Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Art of Port Scanning
https://cdn-images-1.medium.com/max/1024/1*5-QyCrjP0Wiwh1VPDUQ0vQ.png
Securing Networks and Identifying Vulnerabilities
Continue reading on Medium »
The Art of Port Scanning
https://cdn-images-1.medium.com/max/1024/1*5-QyCrjP0Wiwh1VPDUQ0vQ.png
Securing Networks and Identifying Vulnerabilities
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Squashed Writeup
https://cdn-images-1.medium.com/max/1944/0*RFwSwU1UzAkmXLuP.png
Hello world and welcome to haxez and my write-up for the Squashed machine. I’ve been getting back into doing Hack The Box machines again…
Continue reading on Medium »
Hack The Box Squashed Writeup
https://cdn-images-1.medium.com/max/1944/0*RFwSwU1UzAkmXLuP.png
Hello world and welcome to haxez and my write-up for the Squashed machine. I’ve been getting back into doing Hack The Box machines again…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Late Writeup
https://cdn-images-1.medium.com/max/1944/0*cfEJvSHZvk1BqzNi.png
Hello world, welcome to Haxez. It’s time for another Hack The Box machine write up and this time we’re looking at Late.
Continue reading on Medium »
Hack The Box Late Writeup
https://cdn-images-1.medium.com/max/1944/0*cfEJvSHZvk1BqzNi.png
Hello world, welcome to Haxez. It’s time for another Hack The Box machine write up and this time we’re looking at Late.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cybersecurity: when vulnerability becomes a threat
https://cdn-images-1.medium.com/max/1080/1*sw809279FGO5xkTxeFQWXQ.png
Cybercrime is the largest threat to small, medium and large businesses today. Recent attacks caused havoc and chaos. What happened? Let’s…
Continue reading on Medium »
Cybersecurity: when vulnerability becomes a threat
https://cdn-images-1.medium.com/max/1080/1*sw809279FGO5xkTxeFQWXQ.png
Cybercrime is the largest threat to small, medium and large businesses today. Recent attacks caused havoc and chaos. What happened? Let’s…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box Weak RSA Writeup
https://cdn-images-1.medium.com/max/1944/0*KE05tAjPGj1-arpM.png
Hello world and welcome to haxez, today I will attempt to solve the Weak RSA crypto challenge on Hack The Box. Please note that I got the…
Continue reading on Medium »
Hack The Box Weak RSA Writeup
https://cdn-images-1.medium.com/max/1944/0*KE05tAjPGj1-arpM.png
Hello world and welcome to haxez, today I will attempt to solve the Weak RSA crypto challenge on Hack The Box. Please note that I got the…
Continue reading on Medium »
https://b.thumbs.redditmedia.com/fdeT9zrzbDOhd8Sf8Z5quTXSQ3dhci7vT7U1Nc02CnE.jpg lol
wait what so it wants me to pay it lmao
https://preview.redd.it/mxifb3p5u9oa1.png?width=874&format=png&auto=webp&s=e64aca0d1b888a6b345d84f38f8ea3df06c8a767
https://preview.redd.it/65yh4tqnt9oa1.png?width=737&format=png&auto=webp&s=5dd7409e7418bfa07d68fadb4bf52191a233febf
https://preview.redd.it/d4gq7to7t9oa1.png?width=973&format=png&auto=webp&s=8a4a75ec91fac24c323af240bc97e9338fed8e11
https://preview.redd.it/5g4p5ji8t9oa1.png?width=884&format=png&auto=webp&s=b81eb5b0e53757bfebafb6032bd21f266548b771
https://preview.redd.it/1rmhi7p8t9oa1.png?width=872&format=png&auto=webp&s=f4d60da3a1a820d0717204f9d4941c714473e80e
https://preview.redd.it/mhldk2r9t9oa1.png?width=822&format=png&auto=webp&s=198f4a2dfae89fa185dc05b3401ab10c8d2a2dd1
submitted by /u/some1did1t
[link] [comments]
wait what so it wants me to pay it lmao
https://preview.redd.it/mxifb3p5u9oa1.png?width=874&format=png&auto=webp&s=e64aca0d1b888a6b345d84f38f8ea3df06c8a767
https://preview.redd.it/65yh4tqnt9oa1.png?width=737&format=png&auto=webp&s=5dd7409e7418bfa07d68fadb4bf52191a233febf
https://preview.redd.it/d4gq7to7t9oa1.png?width=973&format=png&auto=webp&s=8a4a75ec91fac24c323af240bc97e9338fed8e11
https://preview.redd.it/5g4p5ji8t9oa1.png?width=884&format=png&auto=webp&s=b81eb5b0e53757bfebafb6032bd21f266548b771
