to? If so how long would it take to get to this feat?

submitted by /u/Based-andredpilled
[link] [comments]
hacking: security in practice
corrupt an executable

Is there any way to make an executable over which I do not have permission to write, to change the name... ? not necessarily by corrupting it, I just want to make it unable to do anything

submitted by /u/JGN1722
[link] [comments]
hacking: security in practice
Excel Macros works like a Trojan?

Hello everyone,

Tomorrow I have an exam at the university that requires the use of the computer because we need an Excel sheet to do it. However, the teacher in the previous call (as he will do tomorrow) provides us with that Excel sheet with a series of activated Macros. These "Macros" (I didn't know they existed) monitor your computer: they are capable of detecting what you have open on your computer. In fact, some student was caught opening Whatsapp during the exam.

My question is, how have they achieved that with Excel? How is it possible? Is there any way to get around it? Maybe a virtual machine?

I already have that Excel sheet if someone want to see it.

Thank you for the info!!

submitted by /u/melontales
[link] [comments]
hacking: security in practice
How should computer forensics experts catch hackers who use VPN/ TOR to mask their Identities/location?

I am throwing this question open for debate. But I would provide my technical opinion.

There are a few ways I have used in defensive scenarios in the past:

Firstly we see repeated code fragments in different attacks that would be difficult to forge without the original source code,that’s a regular certainty with some failed attacking scenarios.

Secondly I believe seeing the same technical techniques used repeatedly to be a dead giveaway in most cases I come across . For example, there are many way to automatically start a program on Windows right? The particular method chosen by a given attacker group is often unique to them. More like their brand.

We then often see IP addresses and domains reused across attacks this is synonymous to rookies . Sometimes the domains and IPs are different but something about the way they are registered or served tips us off that they're related. Sometimes the attacker forgets to turn on the vpn or in a particular case where an attacker had bad connection and the attacking VPN had no kill switch. It’s rare but extremely valuable.

Often the victim has only a few capable known enemies. Russia, China and Israel have no reason to hack Sony. An attack against an Iranian nuclear facility has just a couple obvious likely attackers. Nobody but China would care to hack Chinese dissidents.

You should be able to track these things over time so that you can link together information across many different attacks to form a clue chain.

Attribution isn't an exact science. Sometimes you can't figure much out details . Sometimes attackers impersonate each other, and probably we sometimes fall for it.

But other times you can clearly tell which group you are looking at.

submitted by /u/Communitybot1
[link] [comments]
hacking: security in practice
I have some new hotspot in my home and I am unable to localize it

I live in eastern Europe and I did notice lately that I see a new WiFi hotspot called "dupa" (ass) in my house. The thing is that I can barely reach my only neighbours Wi-Fi (0-1) but I get this dupa one pretty well (3-5) so I am assuming that it comes somewhere from inside my home (it is 2 floor and over 800square meters). Is there any free tool that I could use to check where does this signal comes from?

submitted by /u/MapedMod
[link] [comments]
Dark Reading: Attacks/Breaches
'Raccoon Stealer' Scurries Back on the Scene After Hiatus

Researchers this week said they had observed criminals using a new and improved version of the prolific malware, barely three months after its authors announced they were quitting.
Dark Reading: Attacks/Breaches
Facebook Business Pages Targeted via Chatbot in Data-Harvesting Campaign

The clever, interactive phishing campaign is a sign of increasingly complex social-engineering attacks, researchers warn.