ChatGPT
https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/
<!-- SC_OFF -->Hey guys , what are your thoughts on chatgpt and how it tends to hide info when asked about payloads or hot topics about hacking, it may answer sometimes tho <!-- SC_ON --> submitted by /u/azersebei (https://www.reddit.com/user/azersebei)
[link] (https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/)
https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/
<!-- SC_OFF -->Hey guys , what are your thoughts on chatgpt and how it tends to hide info when asked about payloads or hot topics about hacking, it may answer sometimes tho <!-- SC_ON --> submitted by /u/azersebei (https://www.reddit.com/user/azersebei)
[link] (https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/zpjsb9/chatgpt/)
Server version Header is visible on some files.
https://www.reddit.com/r/Pentesting/comments/zpk7oo/server_version_header_is_visible_on_some_files/
https://www.reddit.com/r/Pentesting/comments/zpk7oo/server_version_header_is_visible_on_some_files/
submitted by /u/diiidaaadooo (https://www.reddit.com/user/diiidaaadooo)
[link] (https://www.reddit.com/gallery/zpk0ix) [comments] (https://www.reddit.com/r/Pentesting/comments/zpk7oo/server_version_header_is_visible_on_some_files/)
[link] (https://www.reddit.com/gallery/zpk0ix) [comments] (https://www.reddit.com/r/Pentesting/comments/zpk7oo/server_version_header_is_visible_on_some_files/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Starter guide to dirb
dirb is not a vulnerability scanner instead it scan for content(files,folder) that may have some vulnerability.
Continue reading on Medium »
Starter guide to dirb
dirb is not a vulnerability scanner instead it scan for content(files,folder) that may have some vulnerability.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to remove a hacker from my phone
How to remove a hacker from my phone: Your telephone contains a portion of your most private and delicate information. Models incorporate…
Continue reading on Medium »
How to remove a hacker from my phone
How to remove a hacker from my phone: Your telephone contains a portion of your most private and delicate information. Models incorporate…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber Forensics Investigation Course in Delhi
https://cdn-images-1.medium.com/max/820/1*Xl4Jbh81EU1t-sxbvEzzIg.jpeg
Cyber Forensics Investigation Course in Delhi
Continue reading on Medium »
Cyber Forensics Investigation Course in Delhi
https://cdn-images-1.medium.com/max/820/1*Xl4Jbh81EU1t-sxbvEzzIg.jpeg
Cyber Forensics Investigation Course in Delhi
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Glupteba malware is back in action after Google disruption
Glupteba malware is back in action after Google disruptionPost Views: 9 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago.In December 2021, Google managed to cause a massive disruption to the blockchain-enabled botnet, securing the court orders to take control of the botnet’s infrastructure and filing complaints against two Russian operators.
Nozomi now reports that blockchain transactions, TLS certificate registrations, and reverse engineering Glupteba samples show a new, large-scale Glupteba campaign that started in June 2022 and is still ongoing.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Hiding in the blockchainGlupteba is a blockchain-enabled, modular malware that infects Windows devices to mine for cryptocurrency, steal user credentials and cookies, and deploy proxies on Windows systems and IoT devices.
These proxies are later sold as ‘residential proxies’ to other cybercriminals.
The malware is predominantly distributed through malvertising on pay-per-install (PPI) networks and traffic distribution systems (TDS) pushing installers disguised as free software, videos, and movies.
Glupteba utilizes the Bitcoin blockchain to evade disruption by receiving updated lists of command and control servers it should contact for commands to execute.
The botnet’s clients retrieve the C2 server address using a discover function that enumerates Bitcoin wallet servers, retrieves their transactions, and parses them to find an AES encrypted address.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/discover-function.png
<figcaptionDiscover function used for retrieving C2 domains (Nozomi)
This strategy has been employed by Glupteba for several years now, offering resilience against takedowns.
That’s because blockchain transactions cannot be erased, so C2 address takedown efforts have a limited impact on the botnet.
