Hacking Articles Tips Tricks Videos Tutorials
is impacted as well. Definitely put this on the top of your test-and-deploy list.” CVE-2021-26419This second critical bug affecting Microsoft’s legacy browser allows RCE, and offers several avenues of attack, according to researchers. “In a web-based attack…
includes the fix for CVE-2021-31207, which made its debut in the 2021 Pwn2Own competition,” he said.
The bug tracked as CVE-2021-31207 is only rated as “moderate,” but the “security feature-bypass exploit was showcased prominently in the Pwn2Own contest and at some point details of the exploit will be published,” Goettl explained. “At that point threat actors will be able to take advantage of the vulnerability if they have not already begun attempting to reverse engineer an exploit.”
There two other publicly disclosed vulnerabilities resolved by Microsoft this month that exist in Common Utilities, found in the NNI open-source toolkit (CVE-2021-31200), and in .NET and Visual Studio (CVE-2021-31204).
“Common Utilities and .NET and Visual Studio are less likely to be targeted, but due to the public disclosures they should not be ignored for long,” Goettl added. Other Notable Microsoft Security Patches for May 2021As for the other patches in the update that stood out to the research community, ZDI’s Childs highlighted a Windows wireless networking information-disclosure bug, tracked as CVE-2020-24587.
“The ZDI doesn’t normally highlight info disclosure bugs, but this one has the potential to be pretty damaging,” Childs said. “This patch fixes a vulnerability that could allow an attacker to disclose the contents of encrypted wireless packets on an affected system. It’s not clear what the range on such an attack would be, but you should assume some proximity is needed. You’ll also note this CVE is from 2020, which could indicate Microsoft has been working on this fix for some time.” Windows Graphics, SharePoint Server PatchesA trio of local privilege escalation flaws – two in the Windows Graphics Component (CVE-2021-31188, CVE-2021-31170) and one in SharePoint Server (CVE-2021-28474) – caught Breen’s eye.
As for the first two, he noted they could be chained with another bug, such as the wormable bug listed above, to become highly dangerous and allow for WannaCry-style attacks.
“This kind of vulnerability is often used by attackers after they have already gained a foothold through an initial infection vector, like phishing or via another exploit like the RCE in HTTP.sys (CVE-2021-31166),” Breen noted via email. “The attackers are looking to increase their privileges so they can move laterally across a network or gain access to other accounts that may have access to more sensitive information.”
Meanwhile, the SharePoint bug allows an authenticated attacker to run code on remote SharePoint Servers.
“As this is post-authentication, it’s likely to be used as part of post-exploitation and lateral movement phases of an attack, rather than the initial-infection vector,” Breen said. “Attackers could gain access to sensitive documents or even replace real documents with weaponized versions, enabling the compromise of more user devices across the organization’s network.” Microsoft Exchange Server PatchesMicrosoft also patched four vulnerabilities in Microsoft Exchange Server. The flaws (CVE-2021-31198, RCE; CVE-2021-31207, spoofing; CVE-2021-31209, security bypass; and CVE-2021-31195, RCE), are all rated important or moderate.
“CVE-2021-31195 is attributed to Orange Tsai of the DEVCORE research team, who was responsible for disclosing the ProxyLogon Exchange Server vulnerabilities that [were] patched in an out-of-band release back in March,” Satnam Narang, staff research engineer with Tenable, told Threatpost. “While none of these flaws are deemed critical in nature, it is a reminder that researchers and attackers are still looking closely at Exchange Server for additional vulnerabilities, so organizations that have yet to update their systems should do so as soon as possible.”
And finally, Ivanti’s Goettl noted that several Microsoft products have reached end-of-life and won’t be getting support going forward.
“This month marks the final update for several Windows 10 and Server [...]
___________________________
@hacking_Attack
@Hacking_Video
The bug tracked as CVE-2021-31207 is only rated as “moderate,” but the “security feature-bypass exploit was showcased prominently in the Pwn2Own contest and at some point details of the exploit will be published,” Goettl explained. “At that point threat actors will be able to take advantage of the vulnerability if they have not already begun attempting to reverse engineer an exploit.”
There two other publicly disclosed vulnerabilities resolved by Microsoft this month that exist in Common Utilities, found in the NNI open-source toolkit (CVE-2021-31200), and in .NET and Visual Studio (CVE-2021-31204).
“Common Utilities and .NET and Visual Studio are less likely to be targeted, but due to the public disclosures they should not be ignored for long,” Goettl added. Other Notable Microsoft Security Patches for May 2021As for the other patches in the update that stood out to the research community, ZDI’s Childs highlighted a Windows wireless networking information-disclosure bug, tracked as CVE-2020-24587.
“The ZDI doesn’t normally highlight info disclosure bugs, but this one has the potential to be pretty damaging,” Childs said. “This patch fixes a vulnerability that could allow an attacker to disclose the contents of encrypted wireless packets on an affected system. It’s not clear what the range on such an attack would be, but you should assume some proximity is needed. You’ll also note this CVE is from 2020, which could indicate Microsoft has been working on this fix for some time.” Windows Graphics, SharePoint Server PatchesA trio of local privilege escalation flaws – two in the Windows Graphics Component (CVE-2021-31188, CVE-2021-31170) and one in SharePoint Server (CVE-2021-28474) – caught Breen’s eye.
