Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
27 ways to learn ethical hacking for free:

1. Root Me — Challenges. 2. Stök’s YouTube — Videos. 3. Hacker101 Videos — Videos. 4. InsiderPhD YouTube — Videos. 5. EchoCTF —…Continue reading on Medium »
Read more...
Proper communication in cybersecurity is essential.

1. Malware Analysis involves writing reports. 2. Access Management involves writing reports. 3. Bug Bounty Hunting involves writing…Continue reading on Medium »
Read more...
hacking: security in practice
GoPhish Sender Profile Alternative

Is there any usable alternative for creating a sender profile in gophish other than setting up your own mail server? I know that google and most other major providers blocked the usage of their smtp server by third parties like gophish.

submitted by /u/Kamelbaum1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Genuine (?) for the 👨‍💻ers

Did you all enjoy the learning process to get to where you have gotten? Was the learning process fun or do you only enjoy the end result?

submitted by /u/bilngbl0w
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
403 bypass lyncdiscover.microsoft.com

Hi, I have been working on the HTTP protocol for some time. After checking and researching, I found out that version 1.0 of the HTTP…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cisco won’t fix authentication bypass zero-day in EoL routers

Cisco won’t fix authentication bypass zero-day in EoL routersPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Cisco says that a new authentication bypass flaw affecting multiple small business VPN routers will not be patched because the devices have reached end-of-life (EoL).This zero-day bug (CVE-2022-20923) is caused by a faulty password validation algorithm that attackers could exploit to log into the VPN on vulnerable devices using what the company describes as “crafted credentials” if the IPSec VPN Server feature is enabled.

“A successful exploit could allow the attacker to bypass authentication and access the IPSec VPN network,” Cisco explained in a security advisory issued on Wednesday.

“The attacker may obtain privileges that are the same level as an administrative user, depending on the crafted credentials that are used.”

To determine if the IPSec VPN Server is enabled on a router, you have to log in to the web-based management interface and go to VPN > IPSec VPN Server > Setup.

If the “Server Enable” check box is checked, the device is exposed to CVE-2022-20923 exploitation attempts.

Luckily, Cisco says that its Product Security Incident Response Team (PSIRT) found no evidence of publicly available proof-of-concept exploits for this zero-day or any threat actors exploiting the bug in the wild until the advisory was published.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Upgrade to newer router models for protectionCisco asked customers still using the RV110W, RV130, RV130W, and RV215W routers affected by this security vulnerability to upgrade to newer models still receiving security updates.

According to an end-of-sale announcement on Cisco’s website, the last day these RV Series routers were available for order was December 2, 2019.

“Cisco has not released and will not release software updates to address the vulnerability described in this advisory,” the company added.

“Customers are encouraged to migrate to Cisco Small Business RV132W, RV160, or RV160W Routers.”
Trending: Security Engineer vs. Software Engineer
Trending: Recon Tool: ZenBuster
CVE-2022-20923 is not the first severe security vulnerability affecting these EoL router models that Cisco left unpatched in recent years.

For instance, in August 2021, the company said it wouldn’t release security patches for a critical vulnerability (CVE-2021-34730) in these RV Series routers that enabled unauthenticated attackers to execute arbitrary code remotely as the root user, asking users to migrate to newer models.

In June 2022, Cisco again advised owners to switch to newer models after disclosing a new critical remote code execution (RCE) vulnerability (CVE-2022-20825) that wouldn’t get patched.
Trending: Critical command injection vulnerability discovered in Bitbucket Server and Data Center Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-7-300x150.png New Linux malware evades detection and deploys cryptocurrency minerSeptember 7, 2022
Reading Time:[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cisco won’t fix authentication bypass zero-day in EoL routers Cisco won’t fix authentication bypass zero-day in EoL routersPost Views: 3 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png…
4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-6-300x150.png TikTok denies that hackers leaked its source code and user dataSeptember 6, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-5-300x150.png Malware dev open-sources CodeRAT after being exposedSeptember 5, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/ezgif.com-gif-maker-1-300x150.jpg WatchGuard firewall exploit threatens appliance takeoverSeptember 2, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Cisco won’t fix authentication bypass zero-day in EoL routers first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Trouble Landing Interviews
https://www.reddit.com/r/Pentesting/comments/x8xrlm/trouble_landing_interviews/

So I have an OSCP, eJPT, and a couple of years working on a testing team. Before that my career was always a blend of networking and security…switches, routers, firewalls, etc. Lately I just get form rejection letters or no response. Starting to feel cursed. The obvious issue is my resume, which I am working on. Is there anything else I could be doing to increase my chances of at least getting an interview? Traditionally I do okay or well with those, especially if they’re practical. All I hear about are vacancies, not enough qualified candidates, and other woes…but it’s tough trying to figure out why I am being passed over for interviews. Thanks in advance for any advice. submitted by /u/Select-Slip6482 (https://www.reddit.com/user/Select-Slip6482)
[link] (https://www.reddit.com/r/Pentesting/comments/x8xrlm/trouble_landing_interviews/) [comments] (https://www.reddit.com/r/Pentesting/comments/x8xrlm/trouble_landing_interviews/)

___________________________
@hacking_Attack
@Hacking_Video