Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
You Better Watch Out: Your iPhone Can Get A Virus From Safari
https://cdn-images-1.medium.com/max/1024/0*v1zPqs-WW7i6LGRn.jpg
It’s possible that you’ve heard that an iPhone cannot get a virus, but this is untrue and the result of former deceptive marketing by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
You Better Watch Out: Your iPhone Can Get A Virus From Safari
https://cdn-images-1.medium.com/max/1024/0*v1zPqs-WW7i6LGRn.jpg
It’s possible that you’ve heard that an iPhone cannot get a virus, but this is untrue and the result of former deceptive marketing by…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
You Better Watch Out: Your iPhone Can Get A Virus From Safari
It’s possible that you’ve heard that an iPhone cannot get a virus, but this is untrue and the result of former deceptive marketing by…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nyx: 1 Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/600/1*VyNdLDII-OmH78ztM4w3VQ.png
Hey folks, Ashish this side. Today we are going to crack this vulnerable machine called Nyx: 1. It is created by 0xatom. This is a Capture…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nyx: 1 Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/600/1*VyNdLDII-OmH78ztM4w3VQ.png
Hey folks, Ashish this side. Today we are going to crack this vulnerable machine called Nyx: 1. It is created by 0xatom. This is a Capture…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nyx: 1 Vulnhub Walkthrough
Hey folks, Ashish this side. Today we are going to crack this vulnerable machine called Nyx: 1. It is created by 0xatom. This is a Capture…
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Athena OS - Dive into a new PentOS
https://external-preview.redd.it/FjQ1fWePz7OCBSNMYvihMAmAoqxZ4Q5OJpXxCiUan04.jpg?width=640&crop=smart&auto=webp&s=5d26ffaebce689f25fb2b13459bbe7dc143928c3 submitted by /u/D3vil0p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Athena OS - Dive into a new PentOS
https://external-preview.redd.it/FjQ1fWePz7OCBSNMYvihMAmAoqxZ4Q5OJpXxCiUan04.jpg?width=640&crop=smart&auto=webp&s=5d26ffaebce689f25fb2b13459bbe7dc143928c3 submitted by /u/D3vil0p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Athena OS - Dive into a new PentOS
Posted in r/hacking by u/D3vil0p • 1 point and 0 comments
hacking: security in practice
How to find online friend's real name
I think my friend killed himself, and I really need to find his exact apartment number and real name so I can call the police to do a well-fare check on him. I have his snapchat and discord, but that's it. Does anyone know how I can find it? Thanks
submitted by /u/1llum1nat1onn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to find online friend's real name
I think my friend killed himself, and I really need to find his exact apartment number and real name so I can call the police to do a well-fare check on him. I have his snapchat and discord, but that's it. Does anyone know how I can find it? Thanks
submitted by /u/1llum1nat1onn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to find online friend's real name
I think my friend killed himself, and I really need to find his exact apartment number and real name so I can call the police to do a well-fare...
The beginning of my future...
https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/
Hello reddit! Now I am 16 years old and in the future I want to become a "hacker" - pentester, because I see this world in the next 100 years as closely connected with information activities, at the moment I am starting this path with learning Python and I am serious about it. I would like you to help me with your advice and guidance. I would be grateful if there is a person who is already in this field and will become for me a kind of teacher who will help me along the way. Thank you all, good vibes! And forgive me for my English - it's not my native language, good luck! :) submitted by /u/Lqont (https://www.reddit.com/user/Lqont)
[link] (https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/) [comments] (https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/
Hello reddit! Now I am 16 years old and in the future I want to become a "hacker" - pentester, because I see this world in the next 100 years as closely connected with information activities, at the moment I am starting this path with learning Python and I am serious about it. I would like you to help me with your advice and guidance. I would be grateful if there is a person who is already in this field and will become for me a kind of teacher who will help me along the way. Thank you all, good vibes! And forgive me for my English - it's not my native language, good luck! :) submitted by /u/Lqont (https://www.reddit.com/user/Lqont)
[link] (https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/) [comments] (https://www.reddit.com/r/Pentesting/comments/vyqwp7/the_beginning_of_my_future/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
The beginning of my future...
Hello reddit! Now I am 16 years old and in the future I want to become a "hacker" - pentester, because I see this world in the next 100 years as...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft releases tweet-size exploit for macOS sandbox escape bug
Microsoft releases tweet-size exploit for macOS sandbox escape bugPost Views: 22 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Microsoft has published the exploit code for a vulnerability in macOS that could help an attacker bypass sandbox restrictions and run code on the system.
