Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw
Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawPost Views: 48 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Microsoft says Cuba ransomware threat actors are hacking Microsoft Exchange servers unpatched against a critical server-side request forgery (SSRF) vulnerability also exploited in Play ransomware attacks.Cloud computing provider Rackspace recently confirmed that Play ransomware used a zero-day exploit dubbed OWASSRF targeting this bug (CVE-2022-41080) to compromise unpatched Microsoft Exchange servers on its network after bypassing ProxyNotShell URL rewrite mitigations.
According to Microsoft, the Play ransomware gang has abused this security flaw since late November 2022. The company advises customers to prioritize CVE-2022-41080 patching to block potential attacks.
Redmond says that this SSRF vulnerability has also been exploited since at least November 17th by another threat group it tracks as DEV-0671 to hack Exchange servers and deploy Cuba ransomware payloads.
Microsoft shared this info in a January update to a private threat analytics report seen by BleepingComputer and available to customers with Microsoft 365 Defender, Microsoft Defender for Endpoint Plan 2, or Microsoft Defender for Business subscriptions.
While Microsoft released security updates to address this SSRF Exchange vulnerability on November 8th and has provided some of its customers with info that ransomware gangs are using the flaw, the advisory is yet to be updated to warn that it’s being exploited in the wild.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Patch your Exchange servers against OWASSRF attacksThe OWASSRF exploit spotted by CrowdStrike security researchers on Rackspaces’s network was also shared online together with some of Play ransomware’s other malicious tools.
This will make it easier for other cybercriminals to adapt Play ransomware’s tooling for their own purposes or create their own custom CVE-2022-41080 exploits, adding to the urgency of patching the vulnerability as soon as possible.
On Tuesday, Cybersecurity and Infrastructure Security Agency (CISA) also ordered Federal Civilian Executive Branch Agencies (FCEB) agencies to patch their systems against this bug by January 31st and strongly urged all organizations to secure their Exchange servers to thwart exploitation attempts.
Organizations with on-premises Microsoft Exchange servers on their networks should deploy the latest Exchange security updates immediately (with November 2022 as the minimum patch level) or disable Outlook Web Access (OWA) until they can apply CVE-2022-41080 patches.
Trending: Operation OpRussia – Anonymous attacks on Russia
Trending: Digital Forensics Tool: Dangerzone Cuba ransomware behind more than 100 attacks worldwideThe FBI and CISA revealed in a joint security advisory issued last month that the Cuba ransomware gang has raked in more than $60 million in ransoms as of August 2022 after breaching over 100 victims worldwide.
Although this paints a bleak picture, samples submitted by victims to the ID-Ransomware platform analysis show that the gang is not very active, proving that even a somewhat inactive ransomware operation can have a huge impact.
https://www.bleepstatic.com/images/news/u/1109292/2023/Cuba%20ransomware%20ID-Ransomware%20sample%20submissions.png
<figcaptionCuba ransomware sample submissions (ID-Ransomware)
Another FBI advisory from December 2021 warned that the ransomware group had compromised a[...]
Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw
Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawPost Views: 48 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Microsoft says Cuba ransomware threat actors are hacking Microsoft Exchange servers unpatched against a critical server-side request forgery (SSRF) vulnerability also exploited in Play ransomware attacks.Cloud computing provider Rackspace recently confirmed that Play ransomware used a zero-day exploit dubbed OWASSRF targeting this bug (CVE-2022-41080) to compromise unpatched Microsoft Exchange servers on its network after bypassing ProxyNotShell URL rewrite mitigations.
According to Microsoft, the Play ransomware gang has abused this security flaw since late November 2022. The company advises customers to prioritize CVE-2022-41080 patching to block potential attacks.
Redmond says that this SSRF vulnerability has also been exploited since at least November 17th by another threat group it tracks as DEV-0671 to hack Exchange servers and deploy Cuba ransomware payloads.
Microsoft shared this info in a January update to a private threat analytics report seen by BleepingComputer and available to customers with Microsoft 365 Defender, Microsoft Defender for Endpoint Plan 2, or Microsoft Defender for Business subscriptions.
