Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Telegram Platform Abused in ‘ToxicEye’ Malware CampaignsPost Views: 134
Reading Time: 1 Minute
Hackers are leveraging the popular Telegram messaging app by embedding its code inside a remote access trojan (RAT) dubbed ToxicEye, new research has found.
A victim’s computer infected with the ToxicEye malware is controlled via a hacker-operated Telegram messaging account. The ToxicEye malware can take over file systems, install ransomware and leak data from victim’s PCs, according to researchers at Check Point Software Technologies.
Check Point said it tracked more than 130 cyberattacks in the last three months that leveraged ToxicEye, which was being managed by threat actors over Telegram. Attackers use the messaging service to communicate with their own server and exfiltrate data to it, according to a report published online Thursday.

Hackers are likely have targeted Telegram, which has more than 500 million active users across the world, as their distribution platform because of its widespread use and popularity, said Idan Sharabi, research and development manager at Check Point.

“We believe attackers are leveraging the fact that Telegram is used and allowed in almost all organizations, utilizing this system to perform cyber attacks, which can bypass security restrictions,” he said in an e-mailed statement.
See Also: Mount Locker Ransomware Aggressively Changes Up Tactics
Researcher point out that Telegram—which is known as a secure and private messaging service–has become even more popular during the pandemic and especially in recent months. That’s because of new privacy and data management policies instituted by WhatsApp raising concern among users and pushing them by the millions to alternative messaging platforms like Telegram.

This growing Telegram userbase has led to a corresponding surge by attackers pelting the Telegram platform with a slew of common malware, researchers report. According to Check Point, dozens of “off-the-shelf” malware samples have also been spotted targeting Telegram users.

Researchers said Telegram is an ideal way to obscure such activity because it isn’t blocked by anti-virus protections and allows attackers to remain anonymous, requiring only a mobile phone number to sign up, researchers noted. The app also allows attackers to easily exfiltrate data from victims’ PCs or transfer new malicious files to infected machines because of its communications infrastructure, and to do so remotely from any location in the world, they said. Infection ChainThe Telegram RAT attacks begin with threat actors creating a Telegram account and a dedicated Telegram bot, or remote account that allows them to interact with other users in various ways–including to chat, add people to groups or send requests directly from the input field by typing the bot’s Telegram username and a query.
See Also: Offensive Security Tool: ADFSBrute Attackers then bundle the bot token with the RAT or other chosen malware and spread the malware via email-based spam campaigns as an email attachment. For example, researchers observed attackers spreading malware via a file called “paypal checker by saint.exe,” they said.

Once a victim opens the malicious attachment, it connects to Telegram and leaves the machine vulnerable to a remote attack via the Telegram bot, which uses the messaging service to connect the victim’s device back to that attackers command-and-control server, according to the report. Post-infection attackers gain full control over a victim’s machine and can engage in a range of nef[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Hacking Stories: Xbox Underground

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: Xbox Undergroundhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-8-1-300x120.png Post Views: 184
Reading Time: 6  Minutes
David Pokora, from being an enthusiastic Xbox gamer to be the leader of Xbox-Underground, a gaming hacker group that hacked into gaming companies’ software and even tried to sell their own Xbox One, years before the Xbox One console was even available for selling.
Early years
Long before the Xbox was even released, in 1995, at just 3 years old, David Pokora, was mastering first-person shooter games on his parent’s computer.  He fell in love with gaming and became fascinated with the idea of the “magical” control that he was able to exercise playing video-games.

He was living with his family in Mississauga, a city in Ontario, Canada. He took some coding lessons throughout elementary school, creating basic programs and he was seen as a “born programmer”. Programming captured his attention ten years later during a family trip in a village in Poland. A place without WIFI and little else to do, he started learning Visual Basic (.NET programming). The experience of learning without access to the Internet made him hooked with programming, upon returning to his home he was flawless and ready to learn more.

As David was already diving into the waters of programming, his parents bought him his first Xbox. He spent countless hours playing his favorite game, that was Halo. As time passed, he wanted to learn more about the console, and he managed to find a hacker community who hacked into Xbox, tweaking its functionalities.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/BOH-2-300x225.jpg
David Pokora - Image Credit: wired.com
Microsoft’s “kindergarten security.”
The hackers reverse-engineer the console and sniff data of communication between the processor, RAM, and the flash memory chip.

