2 479
Subscribers
No data24 hours
+47 days
+1830 days
Posts Archive
2 479
Sizden gelen sorular;
Bir disk imajından #MFT, #Prefetch, #Amcache ve #Shimcache gibi artefaktları analiz etmek mümkün müdür? Örneğin, #CyberDefenders gibi platformlarda paylaşılan disk imajları bu tür analizler için yeterli veri sağlar mı? Bu tür analizler için hangi araçlar tercih edilmelidir?
Cevap;
Evet, bir disk imajından MFT, Prefetch, Amcache ve Shimcache gibi artefaktları analiz etmek mümkündür. Bu tür veriler, genellikle disk imajının türüne ve olayın detaylarına bağlı olarak bulunabilir. Bu vb. platformlarda paylaşılan disk imajları, genellikle bu tür analizler için oldukça zengin veri içerir.
#CyberDefenders ve benzeri #CTF platformları, genelde dolu dolu disk imajları sunar. Bu sayede hem teknik bilginizi artırır hem de pratik yaparsınız.
Eric Zimmerman’ın araçları bu tarz analizlerde oldukça kullanışlıdır ve ücretsiz olarak ulaşabilirsiniz.
İmajı analiz etmek için başlangıçta Autopsy, FTK Imager gibi araçlar kullanabilir, ardından daha spesifik ihtiyaçlar için komut satırı araçlarına geçebilirsiniz.
2 479
Thousands of #MikroTik #routers become part of a #malicious #network
#Infoblox specialists have discovered a network of 13,000 compromised MikroTik routers. The #attackers used these devices to send #phishing emails, disguised as #DHL Express.
The #attackers #exploited a #vulnerability in the #SPF record settings with the "+all" parameter, which affected about 20,000 domains. This configuration error allowed any #server to send emails on behalf of legitimate domains.
#Infected devices were used as #SOCKS4 #proxy servers to conduct #DDoS #attacks and #steal #data. In the summer of 2024, this botnet was already seen in a record-breaking 840 Mpps DDoS attack on #OVHcloud #infrastructure
2 479
4,200 Computers Running PlugX: FBI Intervenes
The FBI conducted a special operation to remove the PlugX malware from 4,200 computers in the United States. The malware was used by the hacker group "Mustang Panda" to steal data and remotely access the victims' systems.
🕷 The malware was distributed via USB drives and had been active since 2012, attacking computers around the world. According to the FBI, since September 2023 alone, about 45,000 IP addresses in the United States have accessed the malware's command server.
⚡️ During the operation, the FBI used the malware's own mechanisms to deactivate it, working together with French law enforcement. A special command message forced PlugX to delete all the files it had created and stop working completely.
2 479
Son zamanlarda, #AWS Müşteri Olay Müdahale Ekibi (#CIRT) ve otomatik güvenlik izleme sistemleri, Amazon Simple Storage Service (Amazon S3) depolama alanlarıyla ilişkili olağandışı şifreleme etkinliklerinde bir artış tespit etti.
#Ransomware #CyberSecurity #InfoSec #DataLoss #DFIR
https://drdisklab.com/Amazon-Sunucularinda-Ransomware-Tehlikesi
2 479
Son zamanlarda, #AWS Müşteri Olay Müdahale Ekibi (#CIRT) ve otomatik güvenlik izleme sistemleri, Amazon Simple Storage Service (Amazon S3) depolama alanlarıyla ilişkili olağandışı şifreleme etkinliklerinde bir artış tespit etti.
#Ransomware #CyberSecurity #InfoSec #DataLoss #DFIR
https://drdisklab.com/Amazon-Sunucularinda-Ransomware-Tehlikesi
2 479
+1
When I do a little research on #Shodan using the same methods, I can get details about a #Fortinet device affected by the #leak. So we can verify that this leak is real and the leaked #data belongs to real devices.
2 479
+1
Dumped #Fortinet config with serial number, and #Shodan #internet scanning showing the same IP having the same serial number.
#Security experts were able to verify that this document is authentic because the devices in it are listed on Shodan and share the same unique serial numbers:
2 479
HDD hata yönetimi, veri kaybını önlemek, disk ömrünü uzatmak ve performansı korumak için hayati öneme sahip bir teknolojidir. SMART izleme, ECC ile hata düzeltme ve yedek sektör tahsisi gibi tekniklerin detayını içeren yazımızı ilginize sunuyoruz...
#DataRecovery #DataProtection #HDDManagement #SMARTMonitoring #ErrorCorrection #SpareSectors
https://drdisklab.com/hdd-hata-yonetimi-p-list-g-list
2 479
+1
#Hackers #leak configs and #VPN #credentials for 15,000 #FortiGate devices
#CyberSec #DataLeak #InfoSec
2 479
😡 Possessor - Simulate user actions via reverse connection
Possessor is a tool that allows you to get a reverse connection using the user impersonation technique, which is not a suspicious behavior for security tools.
