Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackear dispositivos explotando la frecuencia de la música (CVE-2022–38392)
https://cdn-images-1.medium.com/max/1690/0*ZIr46zPLjRCBGxkQ
No haga que su computadora portátil escuche melodías de Janet Jackson, puede bloquear los discos duros de la computadora portátil.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackear dispositivos explotando la frecuencia de la música (CVE-2022–38392)
https://cdn-images-1.medium.com/max/1690/0*ZIr46zPLjRCBGxkQ
No haga que su computadora portátil escuche melodías de Janet Jackson, puede bloquear los discos duros de la computadora portátil.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackear dispositivos explotando la frecuencia de la música (CVE-2022–38392)
No haga que su computadora portátil escuche melodías de Janet Jackson, puede bloquear los discos duros de la computadora portátil.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Operaciones de ransomware utilizan BitLocker
https://cdn-images-1.medium.com/max/1696/0*Thz6dE6hUHgH0Q4K
El equipo de inteligencia de amenazas de Microsoft asegura que el grupo DEV-0270 (también conocido como Nemesis Kitten o Phosphorus) ha…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Operaciones de ransomware utilizan BitLocker
https://cdn-images-1.medium.com/max/1696/0*Thz6dE6hUHgH0Q4K
El equipo de inteligencia de amenazas de Microsoft asegura que el grupo DEV-0270 (también conocido como Nemesis Kitten o Phosphorus) ha…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Operaciones de ransomware utilizan BitLocker
El equipo de inteligencia de amenazas de Microsoft asegura que el grupo DEV-0270 (también conocido como Nemesis Kitten o Phosphorus) ha…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Membersgram Mod APK Download (Latest v8.2.9 ) for Android
Many people work hard to get people to join their Telegram channels. When there aren’t enough people in a channel, many Telegram users…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Membersgram Mod APK Download (Latest v8.2.9 ) for Android
Many people work hard to get people to join their Telegram channels. When there aren’t enough people in a channel, many Telegram users…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Membersgram Mod APK Download (Latest v8.2.9 ) for Android
Many people work hard to get people to join their Telegram channels. When there aren’t enough people in a channel, many Telegram users…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Will the Cloud End the Endpoint?
When an organization fully embraces the cloud, traditional endpoints become disposable. Organizations must adapt their security strategy for this reality.
___________________________
@hacking_Attack
@Hacking_Video
Will the Cloud End the Endpoint?
When an organization fully embraces the cloud, traditional endpoints become disposable. Organizations must adapt their security strategy for this reality.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Will the Cloud End the Endpoint?
When an organization fully embraces the cloud, traditional endpoints become disposable. Organizations must adapt their security strategy for this reality.
Dark Reading: Attacks/Breaches
Note to Security Vendors — Companies Are Picking Favorites
A stunning three-quarters of companies are looking to consolidate their security products this year, up from 29% in 2020, suggesting fiercer competition between cybersecurity vendors.
___________________________
@hacking_Attack
@Hacking_Video
Note to Security Vendors — Companies Are Picking Favorites
A stunning three-quarters of companies are looking to consolidate their security products this year, up from 29% in 2020, suggesting fiercer competition between cybersecurity vendors.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Note to Security Vendors: Companies Are Picking Favorites
A stunning three-quarters of companies are looking to consolidate their security products this year, up from 29% in 2020, suggesting fiercer competition among cybersecurity vendors.
All about: Open Redirects
Sites often use HTTP or URL parameters to redirect users to a specified URL without any user action. While this behavior can be useful, it…Continue reading on Medium »
Read more...
Sites often use HTTP or URL parameters to redirect users to a specified URL without any user action. While this behavior can be useful, it…Continue reading on Medium »
Read more...
All about: Open Redirects
https://sl4x0.medium.com/all-about-open-redirects-d69cf6726122?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sl4x0.medium.com/all-about-open-redirects-d69cf6726122?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: Open Redirects
Sites often use HTTP or URL parameters to redirect users to a specified URL without any user action. While this behavior can be useful, it…
Sites often use HTTP or URL parameters to redirect users to a specified URL without any user action. While this behavior can be useful, it…Continue reading on Medium » (https://sl4x0.medium.com/all-about-open-redirects-d69cf6726122?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
All about: Open Redirects
Sites often use HTTP or URL parameters to redirect users to a specified URL without any user action. While this behavior can be useful, it…
hacking: security in practice
So, if a company gives out work tablets or laptops to employees, what is the degree of risk and likelihood in that computer/tablet/laptop being used by a threat actor in a cyberattack?
You would think that this would be an issue as many companies do this, so how are they defended?
