Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pool on the roof - March 20, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Pool on the roof - March 20, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I am going to enroll for OSCP, i would appreciate any possibile insights!
I've been using Linux since i was 14 because i only had my father's old laptop from 2008 and that thing couldn't run anything more than linux, right now I'm 19 and have been doing bug bounties from 6 ish months. I'm a bit behind academically but i am going to do bachelor's in computer science specialization in cybersecurity this year, I've looked through the syllabus and I'm mostly familiar with every subject except advance engineering mathematics. Since I'm gonna have a lot of free time and it's been my dream to pursue OSCP i am going to enroll for OSCP this year. i would appreciate any and all kind of advice and insight.
I'm fairly sure with 3 months of lab and 9 months of training I'll be able to pass OSCP, and over the past two years i have hacked hundreds of vulnhub virtual machines. Not being too cocky though cause i read a lot on this sub how OSCP can fail even the best so my next best move is to learn from other people's failures and give it my best and hopefully pass.
submitted by /u/Naitikxo
[link] [comments]
I am going to enroll for OSCP, i would appreciate any possibile insights!
I've been using Linux since i was 14 because i only had my father's old laptop from 2008 and that thing couldn't run anything more than linux, right now I'm 19 and have been doing bug bounties from 6 ish months. I'm a bit behind academically but i am going to do bachelor's in computer science specialization in cybersecurity this year, I've looked through the syllabus and I'm mostly familiar with every subject except advance engineering mathematics. Since I'm gonna have a lot of free time and it's been my dream to pursue OSCP i am going to enroll for OSCP this year. i would appreciate any and all kind of advice and insight.
I'm fairly sure with 3 months of lab and 9 months of training I'll be able to pass OSCP, and over the past two years i have hacked hundreds of vulnhub virtual machines. Not being too cocky though cause i read a lot on this sub how OSCP can fail even the best so my next best move is to learn from other people's failures and give it my best and hopefully pass.
submitted by /u/Naitikxo
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes HinataBot targetsAkamai researchers recently discovered a new malware botnet known as HinataBot that targets Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into a distributed denial of service (DDoS) swarm. The botnet exploits old flaws such as CVE-2014-8361 and CVE-2017-17215 and was first detected in mid-January 2023. HinataBot seems to be based on Mirai and is a Go-based variant of the notorious malware strain. Akamai’s researchers captured multiple samples from active campaigns as recently as March 2023 and deduced that the malware is under active development, featuring functional improvements and anti-analysis additions.
HinataBot is distributed by brute-forcing Secure Shell (SSH) endpoints or using infection scripts and Remote Code Execution (RCE) payloads for known vulnerabilities. After infecting devices, the malware remains silent, waiting for commands to execute from the command and control server. Even though the newer variants only feature HTTP and User Datagram Protocol (UDP) flood attacks, the botnet can potentially perform powerful DDoS attacks. Older versions of HinataBot supported HTTP, UDP, Internet Control Message Protocol (ICMP), and Transmission Control Protocol (TCP) floods.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 3.3 Tbps DDoS attacksAkamai researchers benchmarked the botnet in 10-second attacks for both HTTP and UDP. In the HTTP attack, the malware generated 20,430 requests for a total size of 3.4 MB. The UDP flood generated 6,733 packages totaling 421 MB of data. The researchers estimated that with 1,000 nodes, the UDP flood could generate roughly 336 Gbps, while at 10,000 nodes, the attack data volume would reach 3.3 Tbps. In the case of the HTTP flood, 1,000 ensnared devices would generate 2,000,000 requests per second, while 10,000 nodes would take that number of 20,400,000 requests per second and 27 Gbps.
https://www.bleepstatic.com/images/news/u/1220909/2023/DDoS/6/udp-capture.jpg
UDP flood packet capture (Akamai)
Trending: A primer on OS Command Injection Attacks Trending: Offensive Security Tool: Bypass Url Parser HinataBot might implement more exploits while widening its scopeAkamai’s analysts created a Command and Control (C2) server of their own and interacted with simulated infections to stage HinataBot for DDoS attacks to observe the malware in action and infer its attack capabilities. Although HinataBot is still in development and might implement more exploits and widen its targeting scope anytime, the fact that its development is so active increases the likelihood of seeing more potent versions circulating in the wild soon. “Let’s hope that the HinataBot authors move onto new hobbies before we have to deal with their botnet at any real scale,” warns Akamai.
