Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Twitter failed to log you out of all devices after password resets

Twitter failed to log you out of all devices after password resetsPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Twitter logged out some users after addressing a bug where some Twitter accounts remained logged on some mobile devices after voluntary password resets.“That means that if you proactively changed your password on one device, but still had an open session on another device, that session may not have been closed. Web sessions were not affected and were closed appropriately,” Twitter explained.

There are some potential privacy risks for Twitter users who were affected by this bug, including having their accounts accessed by others who got their hands on devices that remained logged in without the user’s knowledge.

Because of this, the company reached out to those who might have been impacted and logged them out of their accounts on all active sessions across all devices.

“We have directly informed the people we were able to identify who may have been affected by this, proactively logged them out of open sessions across devices, and prompted them to log in again,” the company added

“We realize this may be inconvenient for some, but it was an important step to keep your account safe and secure from potential unwanted access.”
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
We fixed a bug that didn't close all active logged in sessions on Android and iOS after an account's password was reset. To keep your account safe, we logged some of you out. You can log back in to keep using Twitter.

For more details on what happened: https://t.co/OmjLKOe5bs

— Twitter Support (@TwitterSupport) September 21, 2022
In July, Twitter was hit by a data breach after threat actors put up for sale a database of phone numbers and email addresses linked to 5.4 million Twitter accounts stolen in December 2021.

The vulnerability the attacker used to collect the data is one disclosed to Twitter through HackerOne on January 1st and fixed on January 13th, as first reported by Restore Privacy.

BleepingComputer verified with some of the Twitter users listed in a small sample of data shared by the hacker that the leaked private info (email addresses and phone numbers) was accurate.

One month later, Twitter confirmed the reports, saying the threat actor used the zero-day vulnerability patched in January to collect private user information.
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: fuxploider As part of the disclosure, Twitter told BleepingComputer that they had begun sending out notifications to alert impacted users that the data breach exposed their phone numbers or email address.

Since July, hacked verified Twitter accounts are also being used to send fake but well-written suspension messages that attempt to steal other verified users’ credentials.
Trending: Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Ima[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
OSINT Tool: Social Hunter

OSINT Tool: Social HunterPost Views: 15 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes Social HunterWhen you prepare special crafted targeted Phishing attacks as part of your Red Teaming process and/or Pentesting Solutions, unlike the automated easy to spot ones, you have to spend time prior of the attack performing OSINT, getting to study your targets so you can then prepare the correct templates, trackers and scenarios.

Social Hunter by utkusen, crawls the given URL(s) and finds broken social media links that can be hijacked. Broken social links may allow an attacker to conduct phishing attacks. It also can cost a loss of the company’s reputation. Broken social media hijack issues are usually accepted on the bug bounty programs.

Currently, it supports Twitter, Facebook, Instagram and Tiktok without any API keys.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
Trending: Recon Tool: ZenBuster
Trending: Offensive Security Tool: Offensive-Azure InstallationFrom BinaryYou can download the pre-built binaries from the releases page and run. For example: wget https://github.com/utkusen/socialhunter/releases/download/v0.1.1/socialhunter_0.1.1_Linux_amd64.tar.gztar xzvf socialhunter_0.1.1_Linux_amd64.tar.gz./socialhunter --helpFrom Source1. Install Go on your system

2. Run: go get -u github.com/utkusen/socialhunterUsagesocialhunter requires 2 parameters to run:

-f : Path of the text file that contains URLs line by line. The crawl function is path-aware. For example, if the URL is https://utkusen.com/blog, it only crawls the pages under /blog path

-w : The number of workers to run (e.g -w 10). The default value is 5. You can increase or decrease this by testing out the capability of your system.
Clone the repo from here: GitHub Link
Trending: How to Exploit “improper error handling” in Web Applications https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent Tools* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/dnsReaper-300x150.png Offensive Security Tool: dnsReaperSeptember 16, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/fuxploider-300x150.png Offensive Security Tool: fuxploiderSeptember 9, 2022
Reading Time: 2 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/ZenBuster-300x150.png Recon Tool: ZenBusterSeptember 2, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/CrossLinked-300x150.png Recon Tool: CrossLinkedAugust 26, 2022
Reading Time: 2 minutes https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post OSINT Tool: Social Hunter first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Twitter failed to log you out of all devices after password resets Twitter failed to log you out of all devices after password resetsPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon…
ges-for-the-News-posts-8-300x150.png Rockstar parent company hacked again as 2K Support sends users malwareSeptember 21, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/2-300x150.png Revolut hack: personal and banking data exposedSeptember 20, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-3-300x150.png GTA 6 source code and videos leaked after Rockstar Games hackSeptember 19, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-2-300x150.png Uber hacked, internal systems breached and vulnerability reports stolenSeptember 16, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Twitter failed to log you out of all devices after password resets first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Exploiting NFS shares to gain root access

https://cdn-images-1.medium.com/max/777/0*y-ygwZS9qMCDgROS.jpg
Recently, while performing a network-level penetration testing activity for one of the clients, I came across a vulnerability that was…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Benefits of Storage and warehouse services in uk

https://cdn-images-1.medium.com/max/990/1*cz87a-qm-NFIKd9PY1GfQg.png
With the increase of business people all over the globe, the need for storage is also increasing at a high rate. Whether you have regular…

Continue reading on Medium »
hacking: security in practice
Resetting vending machine NFC key data

Years ago I got a key for vending machines to grab coffee and a friend of a friend had taken the key, modified and made it possible through Mifare Classic Tools on Smartphone to bring the Key to the phone via NFC, reset it and in practice have infinite money. Anyone know the process to change the key? the friend I'm talking about I have no more way to contact him otherwise I would have asked him

submitted by /u/itsm3tt
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
OSRipper - AV Evading OSX Backdoor And Crypter Framework

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgbR92Al9Iu7-v4Ki-Atw6q3w8R3epKooAWQ5K4feSMG2gsDCpPFUzwQvIBZHKAQll8IhsoX_DF3PhrJGfa6HOPUzIdSNUrENcm9hWtL9IM8CzSlv7J5McZvN1822KuRntsQPgIM73X_OZiaQnrgBo2omRcr1HbjiiRzmsdvgng1yKKvebWKhf-0dZlA/s16000/OSRipper_1_OSRipper.png OSripper is a fully undetectable Backdoor generator and Crypter which specialises in OSX M1 malware. It will also work on windows but for now there is no support for it and it IS NOT FUD for windows (yet at least) and for now i will not focus on windows.

