Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tracking a WhatsApp hacker and protecting your account:
https://cdn-images-1.medium.com/max/602/0*sUWr8NdrbvLuikbW
WhatsApp is one of the most popular messaging apps in the world, with over 2 billion active users. Unfortunately, with such a large user…
Continue reading on Medium »
Tracking a WhatsApp hacker and protecting your account:
https://cdn-images-1.medium.com/max/602/0*sUWr8NdrbvLuikbW
WhatsApp is one of the most popular messaging apps in the world, with over 2 billion active users. Unfortunately, with such a large user…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
johntheripper/hashcat list key possibilities in plain text.
Can either of these just list out every key possibility in plain text?
I'm not cracking any file but it is possible to just list them out in plain text without the need of a file.
If it helps at all I'm cracking RC4/Motorola ADP.
submitted by /u/LukeCrews
[link] [comments]
johntheripper/hashcat list key possibilities in plain text.
Can either of these just list out every key possibility in plain text?
I'm not cracking any file but it is possible to just list them out in plain text without the need of a file.
If it helps at all I'm cracking RC4/Motorola ADP.
submitted by /u/LukeCrews
[link] [comments]
Finding Host header injection
Hello everyone! This is Jody Ritonga, back again with another bug bounty writeup! In this article, I want to tell you about Host Header…Continue reading on System Weakness »
Read more...
Hello everyone! This is Jody Ritonga, back again with another bug bounty writeup! In this article, I want to tell you about Host Header…Continue reading on System Weakness »
Read more...
Privilege Escalation through ID Reflection
As technology continues to advance, companies are becoming increasingly reliant on digital systems to store and manage their data.Continue reading on Medium »
Read more...
As technology continues to advance, companies are becoming increasingly reliant on digital systems to store and manage their data.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Wanna Bypass the Windows Login?
https://cdn-images-1.medium.com/max/1065/1*is01Psw-eCQekB24SK9j7A.png
Hi folks, you may have searched for this topic in many situations like when you forgot your password, someone has reset your account, or…
Continue reading on Medium »
Wanna Bypass the Windows Login?
https://cdn-images-1.medium.com/max/1065/1*is01Psw-eCQekB24SK9j7A.png
Hi folks, you may have searched for this topic in many situations like when you forgot your password, someone has reset your account, or…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pool on the roof - March 20, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Pool on the roof - March 20, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I am going to enroll for OSCP, i would appreciate any possibile insights!
I've been using Linux since i was 14 because i only had my father's old laptop from 2008 and that thing couldn't run anything more than linux, right now I'm 19 and have been doing bug bounties from 6 ish months. I'm a bit behind academically but i am going to do bachelor's in computer science specialization in cybersecurity this year, I've looked through the syllabus and I'm mostly familiar with every subject except advance engineering mathematics. Since I'm gonna have a lot of free time and it's been my dream to pursue OSCP i am going to enroll for OSCP this year. i would appreciate any and all kind of advice and insight.
I'm fairly sure with 3 months of lab and 9 months of training I'll be able to pass OSCP, and over the past two years i have hacked hundreds of vulnhub virtual machines. Not being too cocky though cause i read a lot on this sub how OSCP can fail even the best so my next best move is to learn from other people's failures and give it my best and hopefully pass.
submitted by /u/Naitikxo
[link] [comments]
I am going to enroll for OSCP, i would appreciate any possibile insights!
I've been using Linux since i was 14 because i only had my father's old laptop from 2008 and that thing couldn't run anything more than linux, right now I'm 19 and have been doing bug bounties from 6 ish months. I'm a bit behind academically but i am going to do bachelor's in computer science specialization in cybersecurity this year, I've looked through the syllabus and I'm mostly familiar with every subject except advance engineering mathematics. Since I'm gonna have a lot of free time and it's been my dream to pursue OSCP i am going to enroll for OSCP this year. i would appreciate any and all kind of advice and insight.
I'm fairly sure with 3 months of lab and 9 months of training I'll be able to pass OSCP, and over the past two years i have hacked hundreds of vulnhub virtual machines. Not being too cocky though cause i read a lot on this sub how OSCP can fail even the best so my next best move is to learn from other people's failures and give it my best and hopefully pass.
submitted by /u/Naitikxo
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes HinataBot targetsAkamai researchers recently discovered a new malware botnet known as HinataBot that targets Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into a distributed denial of service (DDoS) swarm. The botnet exploits old flaws such as CVE-2014-8361 and CVE-2017-17215 and was first detected in mid-January 2023. HinataBot seems to be based on Mirai and is a Go-based variant of the notorious malware strain. Akamai’s researchers captured multiple samples from active campaigns as recently as March 2023 and deduced that the malware is under active development, featuring functional improvements and anti-analysis additions.
