Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
is impacted as well. Definitely put this on the top of your test-and-deploy list.” CVE-2021-26419This second critical bug affecting Microsoft’s legacy browser allows RCE, and offers several avenues of attack, according to researchers. “In a web-based attack…
includes the fix for CVE-2021-31207, which made its debut in the 2021 Pwn2Own competition,” he said.

The bug tracked as CVE-2021-31207 is only rated as “moderate,” but the “security feature-bypass exploit was showcased prominently in the Pwn2Own contest and at some point details of the exploit will be published,” Goettl explained. “At that point threat actors will be able to take advantage of the vulnerability if they have not already begun attempting to reverse engineer an exploit.”

There two other publicly disclosed vulnerabilities resolved by Microsoft this month that exist in Common Utilities, found in the NNI open-source toolkit (CVE-2021-31200), and in .NET and Visual Studio (CVE-2021-31204).

“Common Utilities and .NET and Visual Studio are less likely to be targeted, but due to the public disclosures they should not be ignored for long,” Goettl added. Other Notable Microsoft Security Patches for May 2021As for the other patches in the update that stood out to the research community, ZDI’s Childs highlighted a Windows wireless networking information-disclosure bug, tracked as CVE-2020-24587.

“The ZDI doesn’t normally highlight info disclosure bugs, but this one has the potential to be pretty damaging,” Childs said. “This patch fixes a vulnerability that could allow an attacker to disclose the contents of encrypted wireless packets on an affected system. It’s not clear what the range on such an attack would be, but you should assume some proximity is needed. You’ll also note this CVE is from 2020, which could indicate Microsoft has been working on this fix for some time.” Windows Graphics, SharePoint Server PatchesA trio of local privilege escalation flaws – two in the Windows Graphics Component (CVE-2021-31188, CVE-2021-31170) and one in SharePoint Server (CVE-2021-28474) – caught Breen’s eye.

As for the first two, he noted they could be chained with another bug, such as the wormable bug listed above, to become highly dangerous and allow for WannaCry-style attacks.

“This kind of vulnerability is often used by attackers after they have already gained a foothold through an initial infection vector, like phishing or via another exploit like the RCE in HTTP.sys (CVE-2021-31166),” Breen noted via email. “The attackers are looking to increase their privileges so they can move laterally across a network or gain access to other accounts that may have access to more sensitive information.”

Meanwhile, the SharePoint bug allows an authenticated attacker to run code on remote SharePoint Servers.

“As this is post-authentication, it’s likely to be used as part of post-exploitation and lateral movement phases of an attack, rather than the initial-infection vector,” Breen said. “Attackers could gain access to sensitive documents or even replace real documents with weaponized versions, enabling the compromise of more user devices across the organization’s network.” Microsoft Exchange Server PatchesMicrosoft also patched four vulnerabilities in Microsoft Exchange Server. The flaws (CVE-2021-31198, RCE; CVE-2021-31207, spoofing; CVE-2021-31209, security bypass; and CVE-2021-31195, RCE), are all rated important or moderate.

“CVE-2021-31195 is attributed to Orange Tsai of the DEVCORE research team, who was responsible for disclosing the ProxyLogon Exchange Server vulnerabilities that [were] patched in an out-of-band release back in March,” Satnam Narang, staff research engineer with Tenable, told Threatpost. “While none of these flaws are deemed critical in nature, it is a reminder that researchers and attackers are still looking closely at Exchange Server for additional vulnerabilities, so organizations that have yet to update their systems should do so as soon as possible.”

And finally, Ivanti’s Goettl noted that several Microsoft products have reached end-of-life and won’t be getting support going forward.

“This month marks the final update for several Windows 10 and Server [...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
includes the fix for CVE-2021-31207, which made its debut in the 2021 Pwn2Own competition,” he said. The bug tracked as CVE-2021-31207 is only rated as “moderate,” but the “security feature-bypass exploit was showcased prominently in the Pwn2Own contest and…
editions, so make sure you have updated any systems to newer branches to avoid a disruption in security update coverage come June,” he said. “Windows 10 1803 and 1809 and Server 1909 all received their final update on May Patch Tuesday 2021.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Yellow-Duck-Malware-90x90.jpg Lemon Duck Cryptojacking Botnet Changes Up Tactics1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/iPhone-Jailbreak-90x90.jpg iPhone Hack Allegedly Used to Spy on China’s Uyghurs2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/cisco-jabber-90x90.jpg Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-1-90x90.png New Crypto-Stealer ‘Panda’ Spread via Discord6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-90x90.png Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-90x90.jpg Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-90x90.png Chinese hackers targeting Russian nuclear submarine design firm with PortDoor malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/F5-Big-IP-e1619725870974-90x90.jpg F5 Big-IP Vulnerable to Security-Bypass Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-1-90x90.jpg Google Chrome V8 Bug Allows Remote Code-Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/apple_logo_store-90x90.jpg Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses2 weeks ago
The post Wormable Windows Bug Opens Door to DoS, RCE first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
what’s the possibility of someone actually have hacked my pc camera?

earlier on discord come creep decided to tell me that he could see me thru my camera and i’m 15 so it rly freaked me out. we talked for maybe 10 minutes, i never clicked any links or anything from him (other than the discord invite) so is there any way he actually could have hacked my pc camera just from my discord acc or am i just being paranoid LOL sorry if this is dumb i just freaked out

submitted by /u/mirasinkclair
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacker for Hire.

Companies hire hackers to strengthen their IT security. Due to the nature of the hacking profession, finding a hacker for hire can be a…

Continue reading on Medium »
APSoft Webscanner (https://www.kitploit.com/search/label/Webscanner) Version 2
new version of APSoft Webscanner Version 1 (https://github.com/APTeamOfficial/APSoft-WebScanner)
Software pictures