You can also PM me on discord for support or to ask for new features SubGlitch1#2983 Features* FUD (for macOS)
* Cloacks as an official app (Microsoft, ExpressVPN etc)
* Dumps; Sys info, Browser History, Logins, ssh/aws/azure/gcloud creds, clipboard content, local users etc. (more on Cedric Owens swiftbelt)
* Encrypted communications
* Rootkit-like Behaviour
* Every Backdoor generated is entirely unique DescriptionPlease check the wiki for information on how OSRipper functions (which changes extremely frequently) https://github.com/SubGlitch1/OSRipper/wiki

Here are example backdoors which were generated with OSRipper https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj06eulcwA3cFF-LHX-87KhIJo45Naa70fncqKpjU46vsiT5wprhGdT18yzMO3fg3hciMMFyBlxx-mBIzt1Es-emEtOqaJz7-M8HhpPs218c6penNJRAOGP3YXF3Fm8jpEu4Hrd555rV6rc81KTJ2moGHsECfYg6nZLK-Exo83j5rW_2leLKsolLlgLGg/w470-h640/OSRipper_3_example.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1_n3eqs-u1R7A-7gpkBA5nJXACaKRNd2YKVZgDtO7HgIcn1EsTKm1Z2JeyDa1fZ0fjYRuGvyOJGbxd8cKEa7X1CjdoQ45FhsQm9s9z54exYkj1_YTQSApbcWDC1R2ZWgaVoY_2npfW50pyL35YKnCk9BTvnZqPvTsvF54ec1CH19uX30aGbA2E_9xYA/w640-h390/OSRipper_4_vt.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip3h53atetp7WHcekT2iEVypTbmEKLlrrSV9WxEZ41utdqF_AfI4SeN5ovGrI1biRvJTDUsIBOMPXF-XdjfgnzzRW0x_XoQINlAZhTv_6oIe1wrcLVxbhoXOXhPLVw3cGXPc2QezS6iJ0o6jvA7aC3sA5xCPU0rlqk6B3X-qcFmajK1wDyEEnQOSBAPg/w640-h376/OSRipper_5_vt_app.png macOS .apps will look like this on vt Getting StartedDependenciesYou need python. If you do not wish to download python you can download a compiled release. The python dependencies are specified in the requirements.txt file.

Since Version 1.4 you will need metasploit installed and on path so that it can handle the meterpreter listeners. InstallingLinuxapt install git python -y
git clone https://github.com/SubGlitch1/OSRipper.git
cd OSRipper
pip3 install -r requirements.txt
Windowsgit clone https://github.com/SubGlitch1/OSRipper.git
cd OSRipper
pip3 install -r requirements.txt
or download the latest release from https://github.com/SubGlitch1/OSRipper/releases/tag/v0.2.3 Executing programOnly this sudo python3 main.py ContributingPlease feel free to fork and open pull repuests. Suggestions/critisizm are appreciated as well Roadmapv0.1*
Get down detection to 0/26 on antiscan.me

*
Add Changelog

*
Daemonise Backdoor

*
Add Crypter

*
Add More Backdoor templates

*
Get down detection to at least 0/68 on VT (for mac malware) v0.2*
Add AntiVM

* [] Implement tor hidden services
*
Add Logger

*
Add Password stealer

* [] Add KeyLogger
*
Add some new evasion options

*
Add SilentMiner

* [] Make proper C2 server v0.3Coming soon HelpJust open a issue and ill make sure to get back to you Changelog*
0.2.1

* OSRipper will now pull all information from the Target and send them to the c2 server over sockets. This includes information like browser history, passwords, system information, keys and etc.

*
0.1.6

* Proccess will now trojanise itself as com.apple.system.monitor and drop to /Users/Shared

*
0.1.5

* Added Crypter[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! OSRipper - AV Evading OSX Backdoor And Crypter Framework https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgbR92Al9Iu7-v4Ki-Atw6q3w8R3epKooAWQ5K4feSMG2gsDCpPFUzwQvIBZHKAQll8IhsoX_DF3PhrJGfa6HOPUzIdSNUrENcm9hWtL9IM8CzSl…
*
0.1.4

* Added 4th Module

*
0.1.3

* Got detection on VT down to 0. Made the Proccess invisible

*
0.1.2

* Added 3rd module and listener

*
0.1.1

* Initial Release LicenseMIT AcknowledgmentsInspiration, code snippets, etc.

* htr
* swiftbelt SupportI am very sorry to even write this here but my finances are not looking good right now. If you appreciate my work i would really be happy about any donation. You do NOT have to this is solely optional

BTC: 1LTq6rarb13Qr9j37176p3R9eGnp5WZJ9T DisclaimerI am not responsible for what is done with this project. This tool is solely written to be studied by other security researchers to see how easy it is to develop macOS malware. Download OSRipper

___________________________
@hacking_Attack
@Hacking_Video