CERTIFIED PRACTICAL ETHICAL HACKER (CPEH) - Query
https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/
<!-- SC_OFF -->Anyone taken CEPH exam by TCM Security ?
https://certifications.tcm-sec.com/ How was the experience ? <!-- SC_ON --> submitted by /u/skinny3l3phant (https://www.reddit.com/user/skinny3l3phant)
[link] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/) [comments] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/)
https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/
<!-- SC_OFF -->Anyone taken CEPH exam by TCM Security ?
https://certifications.tcm-sec.com/ How was the experience ? <!-- SC_ON --> submitted by /u/skinny3l3phant (https://www.reddit.com/user/skinny3l3phant)
[link] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/) [comments] (https://www.reddit.com/r/Pentesting/comments/nfz763/certified_practical_ethical_hacker_cpeh_query/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft, Adobe Exploits Top List of Crooks’ Wish ListPost Views: 35
Reading Time: 2 Minutes
A year-long study into the underground market for exploits in cybercriminal forums shows that crooks are salivating for Microsoft bugs, which are far and away the most requested and most sold exploits.
According to researchers (see chart below) Microsoft products made up a whopping 47 percent of the requests, compared with, say, internet of things (IoT) exploits, which only accounted for 5 percent.
The exploit market is accommodating cybercrooks’ hunger for puncturing Microsoft products, according to Trend Micro. A second data point (see chart below) shows that 61 percent of sold exploits targeted Microsoft products, including Office, Windows, Internet Explorer and Microsoft Remote Desktop Protocol (RDP).
No surprise there. Flashpoint researchers also reported in December, prices for RDP server access has been surging.
The research was presented on Monday at the all-virtual RSA Conference 2021, by Trend Micro Senior Researcher Mayra Rosario Fuentes. In her session, titled Tales from the Underground: The Vulnerability Weaponization Lifecycle, Fuentes said that the study tracked the exploits that were sold and requested on more than 600 underground forums over a year. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225827/Sold-Market-300x245.png What gets sold on the exploits market. Source: Trend Micro
Researchers found that the average price for exploits that threat actors were willing to pay was $2,000. The crooks are going after fresh, tender new vulnerabilities, with 52 percent of exploits on their wish list being less than 2 years old: an age bracket that also accounts for 54 percent of exploits being sold. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225807/Most-Requested-Exploits-300x203.png Most-requested exploits. Source: Trend Micro See Also: Bizarro Banking Trojan Sports Sophisticated Backdoor Oldies But Goodies Are Still Hot-Hot-HotOlder vulnerabilities are still in demand, though: 22 percent of the exploits sold in the underground were 3+ years old, according to Fuentes. The oldest vulnerability was downright arthritic, dating back to 1999.
Of the “outdated” exploits being sold, 45 percent were Microsoft-flavored, with the second crook crowd-pleaser being Adobe exploits. Fuentes pointed out that the average time to patch an internet-facing system is 71 days: a whole lot of time for attackers to do some damage. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225814/Outdated-Exploits-Sold-300x244.png Outdated exploits being sold on underground forums. Source: Trend Micro
You can see one example of an exploit request below, where the potential purchaser was looking for an exploit of CVE-2019-1151 – a remote code execution (RCE) of a Microsoft Graphics vulnerability.
Another request, posted on Dec. 23, 2020, was looking for “a potential 1-day RCE vulnerability” in Apache Web Server: not a surprising find, given that the RiskSense Spotlight Report found that the WordPress and Apache Struts web frameworks were the most-targeted by cybercriminals in 2019.
See Also: Offensive Security Tool: EyeWitness Trend Micro researchers found that Office and Adobe exploits were most common in English-speaking forums. As of last week, Adobe Acrobat, the world’s leading PDF reader, was under active attack after a vulnerability that could lead to RCE was exploited. That one affected both Windows – one of attackers’ pre[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft, Adobe Exploits Top List of Crooks’ Wish ListPost Views: 35
Reading Time: 2 Minutes
A year-long study into the underground market for exploits in cybercriminal forums shows that crooks are salivating for Microsoft bugs, which are far and away the most requested and most sold exploits.
