Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How To Exploit CSRF In DVWA — StackZero

This tutorial will show you how to exploit a CSRF vulnerability in the DVWA. You will learn some techniques to inject a malicious formContinue reading on InfoSec Write-ups »
Read more...
BITRA Comes To Azbit

BITRA is the native currency of the BugSpace cybersecurity project. The team provides bug hunting services to large companies, ensuring…Continue reading on Azbit News »
Read more...
hacking: security in practice
Android hotspot prank

When someone connects on my hotspot, I can make custom images pop up in their whole phone screen

submitted by /u/BaconShadow
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Google Chrome extension used to steal cryptocurrency, passwords

Google Chrome extension used to steal cryptocurrency, passwordsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes An information-stealing Google Chrome browser extension named ‘VenomSoftX’ is being deployed by Windows malware to steal cryptocurrency and clipboard contents as users browse the web. This Chrome extension is being installed by the ViperSoftX Windows malware, which acts as a JavaScript-based RAT (remote access trojan) and cryptocurrency hijacker.

ViperSoftX has been around since 2020, previously disclosed by security researchers Cerberus and Colin Cowie, and in a report by Fortinet.

However, in a new report today by Avast, researchers provide more details regarding the malicious browser extension and how the malware operation has undergone extensive development lately.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Recent activitySince the beginning of 2022, Avast has detected and stopped 93,000 ViperSoftX infection attempts against its customers, mainly impacting the United States, Italy, Brazil, and India.
https://www.bleepstatic.com/images/news/u/1220909/Maps/heatmap(7).png
Infecting ChromeTo stay hidden from the victims, the installed extension masquerades as “Google Sheets 2.1”, supposedly a Google productivity app. In May, security researcher Colin Cowie also spotted the extension installed as ‘Update Manager.’
https://www.bleepstatic.com/images/news/u/1220909/Software/google-sheets.png
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Google Chrome extension used to steal cryptocurrency, passwords Google Chrome extension used to steal cryptocurrency, passwordsPost Views: 2 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/09/Patreon.png…
before it is sent to redirect the money to the attacker instead.”

The services targeted by VenomSoftX are Blockchain.com, Binance, Coinbase, Gate.io, and Kucoin, while the extension also monitors the clipboard for the addition of wallet addresses.
https://www.bleepstatic.com/images/news/malware/venom-hijack.jpg
www.blockchain.comand it tries to hook https://blockchain.info/wallet. It also modifies the getter of the password field to steal entered passwords,” explains Avast.

“Once the request to the API endpoint is sent, the wallet address is extracted from the request, bundled with the password, and sent to the collector as a base64-encoded JSON via MQTT.”

Finally, if a user pastes content into any website, the extension will check if it matches any of the regular expressions shown above, and if so, send the pasted content to the threat actors.

As Google Sheets is normally installed in Google Chrome as an app under chrome://apps/and not an extension, you can check your browser’s extension page to determine if Google Sheets is installed.