Cryptography expert, Bruce Schneier, called the discovery “kindergarten security.” Microsoft left the decryption key for booting the machine in the available memory area, this allowed downloading self-made programs on Xbox, making it transfer music, running Linux, and emulating other game consoles like Nintendo, the only necessary thing was to reflash the console.

As soon as he found out what he could do, David started tweaking things to his beloved Halo. He started chatting with hacker communities on IRC, learning things from how to change the physics of the game to fill out landscapes with digitized water or change the blue sky to rain.
The holy grail of Xbox hackers.
In 2005, the second generation of Xbox, Xbox-360, was released without the ridiculous security flaws of the previous version, ending the happy days for hackers who could no longer run code that was not approved by Microsoft. The only workaround at the time was a piece of equipment called the Xbox 360 development kit, known as Dev-kits.

Dev-kits are machines that were used by Microsoft developers to build the Xbox, they looked like regular consoles but they contained inside tools for game development, including debugging tools. This meant that in the hands of a hacker, a dev-kit could be used to manipulate the Xbox’s software and run code like an authorized programmer.

The dev-kits were extremely hard to find, Microsoft was sending them only to verified game development companies. In the mid-2000s some bankrupt companies were dumping the dev-kits in the recycling centers. This is where Rowdy Vav Cleve, a technology manager in California, and member of the hacker group Team Ava[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Telegram Platform Abused in ‘ToxicEye’ Malware CampaignsPost Views: 134…
arious activities, researchers said.

In attacks that Check Point observed, the ToxicEye RAT was used to locate and steal passwords, computer information, browser history and cookies from people’s devices; delete and transfer files or kill PC processes as well as take over a PC’s task manager; deploy a keylogger or record audio and video of the victim’s surroundings as well as steal clipboard contents; and use ransomware to encrypt and decrypt victims’ files. See Also: Hacking Stories: When two young hackers played war games with PentagonIdentification and MitigationCheck Point said indication of infection on PCs is the presence of a file called “rat.exe” located within the directory C:\Users\ToxicEye\rat[.]exe.

Organizations also should monitor the traffic generated from PCs to Telegram accounts when the Telegram app is not installed on the systems in question, researchers said.

Researchers encourage hyper-vigilance when it comes to scrutinizing emails. Recipients need to always check the recipient line of an email that appears suspicious before engaging with it, Check Point said. If there is no recipient named or the recipient is unlisted or undisclosed, this likely indicates the email is a phishing or malicious message. Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-1-4-90x90.png Mount Locker Ransomware Aggressively Changes Up Tactics4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-11-90x90.png Pulse Secure Critical Zero-Day Security Bug Under Active Exploit5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/firefox_patch-90x90.jpg Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Discord-Nitro-e1618858537976-90x90.png NitroRansomware Asks for Discord Gift Codes, Steals Access Tokens7 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Untitled-design-10-90x90.png WordPress could treat Google FloC as a security issue1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Crypto_Mining_Bitcoin-90x90.jpg Attackers Target ProxyLogon Exploit to Install Cryptojacker2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/patchtues1-90x90.jpg Microsoft to Patch multiple Zero-Days, 110 vulnerabilities in total2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-90x90.jpg Chrome Zero-Day Exploit Posted on Twitter2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Clubhouse2-e1618258606781-90x90.png 1.3M Clubhouse Users’ Data Dumped in Hacker Forum for Free2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/linkedin-90x90.png Data from 500M LinkedIn Users Posted for Sale Online2 weeks ago
The post Telegram Platform Abused in ‘ToxicEye’ Malware Campaigns first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Hacking Stories: Xbox Underground https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Hacking Stories: Xbox Undergroundhttps://www.blackhatethicalhacking.com/wp-content/uploads/2020/11/BECOME…
launch found out about a nearby waste recycling center that was selling Xbox DVDs cheaply. Upon purchasing some equipment along with some motherboards, he installed one of the motherboards on his Xbox 360 and he was more than surprised when it booted the machine and the debug mode was activated. He stumbled upon the holy grail for all Xbox hackers.

He then persuaded the manager of the recycling center to purchase all the Xbox equipment from the trash. He stored some of the equipment in his house, sell to some buyers he trusted, and distributed some to his friends.

One of his trusted buyers was the 16 years old then David Pokora, who also help Van Cleve to sell some of the equipment acquired. He was able to make friendships with some of his customers, including a guy named Justin May, who lived in Delaware.

