Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs
Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsPost Views: 33 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution.
The Azure Site Recovery service is a disaster recovery service that will automatically fail-over workloads to secondary locations when a problem is detected.
As part of the July 2022 Patch Tuesday, Microsoft fixed 84 flaws, with Azure Site Recovery vulnerability accounting for more than a third of the bugs fixed today.
Of the thirty-two vulnerabilities fixed in Azure Site Recovery, two allow remote code execution, and a whopping thirty vulnerabilities allow for elevation of privileges.
In an advisory released today, Microsoft states that SQL injection vulnerabilities caused most of the privilege escalation bugs.
However, Microsoft also highlighted a CVE-2022-33675 vulnerability caused by a DLL hijacking vulnerability discovered by Tenable.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course A DLL hijacking flawThe DLL hijacking flaw is tracked as CVE-2022-33675 and has a CVSS v3 severity rating of 7.8. It was discovered by researchers at Tenable, who disclosed it to Microsoft on April 8, 2022.
DLL hijacking attacks exploit vulnerabilities caused by insecure permission on folders that a Windows OS searches and loads DLLs required when an application is launched.
To perform the attack, a threat actor can create a custom, malicious DLL using the same name as a regular DLL loaded by the Azure Site Recovery application. This malicious DLL is then stored in a folder that Windows searches, causing it to be loaded and executed when the application starts.
According to Tenable, the “cxprocessserver” service of ASR runs with SYSTEM level privileges by default, and its executable lies in a directory that has been incorrectly set to allow ‘write’ permissions to any user.
https://www.bleepstatic.com/images/news/u/1220909/Security/wrong-permissions(1).png
Potential implicationsBy acquiring admin-level privileges on a target system, an attacker would be free to change the OS security settings, make changes to user accounts, access all files on the system without restrictions, and install additional software.
Considering how widely ASR is used in corporate environments that rely on uninterrupted cloud applications and services, it could serve as a crucial weak point [...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs
Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsPost Views: 33 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution.
The Azure Site Recovery service is a disaster recovery service that will automatically fail-over workloads to secondary locations when a problem is detected.
As part of the July 2022 Patch Tuesday, Microsoft fixed 84 flaws, with Azure Site Recovery vulnerability accounting for more than a third of the bugs fixed today.
Of the thirty-two vulnerabilities fixed in Azure Site Recovery, two allow remote code execution, and a whopping thirty vulnerabilities allow for elevation of privileges.
In an advisory released today, Microsoft states that SQL injection vulnerabilities caused most of the privilege escalation bugs.
However, Microsoft also highlighted a CVE-2022-33675 vulnerability caused by a DLL hijacking vulnerability discovered by Tenable.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course A DLL hijacking flawThe DLL hijacking flaw is tracked as CVE-2022-33675 and has a CVSS v3 severity rating of 7.8. It was discovered by researchers at Tenable, who disclosed it to Microsoft on April 8, 2022.
DLL hijacking attacks exploit vulnerabilities caused by insecure permission on folders that a Windows OS searches and loads DLLs required when an application is launched.
To perform the attack, a threat actor can create a custom, malicious DLL using the same name as a regular DLL loaded by the Azure Site Recovery application. This malicious DLL is then stored in a folder that Windows searches, causing it to be loaded and executed when the application starts.
According to Tenable, the “cxprocessserver” service of ASR runs with SYSTEM level privileges by default, and its executable lies in a directory that has been incorrectly set to allow ‘write’ permissions to any user.
https://www.bleepstatic.com/images/news/u/1220909/Security/wrong-permissions(1).png
Potential implicationsBy acquiring admin-level privileges on a target system, an attacker would be free to change the OS security settings, make changes to user accounts, access all files on the system without restrictions, and install additional software.
Considering how widely ASR is used in corporate environments that rely on uninterrupted cloud applications and services, it could serve as a crucial weak point [...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs | Black Hat Ethical Hacking
Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking News – new template post News – new template postPost Views: 31 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode. Reading Time: 3 Minutes Researchers…
attention to the event logs in the campaign isn’t limited to storing shellcodes,” the researchers added. “Dropper modules also patch Windows native API functions, related to event tracing (ETW) and anti-malware scan interface (AMSI), to make the infection process stealthier.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo
Trending: OSINT Tool: Pagodo Unidentified Adversary Delivers Payload of PainUsing this stealthy approach, the attackers can deliver either of their two remote access trojans (RATs), each one a combination of complex, custom code and elements of publicly available software.
In all, with their “ability to inject code into any process using Trojans, the attackers are free to use this feature widely to inject the next modules into Windows system processes or trusted applications.”