If it is installed as an extension, you should remove it and clear your browser data to ensure the
Trending: Windows Kerberos authentication breaks after November updates
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-6-2-300x150.png Attackers bypass Coinbase and MetaMask 2FA via TeamViewer, fake support chatNovember 22, 2022
Reading Time: 5 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-5-1-300x150.png AXLocker – a new ransomware that encrypts yours files, and then steals your Discord accountNovember 21, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-4-1-300x150.png Google Roulette: Developer console trick can trigger XSS in Chromium browsersNovember 18, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/11/Images-for-the-News-posts-8-1-300x150.png Updated RapperBot malware targets game servers in DDoS attacksNovember 17, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Google Chrome extension used to steal cryptocurrency, passwords first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
It focuses on:lightness: native, displays only the device screenperformance: 30~120fps, depending on the devicequality: 1920×1080 or abovelow latency: 35~70ms (https://github.com/Genymobile/scrcpy/pull/646)low startup time: ~1 second to display the first imagenon-intrusiveness: nothing is left installed on the Android deviceuser benefits: no account, no ads, no internet requiredfreedom: free and open source softwareIts features include:recording (https://github.com/Genymobile/scrcpy#recording)mirroring with Android device screen off (https://github.com/Genymobile/scrcpy#turn-screen-off)copy-paste (https://github.com/Genymobile/scrcpy#copy-paste) in both directionsconfigurable quality (https://github.com/Genymobile/scrcpy#capture-configuration)Android device as a webcam (V4L2) (https://github.com/Genymobile/scrcpy#v4l2loopback) (Linux-only)physical keyboard (https://github.com/Genymobile/scrcpy#physical-keyboard-simulation-hid)simulation (https://www.kitploit.com/search/label/Simulation) (HID)physical mouse simulation (HID) (https://github.com/Genymobile/scrcpy#physical-mouse-simulation-hid)OTG mode (https://github.com/Genymobile/scrcpy#otg)and more…RequirementsThe Android device requires at least API 21 (Android 5.0).Make sure you enable adb debugging (https://developer.android.com/studio/command-line/adb.html#Enabling) on your device(s).On some devices, you also need to enable an additional option (https://github.com/Genymobile/scrcpy/issues/70#issuecomment-373286323) to control it using a keyboard and mouse.Get the app SummaryLinux: apt install scrcpyWindows: download (https://github.com/Genymobile/scrcpy/releases/download/v1.24/scrcpy-win64-v1.24.zip)macOS: brew install scrcpyBuild from sources: BUILD (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md) (simplified process (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md#simple))LinuxOn Debian and Ubuntu:apt install scrcpy
On Arch Linux:pacman -S scrcpy
A Snap (https://en.wikipedia.org/wiki/Snappy_(package_manager)) package is available: scrcpy.For Fedora, a COPR (https://fedoraproject.org/wiki/Category:Copr) package is available: scrcpy.For Gentoo, an Ebuild (https://wiki.gentoo.org/wiki/Ebuild) is available: scrcpy/.You can also build the app manually (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md) (simplified process (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md#simple)).WindowsFor Windows, a prebuilt archive with all the dependencies (including adb) is available:scrcpy-win64-v1.24.zip
SHA-256: 6ccb64cba0a3e75715e85a188daeb4f306a1985f8ce123eba92ba74fc9b27367It is also available in Chocolatey (https://chocolatey.org/):choco install scrcpy
choco install adb # if you don't have it yetAnd in Scoop (https://scoop.sh/):scoop install scrcpy
scoop install adb # if you don't have it yetYou can also build the app manually (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md).macOSThe application is available in Homebrew (https://brew.sh/). Just install it:brew install scrcpyYou need adb, accessible from your PATH. If you don't have it yet:brew install android-platform-toolsIt's also available in MacPorts (https://www.macports.org/), which sets up adb for you:sudo port install scrcpyYou can also build the app manually (https://github.com/Genymobile/scrcpy/blob/master/BUILD.md).RunPlug an Android device into your computer, and execute:scrcpyIt accepts command-line arguments, listed by:scrcpy --helpFeaturesCapture configurationReduce sizeSometimes, it is useful to mirror an Android device at a lower resolution to increase performance.To limit both the width and height to some value (e.g. 1024):scrcpy --max-size 1024
scrcpy -m 1024 # short versionThe other dimension is computed so that the Android device aspect ratio is preserved. That way, a device in 1920×1080 will be mirrored at 1024×576.Change bit-rateThe default bit-rate is 8 Mbps. To change the video bitrate (e.g. to 2 Mbps):scrcpy --bit-rate 2M

