Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Web3世界,谁来为我的钱包安全负责?
https://cdn-images-1.medium.com/max/1078/0*dlAmBT1oUHw7PAmN
Blockchain 行业从诞生到现在,安全话题几乎围绕着每个人。虽然越来越多的人进入了这个领域,但安全问题并没有因此而减少,随着应用场景的增多越来越多的安全事件随之出现。安全可以说是区块链行业需要从底层解决的一个巨大问题,没有安全保障海量的互联网用户就不可能进入 Web3…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Web3世界,谁来为我的钱包安全负责?
https://cdn-images-1.medium.com/max/1078/0*dlAmBT1oUHw7PAmN
Blockchain 行业从诞生到现在,安全话题几乎围绕着每个人。虽然越来越多的人进入了这个领域,但安全问题并没有因此而减少,随着应用场景的增多越来越多的安全事件随之出现。安全可以说是区块链行业需要从底层解决的一个巨大问题,没有安全保障海量的互联网用户就不可能进入 Web3…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Web3世界,谁来为我的钱包安全负责?
Blockchain 行业从诞生到现在,安全话题几乎围绕着每个人。虽然越来越多的人进入了这个领域,但安全问题并没有因此而减少,随着应用场景的增多越来越多的安全事件随之出现。安全可以说是区块链行业需要从底层解决的一个巨大问题,没有安全保障海量的互联网用户就不可能进入 Web3…
Bug Bounty Tips and Getting Persistence With Electron Applications
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and moreContinue reading on InfoSec Write-ups »
Read more...
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and moreContinue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chat
Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chatPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A crypto-stealing phishing campaign is underway to bypass multi-factor authentication and gain access to accounts on Coinbase, MetaMask, Crypto.com, and KuCoin and steal cryptocurrency.
The threat actors abuse the Microsoft Azure Web Apps service to host a network of phishing sites and lure victims to them via phishing messages impersonating bogus transaction confirmation requests or suspicious activity detection.
For example, one of the phishing emails seen in the attacks pretended to be from Coinbase, which says they locked the account due to suspicious activity.
https://www.bleepstatic.com/images/news/u/1220909/Phishing/phishing-email(4).png
<figcaptionPhishing email impersonating Coinbase
Source: PIXM
When the targets visit the phishing site, they are presented with a chat window supposedly for ‘customer support,’ controlled by a scammer who directs visitors through a multi-step defrauding process.
PIXM has been tracking this campaign since 2021 when the threat group targeted only Coinbase. Recently, PIXM’s analysts noticed an expansion in the campaign’s targeting scope to include MetaMask, Crypto.com, and KuCoin.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Bypassing 2FAThe first phase of the attack in the fake crypto exchange phishing sites involves a bogus login form followed by a two-factor authentication prompt.
Regardless of the credentials entered during this stage, they will still be stolen by the threat actors. The page then proceeds to a prompt asking for the 2FA code needed to access the account.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/2fa-page.png
<figcaption2FA step of the phishing site
Source: PIXM
The attackers try out the entered credentials on the legitimate website, triggering the sending of a 2FA code to the victim, who then enters a valid 2FA on the phishing site.
The threat actors then attempt to use the entered 2FA code to log in to the victim’s account as long as they act before the timer runs out.
It should be noted that the MetaMask phishing attacks are targeting recovery phrases, rather than credentials or 2FA codes. Chatting with scammersRegardless of whether a 2FA code works, the researchers say that the scammers trigger the next attack stage, which is to launch on-screen chat support.
This is done by displaying a fake error message stating the account has been suspended due to suspicious activity and asking the visitor to contact support to resolve the matter.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/fake-error.png
<figcaptionGenerating a fake login error
Source: PIXM
In this support chat, the threat actors start a conversation with the targeted victim to keep them around in case different credentials, recovery phrases, or 2FA codes are needed for the threat actors to log in to the account.
“They will prompt the user for their username, password, and 2-Factor authentication code directly in the chat,” explains the new PIXM report.
“The criminal will then take this directly to a browser on their machine and again try to access the users account.”
For successfully breached accounts, the victim is still engaged with customer support in case they need to confirm fund transfers while the crooks empty their wallets.
However, for accounts they cannot[...]
Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chat
Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chatPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A crypto-stealing phishing campaign is underway to bypass multi-factor authentication and gain access to accounts on Coinbase, MetaMask, Crypto.com, and KuCoin and steal cryptocurrency.
The threat actors abuse the Microsoft Azure Web Apps service to host a network of phishing sites and lure victims to them via phishing messages impersonating bogus transaction confirmation requests or suspicious activity detection.
