Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
50% of Cyberattactacks Target Small Business! Why Small Business Often Become a Target?
https://cdn-images-1.medium.com/max/1366/1*fjyq9B_TE9gX893coNpJYA.jpeg
Cybercriminals will often use cyber-attacks on smaller businesses because there is less sophistication in the cybersecurity of the company…
Continue reading on Medium »
50% of Cyberattactacks Target Small Business! Why Small Business Often Become a Target?
https://cdn-images-1.medium.com/max/1366/1*fjyq9B_TE9gX893coNpJYA.jpeg
Cybercriminals will often use cyber-attacks on smaller businesses because there is less sophistication in the cybersecurity of the company…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Avoid Common Online Scams and Protect Your Money
https://cdn-images-1.medium.com/max/2600/1*iZMxTvANnDjxVRu0k5F6WA.jpeg
If you’re like most people, you probably think that you’re pretty savvy when it comes to avoiding online scams. But the truth is, even the…
Continue reading on Medium »
How to Avoid Common Online Scams and Protect Your Money
https://cdn-images-1.medium.com/max/2600/1*iZMxTvANnDjxVRu0k5F6WA.jpeg
If you’re like most people, you probably think that you’re pretty savvy when it comes to avoiding online scams. But the truth is, even the…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Solana Hack Drains Millions In Assets from Wallets
https://cdn-images-1.medium.com/max/1024/0*TdOOup6K8PzWTVkZ
The Solana hack in the blockchain space is targeting hot wallets linked to the Solana ecosystem.
Continue reading on Medium »
Solana Hack Drains Millions In Assets from Wallets
https://cdn-images-1.medium.com/max/1024/0*TdOOup6K8PzWTVkZ
The Solana hack in the blockchain space is targeting hot wallets linked to the Solana ecosystem.
Continue reading on Medium »
hacking: security in practice
Novel (?) PDF attack (and a new PDF visualization/threat assessment tool): JavaScript injected into the encrypted section of Adobe Type 1 font binaries is not detectable by malware scanners (nor does it interfere with the decryption of the font)
submitted by /u/thenextsymbol
[link] [comments]
Novel (?) PDF attack (and a new PDF visualization/threat assessment tool): JavaScript injected into the encrypted section of Adobe Type 1 font binaries is not detectable by malware scanners (nor does it interfere with the decryption of the font)
submitted by /u/thenextsymbol
[link] [comments]
reddit
Novel (?) PDF attack (and a new PDF visualization/threat...
Posted in r/hacking by u/thenextsymbol • 1 point and 0 comments
hacking: security in practice
does art imitate life? how accurate are the movies?
Im sorry if this is a dumb question as I'm completely illiterate when it comes to hacking heck even most computer stuff but I am morbidly curious...Do the movies and common depictions of hacking reflect somewhat what hacking actually is?
Like is it theoretically possible to remotely access anything, from smartphones, laptops, emails, all from the convenience of a coffee shop or your neighbors wifi?
I'm asking if after years of training and dedication could you have this superpower of getting a front row seat to everyone personal data and private lives. Like being able to know people without even having to meet them. That sounds insane.
submitted by /u/ChristIsKing3
[link] [comments]
does art imitate life? how accurate are the movies?
Im sorry if this is a dumb question as I'm completely illiterate when it comes to hacking heck even most computer stuff but I am morbidly curious...Do the movies and common depictions of hacking reflect somewhat what hacking actually is?
Like is it theoretically possible to remotely access anything, from smartphones, laptops, emails, all from the convenience of a coffee shop or your neighbors wifi?
I'm asking if after years of training and dedication could you have this superpower of getting a front row seat to everyone personal data and private lives. Like being able to know people without even having to meet them. That sounds insane.
submitted by /u/ChristIsKing3
[link] [comments]
reddit
does art imitate life? how accurate are the movies?
Im sorry if this is a dumb question as I'm completely illiterate when it comes to hacking heck even most computer stuff but I am morbidly...