___________________________
@hacking_Attack
@Hacking_Video
scrcpy -b 2M # short versionLimit frame rateThe capture frame rate can be limited:scrcpy --max-fps 15This is officially supported since Android 10, but may work on earlier versions.The actual capture framerate may be printed to the console:scrcpy --print-fps
It may also be enabled or disabled at any time with MOD+i.CropThe device screen may be cropped to mirror only part of the screen.This is useful, for example, to mirror only one eye of the Oculus Go:scrcpy --crop 1224:1440:0:0 # 1224x1440 at offset (0,0)If --max-size is also specified, resizing is applied after cropping.Lock video orientationTo lock the orientation of the mirroring:scrcpy --lock-video-orientation # initial (current) orientation
scrcpy --lock-video-orientation=0 # natural orientation
scrcpy --lock-video-orientation=1 # 90° counterclockwise
scrcpy --lock-video-orientation=2 # 180°
scrcpy --lock-video-orientation=3 # 90° clockwiseThis affects recording orientation.The window may also be rotated (https://github.com/Genymobile/scrcpy#rotation) independently.EncoderSome devices have more than one encoder, and some of them may cause issues or crash. It is possible to select a different encoder:scrcpy --encoder OMX.qcom.video.encoder.avcTo list the available encoders, you can pass an invalid encoder name; the error will give the available encoders:scrcpy --encoder _CaptureRecordingIt is possible to record the screen while mirroring:scrcpy --record file.mp4
scrcpy -r file.mkvTo disable mirroring while recording:scrcpy --no-display --record file.mp4
scrcpy -Nr file.mkv
# interrupt recording with Ctrl+C"Skipped frames" are recorded, even if they are not displayed in real time (for performance reasons). Frames are timestamped on the device, so packet delay variation (https://en.wikipedia.org/wiki/Packet_delay_variation) does not impact the recorded file.v4l2loopbackOn Linux, it is possible to send the video stream to a v4l2 loopback device, so that the Android device can be opened like a webcam by any v4l2-capable tool.The module v4l2loopback must be installed:sudo apt install v4l2loopback-dkmsTo create a v4l2 device:sudo modprobe v4l2loopbackThis will create a new video device in /dev/videoN, where N is an integer (more options (https://github.com/umlaeute/v4l2loopback#options) are available to create several devices or devices with specific IDs).To list the enabled devices:# requires v4l-utils package
v4l2-ctl --list-devices

# simple but might be sufficient
ls /dev/video*To start scrcpy using a v4l2 sink:scrcpy --v4l2-sink=/dev/videoN
scrcpy --v4l2-sink=/dev/videoN --no-display # disable mirroring window
scrcpy --v4l2-sink=/dev/videoN -N # short version(replace N with the device ID, check with ls /dev/video*)Once enabled, you can open your video stream with a v4l2-capable tool:ffplay -i /dev/videoN
vlc v4l2:///dev/videoN # VLC might add some buffering delayFor example, you could capture the video within OBS (https://obsproject.com/).BufferingIt is possible to add buffering. This increases latency, but reduces jitter (see #2464 (https://github.com/Genymobile/scrcpy/issues/2464)).The option is available for display buffering:scrcpy --display-buffer=50 # add 50 ms buffering for displayand V4L2 sink:scrcpy --v4l2-buffer=500 # add 500 ms buffering for v4l2 sinkConnectionTCP/IP (wireless)Scrcpy uses adb to communicate with the device, and adb can connect (https://developer.android.com/studio/command-line/adb.html#wireless) to a device over TCP/IP. The device must be connected on the same network as the computer.AutomaticAn option --tcpip allows to configure the connection automatically. There are two variants.If the device (accessible at 192.168.1.1 in this example) already listens on a port (typically 5555) for incoming adb connections, then run:scrcpy --tcpip=192.168.1.1 # default port is 5555