According to researchers (see chart below) Microsoft products made up a whopping 47 percent of the requests, compared with, say, internet of things (IoT) exploits, which only accounted for 5 percent.
The exploit market is accommodating cybercrooks’ hunger for puncturing Microsoft products, according to Trend Micro. A second data point (see chart below) shows that 61 percent of sold exploits targeted Microsoft products, including Office, Windows, Internet Explorer and Microsoft Remote Desktop Protocol (RDP).
No surprise there. Flashpoint researchers also reported in December, prices for RDP server access has been surging.
The research was presented on Monday at the all-virtual RSA Conference 2021, by Trend Micro Senior Researcher Mayra Rosario Fuentes. In her session, titled Tales from the Underground: The Vulnerability Weaponization Lifecycle, Fuentes said that the study tracked the exploits that were sold and requested on more than 600 underground forums over a year. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225827/Sold-Market-300x245.png What gets sold on the exploits market. Source: Trend Micro
Researchers found that the average price for exploits that threat actors were willing to pay was $2,000. The crooks are going after fresh, tender new vulnerabilities, with 52 percent of exploits on their wish list being less than 2 years old: an age bracket that also accounts for 54 percent of exploits being sold. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225807/Most-Requested-Exploits-300x203.png Most-requested exploits. Source: Trend Micro See Also: Bizarro Banking Trojan Sports Sophisticated Backdoor Oldies But Goodies Are Still Hot-Hot-HotOlder vulnerabilities are still in demand, though: 22 percent of the exploits sold in the underground were 3+ years old, according to Fuentes. The oldest vulnerability was downright arthritic, dating back to 1999.
Of the “outdated” exploits being sold, 45 percent were Microsoft-flavored, with the second crook crowd-pleaser being Adobe exploits. Fuentes pointed out that the average time to patch an internet-facing system is 71 days: a whole lot of time for attackers to do some damage. https://media.threatpost.com/wp-content/uploads/sites/103/2021/05/17225814/Outdated-Exploits-Sold-300x244.png Outdated exploits being sold on underground forums. Source: Trend Micro
You can see one example of an exploit request below, where the potential purchaser was looking for an exploit of CVE-2019-1151 – a remote code execution (RCE) of a Microsoft Graphics vulnerability.
Another request, posted on Dec. 23, 2020, was looking for “a potential 1-day RCE vulnerability” in Apache Web Server: not a surprising find, given that the RiskSense Spotlight Report found that the WordPress and Apache Struts web frameworks were the most-targeted by cybercriminals in 2019.
See Also: Offensive Security Tool: EyeWitness Trend Micro researchers found that Office and Adobe exploits were most common in English-speaking forums. As of last week, Adobe Acrobat, the world’s leading PDF reader, was under active attack after a vulnerability that could lead to RCE was exploited. That one affected both Windows – one of attackers’ pre[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
___________________________
@hacking_Attack
@Hacking_Video
Microsoft, Adobe Exploits Top List of Crooks’ Wish List
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/cenotaphx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Closer Look at the DarkSide Ransomware Gang
https://external-preview.redd.it/AeFNJAzSMeOHOYMRQjPFuSlfDsZ1nCAB437iT58IW0g.jpg?width=640&crop=smart&auto=webp&s=4135119ac3b8a05175d254bc7194b2b666d77182 submitted by /u/cenotaphx
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Closer Look at the DarkSide Ransomware Gang
Posted in r/hacking by u/cenotaphx • 2 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How in 1982, a one-bit hack let me skip out on a summer of filling in potholes
https://external-preview.redd.it/yJRx2AddZnXgn5_odghbL7_OpUbMplPZYeC2CUZlQys.jpg?width=640&crop=smart&auto=webp&s=766507dcc79cc030ae0bb335ba87b9ce54fa578e submitted by /u/mad_ned
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How in 1982, a one-bit hack let me skip out on a summer of filling in potholes
https://external-preview.redd.it/yJRx2AddZnXgn5_odghbL7_OpUbMplPZYeC2CUZlQys.jpg?width=640&crop=smart&auto=webp&s=766507dcc79cc030ae0bb335ba87b9ce54fa578e submitted by /u/mad_ned
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How in 1982, a one-bit hack let me skip out on a summer of filling...
