hacking: security in practice
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Funniest shit ever, friend of mine brought it up. Happened to them, still has the picture he took when his laptop cam took his picture! Man looked like a deer in headlights.
submitted by /u/TKOx13
[link] [comments]
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Funniest shit ever, friend of mine brought it up. Happened to them, still has the picture he took when his laptop cam took his picture! Man looked like a deer in headlights.
submitted by /u/TKOx13
[link] [comments]
Reddit
r/hacking on Reddit: Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was…
Posted by u/TKOx13 - No votes and no comments
hacking: security in practice
Covenant C2 - unrecognized connections
So I wake up this morning and decide to continue dicking around with a C2 server I had setup to demo some hacking related things to friends a while back...
And discovered about 100 apparently live connections from machines I have never seen or interacted with before.
Quickly killed the C2 and promptly began freaking tf out.
These machines should not be there ---
Checking the logs it doesn't look like there was any commands issued to them...not a whoami, nothing... just connections so I am hoping this means no one has been using my C2 for thier own nefarious purposes.
I nmaped my c2 server's bridge port, and also tried to netcat into it - neither of these things made a new connection appear in the C2's list... which means all these machines I am seeing are probably not just bots port scanning stuff...
I have the dropper hosted on a little http server on the same machine, it's just an exe that sits there... as far as I know, basically the only way to get a connection to the C2 is to 1. Disable your antivirus 2. download this file 3. Run it.
So like... I guess my questions are:
1.
How much shit am I in? As far as I know there's not been any commands issued from my C2 to these zombies or whatever you want to call them. But is just making a connection to it a problem? Even if these machines did so apparently of thier own accord?
2.
How the fuck are these machines even here?
3.
Is it possible these machines might be securty researchers or honeypots, waiting to see if they make a connection to this C2, what type of commands might come from it. Or like "let's download this malware and see what it does so we can figure out what it's trying to do and if it's part of some kind of larger illegal activity so we can stop it" type thing?
Most of the host names and usernames look legit... there are a couple basically random strings as host names... but some of them are a bit too on-the-nose, "John, fred" etc. Like too much like "oh I'm just a dumb user who doesn't know anything about computers, please attack me" type vibes.
Gave me quite the scare this morning, was not expecting that. I suppose if I want to demo this stuff I'll need to think of another option that I can somehow hide from the prying eyes of... I guess people who purposefully download and run, as far as they know, malicious software? Lesson learned I think.
submitted by /u/throwaway_h478shk2i7
[link] [comments]
Covenant C2 - unrecognized connections
So I wake up this morning and decide to continue dicking around with a C2 server I had setup to demo some hacking related things to friends a while back...
And discovered about 100 apparently live connections from machines I have never seen or interacted with before.
Quickly killed the C2 and promptly began freaking tf out.
These machines should not be there ---
Checking the logs it doesn't look like there was any commands issued to them...not a whoami, nothing... just connections so I am hoping this means no one has been using my C2 for thier own nefarious purposes.
I nmaped my c2 server's bridge port, and also tried to netcat into it - neither of these things made a new connection appear in the C2's list... which means all these machines I am seeing are probably not just bots port scanning stuff...
I have the dropper hosted on a little http server on the same machine, it's just an exe that sits there... as far as I know, basically the only way to get a connection to the C2 is to 1. Disable your antivirus 2. download this file 3. Run it.
So like... I guess my questions are:
1.
How much shit am I in? As far as I know there's not been any commands issued from my C2 to these zombies or whatever you want to call them. But is just making a connection to it a problem? Even if these machines did so apparently of thier own accord?
2.
How the fuck are these machines even here?
3.
Is it possible these machines might be securty researchers or honeypots, waiting to see if they make a connection to this C2, what type of commands might come from it. Or like "let's download this malware and see what it does so we can figure out what it's trying to do and if it's part of some kind of larger illegal activity so we can stop it" type thing?
Most of the host names and usernames look legit... there are a couple basically random strings as host names... but some of them are a bit too on-the-nose, "John, fred" etc. Like too much like "oh I'm just a dumb user who doesn't know anything about computers, please attack me" type vibes.