While Microsoft released security updates to address this SSRF Exchange vulnerability on November 8th and has provided some of its customers with info that ransomware gangs are using the flaw, the advisory is yet to be updated to warn that it’s being exploited in the wild.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course Patch your Exchange servers against OWASSRF attacksThe OWASSRF exploit spotted by CrowdStrike security researchers on Rackspaces’s network was also shared online together with some of Play ransomware’s other malicious tools.
This will make it easier for other cybercriminals to adapt Play ransomware’s tooling for their own purposes or create their own custom CVE-2022-41080 exploits, adding to the urgency of patching the vulnerability as soon as possible.
On Tuesday, Cybersecurity and Infrastructure Security Agency (CISA) also ordered Federal Civilian Executive Branch Agencies (FCEB) agencies to patch their systems against this bug by January 31st and strongly urged all organizations to secure their Exchange servers to thwart exploitation attempts.
Organizations with on-premises Microsoft Exchange servers on their networks should deploy the latest Exchange security updates immediately (with November 2022 as the minimum patch level) or disable Outlook Web Access (OWA) until they can apply CVE-2022-41080 patches.
Trending: Operation OpRussia – Anonymous attacks on Russia
Trending: Digital Forensics Tool: Dangerzone Cuba ransomware behind more than 100 attacks worldwideThe FBI and CISA revealed in a joint security advisory issued last month that the Cuba ransomware gang has raked in more than $60 million in ransoms as of August 2022 after breaching over 100 victims worldwide.
Although this paints a bleak picture, samples submitted by victims to the ID-Ransomware platform analysis show that the gang is not very active, proving that even a somewhat inactive ransomware operation can have a huge impact.
https://www.bleepstatic.com/images/news/u/1109292/2023/Cuba%20ransomware%20ID-Ransomware%20sample%20submissions.png
<figcaptionCuba ransomware sample submissions (ID-Ransomware)
Another FBI advisory from December 2021 warned that the ransomware group had compromised a[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flawPost Views: 48 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/202…
t least 49 organizations from U.S. critical infrastructure sectors.
In both advisories, the FBI strongly urged reporting Cuba ransomware attacks to local FBI field offices and asked victims to share related information with their local FBI Cyber Squad to help identify the ransomware gang’s members and the cybercriminals they’re working with.
While not as prolific as Cuba ransomware and although first spotted a lot more recently, in June 2022, Play ransomware has been quite active and has already hit dozens of victims worldwide, including Rackspace, the German H-Hotels hotel chain, the Belgium city of Antwerp, and Argentina’s Judiciary of Córdoba.
Trending: Over 60,000 Exchange servers vulnerable to ProxyNotShell attacks Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-7-300x150.png Cisco warns of auth bypass bug with public exploit in EoL routersJanuary 12, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-6-1-300x150.png Trojan Puzzle attack trains AI assistants into suggesting malicious codeJanuary 11, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-5-1-300x150.png GitHub makes it easier to scan your code for vulnerabilitiesJanuary 10, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-4-1-300x150.png Malicious PyPi packages create CloudFlare Tunnels to bypass firewallsJanuary 9, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw first appeared on Black Hat Ethical Hacking.
In both advisories, the FBI strongly urged reporting Cuba ransomware attacks to local FBI field offices and asked victims to share related information with their local FBI Cyber Squad to help identify the ransomware gang’s members and the cybercriminals they’re working with.
While not as prolific as Cuba ransomware and although first spotted a lot more recently, in June 2022, Play ransomware has been quite active and has already hit dozens of victims worldwide, including Rackspace, the German H-Hotels hotel chain, the Belgium city of Antwerp, and Argentina’s Judiciary of Córdoba.