I'm asking for college. It's one of the discussion post things we have to write about based around Network Security.
submitted by /u/ZenithCrests
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
So, if a company gives out work tablets or laptops to employees, what is the degree of risk and likelihood in that computer/tablet/laptop being used by a threat actor in a cyberattack?
You would think that this would be an issue as many companies do this, so how are they defended?
I'm asking for college. It's one of the discussion post things we have to write about based around Network Security.
submitted by /u/ZenithCrests
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
So, if a company gives out work tablets or laptops to employees,...
You would think that this would be an issue as many companies do this, so how are they defended? I'm asking for college. It's one of the...
hacking: security in practice
is there any way to hack emails other than phishing?
until recently afaik you could hack Gmail accounts by brute forcing smtp ( I could be wrong I only read they fixed it in may 2022 ), and that got me wondering is there any way to hack emails other than phishing?
also ik that its illegal to hack even your own account so how can I legally try it out? ( if there is anything at all that can be done )
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is there any way to hack emails other than phishing?
until recently afaik you could hack Gmail accounts by brute forcing smtp ( I could be wrong I only read they fixed it in may 2022 ), and that got me wondering is there any way to hack emails other than phishing?
also ik that its illegal to hack even your own account so how can I legally try it out? ( if there is anything at all that can be done )
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is there any way to hack emails other than phishing?
until recently afaik you could hack Gmail accounts by brute forcing smtp ( I could be wrong I only read they fixed it in may 2022 ), and that got...
hacking: security in practice
Does anyone know any good virus maker tools for free?
They seem like fund and i would like to try them out with my other devices.
submitted by /u/Yeetler69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does anyone know any good virus maker tools for free?
They seem like fund and i would like to try them out with my other devices.
submitted by /u/Yeetler69
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does anyone know any good virus maker tools for free?
They seem like fund and i would like to try them out with my other devices.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Why Browser Anti-Fingerprinting Techniques Are Not Effective
https://external-preview.redd.it/2zKINZZLinpulz4as85CenEFk3UFJ4tPegSSlgM1Pu8.jpg?width=640&crop=smart&auto=webp&s=6adbe54968da6185e23cfa8231924c2330737ea7 submitted by /u/iamvalentin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why Browser Anti-Fingerprinting Techniques Are Not Effective
https://external-preview.redd.it/2zKINZZLinpulz4as85CenEFk3UFJ4tPegSSlgM1Pu8.jpg?width=640&crop=smart&auto=webp&s=6adbe54968da6185e23cfa8231924c2330737ea7 submitted by /u/iamvalentin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/hacking on Reddit: Why Browser Anti-Fingerprinting Techniques Are Not Effective
Posted by u/iamvalentin - 10 votes and no comments
hacking: security in practice
How do i get into hacking and programming?
Man, i'm 16 and i love tech and hacking shit, but i dunno how to hack or to program... I don't know where to read things about it, where to search, HOW to search, etc... Can you dudes help me?
submitted by /u/Chumaludo_Plays
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do i get into hacking and programming?
Man, i'm 16 and i love tech and hacking shit, but i dunno how to hack or to program... I don't know where to read things about it, where to search, HOW to search, etc... Can you dudes help me?
submitted by /u/Chumaludo_Plays
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do i get into hacking and programming?
Man, i'm 16 and i love tech and hacking shit, but i dunno how to hack or to program... I don't know where to read things about it, where to...
hacking: security in practice
Hashcat: If one has the progress percent before a crash, can one restart at roughly that percent?
I was running hashcat on some digests and got to about 26%, saying
Assuming hashcat runs through the same possibilities in the same order for a given command (no parallelism other than within the GPU), I should be able to skip to, say, 25% and continue, right? If so, how might one do this?
(I'm cracking legally acquired, publicly available hashes.)
submitted by /u/gnulynnux
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hashcat: If one has the progress percent before a crash, can one restart at roughly that percent?
I was running hashcat on some digests and got to about 26%, saying
Progress.........: 863477760/3313552704 (26.06%). Accidentally hit 'q' for quit right after hitting 's' for status.Assuming hashcat runs through the same possibilities in the same order for a given command (no parallelism other than within the GPU), I should be able to skip to, say, 25% and continue, right? If so, how might one do this?
(I'm cracking legally acquired, publicly available hashes.)
submitted by /u/gnulynnux
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hashcat: If one has the progress percent before a crash, can one...
I was running hashcat on some digests and got to about 26%, saying `Progress.........: 863477760/3313552704 (26.06%)`. Accidentally hit 'q' for...
