Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Someone is trying to extort me, I have the cellphone, what can I do?

Today someone wrote me and said personal data of me and a treat in Indian, it seems like a noob but it makes me feel uneasy because he knows my direction and family names, what can I do? I just have the cellphone

submitted by /u/Intelligent-Emu-4740
[link] [comments]
hacking: security in practice
Login attempts maximum has been reached

Recently I noticed a plethora of Ip addresses in my network. Ranging from Japan, to right down the street.

My question is why or how can my cpu continue to state maximum “login attempts reached” when I literally just booted up my cpu. At first I thought it was my child who was keyboard mashing. But this is not the case. This is like the third of fourth time I walk away from my cpu and then return to sign in and boom! Maximum login attempts reach please enter A1B2C3. Thoughts and advice will be greatly appreciated.

submitted by /u/MadScientist2023
[link] [comments]
Unveiling the Secrets: My Journey of Hacking Google’s OSS

- August 22, 2022Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DDOS Attack on Karachi & Lahore Airport Websites

https://cdn-images-1.medium.com/max/1080/1*hEsCwydYUfusPreXrrAYiA.png
DDoS (Distributed Denial of Service) can be very dangerous as they make an online service, network resource or host machine unavailable to…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Great Router Heist: My Journey to Pwn2Own Tokyo

https://cdn-images-1.medium.com/max/1060/1*1vJEFBeFwdghqx0cuqtuYQ.png
Whattup hackers, gather ‘round and let me regale you with the thrilling tale of my journey to one day compete at the embedded security leg…

Continue reading on Medium »
The Great Router Heist: My Journey to Pwn2Own Tokyo

Whattup hackers, gather ‘round and let me regale you with the thrilling tale of my journey to one day compete at the embedded security leg…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft’s Misconfigured Application Allowed for Real-Time Breach Attempts on Bing.com

Microsoft’s Misconfigured Application Allowed for Real-Time Breach Attempts on Bing.comPost Views: 1 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes BingBang FlawMicrosoft has fixed a security flaw that could have allowed malicious actors to modify Bing.com search results and potentially breach the accounts of Office 365 users. The flaw was discovered by Wiz Research, which dubbed the attack “BingBang.”

According to Wiz researchers, the security issue arose due to a misconfigured Microsoft application that allowed users to log in and make modifications in real-time. The researchers found that when creating an application in Azure App Services and Azure Functions, it could be mistakenly configured to allow users from any Microsoft tenant, including public users, to log in to the application.

This configuration setting is called ‘Support account types’ and lets developers specify if a specific tenant multi-tenant, personal accounts, or a mix of multi and personal accounts should be allowed to access the application.

This configuration option is offered for legitimate cases where developers must make their apps available across organizational boundaries. However, if a developer mistakenly assigns looser permissions, it could cause unwanted access to the application and its features.

https://www.bleepstatic.com/images/news/u/1220909/2023/Security/14/configuration.png Azure AD user access configuration options (Wiz)
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses
Wiz researchers also found a misconfigured “Bing Trivia” app that allowed anyone to log in to the application and access its CMS (Content Management System). The app was directly linked to Bing.com, allowing the researchers to modify the live content shown in Bing search results. They succeeded in modifying search results for the “best soundtracks” search term, adding arbitrary results to the top carousel. XSS attacksNext, the analysts tested if they could inject a payload into the Bing search results using this same CMS and found they could execute a cross-site scripting (XSS) attack on Bing.com.

https://www.bleepstatic.com/images/news/security/attacks/bing-xss-attack.jpg Bing.com XSS attack (Wiz)
After confirming that the XSS was possible, Wiz reported its findings to Microsoft and worked with the software company to determine the exact impact of this second attack. A test XSS showed that it was possible to compromise the Office 365 token of any Bing user that saw the carousel in the search results, giving them full access to the searchers’ accounts, including access to Outlook emails, calendar data, messages on Teams, SharePoint documents, and OneDrive files.
Trending: Exploit XSS Injections in a one-line powerful Technique
Trending: Offensive Security Tool: OpenRediWrecked Microsoft issues a fixMicrosoft downplayed the issue, saying that the misconfiguration that allowed external parties read and write access impacted only a small number of internal applications and was corrected immediately. Microsoft added that it has introduced security enhancements that will prevent Azure AD misconfiguration issues from becoming a problem again.

Microsoft has also stopped issuing access tokens to clients not registered in the resource tenants, limiting access only to properly registered clients. “This functionality has been disabled for more than 99% of customer applications,” reads Microsoft’s advisory. “For the remainder of multi-tenant r[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft’s Misconfigured Application Allowed for Real-Time Breach Attempts on Bing.com Microsoft’s Misconfigured Application Allowed for Real-Time Breach Attempts on Bing.comPost Views: 1 Premium Contenthttps://www.blackhatethi…
esource applications that rely on access from clients without a service principal, we have provided instructions in an Azure Service Health Security Advisory to Global Admins (Azure Portal and email) and in the Microsoft 365 Message Center.”

In addition to these measures, Microsoft has also added additional security checks for multi-tenant applications, checking for tenant ID matching on a set allow-list and the presence of a client registration (Service Principal). Developers and admins that control multi-tenant applications are recommended to consult Microsoft’s updated guidance on securing them properly.

Wiz Research received a bug bounty of $40,000 for responsibly disclosing their findings to Microsoft. While Microsoft has fixed the issue, this security flaw underscores the importance of proper security configurations and highlights the risks associated with misconfigured applications. Developers and admins must be aware of the risks and take the necessary steps to secure their applications properly to avoid such issues in the future.
Trending: Severe Privacy Vulnerability ‘Acropalypse’ Affects Windows 11 Snipping Tool
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-19-300x150.png Major Companies Hit in Ongoing 3CX VoIP Supply Chain AttackMarch 30, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-17-300x150.png Attackers Could Exploit Flaw in WiFi Protocol to Hijack TCP ConnectionsMarch 29, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-16-300x150.png MacStealer: The new info-stealing malware targeting Mac usersMarch 28, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-15-300x150.png Microsoft Uncovers Evidence of Russian Hackers Exploiting Outlook VulnerabilityMarch 27, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post Microsoft’s Misconfigured Application Allowed for Real-Time Breach Attempts on Bing.com first appeared on Black Hat Ethical Hacking.