Trending: Over 60,000 Exchange servers vulnerable to ProxyNotShell attacks Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-7-300x150.png Cisco warns of auth bypass bug with public exploit in EoL routersJanuary 12, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-6-1-300x150.png Trojan Puzzle attack trains AI assistants into suggesting malicious codeJanuary 11, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-5-1-300x150.png GitHub makes it easier to scan your code for vulnerabilitiesJanuary 10, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/01/Images-for-the-News-posts-4-1-300x150.png Malicious PyPi packages create CloudFlare Tunnels to bypass firewallsJanuary 9, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft: Cuba ransomware hacking Exchange servers via OWASSRF flaw first appeared on Black Hat Ethical Hacking.
Clear communication is crucial: why writing effective vulnerability reports matters
First, let’s address the question of why it is necessary to write a clear report. A clear report is essential for effective communication…Continue reading on InfoSec Write-ups »
Read more...
First, let’s address the question of why it is necessary to write a clear report. A clear report is essential for effective communication…Continue reading on InfoSec Write-ups »
Read more...
Strange 2FA Misconfiguration
Hey guys I am back again with another interesting bug bounty writeup.Continue reading on InfoSec Write-ups »
Read more...
Hey guys I am back again with another interesting bug bounty writeup.Continue reading on InfoSec Write-ups »
Read more...
my mobile is hacked
https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/
<!-- SC_OFF -->Hi i think my mobile is hacked .. My friends are knowing my search history and everything...like location too.. They are including these search terms in conversations subtly so I cant question directly... Can't find a legit proof... I don't know if this is for fun or serious...could anyone help...😓 <!-- SC_ON --> submitted by /u/Rough-Delivery8549 (https://www.reddit.com/user/Rough-Delivery8549)
[link] (https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/) [comments] (https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/)
https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/
<!-- SC_OFF -->Hi i think my mobile is hacked .. My friends are knowing my search history and everything...like location too.. They are including these search terms in conversations subtly so I cant question directly... Can't find a legit proof... I don't know if this is for fun or serious...could anyone help...😓 <!-- SC_ON --> submitted by /u/Rough-Delivery8549 (https://www.reddit.com/user/Rough-Delivery8549)
[link] (https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/) [comments] (https://www.reddit.com/r/Pentesting/comments/10aqtz4/my_mobile_is_hacked/)
Clear communication is crucial: why writing effective vulnerability reports matters
https://infosecwriteups.com/clear-communication-is-crucial-why-writing-effective-vulnerability-reports-matters-5f989ee2e401?source=rss------bug_bounty-5
https://infosecwriteups.com/clear-communication-is-crucial-why-writing-effective-vulnerability-reports-matters-5f989ee2e401?source=rss------bug_bounty-5
First, let’s address the question of why it is necessary to write a clear report. A clear report is essential for effective communication…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/clear-communication-is-crucial-why-writing-effective-vulnerability-reports-matters-5f989ee2e401?source=rss------bug_bounty-5)
Strange 2FA Misconfiguration
https://infosecwriteups.com/strange-2fa-misconfiguration-ff1d375c447e?source=rss------bug_bounty-5
https://infosecwriteups.com/strange-2fa-misconfiguration-ff1d375c447e?source=rss------bug_bounty-5
Hey guys I am back again with another interesting bug bounty writeup.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/strange-2fa-misconfiguration-ff1d375c447e?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
is there a way to skip phone verifucation for outlook and gmail?
After you create a few accounts they start asking for phone number. Is there a way to bypass that? I tried using a vpn but it doesn't work.
submitted by /u/tres67lll987
[link] [comments]
is there a way to skip phone verifucation for outlook and gmail?