Attribution in cyberspace is tricky. The best that analysts can do is dig deep into attackers’ tactics, techniques and procedures (TTPs), and the code they write. If those TTPs or that code overlaps with past campaigns from known actors, it might be the basis for incriminating a suspect.
In this case, the researchers found attribution difficult.
That’s because, beyond the unprecedented technique of injecting shellcode into Windows event logs, there’s one other unique component to this campaign: the code itself. While the droppers are commercially available products, the anti-detection wrappers and RATs they come paired with are custom made (though, the researchers hedged, “some modules which we consider custom, such as wrappers and last stagers, could possibly be parts of commercial products”).
According to the report, “the code is quite unique, with no similarities to known malware.” For that reason, the researchers have yet to determine the identity of the attackers.
“If new modules appear and allow us to connect the activity to some actor we will update the name accordingly.”
Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: threatpost.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-300x150.png New stealthy OrBit malware steals data from Linux devicesJuly 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post News – new template post first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo
Trending: OSINT Tool: Pagodo Unidentified Adversary Delivers Payload of PainUsing this stealthy approach, the attackers can deliver either of their two remote access trojans (RATs), each one a combination of complex, custom code and elements of publicly available software.
In all, with their “ability to inject code into any process using Trojans, the attackers are free to use this feature widely to inject the next modules into Windows system processes or trusted applications.”
Attribution in cyberspace is tricky. The best that analysts can do is dig deep into attackers’ tactics, techniques and procedures (TTPs), and the code they write. If those TTPs or that code overlaps with past campaigns from known actors, it might be the basis for incriminating a suspect.
In this case, the researchers found attribution difficult.
That’s because, beyond the unprecedented technique of injecting shellcode into Windows event logs, there’s one other unique component to this campaign: the code itself. While the droppers are commercially available products, the anti-detection wrappers and RATs they come paired with are custom made (though, the researchers hedged, “some modules which we consider custom, such as wrappers and last stagers, could possibly be parts of commercial products”).
According to the report, “the code is quite unique, with no similarities to known malware.” For that reason, the researchers have yet to determine the identity of the attackers.
“If new modules appear and allow us to connect the activity to some actor we will update the name accordingly.”
Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: threatpost.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-300x150.png New stealthy OrBit malware steals data from Linux devicesJuly 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post News – new template post first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsPost Views: 33 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploa…
in network intrusions.
Tenable highlights the scenario of ransomware attacks where the threat actors could leverage CVE-2022-33675 to wipe backups and make free data restoration impossible. However, this is just one of the many examples.
Microsoft has also published an advisory to provide an overview of all the issues fixed in ASR this month, mentioning SQL injection and remote code execution in the impact section.
For these attacks, administrative credentials on the VMs are required; hence, CVE-2022-33675 can’t be used as a funnel to widen the scope of impact, but it could help lay the ground for acquiring those credentials on the target.
To address all security issues, make sure to apply this month’s updates. Those who can’t apply the patches could mitigate the risk by manually changing the write permission setting on the impacted directory. Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-300x150.png New stealthy OrBit malware steals data from Linux devicesJuly 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Tenable highlights the scenario of ransomware attacks where the threat actors could leverage CVE-2022-33675 to wipe backups and make free data restoration impossible. However, this is just one of the many examples.
Microsoft has also published an advisory to provide an overview of all the issues fixed in ASR this month, mentioning SQL injection and remote code execution in the impact section.
For these attacks, administrative credentials on the VMs are required; hence, CVE-2022-33675 can’t be used as a funnel to widen the scope of impact, but it could help lay the ground for acquiring those credentials on the target.
To address all security issues, make sure to apply this month’s updates. Those who can’t apply the patches could mitigate the risk by manually changing the write permission setting on the impacted directory. Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ban6-Recovered-Recovered-Recovered-300x150.png New stealthy OrBit malware steals data from Linux devicesJuly 8, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
COLIZEUM Bug-Bounty Program
https://medium.com/@colizeum/colizeum-bug-bounty-program-717dc437d3c0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@colizeum/colizeum-bug-bounty-program-717dc437d3c0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
COLIZEUM Bug-Bounty Program
Report a bug and get Whitelisted for Colizeum ELITE NFT sale, this is an opportunity to get hands-on ELITE NFT before anybody else does.
Report a bug and get Whitelisted for Colizeum ELITE NFT sale, this is an opportunity to get hands-on ELITE NFT before anybody else does.Continue reading on Medium » (https://medium.com/@colizeum/colizeum-bug-bounty-program-717dc437d3c0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
COLIZEUM Bug-Bounty Program
Report a bug and get Whitelisted for Colizeum ELITE NFT sale, this is an opportunity to get hands-on ELITE NFT before anybody else does.