For example, one of the phishing emails seen in the attacks pretended to be from Coinbase, which says they locked the account due to suspicious activity.
https://www.bleepstatic.com/images/news/u/1220909/Phishing/phishing-email(4).png
<figcaptionPhishing email impersonating Coinbase
Source: PIXM
When the targets visit the phishing site, they are presented with a chat window supposedly for ‘customer support,’ controlled by a scammer who directs visitors through a multi-step defrauding process.
PIXM has been tracking this campaign since 2021 when the threat group targeted only Coinbase. Recently, PIXM’s analysts noticed an expansion in the campaign’s targeting scope to include MetaMask, Crypto.com, and KuCoin.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Bypassing 2FAThe first phase of the attack in the fake crypto exchange phishing sites involves a bogus login form followed by a two-factor authentication prompt.
Regardless of the credentials entered during this stage, they will still be stolen by the threat actors. The page then proceeds to a prompt asking for the 2FA code needed to access the account.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/2fa-page.png
<figcaption2FA step of the phishing site
Source: PIXM
The attackers try out the entered credentials on the legitimate website, triggering the sending of a 2FA code to the victim, who then enters a valid 2FA on the phishing site.
The threat actors then attempt to use the entered 2FA code to log in to the victim’s account as long as they act before the timer runs out.
It should be noted that the MetaMask phishing attacks are targeting recovery phrases, rather than credentials or 2FA codes. Chatting with scammersRegardless of whether a 2FA code works, the researchers say that the scammers trigger the next attack stage, which is to launch on-screen chat support.
This is done by displaying a fake error message stating the account has been suspended due to suspicious activity and asking the visitor to contact support to resolve the matter.
https://www.bleepstatic.com/images/news/u/1220909/Website%20snaps/fake-error.png
<figcaptionGenerating a fake login error
Source: PIXM
In this support chat, the threat actors start a conversation with the targeted victim to keep them around in case different credentials, recovery phrases, or 2FA codes are needed for the threat actors to log in to the account.
“They will prompt the user for their username, password, and 2-Factor authentication code directly in the chat,” explains the new PIXM report.
“The criminal will then take this directly to a browser on their machine and again try to access the users account.”
For successfully breached accounts, the victim is still engaged with customer support in case they need to confirm fund transfers while the crooks empty their wallets.
However, for accounts they cannot[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chat Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chatPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-cont…
breach through the support chat, the threat actors switch to an alternative method to authenticate their device as “trustworthy” for the cryptocurrency platform.
Trending: How to Exploit “improper error handling” in Web Applications Trending: Recon Tool: Maigret Remote trickeryTo overcome the authenticated device obstacle, the attackers convince the victim to download and install the ‘TeamViewer’ remote access app.
Next, the scammers ask the victims to log in to their cryptocurrency wallet or exchange accounts, and while they do so, the threat actors add a random character in the password field to cause a login failure.
The attacker then asks the victim to paste the password on the TeamViewer chat, uses the password (minus the random character) to login on to their device, and then snatches the device confirmation link sent to the victim to authenticate their device as trusted.
https://www.bleepstatic.com/images/news/u/1220909/Software/trusted-device.png
Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-1-300x150.png AXLocker – a new ransomware that encrypts yours files, and then steals your Discord accountNovember 21, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-1-300x150.png Google Roulette: Developer console trick can trigger XSS in Chromium browsersNovember 18, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-1-300x150.png Updated RapperBot malware targets game servers in DDoS attacksNovember 17, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chat first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Trending: How to Exploit “improper error handling” in Web Applications Trending: Recon Tool: Maigret Remote trickeryTo overcome the authenticated device obstacle, the attackers convince the victim to download and install the ‘TeamViewer’ remote access app.
Next, the scammers ask the victims to log in to their cryptocurrency wallet or exchange accounts, and while they do so, the threat actors add a random character in the password field to cause a login failure.
The attacker then asks the victim to paste the password on the TeamViewer chat, uses the password (minus the random character) to login on to their device, and then snatches the device confirmation link sent to the victim to authenticate their device as trusted.