As for the first two, he noted they could be chained with another bug, such as the wormable bug listed above, to become highly dangerous and allow for WannaCry-style attacks.
“This kind of vulnerability is often used by attackers after they have already gained a foothold through an initial infection vector, like phishing or via another exploit like the RCE in HTTP.sys (CVE-2021-31166),” Breen noted via email. “The attackers are looking to increase their privileges so they can move laterally across a network or gain access to other accounts that may have access to more sensitive information.”
Meanwhile, the SharePoint bug allows an authenticated attacker to run code on remote SharePoint Servers.
“As this is post-authentication, it’s likely to be used as part of post-exploitation and lateral movement phases of an attack, rather than the initial-infection vector,” Breen said. “Attackers could gain access to sensitive documents or even replace real documents with weaponized versions, enabling the compromise of more user devices across the organization’s network.” Microsoft Exchange Server PatchesMicrosoft also patched four vulnerabilities in Microsoft Exchange Server. The flaws (CVE-2021-31198, RCE; CVE-2021-31207, spoofing; CVE-2021-31209, security bypass; and CVE-2021-31195, RCE), are all rated important or moderate.
“CVE-2021-31195 is attributed to Orange Tsai of the DEVCORE research team, who was responsible for disclosing the ProxyLogon Exchange Server vulnerabilities that [were] patched in an out-of-band release back in March,” Satnam Narang, staff research engineer with Tenable, told Threatpost. “While none of these flaws are deemed critical in nature, it is a reminder that researchers and attackers are still looking closely at Exchange Server for additional vulnerabilities, so organizations that have yet to update their systems should do so as soon as possible.”
And finally, Ivanti’s Goettl noted that several Microsoft products have reached end-of-life and won’t be getting support going forward.
“This month marks the final update for several Windows 10 and Server [...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
includes the fix for CVE-2021-31207, which made its debut in the 2021 Pwn2Own competition,” he said. The bug tracked as CVE-2021-31207 is only rated as “moderate,” but the “security feature-bypass exploit was showcased prominently in the Pwn2Own contest and…
editions, so make sure you have updated any systems to newer branches to avoid a disruption in security update coverage come June,” he said. “Windows 10 1803 and 1809 and Server 1909 all received their final update on May Patch Tuesday 2021.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Yellow-Duck-Malware-90x90.jpg Lemon Duck Cryptojacking Botnet Changes Up Tactics1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/iPhone-Jailbreak-90x90.jpg iPhone Hack Allegedly Used to Spy on China’s Uyghurs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/cisco-jabber-90x90.jpg Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-1-90x90.png New Crypto-Stealer ‘Panda’ Spread via Discord6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-90x90.png Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-90x90.jpg Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-90x90.png Chinese hackers targeting Russian nuclear submarine design firm with PortDoor malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/F5-Big-IP-e1619725870974-90x90.jpg F5 Big-IP Vulnerable to Security-Bypass Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-1-90x90.jpg Google Chrome V8 Bug Allows Remote Code-Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/apple_logo_store-90x90.jpg Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses2 weeks ago
The post Wormable Windows Bug Opens Door to DoS, RCE first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Yellow-Duck-Malware-90x90.jpg Lemon Duck Cryptojacking Botnet Changes Up Tactics1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/iPhone-Jailbreak-90x90.jpg iPhone Hack Allegedly Used to Spy on China’s Uyghurs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/cisco-jabber-90x90.jpg Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-1-90x90.png New Crypto-Stealer ‘Panda’ Spread via Discord6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-90x90.png Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-90x90.jpg Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-90x90.png Chinese hackers targeting Russian nuclear submarine design firm with PortDoor malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/F5-Big-IP-e1619725870974-90x90.jpg F5 Big-IP Vulnerable to Security-Bypass Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-1-90x90.jpg Google Chrome V8 Bug Allows Remote Code-Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/apple_logo_store-90x90.jpg Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses2 weeks ago
The post Wormable Windows Bug Opens Door to DoS, RCE first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/LogicalRiver
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/LogicalRiver
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Closer Look at the DarkSide Ransomware Gang
Posted in r/hacking by u/LogicalRiver • 2 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
WiFi devices going back to 1997 vulnerable to new Frag Attacks
https://external-preview.redd.it/wXNvoVvaE-YWDdCDOflkWkIvXK-cwMVf4njg5sjzxcc.jpg?width=640&crop=smart&auto=webp&s=56a2d902717066930662701948c01fe0587d71eb submitted by /u/LogicalRiver
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
WiFi devices going back to 1997 vulnerable to new Frag Attacks
https://external-preview.redd.it/wXNvoVvaE-YWDdCDOflkWkIvXK-cwMVf4njg5sjzxcc.jpg?width=640&crop=smart&auto=webp&s=56a2d902717066930662701948c01fe0587d71eb submitted by /u/LogicalRiver
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
WiFi devices going back to 1997 vulnerable to new Frag Attacks
Posted in r/hacking by u/LogicalRiver • 2 points and 0 comments
hacking: security in practice
what’s the possibility of someone actually have hacked my pc camera?
