The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…Continue reading on Medium » (https://medium.com/@nixiebytes/recox-v2-0-classifying-vulnerabilities-in-web-applications-f32f78f4b6e0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recox v2.0 -classifying vulnerabilities in web applications
The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…
Interview with a 16-year-old Lapsus$ Hacker
https://www.reddit.com/r/redteamsec/comments/vx5upk/interview_with_a_16yearold_lapsus_hacker/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=QuPWtMs02tU&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/vx5upk/interview_with_a_16yearold_lapsus_hacker/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vx5upk/interview_with_a_16yearold_lapsus_hacker/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=QuPWtMs02tU&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/vx5upk/interview_with_a_16yearold_lapsus_hacker/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Interview with a 16-year-old Lapsus$ Hacker
Posted in r/redteamsec by u/cybersocdm • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google Hacking
https://cdn-images-1.medium.com/max/1280/1*-OkuBN388He6OTNN11DRCA.jpeg
Apa itu Google Dork?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Google Hacking
https://cdn-images-1.medium.com/max/1280/1*-OkuBN388He6OTNN11DRCA.jpeg
Apa itu Google Dork?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Google Hacking
Apa itu Google Dork?
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
CSRF Vulnerability
https://cdn-images-1.medium.com/max/600/1*hm0jEPQjOQLhgM3rKmw19g.gif
Hello, welcome to my new article, this article will talk about how I found CSRF on the login page.
First, let me introduce myself, my name…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CSRF Vulnerability
https://cdn-images-1.medium.com/max/600/1*hm0jEPQjOQLhgM3rKmw19g.gif
Hello, welcome to my new article, this article will talk about how I found CSRF on the login page.
First, let me introduce myself, my name…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CSRF Vulnerability
Hello, welcome to my new article, this article will talk about how I found CSRF on the login page. First, let me introduce myself, my name…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Internet of Things? | How IoT Works
https://cdn-images-1.medium.com/max/770/0*M1Z80Wz6LEo-d1S-.png
CYBER SECURITY ETHICAL HACKING IOT
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Internet of Things? | How IoT Works
https://cdn-images-1.medium.com/max/770/0*M1Z80Wz6LEo-d1S-.png
CYBER SECURITY ETHICAL HACKING IOT
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Internet of Things? | How IoT Works
CYBER SECURITY ETHICAL HACKING IOT
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Recox v2.0 -classifying vulnerabilities in web applications
https://cdn-images-1.medium.com/max/606/0*BSILmDKmGAUPwZpZ.png
The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Recox v2.0 -classifying vulnerabilities in web applications
https://cdn-images-1.medium.com/max/606/0*BSILmDKmGAUPwZpZ.png
The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recox v2.0 -classifying vulnerabilities in web applications
The script’s goal is to aid in the classification of vulnerabilities in web applications. RecoX, the emerging methodology, can detect…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SpaceX Looks At Starlink’s Expansion In India
https://cdn-images-1.medium.com/max/640/0*eq4_mrCnpKwzc-Q0.png
SpaceX Looks At Starlink’s Expansion In India
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SpaceX Looks At Starlink’s Expansion In India
https://cdn-images-1.medium.com/max/640/0*eq4_mrCnpKwzc-Q0.png
SpaceX Looks At Starlink’s Expansion In India
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SpaceX Looks At Starlink’s Expansion In India
SpaceX Looks At Starlink’s Expansion In India
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Twitch Source Code And Creator Income Exposed In 125GB Leak
https://cdn-images-1.medium.com/max/640/0*jNJjWJ04Ean5i1Sq.png
Twitch Source Code And Creator Income Exposed In 125GB Leak
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Twitch Source Code And Creator Income Exposed In 125GB Leak
https://cdn-images-1.medium.com/max/640/0*jNJjWJ04Ean5i1Sq.png
Twitch Source Code And Creator Income Exposed In 125GB Leak
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Twitch Source Code And Creator Income Exposed In 125GB Leak
Twitch Source Code And Creator Income Exposed In 125GB Leak
hacking: security in practice
What non-fiction books would a typical black hat hacker read ?
I wanna know what all non fiction or to some extent fiction books would a black hat hacker read. I know for sure that Cryptonomicon would be there in the list. what else ?
submitted by /u/dassicity
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What non-fiction books would a typical black hat hacker read ?
I wanna know what all non fiction or to some extent fiction books would a black hat hacker read. I know for sure that Cryptonomicon would be there in the list. what else ?
submitted by /u/dassicity
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What non-fiction books would a typical black hat hacker read ?