Network Segmentation PenTesting
https://akash-venky091.medium.com/network-segmentation-pentesting-97238d63b001?source=rss------bug_bounty-5
https://akash-venky091.medium.com/network-segmentation-pentesting-97238d63b001?source=rss------bug_bounty-5
— — — — —-— — — — — Happy Engineer`s Day — — — — — — — — — —Continue reading on Medium » (https://akash-venky091.medium.com/network-segmentation-pentesting-97238d63b001?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Defacing POC El-Finder
https://cdn-images-1.medium.com/max/728/1*W26Uig5sLTbz7kKDTEBXTQ.jpeg
Satu lagi kita akan membahas defacing tanpa perlu merusak database yang ada di dalam website. Metode deface yang akan kita bahas yakni…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Defacing POC El-Finder
https://cdn-images-1.medium.com/max/728/1*W26Uig5sLTbz7kKDTEBXTQ.jpeg
Satu lagi kita akan membahas defacing tanpa perlu merusak database yang ada di dalam website. Metode deface yang akan kita bahas yakni…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Defacing POC El-Finder
Satu lagi kita akan membahas defacing tanpa perlu merusak database yang ada di dalam website. Metode deface yang akan kita bahas yakni…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Log4j being used to hack Energy companies by Lazarus ⚡
https://cdn-images-1.medium.com/max/1200/1*MOUGBB86DOo5uLsucO_znA.png
Lazarus, also known as APT38, a state-sponsored North Korean hacker outfit, has targeted energy companies from all around the world…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Log4j being used to hack Energy companies by Lazarus ⚡
https://cdn-images-1.medium.com/max/1200/1*MOUGBB86DOo5uLsucO_znA.png
Lazarus, also known as APT38, a state-sponsored North Korean hacker outfit, has targeted energy companies from all around the world…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Log4j being used to hack Energy companies by Lazarus ⚡
Lazarus, also known as APT38, a state-sponsored North Korean hacker outfit, has targeted energy companies from all around the world…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A vulnerability disclosed in Profanity, an Ethereum vanity address tool
https://cdn-images-1.medium.com/max/1920/1*rQSQzl0pN6COy-rA5E1Iqw.png
This post explains an apparent hack of the Ethereum vanity address generating tool Profanity, uncovered by 1inch contributors.
Continue reading on 1inch Network »
___________________________
@hacking_Attack
@Hacking_Video
A vulnerability disclosed in Profanity, an Ethereum vanity address tool
https://cdn-images-1.medium.com/max/1920/1*rQSQzl0pN6COy-rA5E1Iqw.png
This post explains an apparent hack of the Ethereum vanity address generating tool Profanity, uncovered by 1inch contributors.
Continue reading on 1inch Network »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A vulnerability disclosed in Profanity, an Ethereum vanity address tool
This post explains an apparent hack of the Ethereum vanity address generating tool Profanity, uncovered by 1inch contributors.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Windows IKE RCE : Researcher releases PoC code for Windows IKE RCE (CVE-2022-34721)
Windows IKE RCE is a critical Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution vulnerability impacting numerous Windows versions, according to a security researcher from the Cyber Security Research Company, 78researchlab. Internet Key Exchange is the mechanism used to create a security association (SA) in the IPsec protocol family, according to Wikipedia. The Oakley protocol and ISAKMP are built upon by IKE. IKE establishes a shared session secret from which cryptographic keys are produced using X.509 certificates for authentication, either pre-shared or distributed using DNS (ideally with DNSSEC).
Microsoft urged users to promptly install fixes since it has issued a warning that a threat actor might use the vulnerability (CVSSv3 base score of 9.8) to execute arbitrary code on the machine. Yuki Chen, who discovered the flaw in Cyber KunLun, was thanked by the company.
This vulnerability allows an attacker to run arbitrary code on the system by delivering a specially crafted IP packet to a Windows node with IPSec enabled. IKEv1 alone is affected by CVE-2022-34721. However, because they accept both V1 and V2 packets, all Windows Servers are impacted. Microsoft patched the flaw on September’s Patch Tuesday.
Today, 78ResearchLab made the proof-of-concept code for this vulnerability available on GitHub, and it will soon publish the analysis report. Users of vulnerable Windows versions are advised to prioritise installing the fixes in order to stop ongoing exploitation efforts in light of the PoC’s release.
Download
___________________________
@hacking_Attack
@Hacking_Video
Windows IKE RCE : Researcher releases PoC code for Windows IKE RCE (CVE-2022-34721)
Windows IKE RCE is a critical Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution vulnerability impacting numerous Windows versions, according to a security researcher from the Cyber Security Research Company, 78researchlab. Internet Key Exchange is the mechanism used to create a security association (SA) in the IPsec protocol family, according to Wikipedia. The Oakley protocol and ISAKMP are built upon by IKE. IKE establishes a shared session secret from which cryptographic keys are produced using X.509 certificates for authentication, either pre-shared or distributed using DNS (ideally with DNSSEC).
Microsoft urged users to promptly install fixes since it has issued a warning that a threat actor might use the vulnerability (CVSSv3 base score of 9.8) to execute arbitrary code on the machine. Yuki Chen, who discovered the flaw in Cyber KunLun, was thanked by the company.