___________________________
@hacking_Attack
@Hacking_Video
scrcpy --tcpip=192.168.1.1:5555If adb TCP/IP mode is disabled on the device (or if you don't know the IP address), connect the device over USB, then run:scrcpy --tcpip # without argumentsIt will automatically find the device IP address, enable TCP/IP mode, then connect to the device before starting.ManualAlternatively, it is possible to enable the TCP/IP connection manually using adb:Plug the device into a USB port on your computer.Connect the device to the same Wi-Fi network as your computer.Get your device IP address, in Settings → About phone → Status, or by executing this command:adb shell ip route | awk '{print $9}'Enable adb over TCP/IP on your device: adb tcpip 5555.Unplug your device.Connect to your device: adb connect DEVICE_IP:5555 (replace DEVICE_IPwith the device IP address you found).Run scrcpy as usual.Since Android 11, a Wireless debugging option (https://developer.android.com/studio/command-line/adb#connect-to-a-device-over-wi-fi-android-11+) allows to bypass having to physically connect your device directly to your computer.If the connection randomly drops, run your scrcpy command to reconnect. If it says there are no devices/emulators found, try running adb connect DEVICE_IP:5555 again, and then scrcpy as usual. If it still says there are none found, try running adb disconnect, and then run those two commands again.It may be useful to decrease the bit-rate and the resolution:scrcpy --bit-rate 2M --max-size 800
scrcpy -b2M -m800 # short versionMulti-devicesIf several devices are listed in adb devices, you can specify the serial:scrcpy --serial 0123456789abcdef
scrcpy -s 0123456789abcdef # short versionThe serial may also be provided via the environment variable ANDROID_SERIAL(also used by adb).If the device is connected over TCP/IP:scrcpy --serial 192.168.0.1:5555
scrcpy -s 192.168.0.1:5555 # short versionIf only one device is connected via either USB or TCP/IP, it is possible to select it automatically:# Select the only device connected via USB
scrcpy -d # like adb -d
scrcpy --select-usb # long version

# Select the only device connected via TCP/IP
scrcpy -e # like adb -e
scrcpy --select-tcpip # long versionYou can start several instances of scrcpy for several devices.Autostart on device connectionYou could use AutoAdb (https://github.com/rom1v/autoadb):autoadb scrcpy -s '{}'TunnelsTo connect to a remote device, it is possible to connect a local adb client to a remote adb server (provided they use the same version of the adbprotocol).Remote ADB serverTo connect to a remote adb server, make the server listen on all interfaces:adb kill-server
adb -a nodaemon server start
# keep this openWarning: all communications between clients and the adb server are unencrypted.Suppose that this server is accessible at 192.168.1.2. Then, from another terminal, run scrcpy:# in bash
export ADB_SERVER_SOCKET=tcp:192.168.1.2:5037
scrcpy --tunnel-host=192.168.1.2:: in cmd
set ADB_SERVER_SOCKET=tcp:192.168.1.2:5037
scrcpy --tunnel-host=192.168.1.2# in PowerShell
$env:ADB_SERVER_SOCKET = 'tcp:192.168.1.2:5037'
scrcpy --tunnel-host=192.168.1.2By default, scrcpy uses the local port used for adb forward tunnel establishment (typically 27183, see --port). It is also possible to force a different tunnel port (it may be useful in more complex situations, when more redirections are involved):scrcpy --tunnel-port=1234
SSH tunnelTo communicate with a remote adb server securely, it is preferable to use an SSH tunnel.First, make sure the adb server is running on the remote computer:adb start-serverThen, establish an SSH tunnel: remote 5037 # local 27183 <-- remote 27183 ssh -CN -L5038:localhost:5037 -R27183:localhost:27183 your_remote_computer # keep this open" dir="auto"># local 5038 --> remote 5037
# local 27183 <-- remote 27183
ssh -CN -L5038:localhost:5037 -R27183:localhost:27183 your_remote_computer
# keep this openFrom another terminal, run scrcpy:# in bash
export ADB_SERVER_SOCKET=tcp:localhost:5038

___________________________
@hacking_Attack
@Hacking_Video