Kali Linux Tutorials
RDPHijack : Uses WinStationConnect API to Perform local/Remote RDP session hijacking
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking. With a valid access token / kerberos ticket (e.g., golden ticket) of the session owner, you will be able to hijack the session remotely without dropping any beacon/tool on the target server.
To enumerate sessions locally/remotely, you could use Quser-BOF.
Usage
Usage: bof-rdphijack [your console session id] [target session id to hijack] [password|server] [argument]
Command Description
password Specifies the password of the user who owns the session to which you want to connect.
server Specifies the remote server that you want to perform RDP hijacking.
Sample usage
Redirect session 2 to session 1 (require SYSTEM privilege):
bof-rdphijack 1 2
Redirect session 2 to session 1 with password of the user who owns the session 2 (require high integrity beacon):
bof-rdphijack 1 2 password P@ssw0rd123
Redirect session 2 to session 1 for a remote server (require token/ticket of the user who owns the session 2):
bof-rdphijack 1 2 server SQL01.lab.internal
Download
RDPHijack : Uses WinStationConnect API to Perform local/Remote RDP session hijacking
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking. With a valid access token / kerberos ticket (e.g., golden ticket) of the session owner, you will be able to hijack the session remotely without dropping any beacon/tool on the target server.
To enumerate sessions locally/remotely, you could use Quser-BOF.
Usage
Usage: bof-rdphijack [your console session id] [target session id to hijack] [password|server] [argument]
Command Description
password Specifies the password of the user who owns the session to which you want to connect.
server Specifies the remote server that you want to perform RDP hijacking.
Sample usage
Redirect session 2 to session 1 (require SYSTEM privilege):
bof-rdphijack 1 2
Redirect session 2 to session 1 with password of the user who owns the session 2 (require high integrity beacon):
bof-rdphijack 1 2 password P@ssw0rd123
Redirect session 2 to session 1 for a remote server (require token/ticket of the user who owns the session 2):
bof-rdphijack 1 2 server SQL01.lab.internal
Download
Kali Linux Tutorials
RDPHijack : Uses WinStationConnect API to Perform local/Remote RDP
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking. With a valid access .
Provide pentesting services
https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/
<!-- SC_OFF -->Hello everyone, does anyone know of a website similar to upwork where I can offer pentesting services independently? <!-- SC_ON --> submitted by /u/Equivalent_Year154 (https://www.reddit.com/user/Equivalent_Year154)
[link] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/) [comments] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/)
https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/
<!-- SC_OFF -->Hello everyone, does anyone know of a website similar to upwork where I can offer pentesting services independently? <!-- SC_ON --> submitted by /u/Equivalent_Year154 (https://www.reddit.com/user/Equivalent_Year154)
[link] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/) [comments] (https://www.reddit.com/r/redteamsec/comments/xp8euj/provide_pentesting_services/)
hacking: security in practice
Is a Bachelors degree in Cyber Security worth it?
Want to pursue a cyber security degree in Texas.
submitted by /u/South_Calligrapher62
[link] [comments]
Is a Bachelors degree in Cyber Security worth it?
Want to pursue a cyber security degree in Texas.
submitted by /u/South_Calligrapher62
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
sirus xm radio spoof mac address
howdy not sure if ok to post hear if not iam sorry for waste peoples time on hear . ok so i am looking in to a way spoof mac a address then try to activate again bypass black list is there any one that could help me out with issue or know of place that could help me out . thank you for your time .
submitted by /u/Unusual-Might-471
[link] [comments]
sirus xm radio spoof mac address
howdy not sure if ok to post hear if not iam sorry for waste peoples time on hear . ok so i am looking in to a way spoof mac a address then try to activate again bypass black list is there any one that could help me out with issue or know of place that could help me out . thank you for your time .
submitted by /u/Unusual-Might-471
[link] [comments]
reddit
sirus xm radio spoof mac address
howdy not sure if ok to post hear if not iam sorry for waste peoples time on hear . ok so i am looking in to a way spoof mac a address then try to...
hacking: security in practice
I miss blackshades
And i aint talkin bout the cracked version either. Anything similar nowadays that will run on Win10-11 that is as stable and somewhat UD? Would kill to go back to the good days. When dubstep was cool.
submitted by /u/lilpill69
[link] [comments]
I miss blackshades
And i aint talkin bout the cracked version either. Anything similar nowadays that will run on Win10-11 that is as stable and somewhat UD? Would kill to go back to the good days. When dubstep was cool.
submitted by /u/lilpill69
[link] [comments]
reddit
I miss blackshades
And i aint talkin bout the cracked version either. Anything similar nowadays that will run on Win10-11 that is as stable and somewhat UD? Would...
hacking: security in practice
If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?