After you create a few accounts they start asking for phone number. Is there a way to bypass that? I tried using a vpn but it doesn't work.
submitted by /u/tres67lll987
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Bkcrack - Crack Legacy Zip Encryption With Biham And Kocher's Known Plaintext Attack
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjC3XSQvb60FabL6LsNZJ7951VKHxdjHrUCnwgGV7QwqfPr70etJD2NJgesotKmqE1Sblur-11xfLZ4zaCi8vFQ36TbJMFiWe2JVG2p20r5Tw0CIH7Y7gFafGumYaTimHAU6WPk9yisW5XeTZimeqfso4Ylgw2tAmgxklGFHRbp4qLXFxMP6bUU66a5A/w640-h248/bkcrack.png Crack legacy zip encryption with Biham and Kocher's known plaintext attack. OverviewA ZIP archive may contain many entries whose content can be compressed and/or encrypted. In particular, entries can be encrypted with a password-based Encryption Algorithm symmetric encryption algorithm referred to as traditional PKWARE encryption, legacy encryption or ZipCrypto. This algorithm generates a pseudo-random stream of bytes (keystream) which is XORed to the entry's content (plaintext) to produce encrypted data (ciphertext). The generator's state, made of three 32-bits integers, is initialized using the password and then continuously updated with plaintext as encryption goes on. This encryption algorithm is vulnerable to known plaintext attacks as shown by Eli Biham and Paul C. Kocher in the research paper A known plaintext attack on the PKZIP stream cipher. Given ciphertext and 12 or more bytes of the corresponding plaintext, the internal state of the keystream generator can be recovered. This internal state is enough to decipher ciphertext entirely as well as other entries which were encrypted with the same password. It can also be used to bruteforce the password with a complexity of nl-6 where n is the size of the character set and l is the length of the password.
bkcrack is a command-line tool which implements this known plaintext attack. The main features are:
* Recover internal state from ciphertext and plaintext.
* Change a ZIP archive's password using the internal state.
* Recover the original password from the internal state. InstallPrecompiled packagesYou can get the latest official release on GitHub.
Precompiled packages for Ubuntu, MacOS and Windows are available for download. Extract the downloaded archive wherever you like.
On Windows, Microsoft runtime libraries are needed for bkcrack to run. If they are not already installed on your system, download and install the latest Microsoft Visual C++ Redistributable package. Compile from sourceAlternatively, you can compile the project with CMake.
First, download the source files or clone the git repository. Then, running the following commands in the source tree will create an installation in the
Bkcrack - Crack Legacy Zip Encryption With Biham And Kocher's Known Plaintext Attack
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjC3XSQvb60FabL6LsNZJ7951VKHxdjHrUCnwgGV7QwqfPr70etJD2NJgesotKmqE1Sblur-11xfLZ4zaCi8vFQ36TbJMFiWe2JVG2p20r5Tw0CIH7Y7gFafGumYaTimHAU6WPk9yisW5XeTZimeqfso4Ylgw2tAmgxklGFHRbp4qLXFxMP6bUU66a5A/w640-h248/bkcrack.png Crack legacy zip encryption with Biham and Kocher's known plaintext attack. OverviewA ZIP archive may contain many entries whose content can be compressed and/or encrypted. In particular, entries can be encrypted with a password-based Encryption Algorithm symmetric encryption algorithm referred to as traditional PKWARE encryption, legacy encryption or ZipCrypto. This algorithm generates a pseudo-random stream of bytes (keystream) which is XORed to the entry's content (plaintext) to produce encrypted data (ciphertext). The generator's state, made of three 32-bits integers, is initialized using the password and then continuously updated with plaintext as encryption goes on. This encryption algorithm is vulnerable to known plaintext attacks as shown by Eli Biham and Paul C. Kocher in the research paper A known plaintext attack on the PKZIP stream cipher. Given ciphertext and 12 or more bytes of the corresponding plaintext, the internal state of the keystream generator can be recovered. This internal state is enough to decipher ciphertext entirely as well as other entries which were encrypted with the same password. It can also be used to bruteforce the password with a complexity of nl-6 where n is the size of the character set and l is the length of the password.
bkcrack is a command-line tool which implements this known plaintext attack. The main features are:
* Recover internal state from ciphertext and plaintext.
* Change a ZIP archive's password using the internal state.
* Recover the original password from the internal state. InstallPrecompiled packagesYou can get the latest official release on GitHub.
Precompiled packages for Ubuntu, MacOS and Windows are available for download. Extract the downloaded archive wherever you like.
