Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pickle Rick TryHackMe Walkthrough
https://cdn-images-1.medium.com/max/811/1*S3Q30JGkREx1OLxIOPuQ1g.png
Pickle Rick on Tryhackme
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pickle Rick TryHackMe Walkthrough
https://cdn-images-1.medium.com/max/811/1*S3Q30JGkREx1OLxIOPuQ1g.png
Pickle Rick on Tryhackme
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pickle Rick TryHackMe Walkthrough
Pickle Rick on Tryhackme
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HTB — Backdoor
https://cdn-images-1.medium.com/max/695/0*kGwRXZbhbziTKsoi
wordpress | LFI | pid’s | gdbserver | misconfiguration | screen
Continue reading on stolabs »
___________________________
@hacking_Attack
@Hacking_Video
HTB — Backdoor
https://cdn-images-1.medium.com/max/695/0*kGwRXZbhbziTKsoi
wordpress | LFI | pid’s | gdbserver | misconfiguration | screen
Continue reading on stolabs »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTB — Backdoor
wordpress | LFI | pid’s | gdbserver | misconfiguration | screen
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Grupo de ransomware filtra archivos robados de Cisco
https://cdn-images-1.medium.com/max/1716/0*r90g2RRXr9XkWHqS
Cisco admitió el 10 de agosto que había detectado una brecha de seguridad el 24 de mayo. La admisión fue motivada por un grupo de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Grupo de ransomware filtra archivos robados de Cisco
https://cdn-images-1.medium.com/max/1716/0*r90g2RRXr9XkWHqS
Cisco admitió el 10 de agosto que había detectado una brecha de seguridad el 24 de mayo. La admisión fue motivada por un grupo de…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Grupo de ransomware filtra archivos robados de Cisco
Cisco admitió el 10 de agosto que había detectado una brecha de seguridad el 24 de mayo. La admisión fue motivada por un grupo de…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Common mistakes that are making your web apps insecure, and how to fix them.
https://cdn-images-1.medium.com/max/2600/1*K--C6DY3s43i464yEOHxYA.jpeg
A successful web app must be reliable, secure, and fast. Compromising on any of these qualities can result in a catastrophe…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Common mistakes that are making your web apps insecure, and how to fix them.
https://cdn-images-1.medium.com/max/2600/1*K--C6DY3s43i464yEOHxYA.jpeg
A successful web app must be reliable, secure, and fast. Compromising on any of these qualities can result in a catastrophe…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Common mistakes that are making your web apps insecure, and how to fix them.
A successful web app must be reliable, secure, and fast. Compromising on any of these qualities can result in a catastrophe…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
NATO documents from Portugal were stolen and put up for sale on the dark web.
https://cdn-images-1.medium.com/max/2600/1*eGHkpxzlnzwfR6yBG1JgWw.jpeg
In August, a group of hackers put secret military documents up for sale on the Internet. Among them are data on the modern weapons systems…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
NATO documents from Portugal were stolen and put up for sale on the dark web.
https://cdn-images-1.medium.com/max/2600/1*eGHkpxzlnzwfR6yBG1JgWw.jpeg
In August, a group of hackers put secret military documents up for sale on the Internet. Among them are data on the modern weapons systems…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
NATO documents from Portugal were stolen and put up for sale on the dark web.
In August, a group of hackers put secret military documents up for sale on the Internet. Among them are data on the modern weapons systems…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Red Team Part 5 — Intro to C2 | TryHackMe
https://cdn-images-1.medium.com/max/2000/0*ct-G4Bbw7YwjijPm.png
Hello world and welcome to HaXeZ where today we’re going to be getting a bit more technical and looking at C2s. To clarify, C2 is short…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Red Team Part 5 — Intro to C2 | TryHackMe
https://cdn-images-1.medium.com/max/2000/0*ct-G4Bbw7YwjijPm.png
Hello world and welcome to HaXeZ where today we’re going to be getting a bit more technical and looking at C2s. To clarify, C2 is short…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Red Team Part 5 — Intro to C2 | TryHackMe
Hello world and welcome to HaXeZ where today we’re going to be getting a bit more technical and looking at C2s. To clarify, C2 is short…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Red Team Part 3 — Red Team Threat Intel | TryHackMe
https://cdn-images-1.medium.com/max/1964/0*kkVojXNl2ecKHvRw.png
Hello world and welcome to HaXeZ, in this post we’re going to be walking through the 3rd Red Team challenge in the Red Team Fundamentals…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Red Team Part 3 — Red Team Threat Intel | TryHackMe
https://cdn-images-1.medium.com/max/1964/0*kkVojXNl2ecKHvRw.png
Hello world and welcome to HaXeZ, in this post we’re going to be walking through the 3rd Red Team challenge in the Red Team Fundamentals…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Red Team Part 3 — Red Team Threat Intel | TryHackMe
Hello world and welcome to HaXeZ, in this post we’re going to be walking through the 3rd Red Team challenge in the Red Team Fundamentals…
Any known case studies on a beacon’s logic executing from within a GPU compute shader?
