Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
True Nature — The Shadowboxer Files
https://cdn-images-1.medium.com/max/2000/1*NdcJEEA8yidV4fKCQM5SeQ.jpeg
It could have been a quiet life. He imagined an old fishing shack stuck on the edge of the water, just a couple of rooms, well insulated…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
True Nature — The Shadowboxer Files
https://cdn-images-1.medium.com/max/2000/1*NdcJEEA8yidV4fKCQM5SeQ.jpeg
It could have been a quiet life. He imagined an old fishing shack stuck on the edge of the water, just a couple of rooms, well insulated…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
True Nature — The Shadowboxer Files
It could have been a quiet life. He imagined an old fishing shack stuck on the edge of the water, just a couple of rooms, well insulated…
CVE-2022–41040 Microsoft Exchange vulnerable to server-side request forgery
Overview:Continue reading on Medium »
Read more...
Overview:Continue reading on Medium »
Read more...
CVE-2022–41040 Microsoft Exchange vulnerable to server-side request forgery
https://medium.com/@Dhamuharker/cve-2022-41040-microsoft-exchange-vulnerable-to-server-side-request-forgery-79de11106ad5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/cve-2022-41040-microsoft-exchange-vulnerable-to-server-side-request-forgery-79de11106ad5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–41040 Microsoft Exchange vulnerable to server-side request forgery
Overview:
Overview:Continue reading on Medium » (https://medium.com/@Dhamuharker/cve-2022-41040-microsoft-exchange-vulnerable-to-server-side-request-forgery-79de11106ad5?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–41040 Microsoft Exchange vulnerable to server-side request forgery
Overview:
hacking: security in practice
I once met a professional hacker on here but lost contact with him...
He was depressed and posted on a subreddit about why he was depressed and wanted dating advice. I gave him my advice and he really like it. So, we struck up a conversation and I was really curious about his hacker world. He said as a rule, he doesn't share content of celebrities. I put him to the test, I had a long lost beau and shared a photo. He not only found him to shared that he was married and divorced. He gave me my old beau's address and I got to reconnect with him. I lost contact with my hacker friend. I hope he is doing well.
submitted by /u/Throwawayiea
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I once met a professional hacker on here but lost contact with him...
He was depressed and posted on a subreddit about why he was depressed and wanted dating advice. I gave him my advice and he really like it. So, we struck up a conversation and I was really curious about his hacker world. He said as a rule, he doesn't share content of celebrities. I put him to the test, I had a long lost beau and shared a photo. He not only found him to shared that he was married and divorced. He gave me my old beau's address and I got to reconnect with him. I lost contact with my hacker friend. I hope he is doing well.
submitted by /u/Throwawayiea
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I once met a professional hacker on here but lost contact with him...
He was depressed and posted on a subreddit about why he was depressed and wanted dating advice. I gave him my advice and he really like it. So, we...
hacking: security in practice
De-indexing a page
Is it possible to hire someone to de-index a news page about you?
Unfortunately the local news paper will not answer my requests and this is destroying my life. I lost two jobs and spent thousands of dollars trying to push it down.
submitted by /u/Traditional-Fig9419
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
De-indexing a page
Is it possible to hire someone to de-index a news page about you?
Unfortunately the local news paper will not answer my requests and this is destroying my life. I lost two jobs and spent thousands of dollars trying to push it down.
submitted by /u/Traditional-Fig9419
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
De-indexing a page
Is it possible to hire someone to de-index a news page about you? Unfortunately the local news paper will not answer my requests and this is...
