hacking: security in practice
Would like to learn about malware and how it is implemented
I'm just about completely new to hacking/cybersecurity- related affairs and would like to learn about malware, mainly Trojan horses and specifically those that plant cryptocurrency miners or perhaps ransomware. How do these work, where can they be found, how are they implemented and is it legal to possess them? If possible, please explain in simple terms.
P.S.: I feel like I should add that this is just for fun and to satisfy my curiosity, not for malicious or criminal reasons
Thank you for your help!
submitted by /u/Antique__throwaway
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Would like to learn about malware and how it is implemented
I'm just about completely new to hacking/cybersecurity- related affairs and would like to learn about malware, mainly Trojan horses and specifically those that plant cryptocurrency miners or perhaps ransomware. How do these work, where can they be found, how are they implemented and is it legal to possess them? If possible, please explain in simple terms.
P.S.: I feel like I should add that this is just for fun and to satisfy my curiosity, not for malicious or criminal reasons
Thank you for your help!
submitted by /u/Antique__throwaway
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Would like to learn about malware and how it is implemented
I'm just about completely new to hacking/cybersecurity- related affairs and would like to learn about malware, mainly Trojan horses and ...
Vishing tools suggestions?
https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/
submitted by /u/Mindless-Study1898 (https://www.reddit.com/user/Mindless-Study1898)
[link] (https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/
submitted by /u/Mindless-Study1898 (https://www.reddit.com/user/Mindless-Study1898)
[link] (https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4sa7f/vishing_tools_suggestions/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Vishing tools suggestions?
Posted in r/Pentesting by u/Mindless-Study1898 • 1 point and 0 comments
Free range internal pen testing
https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/
My boss told me that he wants to see what a hacker could potentially do to our network in a real setup. Basically said he'd like me to use my workstation, regular user account and try to own the network. I am not experienced pen tester (he's aware). As long as I don't shut systems down or cause negative impacts I should be fine. My OS is windows 10. Installing software is pretty restricted through AD & carbon black policies. Where would you start in my position and what would you do next? NOTE: my boss and I both know the best option is to hire an experienced pen tester. That's not in doubt here. Edit: I am security analyst and have been learning pen testing foundations for some time now. Practicing with tryhackme and vulnerable VMs. submitted by /u/AccomplishedRush4869 (https://www.reddit.com/user/AccomplishedRush4869)
[link] (https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/
My boss told me that he wants to see what a hacker could potentially do to our network in a real setup. Basically said he'd like me to use my workstation, regular user account and try to own the network. I am not experienced pen tester (he's aware). As long as I don't shut systems down or cause negative impacts I should be fine. My OS is windows 10. Installing software is pretty restricted through AD & carbon black policies. Where would you start in my position and what would you do next? NOTE: my boss and I both know the best option is to hire an experienced pen tester. That's not in doubt here. Edit: I am security analyst and have been learning pen testing foundations for some time now. Practicing with tryhackme and vulnerable VMs. submitted by /u/AccomplishedRush4869 (https://www.reddit.com/user/AccomplishedRush4869)
[link] (https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4szyj/free_range_internal_pen_testing/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Free range internal pen testing
My boss told me that he wants to see what a hacker could potentially do to our network in a real setup. Basically said he'd like me to use my...
What certifications do you need to become a pen tester?
https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/
Let’s say if someone wants to become a pen tester, can they become one if they have there OSCP certificate, and if they practice the hack the box academy/try hack me/ Virtual Hacking Labs exercises for 3 to 6 months?What other certifications do you need to become a pen tester? What are the stages of pen testing? And can someone become a pen tester if they have ADHD? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/
Let’s say if someone wants to become a pen tester, can they become one if they have there OSCP certificate, and if they practice the hack the box academy/try hack me/ Virtual Hacking Labs exercises for 3 to 6 months?What other certifications do you need to become a pen tester? What are the stages of pen testing? And can someone become a pen tester if they have ADHD? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/) [comments] (https://www.reddit.com/r/Pentesting/comments/w4uvtt/what_certifications_do_you_need_to_become_a_pen/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What certifications do you need to become a pen tester?