Looking for thoughts, advice, or known prior art of building an alternative to hooking: behavior baseline by predicting a limited subset of machine code's probable control flow in memory at runtime.
https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/
Hooking is pretty easy to beat. It's efficient, low overhead, but unreliable. It also results in very low resolution scrutiny of program behavior. I think I have an idea, not to replace hooking, but maybe add a more resilient redundant behavior analysis mechanism. Computational overhead is my primary concern, and also I'm unsure how often you can halt a process's normal execution flow to do this without noticeable performance impact. To be honest, I'm actually not even sure how, without implementing this in the kernel, you would, at some interval, redirect the instruction pointer to your analysis code (by force, not by hooking) and also protect it from attacker modification. But I think the idea itself is interesting enough to be discussion-worthy. I think the defender's best option to deal with higher end EDR evasion and obfuscation techniques is to analyze the control flow of the x86 machine code at run-time to build a baseline and detect when there's significant deviation. We know the control flow is unpredictable (https://www.reddit.com/r/cybersecurity/comments/qopemf/i_attempted_to_diagram_everything_ive_learned/), but it should be fairly predictable outside of malicious activity and a few edge-cases (JIT compilation, like in a browser). So I propose this idea of, at a set interval, decode a limited number of instructions ahead of the current IP, disassemble them, and map that disassembly to a behavior baseline. Make sure the control flow matches the baseline - a baseline generated and extrapolated on and broadened by comparing analysis of the same process on hundreds or thousands of hosts in a network.. The next interval, test your last prediction; make sure the IP is within the predicted control flow range. If not, log an alert to a SIEM. Maybe it's a false positive, but the SIEM's logic or some SOAR solution can at least more carefully scrutinize the process / host, maybe treat any other alerts from that host with higher sensitivity. These baselines could also be used as signatures. An attacker might re-write the implementation of a PowerShell command to evade improving PS auditing apparatuses, for example. Or Python, or any other LOLBIN vector. Or they might just do some unhooking on the mechanisms that perform that auditing. This measure would potentially be resistant to those evasion vectors along with control flow obfuscation. You would either identify a baseline that matches some other known baseline (like a PowerShell command, or a Python interpreter) or worse, one that doesn't match any baseline. submitted by /u/Jonathan-Todd (https://www.reddit.com/user/Jonathan-Todd)
[link] (https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/) [comments] (https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/
Hooking is pretty easy to beat. It's efficient, low overhead, but unreliable. It also results in very low resolution scrutiny of program behavior. I think I have an idea, not to replace hooking, but maybe add a more resilient redundant behavior analysis mechanism. Computational overhead is my primary concern, and also I'm unsure how often you can halt a process's normal execution flow to do this without noticeable performance impact. To be honest, I'm actually not even sure how, without implementing this in the kernel, you would, at some interval, redirect the instruction pointer to your analysis code (by force, not by hooking) and also protect it from attacker modification. But I think the idea itself is interesting enough to be discussion-worthy. I think the defender's best option to deal with higher end EDR evasion and obfuscation techniques is to analyze the control flow of the x86 machine code at run-time to build a baseline and detect when there's significant deviation. We know the control flow is unpredictable (https://www.reddit.com/r/cybersecurity/comments/qopemf/i_attempted_to_diagram_everything_ive_learned/), but it should be fairly predictable outside of malicious activity and a few edge-cases (JIT compilation, like in a browser). So I propose this idea of, at a set interval, decode a limited number of instructions ahead of the current IP, disassemble them, and map that disassembly to a behavior baseline. Make sure the control flow matches the baseline - a baseline generated and extrapolated on and broadened by comparing analysis of the same process on hundreds or thousands of hosts in a network.. The next interval, test your last prediction; make sure the IP is within the predicted control flow range. If not, log an alert to a SIEM. Maybe it's a false positive, but the SIEM's logic or some SOAR solution can at least more carefully scrutinize the process / host, maybe treat any other alerts from that host with higher sensitivity. These baselines could also be used as signatures. An attacker might re-write the implementation of a PowerShell command to evade improving PS auditing apparatuses, for example. Or Python, or any other LOLBIN vector. Or they might just do some unhooking on the mechanisms that perform that auditing. This measure would potentially be resistant to those evasion vectors along with control flow obfuscation. You would either identify a baseline that matches some other known baseline (like a PowerShell command, or a Python interpreter) or worse, one that doesn't match any baseline. submitted by /u/Jonathan-Todd (https://www.reddit.com/user/Jonathan-Todd)
[link] (https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/) [comments] (https://www.reddit.com/r/redteamsec/comments/xfeocn/looking_for_thoughts_advice_or_known_prior_art_of/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking for thoughts, advice, or known prior art of building an...
Hooking is pretty easy to beat. It's efficient, low overhead, but unreliable. It also results in very low resolution scrutiny of program behavior....