Pivoting Over TTLS-PAP WPA Enterprise Networks
https://www.reddit.com/r/redteamsec/comments/y1vmcy/pivoting_over_ttlspap_wpa_enterprise_networks/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/pivoting-over-ttls-pap-wifi-network/) [comments] (https://www.reddit.com/r/redteamsec/comments/y1vmcy/pivoting_over_ttlspap_wpa_enterprise_networks/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/y1vmcy/pivoting_over_ttlspap_wpa_enterprise_networks/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/pivoting-over-ttls-pap-wifi-network/) [comments] (https://www.reddit.com/r/redteamsec/comments/y1vmcy/pivoting_over_ttlspap_wpa_enterprise_networks/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pivoting Over TTLS-PAP WPA Enterprise Networks
Posted in r/redteamsec by u/tbhaxor • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DoS website local menggunakan hping3
https://cdn-images-1.medium.com/max/1366/1*Ff04mPeUsZIapZnktTNFCg.png
Baik kali ini saya akan sharing tentang bagaimana cara melakukan serangan DoS menggunakan hping3, di tutorial kali ini akan sangat simpel…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DoS website local menggunakan hping3
https://cdn-images-1.medium.com/max/1366/1*Ff04mPeUsZIapZnktTNFCg.png
Baik kali ini saya akan sharing tentang bagaimana cara melakukan serangan DoS menggunakan hping3, di tutorial kali ini akan sangat simpel…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DoS website local menggunakan hping3
Baik kali ini saya akan sharing tentang bagaimana cara melakukan serangan DoS menggunakan hping3, di tutorial kali ini akan sangat simpel…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Wormhole Hack: 2022’s 2nd Largest DeFi Hack (So Far)
https://cdn-images-1.medium.com/max/2171/1*hrVA_q2FW50_08xw_EC9Mg.png
The Wormhole hack demonstrated that the cryptocurrency industry is more vulnerable than most people think.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Wormhole Hack: 2022’s 2nd Largest DeFi Hack (So Far)
https://cdn-images-1.medium.com/max/2171/1*hrVA_q2FW50_08xw_EC9Mg.png
The Wormhole hack demonstrated that the cryptocurrency industry is more vulnerable than most people think.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Wormhole Hack: 2022’s 2nd Largest DeFi Hack (So Far)
The Wormhole hack demonstrated that the cryptocurrency industry is more vulnerable than most people think.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Meretas password ssh dengan teknik brute force
https://cdn-images-1.medium.com/max/1366/1*jxS3wHM40MVwwRuXhZMayA.png
Halo semuanya, kali ini saya ingin sedikit memberi tau bagaimana cara meretas password ssh dengan teknik brute force, sebelum ke tutorial…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Meretas password ssh dengan teknik brute force
https://cdn-images-1.medium.com/max/1366/1*jxS3wHM40MVwwRuXhZMayA.png
Halo semuanya, kali ini saya ingin sedikit memberi tau bagaimana cara meretas password ssh dengan teknik brute force, sebelum ke tutorial…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Meretas password ssh dengan teknik brute force
Halo semuanya, kali ini saya ingin sedikit memberi tau bagaimana cara meretas password ssh dengan teknik brute force, sebelum ke tutorial…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Critical RCE Vulnerability Found in vm2 Sandbox Library
Critical RCE Vulnerability Found in vm2 Sandbox LibraryPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Researchers are warning of a critical remote code execution flaw in ‘vm2’, a JavaScript sandbox library downloaded over 16 million times per month via the NPM package repository.The vm2 vulnerability is tracked as CVE-2022-36067 and received a severity rating of 10.0, the maximum score in the CVSS system, as it could allow attackers to escape the sandbox environment and run commands on a host system.
Sandboxes are meant to be an isolated environment that is walled off from the rest of the operating system. However, as developers commonly use sandboxes to run or test potentially unsafe code, the ability to “escape” from this confined environment and execute code on the host is a massive security problem.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Escaping the sandboxSecurity researchers at Oxeye have found a clever way to customize the call stack of an error that occurs in VM2 to generate “CallSite” objects created outside the sandbox and use them to access Node’s global objects and execute commands.
While the library’s authors attempted to mitigate this possibility in the past, Oxeye’s researchers found a way to bypass this mitigation mechanism by using a custom implementation of the “prepareStackTrace” method.
“The reporter’s POC bypassed the logic above since vm2 missed wrapping specific methods related to the “WeakMap” JavaScript built-in type,” the researchers explain in their report.
“This allowed the attacker to provide their own implementation of “prepareStackTrace,” then trigger an error, and escape the sandbox.”
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/sandbox-escape-process.png
Update as soon as possibleOxeye’s research team discovered this critical problem on August 16, 2022, and reported it to the VM2 team a couple of days later, who confirmed they had launched an investigation.
Eventually, the authors of the popular library released version 3.9.11 on August 28, 2022, which addressed the sandbox escape and code execution problems.
Software developers are urged to update to the latest VM2 version and replace older releases in their projects as soon as possible.
For end users, it is important to note that it could take a while before virtualization software tools relying on VM2 apply the available security update.
As we saw with Log4Shell, a critical security problem in a widely deployed open-source library may persist for extended periods without the impacted users even knowing they’re vulnerable due to the obscurity in the supply chain.
If you use a sandbox solution, check if it relies on VM2 and whether it’s using the latest version.
Trending: Microsoft SQL servers hacked with FARGO ransomware attacks Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Secur[...]
___________________________
@hacking_Attack
@Hacking_Video
Critical RCE Vulnerability Found in vm2 Sandbox Library
Critical RCE Vulnerability Found in vm2 Sandbox LibraryPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Researchers are warning of a critical remote code execution flaw in ‘vm2’, a JavaScript sandbox library downloaded over 16 million times per month via the NPM package repository.The vm2 vulnerability is tracked as CVE-2022-36067 and received a severity rating of 10.0, the maximum score in the CVSS system, as it could allow attackers to escape the sandbox environment and run commands on a host system.
