Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Dropper.Win32.Dycler.vrp Insecure Permissions

https://3.bp.blogspot.com/-WgHI0tg_gBA/WWlu6qiRwXI/AAAAAAAAIJQ/y7F9DyJjlcsOiH2i6j2FGMtA3ctyoL26QCLcBGAs/s1600/h109.png
Trojan-Dropper.Win32.Dycler.vrp malware suffers from an insecure permissions vulnerability.

MD5 | 9975cb2e3f2abc05550a8482fa39a28d

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/1d6d6d3c077250b7b3ad053e71054ecc.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan-Dropper.Win32.Dycler.vrp
Vulnerability: Insecure Permissions
Description: The malware creates an insecure dir named "Drivers" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 1d6d6d3c077250b7b3ad053e71054ecc
Vuln ID: MVID-2021-0186
Dropped files: dlhost.exe, hgo.bat
Disclosure: 04/27/2021
Exploit/PoC:
C:\>cacls Drivers
C:\Drivers BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\Drivers>attrib -s -h symbols

C:\Drivers>dir symbols
Volume in drive C has no label.F

Directory of C:\Drivers\symbols

10/13/2011 09:50 AM 1,710,592 dlhost.exe
10/13/2011 09:52 AM 79 hgo.bat
04/26/2021 08:36 PM Microsoft.VC90.CRT
2 File(s) 1,710,671 bytes
3 Dir(s) 6,918,037,504 bytes free
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Dropper.Win32.Injector.aobl Insecure Permissions

https://3.bp.blogspot.com/-D44pcoGQpVY/WWlvlv4DR7I/AAAAAAAAIRA/cd0U1aMX9aAjFzK0BP_4B5_C_6s8ROTKQCLcBGAs/s1600/h99.png
Trojan-Dropper.Win32.Injector.aobl malware suffers from an insecure permissions vulnerability.

MD5 | 31ca6fb7c8e15e51ac9b37dec47ac47c

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/842f6f21a2a83792e98900df90c9340b.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan-Dropper.Win32.Injector.aobl
Vulnerability: Insecure Permissions
Description: The malware creates a insecure dir named "winholder" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 842f6f21a2a83792e98900df90c9340b
Vuln ID: MVID-2021-0187
Dropped files: 8A4A89B415C.exe
Disclosure: 04/27/2021

Exploit/PoC:
C:\>cacls winholder
C:\winholder BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F
BUILTIN\Users:(OI)(CI)(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
C:\>dir winholder
Volume in drive C has no label.

Directory of C:\winholder

02/10/2018 01:21 AM 3,485,392 8A4A89B415C.exe
1 File(s) 3,485,392 bytes
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
prevent/detect IMSI-catcher?

How to detect a "Stingray Device" - IMSI-catcher? I do not have an android phone, those apps do not apply. I'm certain the tech is being used on me for corp espionage, how to detect and prevent it?



If you shut down the thread please send msg me explaining why.

submitted by /u/Stonk-tronaut
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
I got scammed, can anything be done :(

I know this is a very big stretch, but I got scammed off 70 USD on a cashapp transaction (I was asking for help to transfer it to my PayPal). This money was quite hard earned, I’m going to college and this lowlife decided to steal this off me. He is on Reddit. more information will be posted on request. If anyone can help I’d be very grateful. I know it’s not like how it is in the movies where you click a couple keys and say “done” and all, but if any progress can be made, god bless your soul.

submitted by /u/filhazz
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Wifi security

Ok so there is this guy in my neighborhood who keeps cracking my wifi password and getting into my windows 10 laptop through the wifi

The first time He exposed himself and told me he was just messing around

After that i learned how to tell if there is someone who has access to my laptop through nmap and task manager

So this is the third time i cought him in my wifi and my laptop

So my question is how can i prevent him from entering my wifi !? Other than mac filter and strong password I use wpa2-psk my router doesn't support wpa3 .

submitted by /u/vipyaser
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Reproxy : Simple Edge Server / Reverse Proxy

Reproxy is a simple edge HTTP(s) server / reverse proxy supporting various providers (docker, static, file). One or more providers supply information about the requested server, requested URL, destination URL, and health check URL. It is distributed as a single binary or as a docker container. Automatic SSL termination with Let’s Encrypt Support of user-provided SSL […]

The post Reproxy : Simple Edge Server / Reverse Proxy appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
BetterXencrypt : A Better Version Of Xencrypt

BetterXencrypt is a better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs. cause Xencrypt is not FUD anymore and easily get caught by AMSI,i recode the stub and now it FUD again. And the original Xencrypt,if you see on the screenshot proof,he’s tested on Windows 8,and if i test […]

The post BetterXencrypt : A Better Version Of Xencrypt appeared first on Kali Linux Tutorials.

___________________________
@hacking_Attack
@Hacking_Video