Trending: Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new tools Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https[...]
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks
Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes HinataBot targetsAkamai researchers recently discovered a new malware botnet known as HinataBot that targets Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into a distributed denial of service (DDoS) swarm. The botnet exploits old flaws such as CVE-2014-8361 and CVE-2017-17215 and was first detected in mid-January 2023. HinataBot seems to be based on Mirai and is a Go-based variant of the notorious malware strain. Akamai’s researchers captured multiple samples from active campaigns as recently as March 2023 and deduced that the malware is under active development, featuring functional improvements and anti-analysis additions.
HinataBot is distributed by brute-forcing Secure Shell (SSH) endpoints or using infection scripts and Remote Code Execution (RCE) payloads for known vulnerabilities. After infecting devices, the malware remains silent, waiting for commands to execute from the command and control server. Even though the newer variants only feature HTTP and User Datagram Protocol (UDP) flood attacks, the botnet can potentially perform powerful DDoS attacks. Older versions of HinataBot supported HTTP, UDP, Internet Control Message Protocol (ICMP), and Transmission Control Protocol (TCP) floods.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses 3.3 Tbps DDoS attacksAkamai researchers benchmarked the botnet in 10-second attacks for both HTTP and UDP. In the HTTP attack, the malware generated 20,430 requests for a total size of 3.4 MB. The UDP flood generated 6,733 packages totaling 421 MB of data. The researchers estimated that with 1,000 nodes, the UDP flood could generate roughly 336 Gbps, while at 10,000 nodes, the attack data volume would reach 3.3 Tbps. In the case of the HTTP flood, 1,000 ensnared devices would generate 2,000,000 requests per second, while 10,000 nodes would take that number of 20,400,000 requests per second and 27 Gbps.
https://www.bleepstatic.com/images/news/u/1220909/2023/DDoS/6/udp-capture.jpg
UDP flood packet capture (Akamai)
Trending: A primer on OS Command Injection Attacks Trending: Offensive Security Tool: Bypass Url Parser HinataBot might implement more exploits while widening its scopeAkamai’s analysts created a Command and Control (C2) server of their own and interacted with simulated infections to stage HinataBot for DDoS attacks to observe the malware in action and infer its attack capabilities. Although HinataBot is still in development and might implement more exploits and widen its targeting scope anytime, the fact that its development is so active increases the likelihood of seeing more potent versions circulating in the wild soon. “Let’s hope that the HinataBot authors move onto new hobbies before we have to deal with their botnet at any real scale,” warns Akamai.
Trending: Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new tools Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksPost Views: 7 Premium Contenthttps://www.blackhatethicalhacking.com/wp-cont…
://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-8-300x150.png Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsMarch 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks first appeared on Black Hat Ethical Hacking.
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-5-1-300x150.png Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new toolsMarch 14, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Akamai warns of new HinataBot malware botnet capable of massive DDoS attacks first appeared on Black Hat Ethical Hacking.
Public Bucket : Change Any User Profile Image
Singkat cerita saya membuka sebuah nft marketplace yaitu https://xanalia.com/ dan seperti biasa saya mencari sebuah bug di website…Continue reading on Medium »
Read more...
Singkat cerita saya membuka sebuah nft marketplace yaitu https://xanalia.com/ dan seperti biasa saya mencari sebuah bug di website…Continue reading on Medium »
Read more...
Understanding CVE-2023–23397: The Microsoft Outlook Vulnerability You Need to Know About
Introduction:Continue reading on InfoSec Write-ups »
Read more...