Sandboxes are meant to be an isolated environment that is walled off from the rest of the operating system. However, as developers commonly use sandboxes to run or test potentially unsafe code, the ability to “escape” from this confined environment and execute code on the host is a massive security problem.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Escaping the sandboxSecurity researchers at Oxeye have found a clever way to customize the call stack of an error that occurs in VM2 to generate “CallSite” objects created outside the sandbox and use them to access Node’s global objects and execute commands.
While the library’s authors attempted to mitigate this possibility in the past, Oxeye’s researchers found a way to bypass this mitigation mechanism by using a custom implementation of the “prepareStackTrace” method.
“The reporter’s POC bypassed the logic above since vm2 missed wrapping specific methods related to the “WeakMap” JavaScript built-in type,” the researchers explain in their report.
“This allowed the attacker to provide their own implementation of “prepareStackTrace,” then trigger an error, and escape the sandbox.”
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/sandbox-escape-process.png
Update as soon as possibleOxeye’s research team discovered this critical problem on August 16, 2022, and reported it to the VM2 team a couple of days later, who confirmed they had launched an investigation.
Eventually, the authors of the popular library released version 3.9.11 on August 28, 2022, which addressed the sandbox escape and code execution problems.
Software developers are urged to update to the latest VM2 version and replace older releases in their projects as soon as possible.
For end users, it is important to note that it could take a while before virtualization software tools relying on VM2 apply the available security update.
As we saw with Log4Shell, a critical security problem in a widely deployed open-source library may persist for extended periods without the impacted users even knowing they’re vulnerable due to the obscurity in the supply chain.
If you use a sandbox solution, check if it relies on VM2 and whether it’s using the latest version.
Trending: Microsoft SQL servers hacked with FARGO ransomware attacks Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Secur[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Critical RCE Vulnerability Found in vm2 Sandbox Library | Black Hat Ethical Hacking
Researchers are warning of a critical remote code execution flaw in 'vm2', a JavaScript sandbox library downloaded over 16 million times per month via the NPM package repository.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Critical RCE Vulnerability Found in vm2 Sandbox Library Critical RCE Vulnerability Found in vm2 Sandbox LibraryPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to…
ity (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-3-300x150.png Zimbra remote code execution vulnerability actively exploited in the wildOctober 11, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-1-300x150.png Intel confirms leaked Alder Lake BIOS Source Code is authenticOctober 10, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-1-1-300x150.png Linux Kernel 5.19.12 bug could damage Intel laptop displaysOctober 7, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-300x150.png Microsoft SQL servers backdoored with new malwareOctober 6, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Critical RCE Vulnerability Found in vm2 Sandbox Library first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-3-300x150.png Zimbra remote code execution vulnerability actively exploited in the wildOctober 11, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-1-300x150.png Intel confirms leaked Alder Lake BIOS Source Code is authenticOctober 10, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-1-1-300x150.png Linux Kernel 5.19.12 bug could damage Intel laptop displaysOctober 7, 2022
Reading Time: 3 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/10/Images-for-the-News-posts-2-300x150.png Microsoft SQL servers backdoored with new malwareOctober 6, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Critical RCE Vulnerability Found in vm2 Sandbox Library first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
IP Address takes you to the friend’s machine
https://medium.com/@krishArse/ip-address-takes-you-to-the-friends-machine-87a488cc43bc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@krishArse/ip-address-takes-you-to-the-friends-machine-87a488cc43bc?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
IP Address takes you to the friend’s machine
Understanding IP Address completly in one article
Understanding IP Address completly in one articleContinue reading on Medium » (https://medium.com/@krishArse/ip-address-takes-you-to-the-friends-machine-87a488cc43bc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
IP Address takes you to the friend’s machine
Understanding IP Address completly in one article
hacking: security in practice
Oh shit
I learned sqlmap and tried to hack with sqlmap my website, and later I found out that when someone wants to order things from that company, they must receive an email for confirmation, but this confirmation no longer goes
Anybody knows how to fix it?
submitted by /u/Rezvord
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Oh shit
I learned sqlmap and tried to hack with sqlmap my website, and later I found out that when someone wants to order things from that company, they must receive an email for confirmation, but this confirmation no longer goes
Anybody knows how to fix it?
submitted by /u/Rezvord
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Oh shit
I learned sqlmap and tried to hack with sqlmap my family's company's website, and later I found out that when someone wants to order things from...