This vulnerability allows an attacker to run arbitrary code on the system by delivering a specially crafted IP packet to a Windows node with IPSec enabled. IKEv1 alone is affected by CVE-2022-34721. However, because they accept both V1 and V2 packets, all Windows Servers are impacted. Microsoft patched the flaw on September’s Patch Tuesday.
Today, 78ResearchLab made the proof-of-concept code for this vulnerability available on GitHub, and it will soon publish the analysis report. Users of vulnerable Windows versions are advised to prioritise installing the fixes in order to stop ongoing exploitation efforts in light of the PoC’s release.
Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs
Microsoft Teams stores auth tokens as cleartext in Windows, Linux, MacsPost Views: 173 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Security analysts have found a severe security vulnerability in the desktop app for Microsoft Teams that gives threat actors access to authentication tokens and accounts with multi-factor authentication (MFA) turned on.Microsoft Teams is a communication platform, included in the 365 product family, used by more than 270 million people for exchanging text messages, videoconferencing, and storing files.
The newly discovered security issue impacts versions of the application for Windows, Linux, and Mac and refers to Microsoft Teams storing user authentication tokens in clear text without protecting access to them.
An attacker with local access on a system where Microsoft Teams is installed could steal the tokens and use them to log into the victim’s account.
“This attack does not require special permissions or advanced malware to get away with major internal damage,” Connor Peoples at cybersecurity company Vectra explains in a report this week.
The researcher adds that by taking “control of critical seats–like a company’s Head of Engineering, CEO, or CFO—attackers can convince users to perform tasks damaging to the organization.”
Vectra researchers discovered the problem in August 2022 and reported it to Microsoft. However, Microsoft did not agree on the severity of the issue and said that it doesn’t meet the criteria for patching.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Problem detailsMicrosoft Teams is an Electron app, meaning that it runs in a browser window, complete with all the elements required by a regular web page (cookies, session strings, logs, etc.).
Electron does not support encryption or protected file locations by default, so while the software framework is versatile and easy to use, it is not considered secure enough for developing mission-critical products unless extensive customization and additional work is applied.
Vectra analyzed Microsoft Teams while trying to find a way to remove deactivated accounts from client apps, and found an ldb file with access tokens in clear text.
“Upon review, it was determined that these access tokens were active and not an accidental dump of a previous error. These access tokens gave us access to the Outlook and Skype APIs.” – Vectra
Additionally, the analysts discovered that the “Cookies” folder also contained valid authentication tokens, along with account information, session data, and marketing tags.
https://www.bleepstatic.com/images/news/u/1220909/Software/token-on-database.png
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs
Microsoft Teams stores auth tokens as cleartext in Windows, Linux, MacsPost Views: 173 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Security analysts have found a severe security vulnerability in the desktop app for Microsoft Teams that gives threat actors access to authentication tokens and accounts with multi-factor authentication (MFA) turned on.Microsoft Teams is a communication platform, included in the 365 product family, used by more than 270 million people for exchanging text messages, videoconferencing, and storing files.
The newly discovered security issue impacts versions of the application for Windows, Linux, and Mac and refers to Microsoft Teams storing user authentication tokens in clear text without protecting access to them.
An attacker with local access on a system where Microsoft Teams is installed could steal the tokens and use them to log into the victim’s account.
“This attack does not require special permissions or advanced malware to get away with major internal damage,” Connor Peoples at cybersecurity company Vectra explains in a report this week.
The researcher adds that by taking “control of critical seats–like a company’s Head of Engineering, CEO, or CFO—attackers can convince users to perform tasks damaging to the organization.”
Vectra researchers discovered the problem in August 2022 and reported it to Microsoft. However, Microsoft did not agree on the severity of the issue and said that it doesn’t meet the criteria for patching.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Problem detailsMicrosoft Teams is an Electron app, meaning that it runs in a browser window, complete with all the elements required by a regular web page (cookies, session strings, logs, etc.).
Electron does not support encryption or protected file locations by default, so while the software framework is versatile and easy to use, it is not considered secure enough for developing mission-critical products unless extensive customization and additional work is applied.
Vectra analyzed Microsoft Teams while trying to find a way to remove deactivated accounts from client apps, and found an ldb file with access tokens in clear text.