Pokora, as soon as he acquired his dev-kit, started cracking the new Halo 3 for hours every day, while his school grades were degrading, but on his mind, the only education that mattered was programming using the dev-kit.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/EHa1H3VUYAAOWdy.png
Xbox 360 Devkits - Image Credit: old_engineer
He met Anthony Clark in a hackers’ forum, 18 years old hacker, who would be working together with David creating a tool for hacking Halo 3, adding unique abilities to the main character of the game. They received compliments from professional programmers when they posted online their work for Halo 3.

This was just the start of a darker story.
By 2009, they use PartnerNet, (was a test environment for Xbox Live, and the only way to connect to it was via a whitelisted Xbox 360 dev-kit that they already had) to steal unreleased gaming software, including a Halo 3 map which they shared with friends. The next time they hacked to steal software they laughed when they notice a message left from Bungie engineers on the main screen: “Winners Don’t Break Into PartnerNet.” They saw no reason to stop playing with them because in their mind they didn’t do it for the riches but their love for the Xbox.
JTAG hack and the money opportunity
JTAG stands for The Joint Test Action Group, it was an industry body in the 80s that recommended the addition of contacts to all the printed circuit boards. The JTAG hack was named after them because of a weakness in the motherboard of the until then (2009), invulnerable Xbox 360, where a special modchip was able to attach to a secret set of contacts on the motherboard, managing to negate the security of the console.

When the news of the hack broke, many people hurried to get their Xbox JTAGed, but Pokora and Clark thought about the opportunity to earn money from it.
They managed to crack the Call of Duty series and make mods into the game where the players could possess superpowers like flying, running at light speed, etc. They then proceed to create the “mod lobby”, a place on Xbox live where players with JTAGed consoles participated in online deathmatches, etc. They would charge up to 100$ per hour for a single player and then for an extra amount of money they offered the so-called “infections”, in which players could have their “superpower” abilities remain also to the standard games which were not hacked. Microsoft tried to sabotage their efforts by scanning the players’ console for the JTAG hack and then ban them. However, David and Clark found a workaround for this, and for their efforts, they were able to earn thousands of dollars per day. David was enjoying the benefits of his success, he was known as Xenomega in the hacking forums, and he was still living with his parents but spend many nights at luxurious hotels and restaurants with his girlfriend.
Epic Games hack
In 2010, a 14 years old Australian hacker named Dylan Wheeler and his American friend under the nickname Gamefreak managed to get a password list of public forums by Epic Games. Dylan found a password of a personal account of an employee in the IT d[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
launch found out about a nearby waste recycling center that was selling Xbox DVDs cheaply. Upon purchasing some equipment along with some motherboards, he installed one of the motherboards on his Xbox 360 and he was more than surprised when it booted the machine…
epartment of Epic Games. Having established themselves in the Epic network, the two hackers needed extra help. Dylan, who knew David from the forums, ask David to help them to pull down the Halo cards from a half-open network of ParterNet and to crack a secure private network where the company stores its sensitive data, by far the more illegal action David did but his curiosity prevailed and he agreed to help him with some basic rules such as not using any credit card information and not leaking any personal information about Epic customers. https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/BOH-4-300x225.jpg
Dylan Wheeler - Image Credit: wired.com
Due to the huge amount of data they found, they enlisted to their group, another hacker named Sanadodeha “Sonic” Nesheiwat, from New Jersey, who downloaded a copy of Gears of War 3 and a lot of private information of the Video Games that Epic Games was developing and send them to David.

David shared the game with several of his friends, including his distributor, Justin May.

Within days, a copy of the game in the form of torrent appeared in forums. The news about the leaked Gears of War 3 resulted in an FBI investigation who the hacker group found out by reading Epic emails.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/BOH-6-300x225.jpg
Sanadodeh Nesheiwat - Image Credit: wired.com
The investigation though, subsided as the company made no visible effort to block the hackers as it seemed that they couldn’t determine the method of entry and the FBI was unable to find them.

The young hackers continued carelessly to hack into other companies-organization through their access to Epic Games. They hack into Scaleform, a middleware company that was providing technology equipment to Epic Games and then they hack their way into Zombie Studios, developer of Spec Ops games where they found tunnels for remote access to customers and US military companies.

