Hacker Team Infiltrates Data
165 subscribers
839 photos
3 videos
4 links
Download Telegram
— 让搜索更高效 · 让信息更有价值 —

🔍帮你找到有趣的群组、频道、视频、音乐、电影、新闻
📢: @CJYQNEWS | 🤖: @CJYQ
👇点击下方按钮,进行搜索👇
— 让搜索更高效 · 让信息更有价值 —

🔍帮你找到有趣的群组、频道、视频、音乐、电影、新闻
📢: @CJYQNEWS | 🤖: @CJYQ
👇点击下方按钮,进行搜索👇
Please open Telegram to view this post
VIEW IN TELEGRAM
Burp Intruder is an extremely powerful automated testing tool in Burp Suite. It is usually used by system security penetration testers in various task testing scenarios. In the process of penetration testing, we often use Burp Intruder. Its working principle is: Intruder modifies various request parameters based on the original request data to obtain different request responses. In each request, Intruder usually carries one or more effective attack payloads (Payload), replays the attack at different locations, and obtains the required feature data through comparison and analysis of the response data. Burp Intruder is usually used in the following scenarios.
1. The attacker constructs special data that contains malicious code
2. The user's browser executes the malicious code
3. The user's data is maliciously stolen and sent to the attacker's website, or the user's behavior is impersonated, and the target website interface is called to perform the operation specified by the attacker. In DOM-type XSS attacks, the malicious code is retrieved and executed by the browser, which is a security vulnerability of the front-end javascript itself.
It can be seen that the repaired part is the urlresolvers.py file, which adds a check on the internal function of the reverse function passed in. Django has always been very secure. Since its release in 2005, there has been no RCE that can be directly exploited unconditionally. In the spirit of learning about Django, let's talk about the RCE caused by improper programming in Django. This time we will talk about the historical vulnerability CVE-2014-0472 and Django's new RCE exploitation method - FileBasedCache.

It can be seen that the repaired part is the urlresolvers.py file, which adds a check on the internal function of the reverse function passed in, and checks whether the method exists in the url routing table. Check whether the method exists in the url routing table.
— 让搜索更高效 · 让信息更有价值 —

🔍帮你找到有趣的群组、频道、视频、音乐、电影、新闻
📢: @CJYQNEWS | 🤖: @CJYQ
👇点击下方按钮,进行搜索👇
— 让搜索更高效 · 让信息更有价值 —

🔍帮你找到有趣的群组、频道、视频、音乐、电影、新闻
📢: @CJYQNEWS | 🤖: @CJYQ
👇点击下方按钮,进行搜索👇
Please open Telegram to view this post
VIEW IN TELEGRAM
A reverse RDP environment was configured using the Fast Reverse Proxy tool to access the Miner robot.
Fast Reverse Proxy is an open source reverse proxy tool. The normal version requires the user to import the target server information from the settings file or enter the information when executing. CoinMiner modified the code of the Fast Reverse Proxy file to automatically connect to the proxy server and use it for attack.

RDP Port Scanning
The proxy server was exposed to the internet. The ransomware checked all ports of systems exposed on the internet to see if they were using RDP and launched a brute force attack as an administrator against all targets with exposed RDP ports. In this case, it appears that the proxy server of the CoinMiner threat actor happened to be exposed, making it a target for a scanning attack that scanned for RDP ports.

Principle of brute force cracking of md5
First, collect some commonly used passwords such as 123456, and then you can brute force crack the website. Encrypt =, reverse, enter the encrypted value, and you can use the encrypted value to check the corresponding password, which is easy to crack.
❤1
In the entire process of surfing the Internet, the DNS link is undoubtedly vulnerable and out of the control of users. DNS hijacking usually occurs on the public DNS servers of network operators that provide Internet access to everyone, so it is difficult for ordinary users to handle and effectively prevent it, so when the target website is hijacked, it will jump to other addresses.
Use FOFA to search assets and get JBoss entry
Use FOFA to collect information on one of the domain names and find that there is unauthorized access to a JBoss asset. Here I directly log in to a shell.
Technical hacker cooperation: @blacktwone
Latest data on vitiligo

Technical hacker cooperation: @blacktwone
India very good board game BC resources, fresh database, data updated in real time, orders required, intermediaries do not disturb, data order customer service
Latest: stock investors, stock fans, Industrial Securities, can filter by region, filter by three networks. Can create groups and build fans, can do telemarketing SMS. Updated daily in real time, first-hand fresh
Use FOFA to search assets and get JBoss entry
Use FOFA to collect information on one of the domain names and find that there is unauthorized access to a JBoss asset. Here I directly log in to a shell.
Technical hacker cooperation: @blacktwone