earlier on discord come creep decided to tell me that he could see me thru my camera and i’m 15 so it rly freaked me out. we talked for maybe 10 minutes, i never clicked any links or anything from him (other than the discord invite) so is there any way he actually could have hacked my pc camera just from my discord acc or am i just being paranoid LOL sorry if this is dumb i just freaked out
submitted by /u/mirasinkclair
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
what’s the possibility of someone actually have hacked my pc camera?
earlier on discord come creep decided to tell me that he could see me thru my camera and i’m 15 so it rly freaked me out. we talked for maybe 10 minutes, i never clicked any links or anything from him (other than the discord invite) so is there any way he actually could have hacked my pc camera just from my discord acc or am i just being paranoid LOL sorry if this is dumb i just freaked out
submitted by /u/mirasinkclair
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
what’s the possibility of someone actually have hacked my pc camera?
earlier on discord come creep decided to tell me that he could see me thru my camera and i’m 15 so it rly freaked me out. we talked for maybe 10...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tale of CVE-2020–28166
https://cdn-images-1.medium.com/max/735/1*ynvMrhfau3nCCIUrmHH6hQ.jpeg
It is estimated that by the end of 2025, there will be 55.75B IoT Devices, creating connectivity of smart appliances, smart grids…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Tale of CVE-2020–28166
https://cdn-images-1.medium.com/max/735/1*ynvMrhfau3nCCIUrmHH6hQ.jpeg
It is estimated that by the end of 2025, there will be 55.75B IoT Devices, creating connectivity of smart appliances, smart grids…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tale of CVE-2020–28166
It is estimated that by the end of 2025, there will be 55.75B IoT Devices, creating connectivity of smart appliances, smart grids…
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
INSTAGRAM LIKES/FOLLOWERS SITES LINK [2021 UPDATED][METHOD] | AND HOW TO CRASH ANY PC |
https://cdn-images-1.medium.com/max/640/0*5RRcVK9HDYUnp52O.gif
🔥 INSTAGRAM LIKES/FOLLOWERS SITES LINK [2021 UPDATED][METHOD] 🔥
Continue reading on Medium »
INSTAGRAM LIKES/FOLLOWERS SITES LINK [2021 UPDATED][METHOD] | AND HOW TO CRASH ANY PC |
https://cdn-images-1.medium.com/max/640/0*5RRcVK9HDYUnp52O.gif
🔥 INSTAGRAM LIKES/FOLLOWERS SITES LINK [2021 UPDATED][METHOD] 🔥
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Your Complete Introductory Guide to Understanding the MITRE Engenuity ATT&CK Evaluation Results
https://cdn-images-1.medium.com/max/1600/0*y2SG7fzyYSJnrklo
In this post, we explain what the evaluations are, who’s running them, why the evaluations are important, and what’s new in this year’s…
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
Your Complete Introductory Guide to Understanding the MITRE Engenuity ATT&CK Evaluation Results
https://cdn-images-1.medium.com/max/1600/0*y2SG7fzyYSJnrklo
In this post, we explain what the evaluations are, who’s running them, why the evaluations are important, and what’s new in this year’s…
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Your Complete Introductory Guide to Understanding the MITRE Engenuity ATT&CK Evaluation Results
In this post, we explain what the evaluations are, who’s running them, why the evaluations are important, and what’s new in this year’s…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacker for Hire.
Companies hire hackers to strengthen their IT security. Due to the nature of the hacking profession, finding a hacker for hire can be a…
Continue reading on Medium »
Hacker for Hire.
Companies hire hackers to strengthen their IT security. Due to the nature of the hacking profession, finding a hacker for hire can be a…
Continue reading on Medium »
Deep Web
What are some interesting things you have seen while browsing on low security mode/JavaScript enabled on TOR in the deep web
submitted by /u/New_Blue09
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What are some interesting things you have seen while browsing on low security mode/JavaScript enabled on TOR in the deep web
submitted by /u/New_Blue09
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What are some interesting things you have seen while browsing on...
Posted in r/deepweb by u/New_Blue09 • 1 point and 0 comments
APSoft-Web-Scanner-v2 - Powerful Dork Searcher And Vulnerability Scanner For Windows Platform
http://www.kitploit.com/2021/05/apsoft-web-scanner-v2-powerful-dork.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/05/apsoft-web-scanner-v2-powerful-dork.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
APSoft-Web-Scanner-v2 - Powerful Dork Searcher And Vulnerability Scanner For Windows Platform
APSoft Webscanner (https://www.kitploit.com/search/label/Webscanner) Version 2
new version of APSoft Webscanner Version 1 (https://github.com/APTeamOfficial/APSoft-WebScanner)
Software pictures
new version of APSoft Webscanner Version 1 (https://github.com/APTeamOfficial/APSoft-WebScanner)
Software pictures