https://preview.redd.it/1rmhi7p8t9oa1.png?width=872&format=png&auto=webp&s=f4d60da3a1a820d0717204f9d4941c714473e80e
https://preview.redd.it/mhldk2r9t9oa1.png?width=822&format=png&auto=webp&s=198f4a2dfae89fa185dc05b3401ab10c8d2a2dd1
submitted by /u/some1did1t
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Addresses Linked to Euler Finance Exploit and Ronin Network Hack Interact - Investor Bites
https://external-preview.redd.it/e4RG7DOF5onBk8ZnuF2Ul97EGmDkEJ8Srj7koEuCjxo.jpg?width=640&crop=smart&auto=webp&s=75dc85117a035ce519173e23f06690d7ae1def6b submitted by /u/Wolf_of_max
[link] [comments]
Addresses Linked to Euler Finance Exploit and Ronin Network Hack Interact - Investor Bites
https://external-preview.redd.it/e4RG7DOF5onBk8ZnuF2Ul97EGmDkEJ8Srj7koEuCjxo.jpg?width=640&crop=smart&auto=webp&s=75dc85117a035ce519173e23f06690d7ae1def6b submitted by /u/Wolf_of_max
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Tehran and Abu Dhabi Seek Stronger Ties: Iran's Security Chief Holds Talks in the UAE
After years of animosity, UAE and Iran started re-engaging only in 2019. The recent visit of Iran's top security official to the UAE highlights Iran's efforts to strengthen ties with its neighbors amidst growing isolation from the West.
submitted by /u/defensive_reaction
[link] [comments]
Tehran and Abu Dhabi Seek Stronger Ties: Iran's Security Chief Holds Talks in the UAE
After years of animosity, UAE and Iran started re-engaging only in 2019. The recent visit of Iran's top security official to the UAE highlights Iran's efforts to strengthen ties with its neighbors amidst growing isolation from the West.
submitted by /u/defensive_reaction
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets
Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsPost Views: 46 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Google’s Project Zero uncovers 18 zero-day vulnerabilities in Samsung Exynos chipsetsGoogle’s bug-hunting team, Project Zero, has identified 18 zero-day vulnerabilities in Samsung’s Exynos chipsets used in mobile devices, wearables, and cars. These vulnerabilities were discovered between late 2022 and early 2023, and four of them were deemed the most serious. The flaws allow remote code execution from the Internet to the baseband, enabling attackers to compromise vulnerable devices without any user interaction.
The security flaws, including CVE-2023-24033 and three others still awaiting a CVE-ID, were described as “Internet-to-baseband remote code execution (RCE) bugs.” Samsung acknowledged the vulnerability in a security advisory, stating that the baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to denial of service or code execution in Samsung Baseband Modem.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Four of the identified Exynos modem security flaws enable remote code executionTim Willis, the Head of Project Zero, has warned that experienced attackers could easily create an exploit that remotely compromises vulnerable devices without triggering the target’s attention. Due to the high level of access these vulnerabilities provide, Project Zero has delayed disclosure for the four vulnerabilities that allow for Internet-to-baseband remote code execution.
The remaining 14 flaws, including CVE-2023-24072, CVE-2023-24073, CVE-2023-24074, CVE-2023-24075, CVE-2023-24076, and nine others awaiting CVE-IDs, are less critical but still pose a risk. Successful exploitation requires local access or a malicious mobile network operator.
End-users still don't have patches 90 days after report…. https://t.co/dkA9kuzTso
— Maddie Stone (@maddiestone) March 16, 2023
Samsung has already provided security updates addressing these vulnerabilities in impacted chipsets to other vendors. However, patches are not public and can’t be applied by all affected users. Each manufacturer’s patch timeline for their devices will differ. Google, for instance, has already addressed CVE-2023-24033 for impacted Pixel devices in its March 2023 security updates.