If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?
I have a new table for the user “postgres “ called “godransom”…. I tried to delete that and the user but I couldn’t until now,,, Just wondering if I really got hack or if my db just crashed…
submitted by /u/Being_incognito_
[link] [comments]
If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?
If all my database/tables disappeared from Postgres and some mysterious table appeared, got hacked right;)?
I have a new table for the user “postgres “ called “godransom”…. I tried to delete that and the user but I couldn’t until now,,, Just wondering if I really got hack or if my db just crashed…
submitted by /u/Being_incognito_
[link] [comments]
reddit
If all my database/tables disappeared from Postgres and some...
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Erbium password-stealing malware spreads as game cracks, cheats
New Erbium password-stealing malware spreads as game cracks, cheatsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The new ‘Erbium’ information-stealing malware is being distributed as fake cracks and cheats for popular video games to steal victims’ credentials and cryptocurrency wallets.Erbium is a new Malware-as-a-Service (MaaS) that provides subscribers with a new information-stealing malware that is gaining popularity in the cybercrime community thanks to its extensive functionality, customer support, and competitive pricing.
Researchers at Cluster25’s team were the first to report on Erbium earlier this month, but a new report by Cyfirma shares further information on how the password-stealing trojan is distributed.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course New Malware-as-a-Service operationErbium has been promoted on Russian-speaking forums since July 2022, but its actual deployment in the wild has been uncertain thus far.
Erbium initially cost $9 per week, but since its popularity rose in late August, the price went up to $100 per month or $1000 for a full-year license.
Compared to the “defacto” choice in the field, RedLine stealer, Erbium’s cost is roughly one-third, so it’s aiming to disrupt the market for malware commonly used by threat actors.
Like other information-stealing malware, Erbium will steal data stored in web browsers (Chromium or Gecko-based), such as passwords, cookies, credit cards, and autofill information.
The malware also attempts to exfiltrate data from a large set of cryptocurrency wallets installed on web browsers as extensions.
https://www.bleepstatic.com/images/news/u/1220909/Tables/targeted-wallets(1).png
<figcaptionTargeted hot cryptocurrency wallets (Cyfirma)
Trending: How to Exploit “improper error handling” in Web Applications Trending: OSINT Tool: Social Hunter
Cold desktop wallets like Exodus, Atomic, Armory, Bitecoin-Core, Bytecoin, Dash-Core, Electrum, Electron, Coinomi, Ethereum, Litecoin-Core, Monero-Core, Zcash, and Jaxx are also stolen.
Erbium also steals two-factor authentication codes from Trezor Password Manager, EOS Authenticator, Authy 2FA, and Authenticator 2FA.
The malware can grab screenshots from all monitors, snatch Steam and Discord tokens, steal Telegram auth files, and profile the host based on the OS and hardware.
All data is exfiltrated to the C2 via a built-in API system, while the operators get an overview of what has been stolen from each infected host on a Erbium dashboard, shown below.
https://www.bleepstatic.com/images/news/u/1220909/Software/dashboard(1).png
<figcaptionErbium’s dashboard (Cyfirma)
The malware uses three URLs for connecting to the panel, including Discord’s Content Delivery Network (CDN), a platform that malware operators have heavily abused.
While Erbium is still a work in progress, users on hacker forums have praised the author’s efforts and willingness to listen to client requests.
Cluster25 reported signs of Erbium infections worldwide, including in the USA, France, Colombia, Spain, Italy, India, Vietnam, and Malaysia.
https://www.bleepstatic.com/images/news/u/1220909/Maps/world-map.png
<figcaptionErbium distribution map (Cluster25)
While the first Erbium campaign uses game cracks as lures, the distribution channels could diversify significantly anytime, as buyers of the malware may choose to push it via different methods.
