Hacking Articles Tips Tricks Videos Tutorials
466 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
Cybersecurity Drives Improvements in Business Goals

Deloitte's Future of Cyber study highlights the fact that cybersecurity is an essential part of business success and should not be limited to just mitigating IT risks.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple security update fixes new iOS zero-day used to hack iPhones

Apple security update fixes new iOS zero-day used to hack iPhonesPost Views: 114 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes In security updates released today, Apple has fixed the tenth zero-day vulnerability since the start of the year, with this latest one actively used in attacks against iPhones.The vulnerability was disclosed in security bulletins released today for iOS/iPadOS 15.7.2, Safari 16.2, tvOS 16.2, and macOS Ventura 13.1, with Apple warning that the flaw “may have been actively exploited” against previous versions.

The bug (CVE-2022-42856) is a type confusion issue in Apple’s Webkit web browser browsing engine.

The flaw was discovered by Clément Lecigne of Google’s Threat Analysis Group, allowing maliciously crafted web content to perform arbitrary code execution on a vulnerable device.

Arbitrary code execution could allow the malicious site to execute commands in the operating system, deploy additional malware or spyware, or perform other malicious actions.

Apple addressed the zero-day vulnerability with improved state handling for the following devices iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Patch your iPhones, iPads, and macOS VenturaWhile Apple has disclosed that threat actors actively exploited the vulnerability, they have yet to provide any details on the attacks.

However, as the vulnerability was discovered by Clément Lecigne of Google’s Threat Intelligence Team, we will likely learn more in a future blog post.

This delay in providing details is commonly done to allow users to patch their devices before other threat actors analyze the fixes and develop their own exploits.

Even though this zero-day flaw was likely used in highly-targeted attacks, it is still suggested to install today’s security updates as soon as possible.
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Offensive Security Tool: Pycrypt This is the tenth zero-day fixed by Apple since the start of the year:

* In October, Apple fixed a zero-day in the iOS Kernel (CVE-2022-42827).
* In September, Apple addressed a flaw in the iOS Kernel (CVE-2022-32917).
* In August, it fixed two more zero-days in the iOS Kernel (CVE-2022-32894) and WebKit (CVE-2022-32893)
* In March, Apple patched two zero-day in the Intel Graphics Driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675).
* In February, Apple released security updates to address another WebKit zero-day bug exploited to target iPhones, iPads, and Macs.
* In January, Apple patched another pair of zero-days allowing code execution with kernel privileges (CVE-2022-22587) and web browsing activity tracking (CVE-2022-22594).
Trending: Kali Linux 2022.4 – New Release adds 6 new tools, Kali NetHunter Update, Azure Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-po[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Apple security update fixes new iOS zero-day used to hack iPhones Apple security update fixes new iOS zero-day used to hack iPhonesPost Views: 114 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png…
sts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/1-300x150.png JSON syntax hack allowed SQL injection payloads to be smuggled past WAFsDecember 12, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-21-300x150.png Cisco discloses high-severity IP phone bug with exploit codeDecember 9, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-20-300x150.png New Zerobot malware has 21 exploits for BIG-IP, Zyxel, D-Link devicesDecember 8, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Apple security update fixes new iOS zero-day used to hack iPhones first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Cloning Car Remote

There are loads of universal garage door remote cloners for sale online, some claim to work with rolling codes.

Just in terms of locking / unlocking the doors... can these be used for cloning car keys? If so:

*
has anyone had much luck

*
is there a list of vunerable makes & models

*
do you need the original keys in hand

*
what specs are essential (for the cloner) and can anyone recommend a good value one?
Thanks guys (purely for research and curiosity).

submitted by /u/Different_Carrot_846
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacking Travel Pass Card Dubai

So Dubai has these NOL cards that can be used for RTA bus services and the metro train. It's an NFC card and the balance is inside the physical card itself and not an online server. You can recharge via special machines that ask you to put the card on the nfc reader, insert cash and then after top up you can remove the card.

Another way you can top up is using the official mobile application. The application first take the amount from your credit/debit card then asks you to put the card under the mobile nfc reader so it can add that amount in the card.

What i was thinking is that can we somehow use a rooted android phone to listen to the data that the application is feeding the nol card for the top up, save it and then use some application reuse the data for unlimited balance in nol cards?

submitted by /u/boboqayum
[link] [comments]