Trending: Major Cyber Attacks of 2022
Trending: Offensive Security Tool: CrackQL Google and Samsung urge users to update devices to mitigate Exynos chipset flawsUntil patches are available, users can disable Wi-Fi calling and Voice-over-LTE (VoLTE) to remove the attack vector and thwart baseband RCE exploitation attempts targeting Samsung’s Exynos chipsets in their device. Samsung has confirmed Project Zero’s workaround and encourages end-users to update their devices as soon as possible to ensure that they are running the latest builds that fix both disclosed and undisclosed security vulnerabilities.
Trending: Proof-of-concept for critical Microsoft Word vulnerability published
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/u[...]
Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets
Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsPost Views: 46 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Google’s Project Zero uncovers 18 zero-day vulnerabilities in Samsung Exynos chipsetsGoogle’s bug-hunting team, Project Zero, has identified 18 zero-day vulnerabilities in Samsung’s Exynos chipsets used in mobile devices, wearables, and cars. These vulnerabilities were discovered between late 2022 and early 2023, and four of them were deemed the most serious. The flaws allow remote code execution from the Internet to the baseband, enabling attackers to compromise vulnerable devices without any user interaction.
The security flaws, including CVE-2023-24033 and three others still awaiting a CVE-ID, were described as “Internet-to-baseband remote code execution (RCE) bugs.” Samsung acknowledged the vulnerability in a security advisory, stating that the baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to denial of service or code execution in Samsung Baseband Modem.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Four of the identified Exynos modem security flaws enable remote code executionTim Willis, the Head of Project Zero, has warned that experienced attackers could easily create an exploit that remotely compromises vulnerable devices without triggering the target’s attention. Due to the high level of access these vulnerabilities provide, Project Zero has delayed disclosure for the four vulnerabilities that allow for Internet-to-baseband remote code execution.
The remaining 14 flaws, including CVE-2023-24072, CVE-2023-24073, CVE-2023-24074, CVE-2023-24075, CVE-2023-24076, and nine others awaiting CVE-IDs, are less critical but still pose a risk. Successful exploitation requires local access or a malicious mobile network operator.
End-users still don't have patches 90 days after report…. https://t.co/dkA9kuzTso
— Maddie Stone (@maddiestone) March 16, 2023
Samsung has already provided security updates addressing these vulnerabilities in impacted chipsets to other vendors. However, patches are not public and can’t be applied by all affected users. Each manufacturer’s patch timeline for their devices will differ. Google, for instance, has already addressed CVE-2023-24033 for impacted Pixel devices in its March 2023 security updates.
Trending: Major Cyber Attacks of 2022
Trending: Offensive Security Tool: CrackQL Google and Samsung urge users to update devices to mitigate Exynos chipset flawsUntil patches are available, users can disable Wi-Fi calling and Voice-over-LTE (VoLTE) to remove the attack vector and thwart baseband RCE exploitation attempts targeting Samsung’s Exynos chipsets in their device. Samsung has confirmed Project Zero’s workaround and encourages end-users to update their devices as soon as possible to ensure that they are running the latest builds that fix both disclosed and undisclosed security vulnerabilities.
Trending: Proof-of-concept for critical Microsoft Word vulnerability published
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/u[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsPost Views: 46 Premium Contenthttps://www.blackhatethicalhacking.com/wp-conte…
ploads/2023/03/M.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-3-1-300x150.png GoBruteforcer: New Golang-based Botnet Malware Scans for and Infects Web ServersMarch 13, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-3-1-300x150.png GoBruteforcer: New Golang-based Botnet Malware Scans for and Infects Web ServersMarch 13, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos Chipsets first appeared on Black Hat Ethical Hacking.
Black Hat Ethical Hacking
Offensive Security Tool: Bypass Url Parser
Offensive Security Tool: Bypass Url Parser
Black Hat Ethical Hacking
Offensive Security Tool: Bypass Url Parser | Black Hat Ethical Hacking
Bypass-url-parser is a tool designed to simplify theprocess of testing URL parsing vulnerabilities in web applications. It tests MANY url bypasses to reach a 40X protected page.