Moreover, without a Bitcoin private key, law enforcement cannot plant payloads onto the controller address, so sudden botnet takeovers or global deactivations like the one that impacted Emotet in early 2021 are impossible.
The only downside is that the Bitcoin blockchain is public, so anyone can access it and scrutinize transactions to gather information.
Trending: A primer on OS Command Injection Attacks
Trending: Digital Forensics Tool: Email Analyzer The return of GluptebaNozomi reports that Glupteba continues to use the blockchain in the same way, today, so its analysts scanned the entire blockchain to unearth hidden C2 domains.
The effort was immense, involving the scrutiny of 1,500 Glupteba samples uploaded to VirusTotal to extract wallet addresses and attempt to decrypt transaction payload data using keys associated with the malware.
Finally, Nozomi used passive DNS records to hunt for Glupteba domains and hosts and examined the latest set of TLS certificates used by the malware to uncover more information about its infrastructure.
The Nozomi investigation identified 15 Bitcoin addresses used in four Glupteba campaigns, with the most recent one starting in June 2022, six months after Google’s disruption. This campaign is still underway.
This campaign uses more Bitcoin addresses than past operations, giving the botnet even more resilience.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/campaigns(1).png
<figcaptionBlockchain transaction diag[...]
Glupteba malware is back in action after Google disruption
Glupteba malware is back in action after Google disruptionPost Views: 9 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago.In December 2021, Google managed to cause a massive disruption to the blockchain-enabled botnet, securing the court orders to take control of the botnet’s infrastructure and filing complaints against two Russian operators.
Nozomi now reports that blockchain transactions, TLS certificate registrations, and reverse engineering Glupteba samples show a new, large-scale Glupteba campaign that started in June 2022 and is still ongoing.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Hiding in the blockchainGlupteba is a blockchain-enabled, modular malware that infects Windows devices to mine for cryptocurrency, steal user credentials and cookies, and deploy proxies on Windows systems and IoT devices.
These proxies are later sold as ‘residential proxies’ to other cybercriminals.
The malware is predominantly distributed through malvertising on pay-per-install (PPI) networks and traffic distribution systems (TDS) pushing installers disguised as free software, videos, and movies.
Glupteba utilizes the Bitcoin blockchain to evade disruption by receiving updated lists of command and control servers it should contact for commands to execute.
The botnet’s clients retrieve the C2 server address using a discover function that enumerates Bitcoin wallet servers, retrieves their transactions, and parses them to find an AES encrypted address.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/discover-function.png
<figcaptionDiscover function used for retrieving C2 domains (Nozomi)
This strategy has been employed by Glupteba for several years now, offering resilience against takedowns.
That’s because blockchain transactions cannot be erased, so C2 address takedown efforts have a limited impact on the botnet.
Moreover, without a Bitcoin private key, law enforcement cannot plant payloads onto the controller address, so sudden botnet takeovers or global deactivations like the one that impacted Emotet in early 2021 are impossible.
The only downside is that the Bitcoin blockchain is public, so anyone can access it and scrutinize transactions to gather information.
Trending: A primer on OS Command Injection Attacks
Trending: Digital Forensics Tool: Email Analyzer The return of GluptebaNozomi reports that Glupteba continues to use the blockchain in the same way, today, so its analysts scanned the entire blockchain to unearth hidden C2 domains.
The effort was immense, involving the scrutiny of 1,500 Glupteba samples uploaded to VirusTotal to extract wallet addresses and attempt to decrypt transaction payload data using keys associated with the malware.
Finally, Nozomi used passive DNS records to hunt for Glupteba domains and hosts and examined the latest set of TLS certificates used by the malware to uncover more information about its infrastructure.
The Nozomi investigation identified 15 Bitcoin addresses used in four Glupteba campaigns, with the most recent one starting in June 2022, six months after Google’s disruption. This campaign is still underway.