In essence, the main idea of the technique is to use a hidden secondary desktop to simulate user actions, while bypassing antivirus analysis.
⏺ Tool on Github
⏺ Video demonstration
#malware
2 479
%PDF-1.7
1 0 obj
<< /Pages 1 0 R /OpenAction 2 0 R >>
endobj
2 0 obj
<< /S /JavaScript /JS (app.alert(1)) >>
endobj
trailer
<< /Root 1 0 R >>
2 479
#HackRf One hakkında bir şeyler karaladık. Umarım faydalı olur..
#CyberSec #InfoSec #RF #SDR
https://drdisklab.com/hackrf-one
2 479
Amerika’da gerçekleşen yangınların akıllı elektrik sayaçlarıyla bağlantısı üzerine güncel bir içerik var mı?
Komplo da olsa okuruz sorun değil :)
2 479
Cellebrite Physical Analyser Offline Map & Language Pack
https://185.148.3.55/cellebrite/Cellebrite%20Physical%20Analyzer/
2 479
📞 Calling the Pope: How Steve Wozniak and Steve Jobs Hacked Phone Systems
• Phreaks (phone system fans) used blue boxes to access free phone service as early as the 1950s , with the first digital blue box designed by Steve Wozniak in 1972. It was marketed and sold by Wozniak (who adopted the phreaker name "Berkeley Blue" ), Jobs (known as "Oaf Tobar" ) and their California friends in 1972 and 1973.
• Wozniak said they made 40-50 units, and Jobs claimed a hundred, but it is certain that many of the boxes were confiscated when the phreak arrests intensified in 1973-75. These blue boxes are the result of the first commercial collaboration between the two giants that became Apple, and their circuit boards were Wozniak's first experience making circuit boards.
• It all started in 1971, when Esquire magazine published an article called “Secrets of the Little Blue Box,” with the subheading “A Story So Unbelievable It Will Make You Feel Sorry for the Phone Company.” The article told the story of a group of engineers who had figured out how to hack into Bell’s automatic switching systems , moving freely through Bell’s long-distance telephone systems using special frequencies generated by “blue boxes.” The story of these “phone phreaks” became a sensation, and a particularly important reader of the article was a young Berkeley engineering student named Steve Wozniak. The first thing Woz did after reading the article was call his good friend Steve Jobs, who was still in high school. The next day, they hopped in their car and headed to the Stanford Linear Accelerator library to scour the shelves for clues that would allow them to follow up on the details of what Esquire had described.
• Steve and Woz found the information they needed and after three weeks Wozniak was able to design the device, and over the next few weeks Wozniak improved the design, eventually creating the world's first digital blue box, capable of producing a much more stable frequency than previous analog devices.
• With a blue box in hand, the two young men and their friends began exploring the phone system, leading to the famous Wozniak story: he called the Vatican, introduced himself as Henry Kissinger , and got the Pope to answer the phone (unfortunately, he was asleep at the time). Soon after, Jobs came up with a plan to distribute these devices to Berkeley students who wanted to make free phone calls. They would knock on a random Berkeley dorm door and ask for a guy with a made-up name, who, of course, would not show up. They would explain that they were looking for a guy who made free phone calls using a blue box. If the person expressed interest or curiosity, they would sell him the box.
• Thanks to Jobs's ingenious marketing plan and Wozniak's architecture, they managed to earn about $6,000 on the project, assembling devices with a cost price of $40 and selling them for $150. Recalling this whole story, Steve Jobs said: "Woz and I learned to work together and developed the confidence that we could solve technical problems and actually produce something." Thus began the story of their collaboration, which resulted in the Apple company...
2 479
CVE-2024-30085 is a heap-based buffer overflow vulnerability affecting the Windows Cloud Files Mini Filter Driver cldflt.sys. By crafting a custom reparse point, it is possible to trigger the buffer overflow to corrupt an adjacent _WNF_STATE_DATA object. The corrupted _WNF_STATE_DATA object can be used to leak a kernel pointer from an ALPC handle table object. A second buffer overflow is then used to corrupt another _WNF_STATE_DATA object, which is then used to corrupt an adjacent PipeAttribute object. By forging a PipeAttribute object in userspace, we are able to leak the token address and override privileges to escalate privileges to NT AUTHORITY\SYSTEM.
Github POC
2 479
North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign
North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie. Contagious Interview aka DeceptiveDevelopment refers to a persistent attack campaign that employs social engineering lures, with the hacking crew often posing as recruiters to trick individuals looking for potential job opportunities into.
https://thehackernews.com/2024/12/15000-four-faith-routers-exposed-to-new.html
2 479
15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials
A highseverity flaw impacting select FourFaith routers has come under active exploitation in the wild, according to new findings from VulnCheck. The vulnerability, tracked as CVE202412856 CVSS score 7.2, has been described as an operating system OS command injection bug affecting router models F3x24 and F3x36. The severity of the shortcoming is lower due to the fact that it only works.
Read More