COLIZEUM Bug-Bounty Program
Report a bug and get Whitelisted for Colizeum ELITE NFT sale, this is an opportunity to get hands-on ELITE NFT before anybody else does.Continue reading on Medium »
Read more...
Report a bug and get Whitelisted for Colizeum ELITE NFT sale, this is an opportunity to get hands-on ELITE NFT before anybody else does.Continue reading on Medium »
Read more...
Free4All Information Technology and Cyber Security Resources
https://www.reddit.com/r/redteamsec/comments/vxzdut/free4all_information_technology_and_cyber/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/user/cybersocdm/comments/vxtkwt/free4all_information_technology_and_cyber/) [comments] (https://www.reddit.com/r/redteamsec/comments/vxzdut/free4all_information_technology_and_cyber/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/vxzdut/free4all_information_technology_and_cyber/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://www.reddit.com/user/cybersocdm/comments/vxtkwt/free4all_information_technology_and_cyber/) [comments] (https://www.reddit.com/r/redteamsec/comments/vxzdut/free4all_information_technology_and_cyber/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit: Free4All Information Technology and Cyber Security Resources
Posted by cybersocdm - 1 vote and no comments
How to find Origin IP
வணக்கம் மக்களே!!! I’m Boopathi. In this blog, I’m gonna discuss about Origin IPContinue reading on Medium »
Read more...
வணக்கம் மக்களே!!! I’m Boopathi. In this blog, I’m gonna discuss about Origin IPContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to hack IOS/ANDROID and any DAtabase
Even though you have said your marriage vows and promised to love and trust each other till eternity, the fact still remains that you and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to hack IOS/ANDROID and any DAtabase
Even though you have said your marriage vows and promised to love and trust each other till eternity, the fact still remains that you and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to hack IOS/ANDROID and any DAtabase
Even though you have said your marriage vows and promised to love and trust each other till eternity, the fact still remains that you and…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IW Weekly #9: Web3 Hacking, Leveraging Google Dorks, Python Flaws, and more…
https://cdn-images-1.medium.com/max/2000/1*lOAxT5BZxjAjapoJG0na_Q.jpeg
Hey 👋
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
IW Weekly #9: Web3 Hacking, Leveraging Google Dorks, Python Flaws, and more…
https://cdn-images-1.medium.com/max/2000/1*lOAxT5BZxjAjapoJG0na_Q.jpeg
Hey 👋
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
👩🏽💻IW Weekly #9: Web3 Hacking, Leveraging Google Dorks, Python Flaws, and more…
Hey 👋
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The PUBG Mobile 2.1
https://cdn-images-1.medium.com/max/2208/1*Sg9YwDs-k9LmBL1-mGEouQ.jpeg
PUBG MOBILE 2.1 Update Announcement. PUBG MOBILE will begin pushing out the update on July 13 at 11:00 (UTC +0).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The PUBG Mobile 2.1
https://cdn-images-1.medium.com/max/2208/1*Sg9YwDs-k9LmBL1-mGEouQ.jpeg
PUBG MOBILE 2.1 Update Announcement. PUBG MOBILE will begin pushing out the update on July 13 at 11:00 (UTC +0).
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The PUBG Mobile 2.1 update can be downloaded here, including the release date, update size, apk & obb, patch notes, and beta version
PUBG MOBILE 2.1 Update Announcement. PUBG MOBILE will begin pushing out the update on July 13 at 11:00 (UTC +0).
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Reverse engineering a react native app.
In a RN app logics are stored in index,android,bundle (i heard correct me if i am wrong). So I came up with 2/3 apps made with RN. I reached to MYapp.apk -> assets which contained 'android.index.bundle' that was encrypted. I tried npm packages like react-native-decompiler but it threw error mentioning binary encrypted packages can't be decrypted. Am I going wrong somewhere? I checked smali files found nothing. Now how am I supposed to modify it.?
Thanks.
submitted by /u/TemporaryAbrocoma468
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reverse engineering a react native app.
In a RN app logics are stored in index,android,bundle (i heard correct me if i am wrong). So I came up with 2/3 apps made with RN. I reached to MYapp.apk -> assets which contained 'android.index.bundle' that was encrypted. I tried npm packages like react-native-decompiler but it threw error mentioning binary encrypted packages can't be decrypted. Am I going wrong somewhere? I checked smali files found nothing. Now how am I supposed to modify it.?
Thanks.
submitted by /u/TemporaryAbrocoma468
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Reverse engineering a react native app.
Explore this post and more from the hacking community
Bypass-Url-Parser - Tool That Tests Many URL Bypasses To Reach A 40X Protected Page
http://www.kitploit.com/2022/07/bypass-url-parser-tool-that-tests-many.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/07/bypass-url-parser-tool-that-tests-many.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.