Let’s say if someone wants to become a pen tester, can they become one if they have there OSCP certificate, and if they practice the hack the box...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
c4ptur3-th3-fl4g TryHackMe WriteUp
https://cdn-images-1.medium.com/max/1080/0*UOwrc-40wuIsT_YL.png
1. c4n y0u c4p7u23 7h3 f149?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
c4ptur3-th3-fl4g TryHackMe WriteUp
https://cdn-images-1.medium.com/max/1080/0*UOwrc-40wuIsT_YL.png
1. c4n y0u c4p7u23 7h3 f149?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
c4ptur3-th3-fl4g TryHackMe WriteUp
1. c4n y0u c4p7u23 7h3 f149?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cómo funciona Google Authenticator y TOTP
https://cdn-images-1.medium.com/max/1675/0*Rnbb6E2r45hA0eJh
PUBLICADO EN 21 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cómo funciona Google Authenticator y TOTP
https://cdn-images-1.medium.com/max/1675/0*Rnbb6E2r45hA0eJh
PUBLICADO EN 21 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cómo funciona Google Authenticator y TOTP
PUBLICADO EN 21 JULIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Real Impact of Hackers on a Business
https://cdn-images-1.medium.com/max/768/0*nraBHnNyCSVqwptY
By ThriveDX Staff Writer
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Real Impact of Hackers on a Business
https://cdn-images-1.medium.com/max/768/0*nraBHnNyCSVqwptY
By ThriveDX Staff Writer
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Real Impact of Hackers on a Business
By ThriveDX Staff Writer
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Malicious Hackers Can Takeover Your Headless Browser: Part 1
https://cdn-images-1.medium.com/max/1290/1*3SoanURVKV7MovFOY1kTZw.png
Examining Headless Browser + Server-Side Request Forgery (SSRF) in Hack The Box Web Challenge: AbuseHumanDB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Malicious Hackers Can Takeover Your Headless Browser: Part 1
https://cdn-images-1.medium.com/max/1290/1*3SoanURVKV7MovFOY1kTZw.png
Examining Headless Browser + Server-Side Request Forgery (SSRF) in Hack The Box Web Challenge: AbuseHumanDB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Malicious Hackers Can Takeover Your Headless Browser: Part 1
Examining Headless Browser + Server-Side Request Forgery (SSRF) in Hack The Box Web Challenge: AbuseHumanDB
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
DASDEC Cross Site Scripting / HTML Injection
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
The Monroe Electronics / Digital Alert Systems OneNet SE DASDEC Emergency Alert System Appliance suffers from cross site scripting and html injection vulnerabilities.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
DASDEC Cross Site Scripting / HTML Injection
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
The Monroe Electronics / Digital Alert Systems OneNet SE DASDEC Emergency Alert System Appliance suffers from cross site scripting and html injection vulnerabilities.
SHA-256 |
82f6d98418853066b6a98235aa9b2f3a0913d729dcbf7cc7b1e70d395b6a8badDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
DASDEC Cross Site Scripting / HTML Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Dr. Fone 4.0.8 Unquoted Service Path
https://4.bp.blogspot.com/-xJ4j9VfFswY/WWlvOf_vUlI/AAAAAAAAIMo/D1-kp_Mj10E1aNmsGMS5n6nKC28DofOXwCLcBGAs/s1600/h25.png
Dr. Fone version 4.0.8 suffers from an unquoted service path vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Dr. Fone 4.0.8 Unquoted Service Path
https://4.bp.blogspot.com/-xJ4j9VfFswY/WWlvOf_vUlI/AAAAAAAAIMo/D1-kp_Mj10E1aNmsGMS5n6nKC28DofOXwCLcBGAs/s1600/h25.png
Dr. Fone version 4.0.8 suffers from an unquoted service path vulnerability.
SHA-256 |
a395c8c5023e9fa3ade5d03f2adda3d54bb86b40825eb131695b52008175f74aDownload
# Exploit Title: Dr. Fone v4.0.8- 'net_updater32.exe' Unquoted Service Path
# Discovery Date: 2022-05-07
# Discovery by: Esant1490
# Vendor Homepage: https://drfone.wondershare.net
# Software Link : https://download.wondershare.net/drfone_full4008.exe
# Tested Version: 4.0.8
# Tested on OS: Windows 10 Pro x64 en
# Vulnerability Type: Unquoted Service Path
# Find the discover Unquoted Service Path Vulnerability:
C:\>wmic service get name,displayname,pathname,startmode |findstr /i "auto"
|findstr /i /v "C:\Windows\\" |findstr /i /v """
Wondershare Install Assist Service Wondershare InstallAssist
C:\ProgramData\Wondershare\Service\InstallAssistService.exe Auto
Wondershare Application Framework Service WsAppService C:\Program Files
(x86)\Wondershare\WAF\2.4.3.243\WsAppService.exe Auto
Wondershare Application Update Service 3.0
WsAppService3 C:\Program Files
(x86)\Wondershare\WAF3\3.0.0.308\WsAppService3.exe Auto
Wondershare Driver Install Service WsDrvInst C:\Program Files
(x86)\Wondershare\drfone\Addins\Unlock\DriverInstall.exe Auto
# Service info:
C:\>sc qc WsDrvInst
[SC] QueryServiceConfig CORRECTO
NOMBRE_SERVICIO: WsDrvInst
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files
(x86)\Wondershare\drfone\Addins\Unlock\DriverInstall.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Wondershare Driver Install Service
DEPENDENCIAS : RPCSS
NOMBRE_INICIO_SERVICIO: LocalSystem
#Exploit:
A successful attempt to exploit this vulnerability could allow to execute
code during startup or reboot with the elevated privileges.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Dr. Fone 4.0.8 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.