Posted in r/hacking by u/mad_ned • 1 point and 0 comments
Second Stage XSS (SSX)
Assalamualaikum Warohmatullahi Wabarokatuh :)Continue reading on Medium »
Read more...
Assalamualaikum Warohmatullahi Wabarokatuh :)Continue reading on Medium »
Read more...
Port 8080 webserver
https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/
Hello all, I am quite the novice when it comes pen testing but have tried my share of vulnerable boxes recently. In conducting an nmap I see that port 8080 is open using golang http. My initial reaction was to use dirb and gobuster but I only found robot.txt and index.html. Redirecting to those locations via the browser does not present anything. Does anyone have any recommendations on how I can retrieve a txt file from that server? The retrieval of a specific txt file is the flag. Perhaps a recommendation to a video or cheat sheet. Any help would greatly be appreciated. submitted by /u/MDfiver14 (https://www.reddit.com/user/MDfiver14)
[link] (https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/) [comments] (https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/
Hello all, I am quite the novice when it comes pen testing but have tried my share of vulnerable boxes recently. In conducting an nmap I see that port 8080 is open using golang http. My initial reaction was to use dirb and gobuster but I only found robot.txt and index.html. Redirecting to those locations via the browser does not present anything. Does anyone have any recommendations on how I can retrieve a txt file from that server? The retrieval of a specific txt file is the flag. Perhaps a recommendation to a video or cheat sheet. Any help would greatly be appreciated. submitted by /u/MDfiver14 (https://www.reddit.com/user/MDfiver14)
[link] (https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/) [comments] (https://www.reddit.com/r/Pentesting/comments/ng2hmg/port_8080_webserver/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Port 8080 webserver
Hello all, I am quite the novice when it comes pen testing but have tried my share of vulnerable boxes recently. In conducting an nmap I see that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Hack The Box] — Resolvendo máquina BANK
https://cdn-images-1.medium.com/max/1056/1*FJofLTmpg5kh_LPuvrs1pg.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
[Hack The Box] — Resolvendo máquina BANK
https://cdn-images-1.medium.com/max/1056/1*FJofLTmpg5kh_LPuvrs1pg.png
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[Hack The Box] — Resolvendo máquina BANK
Fala galera, esse é o meu primeiro post em toda a internet (rsrs). Estou começando meus estudos em SI e não há melhor lugar para testar conhecimentos como HackTheBox. Hoje irei falar na máquina Bank…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking, Hackers and Types!
https://cdn-images-1.medium.com/max/1024/1*tve4H8EdssNktR5h6Yuiyw.jpeg
Hello readers, long time it has been since by last blog on Cyber Security: A Brief Introduction.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking, Hackers and Types!
https://cdn-images-1.medium.com/max/1024/1*tve4H8EdssNktR5h6Yuiyw.jpeg
Hello readers, long time it has been since by last blog on Cyber Security: A Brief Introduction.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking, Hackers and Types!
Hello readers, long time it has been since by last blog on Cyber Security: A Brief Introduction. This blog is second in the series of Cyber…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Time-Based SQL Injection to Dumping the Database
https://cdn-images-1.medium.com/max/660/0*-JeWf25NioIFvrJL.png
Dumping the whole database
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Time-Based SQL Injection to Dumping the Database
https://cdn-images-1.medium.com/max/660/0*-JeWf25NioIFvrJL.png
Dumping the whole database
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Time-Based SQL Injection to Dumping the Database
Dumping the whole database
Generic techniques to try and bypass a WAF rulesetContinue reading on Medium » (https://thexssrat.medium.com/waf-bypass-checklist-ad615dfa7cfc?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
WAF Bypass Checklist
Generic techniques to try and bypass a WAF ruleset
Second Stage XSS (SSX)
https://dimazarno.medium.com/second-stage-xss-ssx-cd42d6e519c5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://dimazarno.medium.com/second-stage-xss-ssx-cd42d6e519c5?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Second Stage XSS (SSX)
Assalamualaikum Warohmatullahi Wabarokatuh :)