Gave me quite the scare this morning, was not expecting that. I suppose if I want to demo this stuff I'll need to think of another option that I can somehow hide from the prying eyes of... I guess people who purposefully download and run, as far as they know, malicious software? Lesson learned I think.
submitted by /u/throwaway_h478shk2i7
[link] [comments]
Reddit
r/hacking on Reddit: Covenant C2 - unrecognized connections
Posted by u/throwaway_h478shk2i7 - No votes and no comments
hacking: security in practice
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Reddit
r/hacking on Reddit: Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was…
Posted by u/TKOx13 - No votes and no comments
hacking: security in practice
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Funniest shit ever, friend of mine brought it up. Happened to them, still has the picture he took when his laptop cam took his picture! Man looked like a deer in headlights.
submitted by /u/TKOx13
[link] [comments]
Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was breaking down your door after the time limit? 🤣
Funniest shit ever, friend of mine brought it up. Happened to them, still has the picture he took when his laptop cam took his picture! Man looked like a deer in headlights.
submitted by /u/TKOx13
[link] [comments]
Reddit
r/hacking on Reddit: Anyone remember the drive by virus from like 10-15 years ago that requested money from you or the FBI was…
Posted by u/TKOx13 - No votes and no comments
hacking: security in practice
Certifications?
Certifications?
Reddit
r/hacking on Reddit: Certifications?
Posted by u/MrRainStormJr - No votes and no comments
hacking: security in practice
It it possible to program a debit card with unlimited virtual money? (Educational purposes)
Note: I am not a hacker and do not know any programming languages.
I am not writing this to promote any illegal activities, this is solely for educational purposes, and to understand how these systems work.
If a regular debit card has a certain value of money on it can it not be replicated?
I understaned that when your card makes a contactless payment such as buying chips from a store, what happens is the card "tells" the machine i am a card and then the card machine contacts the bank database to see how much money is stored on the card - this is probably some sort of computer value. I would assume that these databases would be insanely encrypted and noone but only a insanly skilled hacker could acsess it, but my question is, cant you make your own programmed bank? With your own unlimted value of money? After all, what we are trying to achive here is to trick the card machine into thinking that it is scanning a real card from a real bank company. I dont see why we cant make our own versin of this exactly as the bank company made these systems and add an unlimited value of money. At the end of the day, every bank account balance is just a programmed computer value.
submitted by /u/chillkid3
[link] [comments]
It it possible to program a debit card with unlimited virtual money? (Educational purposes)
Note: I am not a hacker and do not know any programming languages.
I am not writing this to promote any illegal activities, this is solely for educational purposes, and to understand how these systems work.
If a regular debit card has a certain value of money on it can it not be replicated?
I understaned that when your card makes a contactless payment such as buying chips from a store, what happens is the card "tells" the machine i am a card and then the card machine contacts the bank database to see how much money is stored on the card - this is probably some sort of computer value. I would assume that these databases would be insanely encrypted and noone but only a insanly skilled hacker could acsess it, but my question is, cant you make your own programmed bank? With your own unlimted value of money? After all, what we are trying to achive here is to trick the card machine into thinking that it is scanning a real card from a real bank company. I dont see why we cant make our own versin of this exactly as the bank company made these systems and add an unlimited value of money. At the end of the day, every bank account balance is just a programmed computer value.
submitted by /u/chillkid3
[link] [comments]
Reddit
r/hacking on Reddit: It it possible to program a debit card with unlimited virtual money? (Educational purposes)
Posted by u/chillkid3 - No votes and no comments
Sweat Economy x Immunefi Bug Bounty!
Continuing our dedication to strengthen our security against malicious actors, we have partnered with Immunefi to deliver rewards for…Continue reading on Sweat Economy »
Read more...
Continuing our dedication to strengthen our security against malicious actors, we have partnered with Immunefi to deliver rewards for…Continue reading on Sweat Economy »
Read more...
How I escalated default credentials to Remote Code Execution
https://pawanchhabria.medium.com/how-i-escalated-default-credentials-to-remote-code-execution-1c34504be7a5?source=rss------bug_bounty-5
https://pawanchhabria.medium.com/how-i-escalated-default-credentials-to-remote-code-execution-1c34504be7a5?source=rss------bug_bounty-5
Hello All, We all know Recon is very important to get P1 bugs. Shodan and Censys are probably the best search engines. I have been testing…Continue reading on Medium » (https://pawanchhabria.medium.com/how-i-escalated-default-credentials-to-remote-code-execution-1c34504be7a5?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[Tryhackme] MD2PDF
https://cdn-images-1.medium.com/max/951/1*6hC4TqJ5HnuV5AmEQ4uY3A.png
For this walkthrough, we’ll be using the provided attackbox in the room.
Continue reading on Medium »
[Tryhackme] MD2PDF
https://cdn-images-1.medium.com/max/951/1*6hC4TqJ5HnuV5AmEQ4uY3A.png
For this walkthrough, we’ll be using the provided attackbox in the room.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google dorks
In this article, i will provide 10 examples of Google Dorks that can be used for both red teaming and penetration testing.
Continue reading on Medium »
Google dorks
In this article, i will provide 10 examples of Google Dorks that can be used for both red teaming and penetration testing.
Continue reading on Medium »