The company released the technical details for the security issue, which is currently identified as CVE-2022-26706, and explained how the macOS App Sandbox rules could be avoided to allow malicious macro code in Word documents to execute commands on the machine.
Abusing macros in Office documents to deploy malware has long been an efficient and popular technique to compromise Windows systems.
The same could be achieved on macOS machines lacking the proper security updates, Microsoft warns in a report today.
“Despite the security restrictions imposed by the App Sandbox’s rules on applications, it’s possible for attackers to bypass the said rules and let malicious codes “escape” the sandbox and execute arbitrary commands on an affected device” – Microsoft
Jonathan Bar Or of the Microsoft 365 Defender Research Team explains that the vulnerability was discovered while looking into methods to run and detect malicious macros in Microsoft Office documents on macOS.
To ensure backward compatibility, Microsoft Word can read and write files that come with the prefix “~$,” which is defined in the app’s sandbox rules.
https://www.bleepstatic.com/images/news/u/1100723/2022/MSWord-sandbox-rule.png
Exploit code in a tweetAfter studying older reports [1, 2] about escaping the macOS sandbox, the researchers found that using Launch Services to run an open –stdin command on a special Python file with the abovementioned prefix allows escaping the App Sandbox on macOS, potentially leading to compromising the system.
The researchers came up with a proof-of-concept (PoC) that used the -stdin option for the open Command on a Python file to bypass the “com.apple.quarantine” extended attribute restriction.
The demo exploit code is as simple as dropping a Python file that contains arbitrary commands and has in its name the special prefix for Word.
Using the open -stdin command starts the Python app with the specially crafted file as the standard input.
“Python happily runs our code, and since it’s a child process of launchd, it isn’t bound to Word’s sandbox rules,” Jonathan Or Bar explains.
https://www.bleepstatic.com/images/news/u/1100723/2022/macOS_SBX_Microsoft.png
___________________________
@hacking_Attack
@Hacking_Video
Microsoft releases tweet-size exploit for macOS sandbox escape bug
Microsoft releases tweet-size exploit for macOS sandbox escape bugPost Views: 22 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
Microsoft has published the exploit code for a vulnerability in macOS that could help an attacker bypass sandbox restrictions and run code on the system.
The company released the technical details for the security issue, which is currently identified as CVE-2022-26706, and explained how the macOS App Sandbox rules could be avoided to allow malicious macro code in Word documents to execute commands on the machine.
Abusing macros in Office documents to deploy malware has long been an efficient and popular technique to compromise Windows systems.
The same could be achieved on macOS machines lacking the proper security updates, Microsoft warns in a report today.
“Despite the security restrictions imposed by the App Sandbox’s rules on applications, it’s possible for attackers to bypass the said rules and let malicious codes “escape” the sandbox and execute arbitrary commands on an affected device” – Microsoft
Jonathan Bar Or of the Microsoft 365 Defender Research Team explains that the vulnerability was discovered while looking into methods to run and detect malicious macros in Microsoft Office documents on macOS.
To ensure backward compatibility, Microsoft Word can read and write files that come with the prefix “~$,” which is defined in the app’s sandbox rules.
https://www.bleepstatic.com/images/news/u/1100723/2022/MSWord-sandbox-rule.png
Exploit code in a tweetAfter studying older reports [1, 2] about escaping the macOS sandbox, the researchers found that using Launch Services to run an open –stdin command on a special Python file with the abovementioned prefix allows escaping the App Sandbox on macOS, potentially leading to compromising the system.
The researchers came up with a proof-of-concept (PoC) that used the -stdin option for the open Command on a Python file to bypass the “com.apple.quarantine” extended attribute restriction.
The demo exploit code is as simple as dropping a Python file that contains arbitrary commands and has in its name the special prefix for Word.
Using the open -stdin command starts the Python app with the specially crafted file as the standard input.