I wanna know what all non fiction or to some extent fiction books would a black hat hacker read. I know for sure that Cryptonomicon would be there...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hackers Say They Can Unlock and Start Honda Cars Remotely
Hackers Say They Can Unlock and Start Honda Cars RemotelyPost Views: 11
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Kevin2600, a security researcher, published a technical report and videos on a vulnerability that he claims allows anyone armed with a simple hardware device to steal the code to unlock Honda vehicles.
Hackers could unlock and remotely start virtually all models of Honda cars, according to security researchers. Kevin2600, who works for cybersecurity firm Star-V Lab, dubbed the attack RollingPWN.
“This weakness allows anyone to permanently open the car door or even start the car engine from a long distance,” Kevin2600 wrote in his report. “The Rolling-PWN bug is a serious vulnerability. We found it in a vulnerable version of the rolling codes mechanism, which is implemented in huge amounts of Honda vehicles.”
In a phone call, Kevin2600 explained that the attack relies on a weakness that allows someone using a software defined radio—such as HackRF—to capture the code that the car owner uses to open the car, and then replay it so that the hacker can open the car as well. In some cases, he said, the attack can be performed from 30 meters (approximately 98 feet) away.
In the videos, Kevin2600 and his colleagues show how the attack works by unlocking different models of Honda cars with a device connected to a laptop.
The Honda models that Kevin2600 and his colleagues tested the attack on use a so-called rolling code mechanism, which means that—in theory—every time the car owner uses the keyfob, it sends a different code to open it. This should make it impossible to capture the code and use it again. But the researchers found that there is a flaw that allows them to roll back the codes and reuse old codes to open the car, Kevin2600 said.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png pic.twitter.com/9hziAqMCC2
— Kevin2600 (@Kevin2600) July 7, 2022
The researcher told Motherboard that he and his colleagues went to a Honda dealership to test the attack on different models, and found that 10 of them are vulnerable, which makes them think all Honda models from 2012 to 2022 are vulnerable to this attack.
A Honda spokesperson told Motherboard that the vulnerability found by Kevin2600 is “old news.”
“Thus, I’d hope that you would treat it as such and move on to something current rather than creating a new round of people thinking that this is a ‘new’ thing,” the spokesperson wrote in an email.
The spokesperson was referring to research from earlier this year, which focused on fixed codes, and not rolling codes.
“We’ve looked into past similar allegations and found them to lack substance. While we don’t yet have enough information to determine if this report is credible, the key fobs in the referenced vehicles are equipped with rolling code technology that would not allow the vulnerability as represented in the report. In addition, the videos offered as evidence of the absence of rolling code do not include sufficient evidence to support the claims,” the spokesperson wrote.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo Trending: OSINT Tool: Pagodo These kinds of attacks to unlock cars and other targets are relatively common. Earlier this year, other security researchers found a similar issue with other Honda cars, although in that case the problem was with fixed codes, as opposed to rolling codes. Then in June, researchers demons[...]
___________________________
@hacking_Attack
@Hacking_Video
Hackers Say They Can Unlock and Start Honda Cars Remotely
Hackers Say They Can Unlock and Start Honda Cars RemotelyPost Views: 11
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Kevin2600, a security researcher, published a technical report and videos on a vulnerability that he claims allows anyone armed with a simple hardware device to steal the code to unlock Honda vehicles.
Hackers could unlock and remotely start virtually all models of Honda cars, according to security researchers. Kevin2600, who works for cybersecurity firm Star-V Lab, dubbed the attack RollingPWN.
“This weakness allows anyone to permanently open the car door or even start the car engine from a long distance,” Kevin2600 wrote in his report. “The Rolling-PWN bug is a serious vulnerability. We found it in a vulnerable version of the rolling codes mechanism, which is implemented in huge amounts of Honda vehicles.”
In a phone call, Kevin2600 explained that the attack relies on a weakness that allows someone using a software defined radio—such as HackRF—to capture the code that the car owner uses to open the car, and then replay it so that the hacker can open the car as well. In some cases, he said, the attack can be performed from 30 meters (approximately 98 feet) away.
In the videos, Kevin2600 and his colleagues show how the attack works by unlocking different models of Honda cars with a device connected to a laptop.
The Honda models that Kevin2600 and his colleagues tested the attack on use a so-called rolling code mechanism, which means that—in theory—every time the car owner uses the keyfob, it sends a different code to open it. This should make it impossible to capture the code and use it again. But the researchers found that there is a flaw that allows them to roll back the codes and reuse old codes to open the car, Kevin2600 said.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Solutions-1.png pic.twitter.com/9hziAqMCC2
— Kevin2600 (@Kevin2600) July 7, 2022
The researcher told Motherboard that he and his colleagues went to a Honda dealership to test the attack on different models, and found that 10 of them are vulnerable, which makes them think all Honda models from 2012 to 2022 are vulnerable to this attack.