https://www.bleepstatic.com/images/news/u/1220909/Software/trusted-device.png
Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-1-300x150.png AXLocker – a new ransomware that encrypts yours files, and then steals your Discord accountNovember 21, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-1-300x150.png Google Roulette: Developer console trick can trigger XSS in Chromium browsersNovember 18, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-1-300x150.png Updated RapperBot malware targets game servers in DDoS attacksNovember 17, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-1-300x150.png Mastodon users vulnerable to password-stealing attacksNovember 16, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chat first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty Tips and Getting Persistence With Electron Applications
https://infosecwriteups.com/bug-bounty-tips-and-getting-persistence-with-electron-applications-c538d4dda446?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/bug-bounty-tips-and-getting-persistence-with-electron-applications-c538d4dda446?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty Tips and Getting Persistence With Electron Applications
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and more
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and moreContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/bug-bounty-tips-and-getting-persistence-with-electron-applications-c538d4dda446?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty Tips and Getting Persistence With Electron Applications
By repacking asar files, electron applications, and other bug bounty tips. Starring Signal, Discord, Nordpass, and more
OTP BYPASS RESPONSE MANIPULATION
https://medium.com/@milanjain7906/otp-bypass-response-manipulation-bb3bed07de5c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@milanjain7906/otp-bypass-response-manipulation-bb3bed07de5c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
OTP BYPASS WithOUT RESPONSE MANIPULATION
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…Continue reading on Medium » (https://medium.com/@milanjain7906/otp-bypass-response-manipulation-bb3bed07de5c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
OTP BYPASS WithOUT RESPONSE MANIPULATION
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…
OTP BYPASS WithOUT RESPONSE MANIPULATION
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…Continue reading on Medium »
Read more...
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…Continue reading on Medium »
Read more...
hacking: security in practice
GlacierCTF
Hey everyone!
We are the CTF-Team of the technical University of Graz (Austria). We are hosting our first CTF this weekend and would love for everyone cybersecurity interested to join.
There will be 1500€ in prizes for the best teams! Everyone is welcome, there will be beginner and advanced challenges in categories like PWN, Crypto, Web or Misc.
See you on Friday :)
https://ctf.glacierctf.com/
submitted by /u/king_yumanji
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
GlacierCTF
Hey everyone!
We are the CTF-Team of the technical University of Graz (Austria). We are hosting our first CTF this weekend and would love for everyone cybersecurity interested to join.
There will be 1500€ in prizes for the best teams! Everyone is welcome, there will be beginner and advanced challenges in categories like PWN, Crypto, Web or Misc.
See you on Friday :)
https://ctf.glacierctf.com/
submitted by /u/king_yumanji
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
GlacierCTF
Hey everyone! We are the CTF-Team of the technical University of Graz (Austria). We are hosting our first CTF this weekend and would love for...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SSRF via DNS Rebinding (CVE-2022–4096)
https://cdn-images-1.medium.com/max/1000/0*zsc_3dnU9kq9sY99.png
Hello everyone myself Basavaraj , Today in this writeup I will explain about my 2nd CVE i.e CVE-2022–4096
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
SSRF via DNS Rebinding (CVE-2022–4096)
https://cdn-images-1.medium.com/max/1000/0*zsc_3dnU9kq9sY99.png
Hello everyone myself Basavaraj , Today in this writeup I will explain about my 2nd CVE i.e CVE-2022–4096
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
SSRF via DNS Rebinding (CVE-2022–4096)
Hello everyone myself Basavaraj , Today in this writeup I will explain about my 2nd CVE i.e CVE-2022–4096
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Dark Side of Permits (EIP2612)
https://cdn-images-1.medium.com/max/964/1*_RLKRHgqGQixgOS47Ryyvw.png
Last week Uniswap introduced Permit2 that is a game-changer and the new chapter for all future dapps.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Dark Side of Permits (EIP2612)
https://cdn-images-1.medium.com/max/964/1*_RLKRHgqGQixgOS47Ryyvw.png
Last week Uniswap introduced Permit2 that is a game-changer and the new chapter for all future dapps.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Dark Side of Permits (EIP2612)
Last week Uniswap introduced Permit2 that is a game-changer and the new chapter for all future dapps.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OTP BYPASS WithOUT RESPONSE MANIPULATION
https://cdn-images-1.medium.com/max/1000/1*oaDyMAFriILcMIgUHIatqA.png
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OTP BYPASS WithOUT RESPONSE MANIPULATION
https://cdn-images-1.medium.com/max/1000/1*oaDyMAFriILcMIgUHIatqA.png
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OTP BYPASS WithOUT RESPONSE MANIPULATION
Hii, all! Scriptkiddie is back with a new hacking story. So a few days ago, I was hunting on one of the website where I am able to bypass…
Stegowiper - A Powerful And Flexible Tool To Apply Active Attacks For Disrupting Stegomalware
http://www.kitploit.com/2022/11/stegowiper-powerful-and-flexible-tool.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/11/stegowiper-powerful-and-flexible-tool.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Stegowiper - A Powerful And Flexible Tool To Apply Active Attacks For Disrupting Stegomalware