“Python happily runs our code, and since it’s a child process of launchd, it isn’t bound to Word’s sandbox rules,” Jonathan Or Bar explains.
https://www.bleepstatic.com/images/news/u/1100723/2022/macOS_SBX_Microsoft.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft releases tweet-size exploit for macOS sandbox escape bug | Black Hat Ethical Hacking
Microsoft has published the exploit code for a vulnerability in macOS that could help an attacker bypass sandbox restrictions and run code on the system.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft releases tweet-size exploit for macOS sandbox escape bug Microsoft releases tweet-size exploit for macOS sandbox escape bugPost Views: 22 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png…
s about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft releases tweet-size exploit for macOS sandbox escape bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/ezgif.com-gif-maker-3-300x150.jpg Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie InfinityJuly 11, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft releases tweet-size exploit for macOS sandbox escape bug first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Recon em ASN’s
Esse artigo visa demonstrar de forma básica o recon em ASN’s. Antes de entrarmos no assunto de recon em ASN’s, é preciso falar de alguns…Continue reading on Medium »
Read more...
Esse artigo visa demonstrar de forma básica o recon em ASN’s. Antes de entrarmos no assunto de recon em ASN’s, é preciso falar de alguns…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking for Beginners: Exploiting Open Ports
https://cdn-images-1.medium.com/max/800/1*VwwDGO4M5CWwiHtoErArMw.jpeg
So, last time I walked through a very simple execution of getting inside an office camera using a few scripts and an open RTSP port. This…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking for Beginners: Exploiting Open Ports
https://cdn-images-1.medium.com/max/800/1*VwwDGO4M5CWwiHtoErArMw.jpeg
So, last time I walked through a very simple execution of getting inside an office camera using a few scripts and an open RTSP port. This…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking for Beginners: Exploiting Open Ports
So, last time I walked through a very simple execution of getting inside an office camera using a few scripts and an open RTSP port. This…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bandit lvl 0
https://cdn-images-1.medium.com/max/1700/1*ZDFbmDzQm1MoOfeTWUEKPw.jpeg
Hi ,Today goona solve bandit level0 CTF
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bandit lvl 0
https://cdn-images-1.medium.com/max/1700/1*ZDFbmDzQm1MoOfeTWUEKPw.jpeg
Hi ,Today goona solve bandit level0 CTF
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bandit lvl 0
Hi ,Today goona solve bandit level0 CTF
KitPloit - PenTest Tools!
Trufflehog - Find Credentials All Over The Place
___________________________
@hacking_Attack
@Hacking_Video
Trufflehog - Find Credentials All Over The Place
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Trufflehog - Find Credentials All Over The Place
hacking: security in practice
Blocked webs by isp
my isp has blocked many webs. tried changing DNS on my PC but it still doesn't open those websites. VPN does work but I am looking for a more permanent method.
submitted by /u/Cpt_Soaps
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Blocked webs by isp
my isp has blocked many webs. tried changing DNS on my PC but it still doesn't open those websites. VPN does work but I am looking for a more permanent method.
submitted by /u/Cpt_Soaps
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Blocked webs by isp
my isp has blocked many webs. tried changing DNS on my PC but it still doesn't open those websites. VPN does work but I am looking for a more...
hacking: security in practice
does anyone know how to get bypass or get rid of a password of a winrar archive?
my friend forgot his winrar password and he got important files in that file, could you give me some ideas? i found a program with a algorithm that is taking too long.
submitted by /u/marius0023
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
does anyone know how to get bypass or get rid of a password of a winrar archive?
my friend forgot his winrar password and he got important files in that file, could you give me some ideas? i found a program with a algorithm that is taking too long.
submitted by /u/marius0023
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
https://external-preview.redd.it/poXaw3rnXeTd3k_pEuaH6mW-aZZy3twVPc712N-CnfI.jpg?width=640&crop=smart&auto=webp&s=d48f47c1da7138b6e526e8c7449964b3acd6cdbe Long story short: I got scammed on Kleinanzeigen (basically German Craigslist) and would love to find out where that guy lives. All I've got are his bank account info, mobile phone number and the ad on Kleinanzeigen: +49 177 9338770, https://www.ebay-kleinanzeigen.de/s-anzeige/gebrauchter-festool-domino-xl-700-eq-super-maschine-/2139889221-282-71
https://preview.redd.it/vknofgmh4jb91.jpg?width=2736&format=pjpg&auto=webp&s=898d65e504999b8f70f0a2fc891d6a9a16b410d6
If someone could do something with this information, then I would highly appreciate it :) Best regards,
--Papa Flammy
submitted by /u/FlammysWood
[link] [comments]
https://preview.redd.it/vknofgmh4jb91.jpg?width=2736&format=pjpg&auto=webp&s=898d65e504999b8f70f0a2fc891d6a9a16b410d6
If someone could do something with this information, then I would highly appreciate it :) Best regards,
--Papa Flammy
submitted by /u/FlammysWood
[link] [comments]