To keep the threat out of your system, avoid downloading pirated softwa[...]
New Erbium password-stealing malware spreads as game cracks, cheats
New Erbium password-stealing malware spreads as game cracks, cheatsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The new ‘Erbium’ information-stealing malware is being distributed as fake cracks and cheats for popular video games to steal victims’ credentials and cryptocurrency wallets.Erbium is a new Malware-as-a-Service (MaaS) that provides subscribers with a new information-stealing malware that is gaining popularity in the cybercrime community thanks to its extensive functionality, customer support, and competitive pricing.
Researchers at Cluster25’s team were the first to report on Erbium earlier this month, but a new report by Cyfirma shares further information on how the password-stealing trojan is distributed.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course New Malware-as-a-Service operationErbium has been promoted on Russian-speaking forums since July 2022, but its actual deployment in the wild has been uncertain thus far.
Erbium initially cost $9 per week, but since its popularity rose in late August, the price went up to $100 per month or $1000 for a full-year license.
Compared to the “defacto” choice in the field, RedLine stealer, Erbium’s cost is roughly one-third, so it’s aiming to disrupt the market for malware commonly used by threat actors.
Like other information-stealing malware, Erbium will steal data stored in web browsers (Chromium or Gecko-based), such as passwords, cookies, credit cards, and autofill information.
The malware also attempts to exfiltrate data from a large set of cryptocurrency wallets installed on web browsers as extensions.
https://www.bleepstatic.com/images/news/u/1220909/Tables/targeted-wallets(1).png
<figcaptionTargeted hot cryptocurrency wallets (Cyfirma)
Trending: How to Exploit “improper error handling” in Web Applications Trending: OSINT Tool: Social Hunter
Cold desktop wallets like Exodus, Atomic, Armory, Bitecoin-Core, Bytecoin, Dash-Core, Electrum, Electron, Coinomi, Ethereum, Litecoin-Core, Monero-Core, Zcash, and Jaxx are also stolen.
Erbium also steals two-factor authentication codes from Trezor Password Manager, EOS Authenticator, Authy 2FA, and Authenticator 2FA.
The malware can grab screenshots from all monitors, snatch Steam and Discord tokens, steal Telegram auth files, and profile the host based on the OS and hardware.
All data is exfiltrated to the C2 via a built-in API system, while the operators get an overview of what has been stolen from each infected host on a Erbium dashboard, shown below.
https://www.bleepstatic.com/images/news/u/1220909/Software/dashboard(1).png
<figcaptionErbium’s dashboard (Cyfirma)
The malware uses three URLs for connecting to the panel, including Discord’s Content Delivery Network (CDN), a platform that malware operators have heavily abused.
While Erbium is still a work in progress, users on hacker forums have praised the author’s efforts and willingness to listen to client requests.
Cluster25 reported signs of Erbium infections worldwide, including in the USA, France, Colombia, Spain, Italy, India, Vietnam, and Malaysia.
https://www.bleepstatic.com/images/news/u/1220909/Maps/world-map.png
<figcaptionErbium distribution map (Cluster25)
While the first Erbium campaign uses game cracks as lures, the distribution channels could diversify significantly anytime, as buyers of the malware may choose to push it via different methods.
To keep the threat out of your system, avoid downloading pirated softwa[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Erbium password-stealing malware spreads as game cracks, cheats New Erbium password-stealing malware spreads as game cracks, cheatsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon…
re, scan all downloaded files on an AV tool, and keep your software up to date by installing the latest available security patches.
Trending: Revolut hack: personal and banking data exposed
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-3-1-300x150.png Microsoft SQL servers hacked with FARGO ransomware attacksSeptember 26, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-2-1-300x150.png Python’s Tarfile path traversal bug from 2007 still present in 350k open source reposSeptember 23, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-3-300x150.png Twitter failed to log you out of all devices after password resetsSeptember 22, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-8-300x150.png Rockstar parent company hacked again as 2K Support sends users malwareSeptember 21, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post New Erbium password-stealing malware spreads as game cracks, cheats first appeared on Black Hat Ethical Hacking.
