Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
my friend found videos of herself online but has no idea how they got out
if there is a subreddit more appropriate to ask for advice i would really appreciate being redirected
i need some advice about how to retrack the person who posted these videos. my friend had gotten a message sent to her from one of her friends who she trusts that sent her an explicit video she found of her online. her friend does only fans, and reverse searches her tag online to find if her content has been reposted so she can take it down. she found herself posted on an explicit website, and found my friend posted by this account as well. the video is real, and my friend knows it exists only on her boyfriends phone and trusts that he had not sent this video to anyone or uploaded it anywhere, and i believe this as well. the account it was posted from has posted other girls of our same (fetishized) race who live in our city. she feels like this was a personal attack and that it is someone local from our city somehow hacking people they know. my question is what possibilities are there as to how someone else could have gotten this access and is there a way they can be tracked? like if we got police involved or hired someone to do a tracking job would it be possible?
submitted by /u/sorbean
[link] [comments]
my friend found videos of herself online but has no idea how they got out
if there is a subreddit more appropriate to ask for advice i would really appreciate being redirected
i need some advice about how to retrack the person who posted these videos. my friend had gotten a message sent to her from one of her friends who she trusts that sent her an explicit video she found of her online. her friend does only fans, and reverse searches her tag online to find if her content has been reposted so she can take it down. she found herself posted on an explicit website, and found my friend posted by this account as well. the video is real, and my friend knows it exists only on her boyfriends phone and trusts that he had not sent this video to anyone or uploaded it anywhere, and i believe this as well. the account it was posted from has posted other girls of our same (fetishized) race who live in our city. she feels like this was a personal attack and that it is someone local from our city somehow hacking people they know. my question is what possibilities are there as to how someone else could have gotten this access and is there a way they can be tracked? like if we got police involved or hired someone to do a tracking job would it be possible?
submitted by /u/sorbean
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
CISA Identifies Critical Vulnerability in Adobe ColdFusion
CISA Identifies Critical Vulnerability in Adobe ColdFusionPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes CISA issues urgent warning to federal agencies to patch ColdFusion serversFollowing the discovery of a critical vulnerability in Adobe ColdFusion, the Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning. The flaw, known as CVE-2023-26360, can be exploited remotely by attackers who do not require user interaction. Adobe has since released security updates to address the flaw, which was being actively exploited in the wild as a zero-day. While ColdFusion 2016 and ColdFusion 11 installations are also affected, Adobe is no longer providing security updates for these versions. As a result, administrators are advised to update their systems within 72 hours, as the risk of exploitation is significant.
To further emphasize the urgency of this situation, CISA has given all U.S. Federal Civilian Executive Branch Agencies (FCEB) three weeks to secure their systems against potential attacks. While the order only applies to federal agencies, all organizations are strongly urged to patch their systems. The consequences of exploitation can be severe, and malicious cyber actors often take advantage of vulnerabilities like this.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Adobe releases security updates to fix ColdFusion vulnerabilitiesIn a separate blog post, Adobe announced the ColdFusion 2021 and 2018 March 2023 Security Updates. However, the company failed to mention that the patched security vulnerabilities were also exploited in the wild. Security researcher Charlie Arehart warned administrators of the importance of these updates and the need to patch them urgently. Arehart reported that he had personally seen both the ‘arbitrary code execution’ and ‘arbitrary file system read’ vulnerabilities being perpetrated on multiple servers.
Trending: Major Cyber Attacks of 2022
Trending: Offensive Security Tool: CrackQL ColdFusion admin warns of the seriousness of recent security updateThe implications of the CVE-2023-26360 vulnerability are significant, and it is crucial that administrators act fast to secure their systems. With CISA and security experts warning of the grave risks posed by this flaw, it is clear that the threat is real and immediate. By installing the security updates and following the recommended security configuration settings, administrators can take steps to protect their systems from exploitation.
Trending: Proof-of-concept for critical Microsoft Word vulnerability published
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023[...]
CISA Identifies Critical Vulnerability in Adobe ColdFusion
CISA Identifies Critical Vulnerability in Adobe ColdFusionPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes CISA issues urgent warning to federal agencies to patch ColdFusion serversFollowing the discovery of a critical vulnerability in Adobe ColdFusion, the Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning. The flaw, known as CVE-2023-26360, can be exploited remotely by attackers who do not require user interaction. Adobe has since released security updates to address the flaw, which was being actively exploited in the wild as a zero-day. While ColdFusion 2016 and ColdFusion 11 installations are also affected, Adobe is no longer providing security updates for these versions. As a result, administrators are advised to update their systems within 72 hours, as the risk of exploitation is significant.
