Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Create an Audio bug using python

https://cdn-images-1.medium.com/max/2000/1*eAi_5zM4hx6cg_8SPfXe1g.jpeg
A few days ago I was working on a system cron script using python and at that time I realize why not create a fun project with it. If you…

Continue reading on Dev Genius »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Exploit Code Released for Actively Exploited GoAnywhere MFT Vulnerability

Exploit Code Released for Actively Exploited GoAnywhere MFT VulnerabilityPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Actively exploited zero-day vulnerability on GoAnywhere MFTAn actively exploited zero-day vulnerability affecting Internet-exposed GoAnywhere MFT (Managed File Transfer) administrator consoles has been made public by security researcher Florian Hauser of IT security consulting firm Code White.
Well done @frycos, such a sweet pre-auth RCE! https://t.co/JRE9DcXOGb pic.twitter.com/cJlvEmL2Km

— ϻг_ϻε (@stevenseeley@infosec.exchange) (@steventseeley) February 4, 2023
GoAnywhere MFT is a web-based tool designed to help organizations securely transfer files and keep audit logs of access. The vulnerability allows for unauthenticated remote code execution on vulnerable GoAnywhere MFT servers.

Although Fortra (the developer behind GoAnywhere MFT) claims that the attack vector requires access to the administrative console of the application, which is usually accessible only from within a private network, Shodan scan results show that almost 1,000 GoAnywhere instances are exposed on the Internet.
https://www.bleepstatic.com/images/news/u/1109292/2023/Map%20of%20vulnerable%20GoAnywhere%20MFT%20servers.jpg Map of vulnerable GoAnywhere MFT servers (Shodan)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Fortra has not yet acknowledged the vulnerabilityFortra has yet to publicly acknowledge the security flaw and has not released any security updates to address the vulnerability, leaving all exposed installations vulnerable to attacks. The company has provided indicators of compromise, including a specific stacktrace that shows up in the logs on compromised systems.
Trending: Major Cyber Attacks of 2022
Trending: Recon Tool: ScopeHunter MitigationTo mitigate the vulnerability, Fortra recommends implementing access controls to allow access to the administrative interface only from trusted sources, disabling the licensing service, revoking stored credentials for other systems, rotating the Master Encryption Key, resetting credentials for all external trading partners/systems, reviewing audit logs and deleting any suspicious admin and/or web user accounts.

The company advises users to contact support via their portal, email or phone for further assistance.
Trending: QNAP NAS Devices at Risk of Remote Malicious Code Injection Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/02/Images-for-the-News-posts-7-300x150.png Royal Ransomware Targets Linux DevicesFebruary 6, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/02/Images-for-the-News-posts-6-300x150.png Cisco IOx Vulnerability Exploited in Command Injection AttacksFebruary 3, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/02/Images-for-the-News-posts-5-300x150.png HeadCrab: The Stealthy Malware Infiltrating Redis Servers for CryptominingFebruary 2, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/0[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Vulnerability Disclosure Policy

BHEH’s Vulnerability Disclosure PolicyBlack Hat Ethical Hacking Vulnerability Disclosure PolicyIntroduction

At Black Hat Ethical Hacking (BHEH), we understand the importance of maintaining the security and privacy of our technology and users. Our goal is to ensure that all systems and data are protected from unauthorized access and tampering. As part of this effort, we encourage responsible vulnerability research and disclosure. This policy outlines our definition of good faith in the context of finding and reporting vulnerabilities, as well as what researchers can expect from us in return.

Expectations

For researchers working in accordance with this policy, BHEH promises to:

* Offer Safe Harbor protection as defined by this policy for your vulnerability research related to this policy.
* Provide a prompt and timely initial response to your report submission.
* Work with you to understand and validate your report.
* Take appropriate action to remediate discovered vulnerabilities in a timely manner.
* Recognize your contribution to improving our security if you are the first to report a unique vulnerability and your report triggers a code or configuration change.

Please note that BHEH does not offer compensation for vulnerability information, but will credit you should we deem it to be a solid impact.

Rules of Engagement

To encourage vulnerability research and to avoid any confusion between good-faith hacking and malicious attacks, researchers must abide by the following rules:

* Do not exploit the issue or issue a denial of service attack.
* Do not change or alter the configuration or data of our systems.
* Do not engage in any activities that violate any applicable laws or regulations.
* Do not use social engineering techniques or attempt to access or destroy data.
* Do not publicly disclose the issue before BHEH has confirmed it and provided a remedy.

Safe Harbor Definition

Researchers are authorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws) and BHEH will not initiate or support legal action against you for accidental, good-faith violations of this policy when conducting genuine vulnerability research in accordance with this policy. Researchers are exempt from the Digital Millennium Copyright Act (DMCA) and BHEH will not bring a claim against you for circumvention of technology controls when conducting genuine vulnerability research in accordance with this policy. Researchers are exempt from restrictions in our Terms and Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy. Researchers must conduct their work in a lawful, helpful, and good-faith manner.

Reporting

To report a security issue or vulnerability, researchers must follow this process:

* Aggregate as much technical information as possible, including steps to reproduce and validate the issue.
* Encrypt your report using BHEH’s GPG key.
* Within 24 hours of discovery, email your encrypted report to the BHEH security team via offensivesecurity@blackhatethicalhacking.com.
* Allow up to 10 business days for confirmation of the reported issue.

Our Commitment

BHEH is committed to securing the confidentiality, integrity, and availability of our systems and the data they store. We take the security of our technology and users seriously and appreciate your contribution to our security efforts. We will work with you to promptly address and remedy any vulnerabilities discovered.

If you have any questions or concerns regarding this policy, please do not hesitate to reach out to us at offensivesecurity@blackhatethicalhacking.com.

Effective Date: 7th of September, 2018

Revised Date: 5h or February 2023
If you have any questions about these Terms, please contact us.
The post Vulnerability Disclosure Policy first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Exploit Code Released for Actively Exploited GoAnywhere MFT Vulnerability Exploit Code Released for Actively Exploited GoAnywhere MFT VulnerabilityPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/up…
2/Images-for-the-News-posts-4-300x150.png Sh1mmer: A New Exploit Enables Unenrollment of Enterprise-Managed ChromebooksFebruary 1, 2023
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Exploit Code Released for Actively Exploited GoAnywhere MFT Vulnerability first appeared on Black Hat Ethical Hacking.
API (Application Programming Interface) vulnerability refers to weaknesses or flaws in a software application’s API that could be…Continue reading on Medium » (https://medium.com/@Theshahid/securing-your-api-a-guide-to-protecting-against-common-vulnerabilities-cb00513d76f0?source=rss------bug_bounty-5)
— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — -Continue reading on Medium » (https://medium.com/@ramawijayas.techdr7/null-pointer-dereference-cwe-476-8acc5f525b0d?source=rss------bug_bounty-5)