➖ Sent by @TheFeedReaderBot ➖
Trending: Revolut hack: personal and banking data exposed
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-3-1-300x150.png Microsoft SQL servers hacked with FARGO ransomware attacksSeptember 26, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-2-1-300x150.png Python’s Tarfile path traversal bug from 2007 still present in 350k open source reposSeptember 23, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-1-3-300x150.png Twitter failed to log you out of all devices after password resetsSeptember 22, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Images-for-the-News-posts-8-300x150.png Rockstar parent company hacked again as 2K Support sends users malwareSeptember 21, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post New Erbium password-stealing malware spreads as game cracks, cheats first appeared on Black Hat Ethical Hacking.
➖ Sent by @TheFeedReaderBot ➖
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Researchers Identify 3 Hacktivist Groups Supporting?
https://cdn-images-1.medium.com/max/728/0*O6FFlb48mlktgUx4.jpg
At least three alleged hacktivist groups working in support of Russian interests are likely doing so in collaboration with state-sponsored…
Continue reading on Medium »
Researchers Identify 3 Hacktivist Groups Supporting?
https://cdn-images-1.medium.com/max/728/0*O6FFlb48mlktgUx4.jpg
At least three alleged hacktivist groups working in support of Russian interests are likely doing so in collaboration with state-sponsored…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
10 Deadliest Computer Viruses You Wish Didn’t Exist.
https://cdn-images-1.medium.com/max/640/1*6lIv6nEnkd2MPEL6YP-rkQ.jpeg
Has your computer even been attacked by a computer virus? Do you have malware detection and protection installed on your computer? Or like…
Continue reading on Medium »
10 Deadliest Computer Viruses You Wish Didn’t Exist.
https://cdn-images-1.medium.com/max/640/1*6lIv6nEnkd2MPEL6YP-rkQ.jpeg
Has your computer even been attacked by a computer virus? Do you have malware detection and protection installed on your computer? Or like…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Linux is no more safe as you think.
https://cdn-images-1.medium.com/max/744/1*cNuVMoqvzxNYbeUKOFOEJg.jpeg
Ransomware attacks that target Linux are increasing as cybercriminals want to broaden their options by focusing their attention on an…
Continue reading on Medium »
Linux is no more safe as you think.
https://cdn-images-1.medium.com/max/744/1*cNuVMoqvzxNYbeUKOFOEJg.jpeg
Ransomware attacks that target Linux are increasing as cybercriminals want to broaden their options by focusing their attention on an…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Chinese Espionage Hackers Target Tibetans?
https://cdn-images-1.medium.com/max/1200/0*KATcDHngEtvoA1iu
A China-aligned advanced persistent threat actor known as TA413 weaponized recently disclosed flaws in Sophos Firewall and Microsoft…
Continue reading on Medium »
Chinese Espionage Hackers Target Tibetans?
https://cdn-images-1.medium.com/max/1200/0*KATcDHngEtvoA1iu
A China-aligned advanced persistent threat actor known as TA413 weaponized recently disclosed flaws in Sophos Firewall and Microsoft…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe Startup Walkthrough (Step by Step)
https://cdn-images-1.medium.com/max/1121/1*3h_vW5Fjd-dYE85OTRJvVw.png
This is a walkthrough of the TryHackMe challenge ‘Startup’. This practice test is considered easy according to THM so let’s explore and…
Continue reading on Medium »
TryHackMe Startup Walkthrough (Step by Step)
https://cdn-images-1.medium.com/max/1121/1*3h_vW5Fjd-dYE85OTRJvVw.png
This is a walkthrough of the TryHackMe challenge ‘Startup’. This practice test is considered easy according to THM so let’s explore and…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mitmproxy and Kubernetes
https://cdn-images-1.medium.com/max/2600/1*G8RbErO2MznCS3gL0ByEtA.png
Solving the untrusted certificate issues in pods !!
Continue reading on Medium »
Mitmproxy and Kubernetes
https://cdn-images-1.medium.com/max/2600/1*G8RbErO2MznCS3gL0ByEtA.png
Solving the untrusted certificate issues in pods !!
Continue reading on Medium »