hacking: security in practice
Is this allowed?
I am bein harrassed at work and have weird stuff happen, including a shovel show up to where I was located, by name, off by a few numbers when I moved.
Today, I got a weird email, by name, telling me, "all good things come to an end."
I was able to locate the email header, IP, and have the email.
If possible, I am trying to get as much detail as possible to see if these are the same people (I am now being retaliated against) and have something to bring to HR and/or the police.
Anyone have any ideas?
submitted by /u/CosmicLipsthatKnow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is this allowed?
I am bein harrassed at work and have weird stuff happen, including a shovel show up to where I was located, by name, off by a few numbers when I moved.
Today, I got a weird email, by name, telling me, "all good things come to an end."
I was able to locate the email header, IP, and have the email.
If possible, I am trying to get as much detail as possible to see if these are the same people (I am now being retaliated against) and have something to bring to HR and/or the police.
Anyone have any ideas?
submitted by /u/CosmicLipsthatKnow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Is this allowed? : r/hacking
2.8M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
hacking: security in practice
so, i wanna make a zip bomb, but im not sure how
to make a zip bomb, i get a file, then fill it with other files that have other files that are then filled, then those are filled, and i just do that x amount of times, then at the very bottom of each ending folder, i put it a slightly large file of like 4.5 gigs, then compress everything, and i mean EVERYTHING into that very first folder?
submitted by /u/SBassGuitar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
so, i wanna make a zip bomb, but im not sure how
to make a zip bomb, i get a file, then fill it with other files that have other files that are then filled, then those are filled, and i just do that x amount of times, then at the very bottom of each ending folder, i put it a slightly large file of like 4.5 gigs, then compress everything, and i mean EVERYTHING into that very first folder?
submitted by /u/SBassGuitar
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
so, i wanna make a zip bomb, but im not sure how : r/hacking
2.8M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
hacking: security in practice
Crash a Zoom meeting
Kinda bored of online lessons now, any way I can crash the meeting I'm in as a participant (using Kali Linux)?
submitted by /u/oldcheeselegend
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Crash a Zoom meeting
Kinda bored of online lessons now, any way I can crash the meeting I'm in as a participant (using Kali Linux)?
submitted by /u/oldcheeselegend
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
Crash a Zoom meeting : r/hacking
2.8M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
Continue reading on Medium » (https://barrierbreak.medium.com/gaad-2021-covidaccessibilitybugbounty-1cf3702919dd?source=rss------bug_bounty-5)
Deep Web
first timer
any tips on what i should do to access the deep web. it’s my first time trying to do it and i just want tips to use it. im mainly interested in alien forums and all those other forums on the deep web about “entities” and all that stuff
submitted by /u/Reddituser49052
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
first timer
any tips on what i should do to access the deep web. it’s my first time trying to do it and i just want tips to use it. im mainly interested in alien forums and all those other forums on the deep web about “entities” and all that stuff
submitted by /u/Reddituser49052
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
first timer
any tips on what i should do to access the deep web. it’s my first time trying to do it and i just want tips to use it. im mainly interested in...
hacking: security in practice
Image "Cloaking" for Personal Privacy - SAND Lab at University of Chicago has developed Fawkes, an algorithm and software tool that "poisons" models that try to learn what you look like, by putting hidden changes into your photos & using them as Trojan horses to any facial recognition models of you.
submitted by /u/StcStasi
[link] [comments]
Image "Cloaking" for Personal Privacy - SAND Lab at University of Chicago has developed Fawkes, an algorithm and software tool that "poisons" models that try to learn what you look like, by putting hidden changes into your photos & using them as Trojan horses to any facial recognition models of you.
submitted by /u/StcStasi
[link] [comments]
Reddit
From the hacking community on Reddit: Image "Cloaking" for Personal Privacy - SAND Lab at University of Chicago has developed Fawkes…
Posted by StcStasi - 699 votes and 22 comments
hacking: security in practice
How do hackers get unreleased music?
Hi. I'm not really interested in obtaining unreleased music myself, but when I see people selling hundreds of unreleased songs on websites like thesource.to, it makes me wonder how they manage to get their hands on this stuff to begin with. I'm assuming a backdoor of some sort, but the fine details are a bit confusing for me so I was hoping somebody would be able to better explain. Thank you!
submitted by /u/Slow-Question9664
[link] [comments]
How do hackers get unreleased music?