This campaign uses more Bitcoin addresses than past operations, giving the botnet even more resilience.
https://www.bleepstatic.com/images/news/u/1220909/Diagrams/campaigns(1).png
<figcaptionBlockchain transaction diag[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Glupteba malware is back in action after Google disruption Glupteba malware is back in action after Google disruptionPost Views: 9 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe…
rams. From left to right, 2022 (most complex), 2021, 2020, and 2019 campaigns (Nozomi)
Additionally, the number of TOR hidden services used as C2 servers has grown ten times since the 2021 campaign, following a similar redundancy approach.
The most prolific address had 11 transactions and communicated to 1,197 samples, with its last activity being registered on November 8, 2022.
Nozomi also reports many Glupteba domain registrations as recently as November 22, 2022, discovered via passive DNS data.
From the above, it’s clear that the Glupteba botnet has returned, and the signs indicate it’s more massive than before and potentially even more resilient, setting up a high number of fallback addresses to resist takedowns by researchers and law enforcement.
Trending: New Python malware backdoors VMware ESXi servers for remote access Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-4-300x150.png Hackers leak personal info allegedly stolen from 5.7M Gemini usersDecember 16, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-2-300x150.png Microsoft patches Windows zero-day used to drop ransomwareDecember 15, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Glupteba malware is back in action after Google disruption first appeared on Black Hat Ethical Hacking.
Additionally, the number of TOR hidden services used as C2 servers has grown ten times since the 2021 campaign, following a similar redundancy approach.
The most prolific address had 11 transactions and communicated to 1,197 samples, with its last activity being registered on November 8, 2022.
Nozomi also reports many Glupteba domain registrations as recently as November 22, 2022, discovered via passive DNS data.
From the above, it’s clear that the Glupteba botnet has returned, and the signs indicate it’s more massive than before and potentially even more resilient, setting up a high number of fallback addresses to resist takedowns by researchers and law enforcement.
Trending: New Python malware backdoors VMware ESXi servers for remote access Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-4-300x150.png Hackers leak personal info allegedly stolen from 5.7M Gemini usersDecember 16, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-2-300x150.png Microsoft patches Windows zero-day used to drop ransomwareDecember 15, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-1-300x150.png Apple security update fixes new iOS zero-day used to hack iPhonesDecember 14, 2022
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Images-for-the-News-posts-300x150.png New Python malware backdoors VMware ESXi servers for remote accessDecember 13, 2022
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Glupteba malware is back in action after Google disruption first appeared on Black Hat Ethical Hacking.
hacking: security in practice
Keep getting password reset emails from all of my accounts
And some random ones on sites I know I never created accounts on. It has been all day today, password verifications or password resets. Should I be worried?
submitted by /u/Dreamchaser_g
[link] [comments]
Keep getting password reset emails from all of my accounts
And some random ones on sites I know I never created accounts on. It has been all day today, password verifications or password resets. Should I be worried?
submitted by /u/Dreamchaser_g
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Dreamware hacking software Windows XP
I was thinking back to when I was younger back in school, there was some software to automate getting elevated privileges, install a keylogger and RAT via usb boot to set up (on winxp and older). I know it would be outdated and useless by now, its just been driving me crazy trying to remember the name. I swear it was dreamware or dream something. If anyone remembers or had used it years ago, help on the name would be appreciated.
submitted by /u/Cautious_Security574
[link] [comments]
Dreamware hacking software Windows XP
I was thinking back to when I was younger back in school, there was some software to automate getting elevated privileges, install a keylogger and RAT via usb boot to set up (on winxp and older). I know it would be outdated and useless by now, its just been driving me crazy trying to remember the name. I swear it was dreamware or dream something. If anyone remembers or had used it years ago, help on the name would be appreciated.