They‘d given to their group the name ‘Xbox Underground’ after a suggestion from Wheeler to instill fear in the people that were trying to find them.
Complications into the hacker group and the newly joined members
David was too absorbed by their access to the forbidden gaming software to listen to any of the advice/warnings that his fellow hackers and friends. They were constantly warning him about being arrested for going too deep but he refused to acknowledge the danger.

He kept stealing preliminary software, including an early copy of Call of Duty: Modern Warfare 3.

David continued hacking and he managed to download a database but he was still proud of how little he cared about making money. In his own words “We could sell them for bitcoins that are not tracked with the right approach. There are fifty thousand lungs.”

In 2010, Justin May got arrested in a Gaming convention in Boston for trying to download gaming software source code. Pokora though trusted Justin, and in 2011, they both made a deal with an Xbox-dev-guy player to sell him some of their stolen pre-released games. Their close relationship caused problems in the hacker group because of the past of Justin, where he got caught in 2010.

In 2012, they added two highly skillful hackers, Austin “AAmonkey” Alcala, a high school student in Indiana, and Nathan “animefre4k” Leroux who lived in Maryland, to help them hack into the Zombie studios network.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/BOH-5-300x225.jpg
Nathan Leroux - Image Credit: wired.com
Pentagon’s Apache Helicopter Simulator and Durango mess
The hacker group stumbled across a tunnel between Zombie studios and a server of the US Army. On the server, they found a simulator for AH-64D Apache helicopter, that Zombie studios were developing under a contract with the Pentagon.

They also managed to steal documents from Microsoft servers for an early version of Durango, the next-generation Xbox, now known as Xbox O[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
epartment of Epic Games. Having established themselves in the Epic network, the two hackers needed extra help. Dylan, who knew David from the forums, ask David to help them to pull down the Halo cards from a half-open network of ParterNet and to crack a secure…
ne. They didn’t sell the documents to a Microsoft competitor, but they assembled and sell copies of the Durango console by using ready-made components and managed to find sellers to sell them to for 5000 dollars. One of the Durango’s never arrived at the customer, this led to a complaint and rumors begun between the members that the FBI took it and was looking for them.
Wheeler then, driven by the glory of becoming the top Xbox hacker, placed a bid auction on eBay for the non-existed console. The bid exceeded 20 thousand dollars before eBay canceled the auction, declaring it fraudulent. Pokora was furious with Wheeler for causing an enormous spike in media attention and broke off his relations with Wheeler.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/duruango-auctioj.jpg
Durango Xbox One Prototype listed on eBay auction - Image Credit: theregister.com
In the next weeks some of the members of the group disappeared without a trace and the rumors about the FBI looking for them along with a suspicion that there was a mole among them, increased the anxiety between the group.
Things got complicated among the group
David focused on Horizon, an Xbox cheat service he created. He split up with Clark because of disagreements in their Call of Duty ‘services’. Clark began then selling virtual currency for FIFA on the black market.

Wheeler after his mess with the eBay auction, continued alone on his way of doing things. At the end of 2012, the FBI raid Santodeha Nesheiwat’s home in New Jersey. He posted the warrant online and Wheeler goes crazy about hiring a hitman to kill the judge who signed the warrant.

After the 2011 leak of Gears of War, the US federal prosecutors started building the case against the hacker group, the leading investigator was Edward McAndrew.
They needed to speed up their actions due to Wheeler’s dangerous behavior, and in February 2013, they raided Wheeler’s home in Perth and took all of his equipment and hard disks, but they didn’t arrest him.

In 2013, Edward McAndrew filed a closed indictment on several counts against Pokora, Neshivevat, and Leroux for crimes like fraud using electronic means, identity fraud, and conspiracy to steal commercial secrets. The case is based on pieces of evidence from an informant, called ‘person A’. According to many sources, the informant named ‘person A’ was Justin May, who didn’t comment when he asked if he was the insider. He was at the time being on a trial for stealing millions of dollars of equipment from Cisco and Microsoft.
The end is near
Without knowing anything about the case, Pokora continued his illegal actions. This time, he cooperated with Alcala, who told him that he knew a guy willing to steal the real prototypes of Durango(Xbox One) from Microsoft campus in Redmond, named Armand. Armand had already taken out one Durango for his personal use a year earlier where he used a cloned RFID card to enter the Microsoft campus.
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/microsoft-headquarters.jpg
Microsoft Headquarters in Redmond - Image Credit: https://commons.wikimedia.org/wiki/User:Coolcaesar
In September of 2013, Armand passed into the building where the Durango prototypes were stored and after a thrilling couple of hours, he managed to squeeze two consoles into his backpack. He then sent the stolen consoles to Pokora and Alcala. A couple of weeks later Armand was hired by Microsoft for a position in the quality assurance department. It took no long before he was identified by investigators from a camera outside the campus of Microsoft as he was seen leaving the building the day where the consoles were stolen.