“Upon review, it was determined that these access tokens were active and not an accidental dump of a previous error. These access tokens gave us access to the Outlook and Skype APIs.” – Vectra
Additionally, the analysts discovered that the “Cookies” folder also contained valid authentication tokens, along with account information, session data, and marketing tags.
https://www.bleepstatic.com/images/news/u/1220909/Software/token-on-database.png
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs | Black Hat Ethical Hacking
Security analysts have found a severe security vulnerability in the desktop app for Microsoft Teams that gives threat actors access to authentication tokens and accounts with multi-factor authentication (MFA) turned on.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs Microsoft Teams stores auth tokens as cleartext in Windows, Linux, MacsPost Views: 173 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uplo…
doing this for other applications, such as Google Chrome, Microsoft Edge, Mozilla Firefox, Discord, and many more.
Trending: Security Engineer vs. Software Engineer
Trending: Recon Tool: ZenBuster Risk mitigationWith a patch unlikely to be released, Vectra’s recommendation is for users to switch to the browser version of the Microsoft Teams client. By using Microsoft Edge to load the app, users benefit from additional protections against token leaks.
The researchers advise Linux users to move to a different collaboaration suite, especially since Microsoft announced plans to stop supporting the app for the platform by December.
For those that can’t move to a different solution immediately, they can create a monitoring rule to discover processes accessing the following directories:
* [Windows] %AppData%\Microsoft\Teams\Cookies
* [Windows] %AppData%\Microsoft\Teams\Local Storage\leveldb
* [macOS] ~/Library/Application Support/Microsoft/Teams/Cookies
* [macOS] ~/Library/Application Support/Microsoft/Teams/Local Storage/leveldb
* [Linux] ~/.config/Microsoft/Microsoft Teams/Cookies
* [Linux] ~/.config/Microsoft/Microsoft Teams/Local Storage/leveldb
BleepingComputer has contacted Microsoft about the company’s plans to release a fix for the issue and will update the article when we get an answer.
Update 9/14/22 – A Microsoft spokesperson sent us the following comment regarding Vectra’s findings:
The technique described does not meet our bar for immediate servicing as it requires an attacker to first gain access to a target network.
We appreciate Vectra Protect’s partnership in identifying and responsibly disclosing this issue and will consider addressing in a future product release. Trending: GIFShell attack creates reverse shell using Microsoft Teams GIFs
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-1-300x150.png Zero-day in WPGateway WordPress plugin actively exploited in thousands WordPress sitesSeptember 14, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/intro-1656368006-300x150.jpg A new Browser-in-the-Browser attack led hackers steal Steam accountsSeptember 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-300x150.png Blind SSRF vulnerability in WordPress Core feature could enable DDoS attacksSeptember 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/ms-teams-cheat-sheet-2022-300x150.jpeg GIFShell attack creates reverse shell using Microsoft Teams GIFsSeptember 9, 2022
Reading Time: 8 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Trending: Security Engineer vs. Software Engineer
Trending: Recon Tool: ZenBuster Risk mitigationWith a patch unlikely to be released, Vectra’s recommendation is for users to switch to the browser version of the Microsoft Teams client. By using Microsoft Edge to load the app, users benefit from additional protections against token leaks.
The researchers advise Linux users to move to a different collaboaration suite, especially since Microsoft announced plans to stop supporting the app for the platform by December.
For those that can’t move to a different solution immediately, they can create a monitoring rule to discover processes accessing the following directories:
* [Windows] %AppData%\Microsoft\Teams\Cookies
* [Windows] %AppData%\Microsoft\Teams\Local Storage\leveldb
* [macOS] ~/Library/Application Support/Microsoft/Teams/Cookies
* [macOS] ~/Library/Application Support/Microsoft/Teams/Local Storage/leveldb
* [Linux] ~/.config/Microsoft/Microsoft Teams/Cookies
* [Linux] ~/.config/Microsoft/Microsoft Teams/Local Storage/leveldb
BleepingComputer has contacted Microsoft about the company’s plans to release a fix for the issue and will update the article when we get an answer.
Update 9/14/22 – A Microsoft spokesperson sent us the following comment regarding Vectra’s findings:
The technique described does not meet our bar for immediate servicing as it requires an attacker to first gain access to a target network.
We appreciate Vectra Protect’s partnership in identifying and responsibly disclosing this issue and will consider addressing in a future product release. Trending: GIFShell attack creates reverse shell using Microsoft Teams GIFs
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-1-300x150.png Zero-day in WPGateway WordPress plugin actively exploited in thousands WordPress sitesSeptember 14, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/intro-1656368006-300x150.jpg A new Browser-in-the-Browser attack led hackers steal Steam accountsSeptember 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-300x150.png Blind SSRF vulnerability in WordPress Core feature could enable DDoS attacksSeptember 12, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/ms-teams-cheat-sheet-2022-300x150.jpeg GIFShell attack creates reverse shell using Microsoft Teams GIFsSeptember 9, 2022
Reading Time: 8 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video