Introduction:Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
NimPlant - A Light-Weight First-Stage C2 Implant Written In Nim
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTvWF-hWsmT64ueqlJxKqahZ8Vo-V7hh064x6tkQ-wH1l_RYIeb5qn78iM_Fb4GXoH-zjpIz6OgdHdSbyBp4EeBvpwY_TbUXXKml5uuWVeUiXTHcQIW02Kr6APuaGHKOCZeIlhI_CtNcHH9eRW--PANMF88Mnw6GlAr8nWmVxpN7E6995LVqalCtYB3g/w640-h142/nimplant-logomark.png By Cas van Cooten (@chvancooten), with special thanks to some awesome folks:
* Fabian Mosch (@S3cur3Th1sSh1t) for sharing dynamic invocation implementation in Nim and the Ekko sleep mask function
* snovvcrash (@snovvcrash) for adding the initial version of
* Furkan Göksel (@frkngksl) for his work on NiCOFF and Guillaume Caillé (@OffenseTeacher) for the initial implementation of
* Mauricio Velazco (@mvelazco), Dylan Makowski (@AnubisOnSec), Andy Palmer (@pivotal8ytes), Medicus Riddick (@retsdem22), Spencer Davis (@nixbyte), and Florian Roth (@cyb3rops), for their efforts in testing the pre-release and contributing detections Feature Overview* Lightweight and configurable implant written in the Nim programming language
* Pretty web GUI that will make you look cool during all your ops
* Encryption and compression of all traffic by default, obfuscates static strings in implant artefacts
* Support for several implant types, including native binaries (exe/dll), shellcode or self-deleting executables
* Wide selection of commands focused on early-stage operations including local enumeration, file or registry management, and web interactions
* Easy deployment of more advanced functionality or payloads via
* Comprehensive logging of all interactions and file operations
* Much, much more, just see below :) InstructionsInstallation* Install Nim and Python3 on your OS of choice (installation via
* Install required packages using the Nimble package manager (
* Install
* If you're on Linux or MacOS, install the
An overview of settings is provided below.
Category Setting Description server ip The IP that the C2 web server (including API) will listen on. Recommended to use 127.0.0.1, only use 0.0.0.0 when you have setup proper firewall or routing rules to protect the C2. server port The port that the C2 web server (including API) will listen on. listener type The listener type, either HTTP or HTTPS. HTTPS options configured below. listener sslCertPath The local path to a HTTPS certificate file (e.g. requested via LetsEncrypt CertBot or self-signed). Ignored when listener type is 'HTTP'. listener sslKeyPath The local path to the corresponding HTTPS certificate private key file. Password will be prompted when running the NimPlant server if set. Ignored when listener type is 'HTTP'. listener hostname The listener hostname. If not empty (""), NimPlant will use this hostname to connect. Make sure you are properly routing traffic from this host to the NimPlant listener port. listener ip The listener IP. Required even if[...]
NimPlant - A Light-Weight First-Stage C2 Implant Written In Nim
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTvWF-hWsmT64ueqlJxKqahZ8Vo-V7hh064x6tkQ-wH1l_RYIeb5qn78iM_Fb4GXoH-zjpIz6OgdHdSbyBp4EeBvpwY_TbUXXKml5uuWVeUiXTHcQIW02Kr6APuaGHKOCZeIlhI_CtNcHH9eRW--PANMF88Mnw6GlAr8nWmVxpN7E6995LVqalCtYB3g/w640-h142/nimplant-logomark.png By Cas van Cooten (@chvancooten), with special thanks to some awesome folks:
* Fabian Mosch (@S3cur3Th1sSh1t) for sharing dynamic invocation implementation in Nim and the Ekko sleep mask function
* snovvcrash (@snovvcrash) for adding the initial version of
execute-assembly& self-deleting implant option* Furkan Göksel (@frkngksl) for his work on NiCOFF and Guillaume Caillé (@OffenseTeacher) for the initial implementation of
inline-execute* Kadir Yamamoto (@yamakadi) for the design work, initial Vue.JS front-end and rusty nimplant, part of an older branch (unmaintained)* Mauricio Velazco (@mvelazco), Dylan Makowski (@AnubisOnSec), Andy Palmer (@pivotal8ytes), Medicus Riddick (@retsdem22), Spencer Davis (@nixbyte), and Florian Roth (@cyb3rops), for their efforts in testing the pre-release and contributing detections Feature Overview* Lightweight and configurable implant written in the Nim programming language
* Pretty web GUI that will make you look cool during all your ops
* Encryption and compression of all traffic by default, obfuscates static strings in implant artefacts
* Support for several implant types, including native binaries (exe/dll), shellcode or self-deleting executables
* Wide selection of commands focused on early-stage operations including local enumeration, file or registry management, and web interactions
* Easy deployment of more advanced functionality or payloads via
inline-execute, shinject(using dynamic invocation), or in-thread execute-assembly* Support for operations on any platform, implant only targeting x64 Windows for now* Comprehensive logging of all interactions and file operations
* Much, much more, just see below :) InstructionsInstallation* Install Nim and Python3 on your OS of choice (installation via
choosenimis recommended, as aptdoesn't always have the latest version).* Install required packages using the Nimble package manager (
cd client; nimble install -d).* Install
requirements.txtfrom the server folder (pip3 install -r server/requirements.txt).* If you're on Linux or MacOS, install the
mingwtoolchain for your platform (brew install mingw-w64 or apt install mingw-w64). Getting StartedConfigurationBefore using NimPlant, create the configuration file config.toml. It is recommended to copy config.toml.exampleand work from there.An overview of settings is provided below.