A Honda spokesperson told Motherboard that the vulnerability found by Kevin2600 is “old news.”
“Thus, I’d hope that you would treat it as such and move on to something current rather than creating a new round of people thinking that this is a ‘new’ thing,” the spokesperson wrote in an email.
The spokesperson was referring to research from earlier this year, which focused on fixed codes, and not rolling codes.
“We’ve looked into past similar allegations and found them to lack substance. While we don’t yet have enough information to determine if this report is credible, the key fobs in the referenced vehicles are equipped with rolling code technology that would not allow the vulnerability as represented in the report. In addition, the videos offered as evidence of the absence of rolling code do not include sufficient evidence to support the claims,” the spokesperson wrote.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo Trending: OSINT Tool: Pagodo These kinds of attacks to unlock cars and other targets are relatively common. Earlier this year, other security researchers found a similar issue with other Honda cars, although in that case the problem was with fixed codes, as opposed to rolling codes. Then in June, researchers demons[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Hackers Say They Can Unlock and Start Honda Cars Remotely | Black Hat Ethical Hacking
Kevin2600, a security researcher, published a technical report and videos on a vulnerability that he claims allows anyone armed with a simple hardware device to steal the code to unlock Honda vehicles.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hackers Say They Can Unlock and Start Honda Cars Remotely Hackers Say They Can Unlock and Start Honda Cars RemotelyPost Views: 11 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/Patreon.png Subscribe…
trated that they were able to unlock Tesla cars with a similar attack. Well-known security researcher Samy Kamkar has made these attacks one of his trademarks, building devices to unlock garage doors and cars.
Kevin2600 wrote that the attack does not leave any traces, so there’s no way to know if anyone has exploited the flaw to open your car. To fix the issue, he wrote, the ideal would be a recall so owners could take the car back to their local dealership, but it’s also possible that the keyfob’s vulnerable firmware could be patched. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers Source: vice.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-90x90.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-90x90.png New stealthy OrBit malware steals data from Linux devices4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-1-90x90.jpg High severity OpenSSL bug could lead to remote code execution5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/hacker-alert-iStock-1330604319-580x358-1-90x90.jpg New RedAlert Ransomware targets Windows, Linux VMware ESXi servers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/django-5-90x90.jpg Django fixes SQL Injection vulnerability in new releases1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-1-90x90.jpg Rogue HackerOne employee steals bug reports to sell on the side1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers worldwide backdoored with new malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-1-90x90.jpg CISA warns of hackers exploiting PwnKit Linux vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/eba5863be05547fb146c9c8c0ed43c52-90x90.jpg Dozens of cryptography libraries vulnerable to private key theft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-90x90.jpg Researchers crack MEGA’s ‘privacy by design’ storage, encryption2 weeks ago
The post Hackers Say They Can Unlock and Start Honda Cars Remotely first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Kevin2600 wrote that the attack does not leave any traces, so there’s no way to know if anyone has exploited the flaw to open your car. To fix the issue, he wrote, the ideal would be a recall so owners could take the car back to their local dealership, but it’s also possible that the keyfob’s vulnerable firmware could be patched. Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers Source: vice.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-90x90.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-90x90.png New stealthy OrBit malware steals data from Linux devices4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-1-90x90.jpg High severity OpenSSL bug could lead to remote code execution5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/hacker-alert-iStock-1330604319-580x358-1-90x90.jpg New RedAlert Ransomware targets Windows, Linux VMware ESXi servers6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/django-5-90x90.jpg Django fixes SQL Injection vulnerability in new releases1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-1-90x90.jpg Rogue HackerOne employee steals bug reports to sell on the side1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-2-90x90.jpg Microsoft Exchange servers worldwide backdoored with new malware2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-1-90x90.jpg CISA warns of hackers exploiting PwnKit Linux vulnerability2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/eba5863be05547fb146c9c8c0ed43c52-90x90.jpg Dozens of cryptography libraries vulnerable to private key theft2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ezgif.com-gif-maker-90x90.jpg Researchers crack MEGA’s ‘privacy by design’ storage, encryption2 weeks ago
The post Hackers Say They Can Unlock and Start Honda Cars Remotely first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Business Logic Vulnerability — REGISTRATION Using Fake Email Account & Valid Company Name
https://medium.com/@Dhamuharker/business-logic-vulnerability-registration-using-fake-email-account-valid-company-name-9e5679115332?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/business-logic-vulnerability-registration-using-fake-email-account-valid-company-name-9e5679115332?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Business Logic Vulnerability — REGISTRATION Using Fake Email Account & Valid Company Name
Description: