Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
My Bug Bounty Journey & Ranking 1st in U.S. DoD & Achieving top 100 hackers in 1 year

I am sharing some of my methodology, recourses, tips and advices to become a better bug bounty hunter.
Read more...
Deep Web
Got ahead of myself

I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are people after me, and I don't understand what I could be up against. I put up a VPN and am avoiding answering any calls I don't know. Is there anyone that could give me more information, so I can deal with this?

submitted by /u/mjharris015
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Help me out with the cyber sec proj
https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/

I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. You have to solve the below challenges and create proper report of your finding and approach that how you solved the challenge with supportive proof of concept (POC) in form of screenshot. Web: 1. Fuzzing : http://65.2.6.176:6008/ 2. Post_me: http://65.2.6.176:8003/ 3. Enum: http://65.2.6.176:7003/ 4. Fetch_me: http://65.2.6.176:8007/ 5. Find_me: http://65.2.6.176:9009/ Misc: 1. Founder: https://drive.google.com/file/d/1uAOHxyRV63Qn3gDmZWDa6-dZzmH6qVOU/view?usp=sharing 2. Hex : https://drive.google.com/file/d/1\_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing (https://drive.google.com/file/d/1%5C_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing) 3. Steg_Mirror: https://drive.google.com/file/d/1HHB9Rzbxf2rd_2kbC4craJ44bRvyAKv_/view?usp=sharing Reverse: 1. Hitpass: https://drive.google.com/file/d/1dlGv1nsZlc70Jy5D54wjcQtMny6I36so/view?usp=sharing 2. Goofy: https://drive.google.com/file/d/1NcEP7ab77_539E09fu5lqtLSXHJsNSGa/view?usp=sharing Cryptography 1. Agent_cat: https://drive.google.com/file/d/13NWZXRYW6Jfe_w_hLM2BLB_Q_boJ093z/view?usp=sharing 2. Double_trouble: DJWbMJE5LHAHEagWK2uuqTIsMT91LzkyK2IhL3W5pUEco259 3. Vision: https://drive.google.com/file/d/1Cus7IsGwSn85C_WXP6zt5aDeVg7fvdG5/view?usp=sharing submitted by /u/Crafty-Blacksmith-99 (https://www.reddit.com/user/Crafty-Blacksmith-99)
[link] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lemon Duck Cryptojacking Botnet Changes Up Tactics

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54
Reading Time: 2 Minutes
The Lemon Duck cryptocurrency-mining botnet has added the ProxyLogon group of exploits to its bag of tricks, targeting Microsoft Exchange servers.
That’s according to researchers at Cisco Talos, who said that the cybercrime group behind Lemon Duck has also added the Cobalt Strike attack framework into its malware toolkit and has beefed up anti-detection capabilities. On the latter front, it’s using fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.

Lemon Duck targets victims’ computer resources to mine the Monero virtual currency, with self-propagating capabilities and a modular framework that allows it to infect additional systems that become part of the botnet. It has been active since at least the end of December 2018, and Cisco Talos calls it “one of the more complex” mining botnets, with several interesting tricks up its sleeve.

For instance, Lemon Duck has at least 12 different initial-infection vectors – more than most malware, with Proxylogon exploits only the latest addition. Its existing capabilities ranged from Server Message Block (SMB) and Remote Desktop Protocol (RDP) password brute-forcing; targeting the RDP BlueKeep flaw (CVE-2019-0708) in Windows machines; targeting internet-of-things devices with weak or default passwords; and exploiting vulnerabilities in Redis (an open-source, in-memory data structure store used as a database, cache and message broker) and YARN Hadoop (a resource-management and job-scheduling technology) in Linux machines.
See Also: iPhone Hack Allegedly Used to Spy on China’s Uyghurs
“Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons,” according to an analysis released Friday.