Hi. I'm not really interested in obtaining unreleased music myself, but when I see people selling hundreds of unreleased songs on websites like thesource.to, it makes me wonder how they manage to get their hands on this stuff to begin with. I'm assuming a backdoor of some sort, but the fine details are a bit confusing for me so I was hoping somebody would be able to better explain. Thank you!
submitted by /u/Slow-Question9664
[link] [comments]
Reddit
[deleted by user] : r/hacking
2.8M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
hacking: security in practice
Fake number tracking
Is there any way to find out information about the person that keeps texting my mom inappropriate things and making nonviolent threats off of fake numbers? I've already done enough research to determine that they're fake but is there anything I can find out??
Please no sarcastic answers.
submitted by /u/kittym0mma
[link] [comments]
Fake number tracking
Is there any way to find out information about the person that keeps texting my mom inappropriate things and making nonviolent threats off of fake numbers? I've already done enough research to determine that they're fake but is there anything I can find out??
Please no sarcastic answers.
submitted by /u/kittym0mma
[link] [comments]
Reddit
Fake number tracking : r/hacking
2.8M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Active vs. Passive Network Scanning
https://cdn-images-1.medium.com/max/2600/0*fvcdv9vekeeigokf
Performing a network scan is an essential task in a penetration test. It helps the tester understand the environment they are working…
Continue reading on Medium »
Active vs. Passive Network Scanning
https://cdn-images-1.medium.com/max/2600/0*fvcdv9vekeeigokf
Performing a network scan is an essential task in a penetration test. It helps the tester understand the environment they are working…
Continue reading on Medium »
CERTIFIED PRACTICAL ETHICAL HACKER (CPEH) - Query
https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/
<!-- SC_OFF -->Anyone taken CEPH exam by TCM Security ?
https://certifications.tcm-sec.com/ How was the experience ? <!-- SC_ON --> submitted by /u/skinny3l3phant (https://www.reddit.com/user/skinny3l3phant)
[link] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/) [comments] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/)
https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/
<!-- SC_OFF -->Anyone taken CEPH exam by TCM Security ?
https://certifications.tcm-sec.com/ How was the experience ? <!-- SC_ON --> submitted by /u/skinny3l3phant (https://www.reddit.com/user/skinny3l3phant)
[link] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/) [comments] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft, Adobe Exploits Top List of Crooks’ Wish ListPost Views: 35
Reading Time: 2 Minutes
A year-long study into the underground market for exploits in cybercriminal forums shows that crooks are salivating for Microsoft bugs, which are far and away the most requested and most sold exploits.
According to researchers (see chart below) Microsoft products made up a whopping 47 percent of the requests, compared with, say, internet of things (IoT) exploits, which only accounted for 5 percent.
The exploit market is accommodating cybercrooks’ hunger for puncturing Microsoft products, according to Trend Micro. A second data point (see chart below) shows that 61 percent of sold exploits targeted Microsoft products, including Office, Windows, Internet Explorer and Microsoft Remote Desktop Protocol (RDP).
No surprise there. Flashpoint researchers also reported in December, prices for RDP server access has been surging.
The research was presented on Monday at the all-virtual RSA Conference 2021, by Trend Micro Senior Researcher Mayra Rosario Fuentes. In her session, titled Tales from the Underground: The Vulnerability Weaponization Lifecycle, Fuentes said that the study tracked the exploits that were sold and requested on more than 600 underground forums over a year. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225827/Sold-Market-300x245.png What gets sold on the exploits market. Source: Trend Micro
Researchers found that the average price for exploits that threat actors were willing to pay was $2,000. The crooks are going after fresh, tender new vulnerabilities, with 52 percent of exploits on their wish list being less than 2 years old: an age bracket that also accounts for 54 percent of exploits being sold. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225807/Most-Requested-Exploits-300x203.png Most-requested exploits. Source: Trend Micro See Also: Bizarro Banking Trojan Sports Sophisticated Backdoor Oldies But Goodies Are Still Hot-Hot-HotOlder vulnerabilities are still in demand, though: 22 percent of the exploits sold in the underground were 3+ years old, according to Fuentes. The oldest vulnerability was downright arthritic, dating back to 1999.
