Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
changing edit history on google docs

hey everyone, Is there a way I can change the history of the edits on google docs, and everyone who has access to the document also has the dates changed. please let me know if this is possible.

submitted by /u/PhoPanda7
[link] [comments]
Sent by @TheFeedReaderBot
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
What is redrooms.com?

I found this website while down a rabbit hole, but it seemed a lot like someone's art project. I wasn't sure so I wanted to see if anyone else had insight on this website.

submitted by /u/TestingCorp
[link] [comments]
The simplest way to install go lang ( Go Language )

Hi friends🙏, today we will see another / simplest way to install go lang (Recommended) on kali Linux. This article gives a step by step…Continue reading on Medium »
Read more...
Hi friends🙏, today we will see another / simplest way to install go lang (Recommended) on kali Linux. This article gives a step by step…Continue reading on Medium » (https://medium.com/@sherlock297/the-simplest-way-to-install-go-lang-go-language-3e2f2a2f96ed?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Generating violent misogyny with GPT-3 or How To Model the Mind of an INCEL

DISCLAIMER: Miranda “agquarx” McKennitt doesn’t approve the message of the machine-generated song. We’re not an INCEL — nor a horny and…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Our Goal Of Realistic CTFs

https://cdn-images-1.medium.com/max/600/1*2vMMGi_vW65rYrDPUwC1Ig.png
Train your hacker persistence. The Parrot CTFs experience is a challenge, persist and finally find a solution that models real-life…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft patches Windows zero-day used to drop ransomware

Microsoft patches Windows zero-day used to drop ransomwarePost Views: 37 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Microsoft has fixed a security vulnerability used by threat actors to circumvent the Windows SmartScreen security feature and deliver Magniber ransomware and Qbot malware payloads.The attackers used malicious standalone JavaScript files to exploit the CVE-2022-44698 zero-day to bypass Mark-of-the-Web security warnings displayed by Windows to alert users that files originating from the Internet should be treated with caution.

“An attacker can craft a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging,” Redmond explained on Tuesday.

According to Microsoft, this security flaw can only be exploited using three attack vectors:

* In a web-based attack scenario, an attacker could host a malicious website that exploits the security feature bypass.
* In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file to exploit the bypass.
* Compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass.

However, in all these scenarios, the threat actors would have to trick their targets into opening malicious files or accessing attacker-controlled websites with CVE-2022-44698 exploits.

Microsoft released security updates to address this zero-day during the December 2022 Patch Tuesday after working on a fix for this actively exploited zero-day vulnerability since late October, as the company told BleepingComputer.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course ​Exploited in malware attacksHP’s threat intelligence team first reported in October that phishing attacks were distributing the Magniber ransomware using standalone.JS JavaScript files digitally signed with a malformed as discovered by Will Dormann, a senior vulnerability analyst at ANALYGENCE.

This would cause SmartCheck to error out and allow the malicious files to execute without throwing any security warnings and install the Magniber ransomware, even though it got tagged with a MoTW flag.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/magniber-chain(1).png
<figcaptionMagniber’s JS infection chain (BleepingComputer)
Last month, the same Windows zero-day vulnerability was also abused in phishing attacks to drop the Qbot malware without displaying MOTW security warnings.

As security researcher ProxyLife found, threat actors behind this recent QBot phishing campaign switched to the Windows Mark of the Web zero-day by distributing JS files signed with the same malformed key used in the Magniber ransomware attacks.

QBot (aka Qakbot) is a Windows banking trojan that has evolved into a malware dropper that will steal emails for use in subsequent phishing attacks or deliver additional payloads such as Brute Ratel, Cobalt Strike, and other malware.
Trending: Exploit XSS Injections in a one-line powerful Technique Trending: Offensive Security Tool: Pycrypt The Egregor, Prolock, and Black Basta ransomware operations are also known to have partnered with QBot to gain access to victims’ corporate networks.

During the December 2022 Patch Tuesday, Microsoft also fixed a publicly disclosed zero-day (CVE-2022-44710) that would allow attackers to gain SYSTEM privileges on unpatc[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft patches Windows zero-day used to drop ransomware Microsoft patches Windows zero-day used to drop ransomwarePost Views: 37 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe…
hed Windows 11 systems.
Trending: Kali Linux 2022.4 – New Release adds 6 new tools, Kali NetHunter Update, Azure Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/1-300x150.png JSON syntax hack allowed SQL injection payloads to be smuggled past WAFsDecember 12, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-21-300x150.png Cisco discloses high-severity IP phone bug with exploit codeDecember 9, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft patches Windows zero-day used to drop ransomware first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Most efficient method of proxying Android apps?

Is there a moderately easy way of proxying Android apps to observe https traffic?

Seems like android app API is super insecure compared to web apps.

submitted by /u/thehunter699
[link] [comments]