To further emphasize the urgency of this situation, CISA has given all U.S. Federal Civilian Executive Branch Agencies (FCEB) three weeks to secure their systems against potential attacks. While the order only applies to federal agencies, all organizations are strongly urged to patch their systems. The consequences of exploitation can be severe, and malicious cyber actors often take advantage of vulnerabilities like this.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Adobe releases security updates to fix ColdFusion vulnerabilitiesIn a separate blog post, Adobe announced the ColdFusion 2021 and 2018 March 2023 Security Updates. However, the company failed to mention that the patched security vulnerabilities were also exploited in the wild. Security researcher Charlie Arehart warned administrators of the importance of these updates and the need to patch them urgently. Arehart reported that he had personally seen both the ‘arbitrary code execution’ and ‘arbitrary file system read’ vulnerabilities being perpetrated on multiple servers.
Trending: Major Cyber Attacks of 2022
Trending: Offensive Security Tool: CrackQL ColdFusion admin warns of the seriousness of recent security updateThe implications of the CVE-2023-26360 vulnerability are significant, and it is crucial that administrators act fast to secure their systems. With CISA and security experts warning of the grave risks posed by this flaw, it is clear that the threat is real and immediate. By installing the security updates and following the recommended security configuration settings, administrators can take steps to protect their systems from exploitation.
Trending: Proof-of-concept for critical Microsoft Word vulnerability published
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking CISA Identifies Critical Vulnerability in Adobe ColdFusion CISA Identifies Critical Vulnerability in Adobe ColdFusionPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe…
/03/Images-for-the-News-posts-3-1-300x150.png GoBruteforcer: New Golang-based Botnet Malware Scans for and Infects Web ServersMarch 13, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-2-1-300x150.png AT&T Data Breach: 9 Million Customers Affected by Marketing Vendor HackMarch 10, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post CISA Identifies Critical Vulnerability in Adobe ColdFusion first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-2-1-300x150.png AT&T Data Breach: 9 Million Customers Affected by Marketing Vendor HackMarch 10, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post CISA Identifies Critical Vulnerability in Adobe ColdFusion first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
GPT_Vuln-analyzer - Uses ChatGPT API And Python-Nmap Module To Use The GPT3 Model To Create Vulnerability Reports Based On Nmap Scan Data
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCBHKSioYKOoSKBRyCLseiCSQ1SaYgS_rUpDdUZtojC97Cf6bBGG8BH4ILfnya8flM37Qmg67Sob9LGgELR6qnVXYrEIh6m1hBZpn2kNjDIcE2NvTa10QnkYqV1inzw3nAAqWTRG2HCj03mv6vCsmoMaMX8Rf0r5oktZPFj5KMjbc_h4wOjaoKoInORg/w640-h360/chatgpt_hack.jpeg This is a Proof Of Concept application that demostrates how AI can be used to generate accurate results for vulnerability analysis and also allows further utilization of the already super useful ChatGPT. Requirements* Python 3.10
* All the packages mentioned in the requirements.txt file
* OpenAi api Usage* First Change the "API__KEY" part of the code with OpenAI api key
Supported in both windows and linux Understanding the codeProfiles:
Parameter Return data Description Nmap Command
The entire structure of request that has to be sent to the openai API is designed in the completion section of the Program.
vulnerability analysis of {} and return a vulnerabilty report in json".format(analize) # A structure for the request completion = openai.Completion.create( engine=model_engine, prompt=prompt, max_tokens=1024, n=1, stop=None, ) response = completion.choices[0].text return response" dir="auto">
* Can increase the effectiveness of the final system
* Highly productive when working with models such as GPT3 Download GPT_Vuln-analyzer
GPT_Vuln-analyzer - Uses ChatGPT API And Python-Nmap Module To Use The GPT3 Model To Create Vulnerability Reports Based On Nmap Scan Data
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCBHKSioYKOoSKBRyCLseiCSQ1SaYgS_rUpDdUZtojC97Cf6bBGG8BH4ILfnya8flM37Qmg67Sob9LGgELR6qnVXYrEIh6m1hBZpn2kNjDIcE2NvTa10QnkYqV1inzw3nAAqWTRG2HCj03mv6vCsmoMaMX8Rf0r5oktZPFj5KMjbc_h4wOjaoKoInORg/w640-h360/chatgpt_hack.jpeg This is a Proof Of Concept application that demostrates how AI can be used to generate accurate results for vulnerability analysis and also allows further utilization of the already super useful ChatGPT. Requirements* Python 3.10
* All the packages mentioned in the requirements.txt file
* OpenAi api Usage* First Change the "API__KEY" part of the code with OpenAI api key
openai.api_key = "__API__KEY" # Enter your API key* second install the packages pip3 install -r requirements.txt
or
pip install -r requirements.txt* run the code python3 gpt_vuln.py or if windows run python gpt_vuln.py Supported in both windows and linux Understanding the codeProfiles:
Parameter Return data Description Nmap Command
p1jsonEffective Scan -Pn -sV -T4 -O -Fp2jsonSimple Scan -Pn -T4 -A -vp3jsonLow Power Scan -Pn -sS -sU -T4 -A -vp4jsonPartial Intense Scan -Pn -p- -T4 -A -vp5jsonComplete Intense Scan -Pn -sS -sU -T4 -A -PE -PP -PS80,443 -PA3389 -PU40125 -PY -g 53 --script=vulnThe profile is the type of scan that will be executed by the nmap subprocess. The Ip or target will be provided via argparse. At first the custom nmap scan is run which has all the curcial arguments for the scan to continue. nextly the scan data is extracted from the huge pile of data which has been driven by nmap. the "scan" object has a list of sub data under "tcp" each labled according to the ports opened. once the data is extracted the data is sent to openai API davenci model via a prompt. the prompt specifically asks for an JSON output and the data also to be used in a certain manner.The entire structure of request that has to be sent to the openai API is designed in the completion section of the Program.