Until the end of 2013, Pokora was hacking Xbox 360 games for his cheat engine Horizon.

In March 2014, David needed a new bumper for his car but the seller wasn’t shipping to Canada so he agreed to meet his friend Justin May in Delaware, Wilmington, where Justin lived. He visite[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
In Appreciation: Dan Kaminsky

Beloved security industry leader and researcher passes away unexpectedly at the age of 42.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Prank my friends bluetooth speaker

Hey there just looking for help on a prank. My roommate has a bluetooth speaker and I'd like to interrupt his music with something nsfw while he's playing. Is there any way to do that?

If this doesn't belong in this sub, do you know which one it does belong in?

submitted by /u/humidifi
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Forwarded from Torrent Leaks
Course Club
[Coursera] Deep Learning Specialization

https://courseclub.me/wp-content/uploads/2021/04/4478514141.jpg
https://courseclub.me/wp-content/uploads/2021/04/4478514141-1024x1024.jpg
Neural Networks and Deep Learning, name of the training video series in the field of data and machine learning can be. These days, one of the educational topics, popular topics, learn deep or the same Deep Learning can be. This period, in fact, part of this knowledge. You in this course with learning the basics, and the basics of neural networks and deep learning with the concept of artificial intelligence, will be familiar. At the end of this course you can get systems with artificial intelligence high will implement and bring it to the stage run drive.

Also in this period tried so well, the concept and the performance of deep learning to pass on to you crafted. This course also can help you in finding an ideal job would also help. You with learning content and training available in this course for your career opportunities to well-prepared you will be. Finally, and with view all sessions and tutorials of this course, you can knowledge deep learning in development programs data use.

Cases in which the course is taught:

* Dating principles with the basics of the topic deep learning
* Learn how to build neural networks and use it
* Improve programming skills in Python language
* Familiarity with how to implement neural networks efficiently
* Understand the key parameters in the architecture of a neural network
* And…

Profile courses :

* Publisher : Coursera
* Language : English
* Duration Time : 80hours
* Number of courses: 184
* Instructor : Andrew Ng
* File format : mp4

This course Neural Networks and Deep Learning

Introduction to deep learning
7 videos (Total 76 min), 2 readings, 1 quiz

Neural Networks Basics
19 videos (Total 161 min), 6 readings, 3 quizzes

Shallow neural networks
12 videos (Total 109 min), 2 readings, 2 quizzes

Deep Neural Networks
8 videos (Total 64 min), 3 readings, 3 quizzes

Size: 3.22 GB

Download Now

https://www.coursera.org/specializations/deep-learning.

The post [Coursera] Deep Learning Specialization appeared first on Course Club.
Forwarded from Torrent Leaks
Free Course Site
NestJS Zero to Hero – Modern TypeScript Back-end Development

https://freecoursesite.com/wp-content/uploads/2019/07/2053219_e620_2.jpg
Develop and deploy enterprise back-end applications following best practices using Node.js and TypeScript What you’ll learn Becoming familiar with the NestJS framework and its components Designing and developing REST APIs performing CRUD operations Authentication and Authorization for back-end applications Using TypeORM for database interaction Security best practices, password hashing and storing sensitive information Persisting data […]

The post NestJS Zero to Hero – Modern TypeScript Back-end Development appeared first on Free Course Site.
Forwarded from Torrent Leaks
Free Course Site
gRPC [Golang] Master Class: Build Modern API & Microservices

https://freecoursesite.com/wp-content/uploads/2021/04/561230122.jpg
Better than REST API! Build a fast scalable HTTP/2 API for a Golang micro service with gRPC, Protocol Buffers (protobuf) What you’ll learn Learn the gRPC theory to understand how gRPC works Compare gRPC and REST API paradigm Write your gRPC service definition in .proto files Generate Server & Client Code in Golang using the […]

The post gRPC [Golang] Master Class: Build Modern API & Microservices appeared first on Free Course Site.