Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hi, my name is Hashar Mujahid and in this blog, we will discuss MFA and the most common MFA vulnerabilities that might occur.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/multi-factor-authentication-vulnerabilities-7a4b647a7b09?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Musician and Influencer in Bangladesh.

https://cdn-images-1.medium.com/max/2512/1*XisbQto5GF1OoEQRhNJ5wg.jpeg
He believes that “If You Work Hard, You Will Be Success “ & He also said that “Every inch of movement is better then miles of Intentions”…

Continue reading on Medium »
Kali Linux Tutorials
RDPHijack : Uses WinStationConnect API to Perform local/Remote RDP session hijacking

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking. With a valid access token / kerberos ticket (e.g., golden ticket) of the session owner, you will be able to hijack the session remotely without dropping any beacon/tool on the target server.

To enumerate sessions locally/remotely, you could use Quser-BOF.

Usage

Usage: bof-rdphijack [your console session id] [target session id to hijack] [password|server] [argument]
Command Description
password Specifies the password of the user who owns the session to which you want to connect.
server Specifies the remote server that you want to perform RDP hijacking.
Sample usage
Redirect session 2 to session 1 (require SYSTEM privilege):
bof-rdphijack 1 2
Redirect session 2 to session 1 with password of the user who owns the session 2 (require high integrity beacon):
bof-rdphijack 1 2 password P@ssw0rd123
Redirect session 2 to session 1 for a remote server (require token/ticket of the user who owns the session 2):
bof-rdphijack 1 2 server SQL01.lab.internal
Download
Provide pentesting services
https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/

<!-- SC_OFF -->Hello everyone, does anyone know of a website similar to upwork where I can offer pentesting services independently? <!-- SC_ON --> submitted by /u/Equivalent_Year154 (https://www.reddit.com/user/Equivalent_Year154)
[link] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/) [comments] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/)
hacking: security in practice
sirus xm radio spoof mac address

howdy not sure if ok to post hear if not iam sorry for waste peoples time on hear . ok so i am looking in to a way spoof mac a address then try to activate again bypass black list is there any one that could help me out with issue or know of place that could help me out . thank you for your time .

submitted by /u/Unusual-Might-471
[link] [comments]
hacking: security in practice
I miss blackshades

And i aint talkin bout the cracked version either. Anything similar nowadays that will run on Win10-11 that is as stable and somewhat UD? Would kill to go back to the good days. When dubstep was cool.

submitted by /u/lilpill69
[link] [comments]
hacking: security in practice
If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?

If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?

I have a new table for the user “postgres “ called “godransom”…. I tried to delete that and the user but I couldn’t until now,,, Just wondering if I really got hack or if my db just crashed…

submitted by /u/Being_incognito_
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Erbium password-stealing malware spreads as game cracks, cheats

New Erbium password-stealing malware spreads as game cracks, cheatsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The new ‘Erbium’ information-stealing malware is being distributed as fake cracks and cheats for popular video games to steal victims’ credentials and cryptocurrency wallets.Erbium is a new Malware-as-a-Service (MaaS) that provides subscribers with a new information-stealing malware that is gaining popularity in the cybercrime community thanks to its extensive functionality, customer support, and competitive pricing.

Researchers at Cluster25’s team were the first to report on Erbium earlier this month, but a new report by Cyfirma shares further information on how the password-stealing trojan is distributed.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course New Malware-as-a-Service operationErbium has been promoted on Russian-speaking forums since July 2022, but its actual deployment in the wild has been uncertain thus far.

Erbium initially cost $9 per week, but since its popularity rose in late August, the price went up to $100 per month or $1000 for a full-year license.

Compared to the “defacto” choice in the field, RedLine stealer, Erbium’s cost is roughly one-third, so it’s aiming to disrupt the market for malware commonly used by threat actors.

Like other information-stealing malware, Erbium will steal data stored in web browsers (Chromium or Gecko-based), such as passwords, cookies, credit cards, and autofill information.

The malware also attempts to exfiltrate data from a large set of cryptocurrency wallets installed on web browsers as extensions.
https://www.bleepstatic.com/images/news/u/1220909/Tables/targeted-wallets(1).png
<figcaptionTargeted hot cryptocurrency wallets (Cyfirma)
Trending: How to Exploit “improper error handling” in Web Applications Trending: OSINT Tool: Social Hunter
Cold desktop wallets like Exodus, Atomic, Armory, Bitecoin-Core, Bytecoin, Dash-Core, Electrum, Electron, Coinomi, Ethereum, Litecoin-Core, Monero-Core, Zcash, and Jaxx are also stolen.

Erbium also steals two-factor authentication codes from Trezor Password Manager, EOS Authenticator, Authy 2FA, and Authenticator 2FA.

The malware can grab screenshots from all monitors, snatch Steam and Discord tokens, steal Telegram auth files, and profile the host based on the OS and hardware.

All data is exfiltrated to the C2 via a built-in API system, while the operators get an overview of what has been stolen from each infected host on a Erbium dashboard, shown below.
https://www.bleepstatic.com/images/news/u/1220909/Software/dashboard(1).png
<figcaptionErbium’s dashboard (Cyfirma)
The malware uses three URLs for connecting to the panel, including Discord’s Content Delivery Network (CDN), a platform that malware operators have heavily abused.

While Erbium is still a work in progress, users on hacker forums have praised the author’s efforts and willingness to listen to client requests.

Cluster25 reported signs of Erbium infections worldwide, including in the USA, France, Colombia, Spain, Italy, India, Vietnam, and Malaysia.
https://www.bleepstatic.com/images/news/u/1220909/Maps/world-map.png
<figcaptionErbium distribution map (Cluster25)
While the first Erbium campaign uses game cracks as lures, the distribution channels could diversify significantly anytime, as buyers of the malware may choose to push it via different methods.

To keep the threat out of your system, avoid downloading pirated softwa[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Erbium password-stealing malware spreads as game cracks, cheats New Erbium password-stealing malware spreads as game cracks, cheatsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon…
re, scan all downloaded files on an AV tool, and keep your software up to date by installing the latest available security patches.
Trending: Revolut hack: personal and banking data exposed
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-3-1-300x150.png Microsoft SQL servers hacked with FARGO ransomware attacksSeptember 26, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-2-1-300x150.png Python’s Tarfile path traversal bug from 2007 still present in 350k open source reposSeptember 23, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-3-300x150.png Twitter failed to log you out of all devices after password resetsSeptember 22, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-8-300x150.png Rockstar parent company hacked again as 2K Support sends users malwareSeptember 21, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post New Erbium password-stealing malware spreads as game cracks, cheats first appeared on Black Hat Ethical Hacking.
Sent by @TheFeedReaderBot