submitted by /u/Cautious_Security574
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pool on the roof - December 19, 2022
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Pool on the roof - December 19, 2022
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Shennina - Automating Host Exploitation With AI
http://www.kitploit.com/2022/12/shennina-automating-host-exploitation.html
http://www.kitploit.com/2022/12/shennina-automating-host-exploitation.html
Shennina is an automated host exploitation framework. The mission of the project is to fully automate the scanning, vulnerability (https://www.kitploit.com/search/label/Vulnerability) scanning/analysis, and exploitation using Artificial Intelligence. Shennina is integrated with Metasploit and Nmap for performing the attacks, as well as being integrated with an in-house Command-and-Control Server for exfiltrating data from compromised machines automatically. This was developed by Mazin Ahmed (https://www.linkedin.com/in/infosecmazinahmed/) and Khalid Farah (https://www.linkedin.com/in/khaledfarah) within the HITB CyberWeek 2019 AI challenge (https://cyberweek.ae/2019/session/hitb-ai-challenge/). The project is developed based on the concept of DeepExploit (https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/DeepExploit) by Isao Takaesu (https://www.linkedin.com/in/isao-takaesu-47485a77/). Shennina scans a set of input targets for available network services, uses its AI engine to identify recommended exploits for the attacks, and then attempts to test and attack the targets. If the attack succeeds, Shennina proceeds with the post-exploitation (https://www.kitploit.com/search/label/Post-Exploitation) phase. The AI engine is initially trained against live targets to learn reliable exploits against remote services. Shennina also supports a "Heuristics" mode for identfying recommended exploits. The documentation can be found in the Docs directory within the project.
Features Automated self-learning approach for finding exploits. High performance (https://www.kitploit.com/search/label/Performance) using managed concurrency design. Intelligent exploits clustering. Post exploitation capabilities. Deception detection. Ransomware simulation capabilities. Automated data exfiltration. Vulnerability scanning mode. Heuristic mode support for recommending exploits. Windows, Linux, and macOS support for agents. Scriptable attack method within the post-exploitation phase. Exploits suggestions for Kernel exploits. Out-of-Band technique testing for exploitation checks. Automated exfiltration (https://www.kitploit.com/search/label/Exfiltration) of important data on compromised servers. Reporting capabilities. Coverage for 40+ TTPs within the MITRE ATT&CK Framework. Supports multi-input targets.
Why are we solving this problem with AI? The problem should be solved by a hash tree without using "AI", however, the HITB Cyber Week AI Challenge required the project to find ways to solve it through AI. Note This project is a security experiment. Legal Disclaimer This project is made for educational and ethical testing purposes only. Usage of Shennina for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Authors Mazin Ahmed (mazin@mazinahmed.net (mailto:mazin@mazinahmed.net)) Khaled Farah (khaled.a.farah@gmail.com (mailto:khaled.a.farah@gmail.com))
Download Shennina (https://github.com/mazen160/shennina)
Features Automated self-learning approach for finding exploits. High performance (https://www.kitploit.com/search/label/Performance) using managed concurrency design. Intelligent exploits clustering. Post exploitation capabilities. Deception detection. Ransomware simulation capabilities. Automated data exfiltration. Vulnerability scanning mode. Heuristic mode support for recommending exploits. Windows, Linux, and macOS support for agents. Scriptable attack method within the post-exploitation phase. Exploits suggestions for Kernel exploits. Out-of-Band technique testing for exploitation checks. Automated exfiltration (https://www.kitploit.com/search/label/Exfiltration) of important data on compromised servers. Reporting capabilities. Coverage for 40+ TTPs within the MITRE ATT&CK Framework. Supports multi-input targets.
Why are we solving this problem with AI? The problem should be solved by a hash tree without using "AI", however, the HITB Cyber Week AI Challenge required the project to find ways to solve it through AI. Note This project is a security experiment. Legal Disclaimer This project is made for educational and ethical testing purposes only. Usage of Shennina for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program. Authors Mazin Ahmed (mazin@mazinahmed.net (mailto:mazin@mazinahmed.net)) Khaled Farah (khaled.a.farah@gmail.com (mailto:khaled.a.farah@gmail.com))
Download Shennina (https://github.com/mazen160/shennina)