HinataBot is distributed by brute-forcing Secure Shell (SSH) endpoints or using infection scripts and Remote Code Execution (RCE) payloads for known vulnerabilities. After infecting devices, the malware remains silent, waiting for commands to execute from the command and control server. Even though the newer variants only feature HTTP and User Datagram Protocol (UDP) flood attacks, the botnet can potentially perform powerful DDoS attacks. Older versions of HinataBot supported HTTP, UDP, Internet Control Message Protocol (ICMP), and Transmission Control Protocol (TCP) floods.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 3.3 Tbps DDoS attacksAkamai researchers benchmarked the botnet in 10-second attacks for both HTTP and UDP. In the HTTP attack, the malware generated 20,430 requests for a total size of 3.4 MB. The UDP flood generated 6,733 packages totaling 421 MB of data. The researchers estimated that with 1,000 nodes, the UDP flood could generate roughly 336 Gbps, while at 10,000 nodes, the attack data volume would reach 3.3 Tbps. In the case of the HTTP flood, 1,000 ensnared devices would generate 2,000,000 requests per second, while 10,000 nodes would take that number of 20,400,000 requests per second and 27 Gbps.
https://www.bleepstatic.com/images/news/u/1220909/2023/DDoS/6/udp-capture.jpg
UDP flood packet capture (Akamai)
Trending: A primer on OS Command Injection Attacks Trending: Offensive Security Tool: Bypass Url Parser HinataBot might implement more exploits while widening its scopeAkamai’s analysts created a Command and Control (C2) server of their own and interacted with simulated infections to stage HinataBot for DDoS attacks to observe the malware in action and infer its attack capabilities. Although HinataBot is still in development and might implement more exploits and widen its targeting scope anytime, the fact that its development is so active increases the likelihood of seeing more potent versions circulating in the wild soon. “Let’s hope that the HinataBot authors move onto new hobbies before we have to deal with their botnet at any real scale,” warns Akamai.
Trending: Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new tools Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https[...]
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes HinataBot targetsAkamai researchers recently discovered a new malware botnet known as HinataBot that targets Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into a distributed denial of service (DDoS) swarm. The botnet exploits old flaws such as CVE-2014-8361 and CVE-2017-17215 and was first detected in mid-January 2023. HinataBot seems to be based on Mirai and is a Go-based variant of the notorious malware strain. Akamai’s researchers captured multiple samples from active campaigns as recently as March 2023 and deduced that the malware is under active development, featuring functional improvements and anti-analysis additions.
HinataBot is distributed by brute-forcing Secure Shell (SSH) endpoints or using infection scripts and Remote Code Execution (RCE) payloads for known vulnerabilities. After infecting devices, the malware remains silent, waiting for commands to execute from the command and control server. Even though the newer variants only feature HTTP and User Datagram Protocol (UDP) flood attacks, the botnet can potentially perform powerful DDoS attacks. Older versions of HinataBot supported HTTP, UDP, Internet Control Message Protocol (ICMP), and Transmission Control Protocol (TCP) floods.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 3.3 Tbps DDoS attacksAkamai researchers benchmarked the botnet in 10-second attacks for both HTTP and UDP. In the HTTP attack, the malware generated 20,430 requests for a total size of 3.4 MB. The UDP flood generated 6,733 packages totaling 421 MB of data. The researchers estimated that with 1,000 nodes, the UDP flood could generate roughly 336 Gbps, while at 10,000 nodes, the attack data volume would reach 3.3 Tbps. In the case of the HTTP flood, 1,000 ensnared devices would generate 2,000,000 requests per second, while 10,000 nodes would take that number of 20,400,000 requests per second and 27 Gbps.
https://www.bleepstatic.com/images/news/u/1220909/2023/DDoS/6/udp-capture.jpg
UDP flood packet capture (Akamai)
Trending: A primer on OS Command Injection Attacks Trending: Offensive Security Tool: Bypass Url Parser HinataBot might implement more exploits while widening its scopeAkamai’s analysts created a Command and Control (C2) server of their own and interacted with simulated infections to stage HinataBot for DDoS attacks to observe the malware in action and infer its attack capabilities. Although HinataBot is still in development and might implement more exploits and widen its targeting scope anytime, the fact that its development is so active increases the likelihood of seeing more potent versions circulating in the wild soon. “Let’s hope that the HinataBot authors move onto new hobbies before we have to deal with their botnet at any real scale,” warns Akamai.
Trending: Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new tools Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-cont…
://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-8-300x150.png Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsMarch 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks first appeared on Black Hat Ethical Hacking.
Public Bucket : Change Any User Profile Image
Singkat cerita saya membuka sebuah nft marketplace yaitu https://xanalia.com/ dan seperti biasa saya mencari sebuah bug di website…Continue reading on Medium »
Read more...
Singkat cerita saya membuka sebuah nft marketplace yaitu https://xanalia.com/ dan seperti biasa saya mencari sebuah bug di website…Continue reading on Medium »
Read more...
Understanding CVE-2023–23397: The Microsoft Outlook Vulnerability You Need to Know About
Introduction:Continue reading on InfoSec Write-ups »
Read more...
Introduction:Continue reading on InfoSec Write-ups »
Read more...