vulnerability analysis of {} and return a vulnerabilty report in json".format(analize) # A structure for the request completion = openai.Completion.create( engine=model_engine, prompt=prompt, max_tokens=1024, n=1, stop=None, ) response = completion.choices[0].text return response" dir="auto">
def profile(ip):
nm.scan('{}'.format(ip), arguments='-Pn -sS -sU -T4 -A -PE -PP -PS80,443 -PA3389 -PU40125 -PY -g 53 --script=vuln')
json_data = nm.analyse_nmap_xml_scan()
analize = json_data["scan"]
# Prompt about what the quary is all about
prompt = "do a vulnerability analysis of {} and return a vulnerabilty report in json".format(analize)
# A structure for the request
completion = openai.Completion.create(
engine=model_engine,
prompt=prompt,
max_tokens=1024,
n=1,
stop=None,
)
response = completion.choices[0].text
return response Advantages* Can be used in developing a more advanced systems completly made of the API and scanner combination* Can increase the effectiveness of the final system
* Highly productive when working with models such as GPT3 Download GPT_Vuln-analyzer
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TRY HACK ME — Warzone 2
https://cdn-images-1.medium.com/max/700/0*kZzwviYSaum36CDQ.png
Hello, today we are going to solve a box on tryhackme “Warzone 2”
Continue reading on Medium »
TRY HACK ME — Warzone 2
https://cdn-images-1.medium.com/max/700/0*kZzwviYSaum36CDQ.png
Hello, today we are going to solve a box on tryhackme “Warzone 2”
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Protect Your Critical Data from Hackers
https://cdn-images-1.medium.com/max/700/1*UXKNs2nI-y7cNVyBFJA1SA.jpeg
Protecting your critical data from hackers is a critical step in ensuring the security of your digital life. Here are some tips to help…
Continue reading on Medium »
How to Protect Your Critical Data from Hackers
https://cdn-images-1.medium.com/max/700/1*UXKNs2nI-y7cNVyBFJA1SA.jpeg
Protecting your critical data from hackers is a critical step in ensuring the security of your digital life. Here are some tips to help…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Protecting Your Digital Fortress: Understanding the Importance of Cybersecurity for Organisations
https://cdn-images-1.medium.com/max/600/1*l0TU4sxsd662mk8Tai8vVg.png
In today’s digital age, cybersecurity has become an increasingly critical aspect for organisations of all sizes and sectors. Cybersecurity…
Continue reading on Medium »
Protecting Your Digital Fortress: Understanding the Importance of Cybersecurity for Organisations
https://cdn-images-1.medium.com/max/600/1*l0TU4sxsd662mk8Tai8vVg.png
In today’s digital age, cybersecurity has become an increasingly critical aspect for organisations of all sizes and sectors. Cybersecurity…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Soccer — Hack The Box
https://cdn-images-1.medium.com/max/700/0*JVbiUVfQBUKtQE05.png
In this blog, we will solve a box on hackthebox called Soccer. it is the last box published on hackthebox for the year 2022.
Continue reading on Medium »
Soccer — Hack The Box
https://cdn-images-1.medium.com/max/700/0*JVbiUVfQBUKtQE05.png
In this blog, we will solve a box on hackthebox called Soccer. it is the last box published on hackthebox for the year 2022.
Continue reading on Medium »
Hacking on Medium
b3dr0ck(EASY)- Try Hack Me
https://cdn-images-1.medium.com/max/700/0*bpdJsIltvC5nv_Tj.png
Hey, today we are going to solve b3dr0ck Try hack me
Continue reading on Medium »
b3dr0ck(EASY)- Try Hack Me
https://cdn-images-1.medium.com/max/700/0*bpdJsIltvC5nv_Tj.png
Hey, today we are going to solve b3dr0ck Try hack me
Continue reading on Medium »
Medium
b3dr0ck(EASY)- Try Hack Me
Hey, today we are going to solve b3dr0ck Try hack me
Hacking on Medium
HACK THE BOX — TRICK
https://cdn-images-1.medium.com/max/700/0*R3_fbUqkl3wfKMwn.png
In this write up we’re going to pwn a box on hack the box called “TRICK”
Continue reading on Medium »
HACK THE BOX — TRICK
https://cdn-images-1.medium.com/max/700/0*R3_fbUqkl3wfKMwn.png
In this write up we’re going to pwn a box on hack the box called “TRICK”
Continue reading on Medium »
Medium
HACK THE BOX — TRICK
In this write up we’re going to pwn a box on hack the box called “TRICK”