Of the “outdated” exploits being sold, 45 percent were Microsoft-flavored, with the second crook crowd-pleaser being Adobe exploits. Fuentes pointed out that the average time to patch an internet-facing system is 71 days: a whole lot of time for attackers to do some damage. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225814/Outdated-Exploits-Sold-300x244.png Outdated exploits being sold on underground forums. Source: Trend Micro
You can see one example of an exploit request below, where the potential purchaser was looking for an exploit of CVE-2019-1151 – a remote code execution (RCE) of a Microsoft Graphics vulnerability.
Another request, posted on Dec. 23, 2020, was looking for “a potential 1-day RCE vulnerability” in Apache Web Server: not a surprising find, given that the RiskSense Spotlight Report found that the WordPress and Apache Struts web frameworks were the most-targeted by cybercriminals in 2019.
See Also: Offensive Security Tool: EyeWitness Trend Micro researchers found that Office and Adobe exploits were most common in English-speaking forums. As of last week, Adobe Acrobat, the world’s leading PDF reader, was under active attack after a vulnerability that could lead to RCE was exploited. That one affected both Windows – one of attackers’ pre[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft, Adobe Exploits Top List of Crooks’ Wish ListPost Views: 35
Reading Time: 2 Minutes
A year-long study into the underground market for exploits in cybercriminal forums shows that crooks are salivating for Microsoft bugs, which are far and away the most requested and most sold exploits.
According to researchers (see chart below) Microsoft products made up a whopping 47 percent of the requests, compared with, say, internet of things (IoT) exploits, which only accounted for 5 percent.
The exploit market is accommodating cybercrooks’ hunger for puncturing Microsoft products, according to Trend Micro. A second data point (see chart below) shows that 61 percent of sold exploits targeted Microsoft products, including Office, Windows, Internet Explorer and Microsoft Remote Desktop Protocol (RDP).
No surprise there. Flashpoint researchers also reported in December, prices for RDP server access has been surging.
The research was presented on Monday at the all-virtual RSA Conference 2021, by Trend Micro Senior Researcher Mayra Rosario Fuentes. In her session, titled Tales from the Underground: The Vulnerability Weaponization Lifecycle, Fuentes said that the study tracked the exploits that were sold and requested on more than 600 underground forums over a year. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225827/Sold-Market-300x245.png What gets sold on the exploits market. Source: Trend Micro
Researchers found that the average price for exploits that threat actors were willing to pay was $2,000. The crooks are going after fresh, tender new vulnerabilities, with 52 percent of exploits on their wish list being less than 2 years old: an age bracket that also accounts for 54 percent of exploits being sold. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225807/Most-Requested-Exploits-300x203.png Most-requested exploits. Source: Trend Micro See Also: Bizarro Banking Trojan Sports Sophisticated Backdoor Oldies But Goodies Are Still Hot-Hot-HotOlder vulnerabilities are still in demand, though: 22 percent of the exploits sold in the underground were 3+ years old, according to Fuentes. The oldest vulnerability was downright arthritic, dating back to 1999.
Of the “outdated” exploits being sold, 45 percent were Microsoft-flavored, with the second crook crowd-pleaser being Adobe exploits. Fuentes pointed out that the average time to patch an internet-facing system is 71 days: a whole lot of time for attackers to do some damage. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225814/Outdated-Exploits-Sold-300x244.png Outdated exploits being sold on underground forums. Source: Trend Micro
You can see one example of an exploit request below, where the potential purchaser was looking for an exploit of CVE-2019-1151 – a remote code execution (RCE) of a Microsoft Graphics vulnerability.
Another request, posted on Dec. 23, 2020, was looking for “a potential 1-day RCE vulnerability” in Apache Web Server: not a surprising find, given that the RiskSense Spotlight Report found that the WordPress and Apache Struts web frameworks were the most-targeted by cybercriminals in 2019.
See Also: Offensive Security Tool: EyeWitness Trend Micro researchers found that Office and Adobe exploits were most common in English-speaking forums. As of last week, Adobe Acrobat, the world’s leading PDF reader, was under active attack after a vulnerability that could lead to RCE was exploited. That one affected both Windows – one of attackers’ pre[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
___________________________
@hacking_Attack
@Hacking_Video
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/cenotaphx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/cenotaphx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Closer Look at the DarkSide Ransomware Gang
Posted in r/hacking by u/cenotaphx • 2 points and 0 comments