Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
VM, Dual boot, or dedicated machine?

What's the best method for hacking/pentesting?

Virtual machine, dual booting into Kali Linux or parrot or something, or just having a separate dedicated computer solely for hacking?

submitted by /u/TheGentlemanJS
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Daily Web App Security | 28 of 100 | Bug bounty basics

In today’s article, we introduce you to the world of bug bountiesContinue reading on Medium »
Read more...
How to Get Into Bug Bounties?( Beginner’s guide)

Hello Future Bug Bounty Hunters!Continue reading on Medium »
Read more...
Reflected XSS using Double Encoding

Bypassing XSS filters using Double EncodingContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Updated RapperBot malware targets game servers in DDoS attacks

Updated RapperBot malware targets game servers in DDoS attacksPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The Mirai-based botnet ‘RapperBot’ has re-emerged via a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers.The malware was discovered by Fortinet researchers last August when it used SSH brute-forcing to spread on Linux servers.

By tracing its activities, the researchers found that RapperBot has been operational since May 2021, but its exact goals were hard to decipher.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/campaigns.png
Lifting the lid on RapperBotFortinet analysts could sample the new variant using C2 communication artifacts collected in the previous campaigns, indicating that this aspect of the botnet’s operation has not changed.

The analysts noticed the new variant featured several differences, including support for Telnet brute-forcing, using the following commands:

* Register (used by the client)
* Keep-Alive/Do nothing
* Stop all DoS attacks and terminate the client
* Perform a DoS attack
* Stop all DoS attacks
* Restart Telnet brute forcing
* Stop Telnet brute forcing

The malware tries to brute force devices using common weak credentials from a hardcoded list, whereas previously, it fetched a list from the C2.

“To optimize brute forcing efforts, the malware compares the server prompt upon connection to a hardcoded list of strings to identify the possible device and then only tries the known credentials for that device,” explains Fortinet.

“Unlike less sophisticated IoT malware, this allows the malware to avoid trying to test a full list of credentials.”

After successfully finding credentials, it reports it to the C2 via port 5123 and then attempts to fetch and install the correct version of the primary payload binary for the detected device architecture.

Currently supported architectures are ARM, MIPS, PowerPC, SH4, and SPARC.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/wget.png
Likely the same operatorsFo[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Updated RapperBot malware targets game servers in DDoS attacks Updated RapperBot malware targets game servers in DDoS attacksPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png…
rtinet believes all detected RapperBot campaigns are orchestrated by the same operators, as newer variants indicate access to the malware’s source code.

Moreover, the C2 communication protocol remains unchanged, the list of credentials used for brute forcing attempts has been the same since August 2021, and there have been no signs of campaign overlaps at this time.

To protect your IoT devices from botnet infections, keep the firmware up to date, change default credentials with a strong and unique password, and place them behind a firewall if possible.
Trending: Azov Ransomware is a wiper, destroying data 666 bytes at a time Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: www.bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-300x150.png Windows Kerberos authentication breaks after November updatesNovember 15, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-300x150.png Russian hacktivists use new Somnia ransomwareNovember 14, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-3-300x150.png Google Pixel screen-lock hack with $70k bug bounty payoutNovember 11, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Updated RapperBot malware targets game servers in DDoS attacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Pentesting CTFs
https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/

All (Jeopardy) CTFs I have participated (Goole, Plaid, etc., etc...) in only had challenges that were based on implementation vulnerabilities. I.e. You get some code (or sometimes not) and you only have to read some flag on the server by exploiting the software without having to nmap etc. the machine and without any priv. escalation. Are there CTFs that provide challenges with all stages of a pentest i.e. Scanning a machine, Finding the vulnerable software and correct operating system, RCE, FIRST FLAG, priv. esc., SECOND FLAG... I failed to find anything but articles that explained the difference between "Real" Pentesting and CTFs... Edit: If possible I would like to avoid Attack-Defense CTFs as they seem really stressful to me. submitted by /u/Hellstorme (https://www.reddit.com/user/Hellstorme)
[link] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/) [comments] (https://www.reddit.com/r/Pentesting/comments/yxnr7q/pentesting_ctfs/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Where to begin

Hello world, how are well hopefully doing well but I came here today to ask you lovely people on this subreddit where to begin my hacking career, I have a limited experience with Linux and networking and some programming here and there.

submitted by /u/Spread-Particular
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video