Category Setting Description server ip The IP that the C2 web server (including API) will listen on. Recommended to use 127.0.0.1, only use 0.0.0.0 when you have setup proper firewall or routing rules to protect the C2. server port The port that the C2 web server (including API) will listen on. listener type The listener type, either HTTP or HTTPS. HTTPS options configured below. listener sslCertPath The local path to a HTTPS certificate file (e.g. requested via LetsEncrypt CertBot or self-signed). Ignored when listener type is 'HTTP'. listener sslKeyPath The local path to the corresponding HTTPS certificate private key file. Password will be prompted when running the NimPlant server if set. Ignored when listener type is 'HTTP'. listener hostname The listener hostname. If not empty (""), NimPlant will use this hostname to connect. Make sure you are properly routing traffic from this host to the NimPlant listener port. listener ip The listener IP. Required even if[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Türkiye’nin ilk ‘Uygulamalı Siber Güvenlikte Yapay Zeka’ Eğitimi
https://cdn-images-1.medium.com/max/1323/1*1mAqCvWka8owlr_0wEsK1g.png
2000'lerin başlarından beri siber güvenlik, yazılım ve gene uzun yıllardır yapay zeka alanında yaptığım çalışmaları birleştirerek siber…
Continue reading on Medium »
Türkiye’nin ilk ‘Uygulamalı Siber Güvenlikte Yapay Zeka’ Eğitimi
https://cdn-images-1.medium.com/max/1323/1*1mAqCvWka8owlr_0wEsK1g.png
2000'lerin başlarından beri siber güvenlik, yazılım ve gene uzun yıllardır yapay zeka alanında yaptığım çalışmaları birleştirerek siber…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Modern Social Engineering Explained: 10 Forms of Social Engineering Cyberattacks
https://cdn-images-1.medium.com/max/744/0*gMWjfaXWX6wgkNtF
Have you ever received a suspicious email or phone call from an unknown number asking for information? Or clicked on that link promising…
Continue reading on Medium »
Modern Social Engineering Explained: 10 Forms of Social Engineering Cyberattacks
https://cdn-images-1.medium.com/max/744/0*gMWjfaXWX6wgkNtF
Have you ever received a suspicious email or phone call from an unknown number asking for information? Or clicked on that link promising…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Meditation: The Ultimate Mind Hack for Modern Life
https://cdn-images-1.medium.com/max/600/0*2ZURg1folAxnQ-WT.png
Meditation is a practice that has been around for centuries, but many people may not realize the full extent of its benefits. While most…
Continue reading on Medium »
“Meditation: The Ultimate Mind Hack for Modern Life
https://cdn-images-1.medium.com/max/600/0*2ZURg1folAxnQ-WT.png
Meditation is a practice that has been around for centuries, but many people may not realize the full extent of its benefits. While most…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
pWnOS Walkthrough
https://cdn-images-1.medium.com/max/666/0*w_PW2Ox7zY3p84ix
pWnOS is a simple boot to root machine I came across at NetSecFocus Trophy Room. Let’s try and get the root together!
Continue reading on Medium »
pWnOS Walkthrough
https://cdn-images-1.medium.com/max/666/0*w_PW2Ox7zY3p84ix
pWnOS is a simple boot to root machine I came across at NetSecFocus Trophy Room. Let’s try and get the root together!
Continue reading on Medium »