On Windows, Microsoft runtime libraries are needed for bkcrack to run. If they are not already installed on your system, download and install the latest Microsoft Visual C++ Redistributable package. Compile from sourceAlternatively, you can compile the project with CMake.
First, download the source files or clone the git repository. Then, running the following commands in the source tree will create an installation in the
installfolder. cmake -S . -B build -DCMAKE_INSTALL_PREFIX=install
cmake --build build --config Release
cmake --build build --config Release --target install Thrid-party packagesbkcrack is available in the package repositories listed on the right. Those packages are provided by external maintainers. UsageList entriesYou can see a list of entry names and metadata in an archive named archive.ziplike this: bkcrack -L archive.zip Entries using ZipCrypto encryption are vulnerable to a known-plaintext attack. Recover internal keysThe attack requires at least 12 bytes of known plaintext. At least 8 of them must be contiguous. The larger the contiguous known plaintext, the faster the attack. Load data from zip archivesHaving a zip archive encrypted.zipwith the entry cipherbeing the ciphertext and plain.zipwith the entry plainas the known plaintext, bkcrack can be run like this: bkcrack -C encrypted.zip -c cipher -P plain.zip -p plain Load data from filesHaving a file cipherfilewith the ciphertext (starting with the 12 bytes corresponding to the encryption header) and plainfilewith the known plaintext, bkcrack can be run like this[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Bkcrack - Crack Legacy Zip Encryption With Biham And Kocher's Known Plaintext Attack https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjC3XSQvb60FabL6LsNZJ7951VKHxdjHrUCnwgGV7QwqfPr70etJD2NJgesotKmqE1Sblur-11xfLZ4zaCi8…
:
For more information, have a look at the documentation and read the source. ContributeDo not hesitate to suggest improvements or submit pull requests on GitHub. LicenseThis project is provided under the terms of the zlib/png license. Download Bkcrack
bkcrack -c cipherfile -p plainfile OffsetIf the plaintext corresponds to a part other than the beginning of the ciphertext, you can specify an offset. It can be negative if the plaintext includes a part of the encryption header. bkcrack -c cipherfile -p plainfile -o offset Sparse plaintextIf you know little contiguous plaintext (between 8 and 11 bytes), but know some bytes at some other known offsets, you can provide this information to reach the requirement of a total of 12 known bytes. To do so, use the -xflag followed by an offset and bytes in hexadecimal. bkcrack -c cipherfile -p plainfile -x 25 4b4f -x 30 21 Number of threadsIf bkcrack was built with parallel mode enabled, the number of threads used can be set through the environment variable OMP_NUM_THREADS. DecipherIf the attack is successful, the deciphered data associated to the ciphertext used for the attack can be saved: bkcrack -c cipherfile -p plainfile -d decipheredfile If the keys are known from a previous attack, it is possible to use bkcrack to decipher data: bkcrack -c cipherfile -k 12345678 23456789 34567890 -d decipheredfile DecompressThe deciphered data might be compressed depending on whether compression was used or not when the zip file was created. If deflate compression was used, a Python 3 script provided in the toolsfolder may be used to decompress data. python3 tools/inflate.py < decipheredfile > decompressedfile Unlock encrypted archiveIt is also possible to generate a new encrypted archive with the password of your choice: bkcrack -C encrypted.zip -k 12345678 23456789 34567890 -U unlocked.zip password The archive generated this way can be extracted using any zip file utility with the new password. It assumes that every entry was originally encrypted with the same password. Recover passwordGiven the internal keys, bkcrack can try to find the original password. You can look for a password up to a given length using a given character set: bkcrack -k 1ded830c 24454157 7213b8c5 -r 10 ?p You can be more specific by specifying a minimal password length: bkcrack -k 18f285c6 881f2169 b35d661d -r 11..13 ?p LearnA tutorial is provided in the examplefolder.For more information, have a look at the documentation and read the source. ContributeDo not hesitate to suggest improvements or submit pull requests on GitHub. LicenseThis project is provided under the terms of the zlib/png license. Download Bkcrack