Cisco Talos researchers previously observed an increase in DNS requests connected with Lemon Duck’s C2 and mining servers last August, with the attacks mainly targeting Egypt, India, Iran, the Philippines and Vietnam. In the latest rash of attacks, which began in April, the group has changed up its geographic targets to focus primarily on North America, followed by Europe and Southeast Asia, and a handful of victims in Africa and South America. Targeting Exchange Servers with Monero-MiningProxyLogon consists of four flaws (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials. This gives them access to email communications and the opportunity to install a web shell for further exploitation within the environment, such as the deployment of ransomware.
See Also: Offensive Security Tool: EyeWitness The highly publicized exploit chain suffered a barrage of attacks from advanced persistent threat (APT) groups to infect systems with everything from ransomware to info-stealers, and now financially motivated groups are getting in on the action too.

In Lemon Duck’s case, once the Exchange servers are compromised, it executes various system commands using the Windows Control Manager (sc.exe), including copying two .ASPX files named “wanlins.aspx” and “wanlin.aspx.”

“These files are likely web shells and were copied from C:\inetpub\wwwroot\aspnet_client\, a known directory where[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Lemon Duck Cryptojacking Botnet Changes Up Tactics https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54 Reading Time:…
a majority of the web shells were initially observed following Microsoft’s release of details related to Hafnium activity,” according to the research.

Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell into the previously created ASPX files, and the modification of the Windows registry to enable RDP access to the system.

“In this case, several characteristics matched portions of code associated with known China Chopper variants identified days after the Exchange Server vulnerabilities were publicized,” they noted. See Also: Hacking Stories: Xbox UndergroundOther interesting aspects of the latest campaign include the fact that Lemon Duck executes a PowerShell script that downloads and executes an additional malware payload, “syspstem.dat,” which includes a “killer” module which contains a hardcoded list of competing cryptocurrency miners that Lemon Duck disables. The module is run every 50 minutes.

Also, the malware is now leveraging Certutil to download and execute two new malicious PowerShell scripts, researchers said. Certutil is a native Windows command-line program that is installed as part of Certificate Services. It is used to verify and dump Certificate Authority (CA) information, get and publish new certificate revocation lists, and so on.

One of the PowerShell scripts, named “dn.ps1,” attempts to uninstall multiple antivirus products, and also retrieves a Cobalt Strike payload. Cobalt Strike Added to the MixCobalt Strike is a penetration-testing tool that’s commercially available. It sends out beacons to detect network vulnerabilities. When used for its intended purpose, it simulates an attack. Threat actors have since figured out how to turn it against networks to exfiltrate data, deliver malware and create fake C2 profiles that look legitimate and avoid detection.

Lemon Duck’s Cobalt Strike payload is configured as a Windows DNS beacon and attempts to communicate with the C2 server using a DNS-based covert channel, researchers noted. The beacon then communicates with this specific subdomain to transmit encoded data via DNS A record query requests.

“This represents a new TTP for Lemon Duck, and is another example of their reliance on offensive security tools (OSTs), including Powersploit’s reflective loader and a modified Mimikatz, which are already included as additional modules and components of Lemon Duck and used throughout the typical attack lifecycle,” according to Cisco Talos. Lemon Duck’s Fresh Anti-Detection TricksWhile Lemon Duck casts a wide net in terms of victimology, it has been exclusively using websites within the TLDs for China (“.cn”), Japan (“.jp”) and South Korea (“.kr”) for its C2 activities since February, rather than the more familiar “.com” or “.net.”

“Considering these [TLDs] are most commonly used for websites in their respective countries and languages…this may allow the threat actor to more effectively hide C2 communications among other web traffic present in victim environments,” according to Cisco Talos. “Due to the prevalence of domains using these [TLDs], web traffic to the domains…may be more easily attributed as noise to victims within these countries.”

During the Lemon Duck infection process, PowerShell is used to invoke the “GetHostAddresses” method from the .NET runtime class “Net.Dns” to obtain the current IP address for an attacker-controlled domain, researchers explained.

“This IP address is combined with a fake hostname hardcoded into the PowerShell command and written as an entry to the Windows hosts file,” they said. “This mechanism allows name resolution to continue even if DNS-based security controls are later deployed, as the translation is now recorded locally and future resolution requests no longer rely upon upstream infrastructure such as DNS servers. This may allow the adversary to achieve longer-term persistence once operational in victi[...]

___________________________
@hacking_Attack
@Hacking_Video