Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to keep multiple hard-drives isolated?

I have one SSD with operating system installed. I use this drive for all my personal and banking related stuff. I keep this drive clean and free from viruses.

I also have another SSD with operating system installed on it aswell. I want to keep this drive isolated since I do alot of testing and running potentially malicious softwares without having to worry about compromising my main hard drive.

Though if I have both these SSD plugged in and select which one to boot from. Is it possible for anything malicious to leak from one drive to the other drive even though I am not using the other drive while both are plugged in?

If so, what is the best way to keep seperate hard drives isolated from each other?

submitted by /u/-obfuscated
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Could you track a newer car?

My 2018 Porsche was stolen. Was wondering if it’s possible to hack/track the cars location? Thanks!

submitted by /u/Pawsaber
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
General Bytes Bitcoin ATMs Hacked via Zero-Day Attack

General Bytes Bitcoin ATMs Hacked via Zero-Day AttackPost Views: 24 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Hackers Used Zero-Day Vulnerability to Steal CryptocurrencyBitcoin ATM manufacturer General Bytes recently disclosed that its management platform was exploited by hackers, resulting in the theft of cryptocurrency from the company and its customers. The attackers used a zero-day vulnerability in the BATM management platform to steal funds from Bitcoin ATMs that allow users to buy or sell over 40 different cryptocurrencies.

According to General Bytes, the attackers remotely uploaded a Java application via the ATM’s master service interface and ran it with “batm” user privileges. This enabled them to perform several actions, including accessing the database, reading and decrypting API keys, sending funds from hot wallets, downloading user names and password hashes, and turning off 2FA.
On March 17-18th, 2023, GENERAL BYTES experienced a security incident.

We released a statement urging customers to take immediate action to protect their personal information.

We urge all our customers to take immediate action to protect their funds and https://t.co/fajc61lcwRhttps://t.co/g5FGqvqZQ7

— GENERAL BYTES (@generalbytes) March 18, 2023
The company has urged its customers to take immediate action and install the latest updates to protect their servers and funds from attackers. General Bytes also provided a list of cryptocurrency addresses used by the hacker during the attack, which shows that the attacker began stealing cryptocurrency from Bitcoin ATM servers on March 17th, with the attacker’s Bitcoin address receiving 56.28570959 BTC, worth approximately $1,589,000, and 21.79436191 Ethereum, worth roughly $39,000.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses General Bytes to Shutter Cloud Service Due to Security ConcernsGeneral Bytes has announced that it will shutter its cloud service, stating that it is “theoretically (and practically) impossible” to secure it from bad actors when it must simultaneously provide access to multiple operators. The company will provide support with data migration to those who would like to install their own standalone Crypto Application Server (CAS), which should now be placed behind a firewall and VPN.

To address the exploited vulnerability, General Byte has released a CAS security fix provided in two patches, 20221118.48 and 20230120.44. The company plans to conduct numerous security audits of its products by multiple companies in a short period to discover and fix other potential flaws before bad actors find them.

However, this is not the first time that General Bytes has faced security incidents. In August 2022, the company experienced a security breach where hackers exploited a zero-day vulnerability in its ATM servers to steal cryptocurrency from its customers. Additionally, researchers from the Kraken cryptocurrency exchange found multiple vulnerabilities in General Bytes’ ATMs in 2021, which the company quickly fixed.
Trending: A primer on OS Command Injection Attacks Trending: Offensive Security Tool: Bypass Url Parser Multiple security audits, but none of them found the exploited vulnerabilityDespite undergoing multiple security audits since 2021, none identified the exploited vulnerability that led to this recent attack. General Bytes’ experience highlights the importance of regularly testing and auditing the security of any software or hardware used in financial transactions. This also underscores the importance of swift action and up[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking General Bytes Bitcoin ATMs Hacked via Zero-Day Attack General Bytes Bitcoin ATMs Hacked via Zero-Day AttackPost Views: 24 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon…
dates in the face of known or potential security threats.