https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/
I’ve been tinkering with writing a chess engine as this fun security engineering project write-up where the vulnerable chess web app uses peer-to-peer and the attacker exploits the victim peer, the pieces start breaking the rules, we use memory forensics to try to analyze and detect the exploitation heuristically via dynamic run-time analysis with baselining… Anyway, I digress. As part of this project I’m thinking a lot about chess engines and wonder: Hmm, I could probably write a chess sim inside a GPU compute shader to calculate a large number of variations in parallel. Then it struck me: If I can do that, couldn’t we write beacons which mostly execute their malicious code within a GPU shader, then pass the I/O in and out of a more benign process? You’d still need to do some stuff on the CPU (any effects on target), but with popular C2 frameworks you have this significant, sort of robust beacon agent code injected in a process to be detected. Sleep masking hides it from memory scanning kinda sorta, but not really against good defensive techniques. Seems like you could hide most of that memory signature inside a GPU compute shader and have much less “robust” code (essentially attack surface for defenders to use for detection) in RAM. Doubt any EDRs out there are scanning VRAM… Even if you did zero processing in a shader, even just hiding data in VRAM when not in-use (example: sleep masking) seems interesting on its own. Maybe someone’s heard of such a thing? Google is terrible with results when “GPU” and “red team” point to non-cyber branding slang. Google Scholar also turned up nothing. submitted by /u/Jonathan-Todd (https://www.reddit.com/user/Jonathan-Todd)
[link] (https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/) [comments] (https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/
I’ve been tinkering with writing a chess engine as this fun security engineering project write-up where the vulnerable chess web app uses peer-to-peer and the attacker exploits the victim peer, the pieces start breaking the rules, we use memory forensics to try to analyze and detect the exploitation heuristically via dynamic run-time analysis with baselining… Anyway, I digress. As part of this project I’m thinking a lot about chess engines and wonder: Hmm, I could probably write a chess sim inside a GPU compute shader to calculate a large number of variations in parallel. Then it struck me: If I can do that, couldn’t we write beacons which mostly execute their malicious code within a GPU shader, then pass the I/O in and out of a more benign process? You’d still need to do some stuff on the CPU (any effects on target), but with popular C2 frameworks you have this significant, sort of robust beacon agent code injected in a process to be detected. Sleep masking hides it from memory scanning kinda sorta, but not really against good defensive techniques. Seems like you could hide most of that memory signature inside a GPU compute shader and have much less “robust” code (essentially attack surface for defenders to use for detection) in RAM. Doubt any EDRs out there are scanning VRAM… Even if you did zero processing in a shader, even just hiding data in VRAM when not in-use (example: sleep masking) seems interesting on its own. Maybe someone’s heard of such a thing? Google is terrible with results when “GPU” and “red team” point to non-cyber branding slang. Google Scholar also turned up nothing. submitted by /u/Jonathan-Todd (https://www.reddit.com/user/Jonathan-Todd)
[link] (https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/) [comments] (https://www.reddit.com/r/redteamsec/comments/xdlssd/any_known_case_studies_on_a_beacons_logic/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit
Explore this post and more from the redteamsec community
Dark Reading: Attacks/Breaches
U-Haul Customer Contract Search Tool Compromised
Password compromise led to unauthorized access to a customer contract search tool over a five-month window, according to the company.
___________________________
@hacking_Attack
@Hacking_Video
U-Haul Customer Contract Search Tool Compromised
Password compromise led to unauthorized access to a customer contract search tool over a five-month window, according to the company.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
U-Haul Customer Contract Search Tool Compromised
Password compromise led to unauthorized access to a customer contract search tool over a five-month window, according to the company.
hacking: security in practice
Accidentally logged into Capital One using gym’s wifi.
Since it’s not recommended to login to public wifis, should I take action to protect myself?
submitted by /u/IsaPixza
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Accidentally logged into Capital One using gym’s wifi.
Since it’s not recommended to login to public wifis, should I take action to protect myself?
submitted by /u/IsaPixza
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Accidentally logged into Capital One using gym’s wifi.
Since it’s not recommended to login to public wifis, should I take action to protect myself?