To protect against such attacks, users of Bitcoin ATMs and other crypto services should remain vigilant, maintain strong passwords and use two-factor authentication whenever possible. They should also regularly update their software and hardware, implement firewalls and VPNs, and monitor their accounts for unusual activity.
Trending: Kali Linux 2023.1 – Adds Kali Purple for defensive security, python updates, new tools Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-9-300x150.png Akamai warns of new HinataBot malware botnet capable of massive DDoS attacksMarch 20, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-8-300x150.png Samsung Users at Risk: 18 Zero-Day Vulnerabilities Found in Exynos ChipsetsMarch 17, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-7-300x150.png CISA Identifies Critical Vulnerability in Adobe ColdFusionMarch 16, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-6-300x150.png Russian hackers exploit Outlook zero-day vulnerability to target European organizationsMarch 15, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post General Bytes Bitcoin ATMs Hacked via Zero-Day Attack first appeared on Black Hat Ethical Hacking.
Dark Reading: Attacks/Breaches
IAM Startup Aembit Secures How Workloads Connect to Services

Aembit launches from stealth with a cloud-based identity access management platform for enterprise workloads.
Detailed Explanation of Status codes for HTTP responses

What HTTP Response Status Codes Are And Why They Are ImportantContinue reading on Bug Zero »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Invoke-PSObfuscation - An In-Depth Approach To Obfuscating The Individual Components Of A PowerShell Payload Whether You'Re On Windows Or Kali Linux

https://blogger.googleusercontent.com/img/a/AVvXsEhvHxpOWiJ1NSyXmIWJcHIH7haCoxHylKQQ9-j13MtsLdnMdFOU3Mzs_QT7x-7RH3us_9j08DEzdwUUYAPpQnJXC_nUaLHCR2LExWqmgwds-IjoRT4nQX-xhj8cAaFUbvlzvaxpYW509hY4DMGpm0kUk_I1wN8WgTaW6V-Q-mPKVPdUK6tCiLavJcby_w=w640-h338 Traditional obfuscation techniques tend to add layers to encapsulate standing code, such as base64 or compression. These payloads do continue to have a varied degree of success, but they have become trivial to extract the intended payload and some launchers get detected often, which essentially introduces chokepoints.

The approach this tool introduces is a methodology where you can target and obfuscate the individual components of a script with randomized variations while achieving the same intended logic, without encapsulating the entire payload within a single layer. Due to the complexity of the obfuscation logic, the resulting payloads will be very difficult to signature and will slip past heuristic engines that are not programmed to emulate the inherited logic.

While this script can obfuscate most payloads successfully on it's own, this project will also serve as a standing framework that I will to use to produce future functions that will utilize this framework to provide dedicated obfuscated payloads, such as one that only produces reverse shells.

I wrote a blog piece for Offensive Security as a precursor into the techniques this tool introduces. Before venturing further, consider giving it a read first: https://www.offensive-security.com/offsec/powershell-obfuscation/ Dedicated PayloadsAs part of my on going work with PowerShell obfuscation, I am building out scripts that produce dedicated payloads that utilize this framework. These have helped to save me time and hope you find them useful as well. You can find them within their own folders at the root of this repository.

1. Get-ReverseShell
2. Get-DownloadCradle
3. Get-Shellcode ComponentsLike many other programming languages, PowerShell can be broken down into many different components that make up the executable logic. This allows us to defeat signature-based detections with relative ease by changing how we represent individual components within a payload to a form an obscure or unintelligible derivative.

Keep in mind that targeting every component in complex payloads is very instrusive. This tool is built so that you can target the components you want to obfuscate in a controlled manner. I have found that a lot of signatures can be defeated simply by targeting cmdlets, variables and any comments. When using this against complex payloads, such as print nightmare, keep in mind that custom function parameters / variables will also be changed. Always be sure to properly test any resulting payloads and ensure you are aware of any modified named paramters.

Component types such as pipes and pipeline variables are introduced here to help make your payload more obscure and harder to decode.

Supported Types

* Aliases (iex)
* Cmdlets (New-Object)
* Comments (# and <#)
* Integers (4444)
* Methods ($client.GetStream())
* Namespace Classes (System.Net.Sockets.TCPClient)
* Pipes (|)
* Pipeline Variables ($_)
* Strings ("value" | 'value')
* Variables ($client) GeneratorsEach component has its own dedicated generator that contains a list of possible static or dynamically generated values that are randomly selected during each execution. If there are multiple instances of a component, then it will iterative each of them individually with a generator. This adds a degree of randomness each time you run this tool against a given payload so each iteration will be different. The only exception to this is variable names.

If an algorithm related to a specific comp[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Rise of Automotive Hacking

https://cdn-images-1.medium.com/max/960/1*uuw-xF-dcScMZjegY90RUg.jpeg
With the increasing use of technology in modern automobiles, the risk of automotive hacking is on the rise. Automotive hacking refers to…

Continue reading on Medium »