2019-02-22 Random Interesting Shit

Categories Hacker Shit, News Feed Stuff, Random Musings, Security Stuff, Stuff To Learn

Today’s Principle to Follow:
Principle #37: Pay Attention to Overall Patterns, and the Anomalies That Do Not Fit.
   Life largely consists of patterns and anomalies. The patterns are the general structures, the things you expect to see because you’ve seen them happen so many times before. In fact, our brains often naturally pick up general patterns and tendencies. Once you know what to expect quite well, you will be prepared to notice anomalies. The things or events that don’t fit with the context. Often, by realizing that there is an anomaly present, we can further investigate it. Darwin realized on his voyage studying other life forms that there were many minor variations among different species of birds. This was inconsistent with his prior worldview that we were all fixed species that never changed form. He took that anomaly and investigated it further, founding the theory of evolution.
   
   Geniuses learn the patterns, the tendencies of a system, and if they come across an anomaly they do not discard it. They focus on it until they understand why it happened. Often times it is the unexpected anomaly that leads to a great breakthrough of a discovery.



Understanding VPN through open systems interconnection model

Understanding VPN through open systems interconnection model


#hackerstuff #HackThePlanet


Major Android ad fraud scam campaign drains battery & eats data

Major Android ad fraud scam campaign drains battery & eats data


#hackerstuff #HackThePlanet


Simple – Better Banking (Android) v. 2.45.0 – 2.45.3 – Sensitive Information Disclosure

Simple – Better Banking (Android) v. 2.45.0 – 2.45.3 – Sensitive Information Disclosure


#hackerstuff #HackThePlanet


Venom – A Multi-hop Proxy for Penetration Testers
Venom is a multi-hop proxy tool developed for penetration testers using Go.
https://github.com/Dliv3/Venom/blob/master/README-en.md
#hackerstuff #HackThePlanet


Breaking out of Docker via runC – Explaining CVE-2019-5736

Breaking out of Docker via runC – Explaining CVE-2019-5736


#hackerstuff #HackThePlanet


Hacking Virtual Reality – Researchers Exploit Popular Bigscreen VR App
https://thehackernews.com/2019/02/bigscreen-vr-hacking.html
#hackerstuff #HackThePlanet


Swiss_E-Voting_Publications – Our publications of the Swiss E-Voting Public Intrusion Test (PIT)
https://github.com/setuid0-sec/Swiss_E-Voting_Publications
#hackerstuff #HackThePlanet


Taking Care of Your Personal Online Security (For Paranoids)

Taking Care of Your Personal Online Security (For Paranoids)


#hackerstuff #HackThePlanet


2019-02-21 Random Interesting Shit

Categories Hacker Shit, News Feed Stuff, Random Musings, Security Stuff, Stuff To Learn

Today’s Principle to Follow:
Principle #36: Know Your Strengths and Weaknesses, and How to Make Them Work For You.
   Everyone has strengths and weaknesses. Some comm on areas of strength and weakness are self-confidence, social skills, and management skills, and a variety of technical skills. Depending on what you want to do, you might not need to fix your weaknesses. If you are a manager, sometimes it is okay not to fully understand all of the technicalities. It is more important to be able to get a team to accomplish the necessary work. Or course, if the weakness is a critical area that you need to perform your daily tasks, then it is important to work on improving it.
   
   You strengths are also important to recognize. If you are naturally good at speaking, but not at writing, you can steer your self toward positions that play up your natural presentational abilities. Be aware of your general strengths and weaknesses, and how you compare to your peers. Also pay attention to which strengths and weaknesses, and how you compare to your peers. Also pay attention to which strengths and weaknesses are most critical for what you want to accomplish. Focusing on the critical skill sets will help you reach your goals more easily.



Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
https://thehackernews.com/2019/02/winrar-malware-exploit.html
#hackerstuff #HackThePlanet


Severe flaws in password managers let hackers extract clear-text passwords

Severe flaws in password managers let hackers extract clear-text passwords


#hackerstuff #HackThePlanet


MikroTik Firewall & NAT Bypass – Exploitation from WAN to LAN
https://medium.com/tenable-techblog/mikrotik-firewall-nat-bypass-b8d46398bf24
#hackerstuff #HackThePlanet


evador – IDS/IPS malware download evasion
https://github.com/Eplox/evador
#hackerstuff #HackThePlanet


Paperclip to a House: Turning Useless Data into an Authenticated User
http://maxwelldulin.com/BlogPost?post=2497767424
#hackerstuff #HackThePlanet


2019-02-20 Random Interesting Shit

Categories Hacker Shit, News Feed Stuff, Random Musings, Security Stuff, Stuff To Learn

Today’s Principle to Follow:
Principle #35: When You Get a Great Idea, Ask Yourself if the Timing is Right to Execute it.
   Will the public be ready for you idea? Imagine that you are living around the time of 1800 in Europe, a time when classical music was popular. If classical music was all you had ever heard, would you be interested in jazz, or techno, or hip-hop? It would probably seem to wild and crazy,m and maybe even hurt your ears. We learn to adapt to what is new, often through a gradual process, not in giant leaps. If an idea is too advanced, too far ahead of its time, the public often won’t understand the use, or them may not believe that it’s really possible.
   
   Even if someone came out with an invention to teleport us tomorrow, would you really be willing to try it out so quickly? Maybe it would make sense if we progressed through decades from teleporting nano-particles, to molecules, to flies, to rodents. But to just all of a sudden have a mechanism for teleporting people safely seems unbelievable. when you get a great idea, ask yourself if the public is ready. Is this an idea they can relate to and understand? Ir is there a way you can convince them that your idea solves a problem they have.



Critical Flaw Uncovered In WordPress That Remained Unpatched for 6 Years
https://thehackernews.com/2019/02/wordpress-remote-code-execution.html
#hackerstuff #HackThePlanet


Rietspoof malware distributes ransomware via messaging apps

Rietspoof malware distributes ransomware via messaging apps


#hackerstuff #HackThePlanet


Uber rewards hacker for finding a bug in Uber developer portal

Uber rewards Indian hacker for finding a bug in Uber developer portal


#hackerstuff #HackThePlanet


Bug Writeup: FBCTF IDOR
https://georgeosterweil.com/2019-02-20-fbctf-idor/
#hackerstuff #HackThePlanet


Critical Security Vulnerabilities Discovered in Amtrak Mobile APIs

Amtrak Mobile APIs – Multiple Vulnerabilities


#hackerstuff #HackThePlanet


Malware writing series – Python Malware, part 1
https://0x00sec.org/t/malware-writing-series-python-malware-part-1/11700
#hackerstuff #HackThePlanet


2019-02-19 Random Interesting Shit

Categories Hacker Shit, News Feed Stuff, Random Musings, Security Stuff, Stuff To Learn

Today’s Principle to Follow:
Principle #34: Don’t Overwhelm Your Natural Ability to Learn.
   If you cram too much information in your head all at once you will not learn well. If you stress yourself too much you also may not be at your best. True learning that is valuable and useful for a lifetime builds up gradually, not all at once. You need to have time to connect what you learn to other things. Cramming, or spending long nonstop sessions working or learning something is not optimal. Taking breaks is not lazy. Our minds need some time to breathe and relax.
   
   Remember, the brain is like a muscle. Weight trainers that exercise their muscles ever day train different muscles and they take breaks after training. They do not consistently exhaust the same muscle over and over. The brain should be treated similarly, rather than completely straining it. For example, Einstein was a notoriously hard worker, focusing intensely for great periods. But even he had a point where he needed a break to do something completely different. For him, that was often playing his violin.



LPG Gas Company Leaked Details, Aadhaar Numbers of 6.7 Million Indian Customers
https://thehackernews.com/2019/02/indane-aadhaar-leak.html
#hackerstuff #HackThePlanet


Kali Linux 2019.1 Release
https://www.kali.org/news/kali-linux-2019-1-release/
#hackerstuff #HackThePlanet


macOS: how to gain root with CVE-2018-4193 in < 10s https://www.synacktiv.com/ressources/OffensiveCon_2019_macOS_how_to_gain_root_with_CVE-2018-4193_in_10s.pdf https://github.com/Synacktiv/CVE-2018-4193 #hackerstuff #HackThePlanet


pwnable.kr – fd , Understanding Linux File Descriptors and creating a simple exploit with python pwntools
https://0xrick.github.io/pwn/fd/
#hackerstuff #HackThePlanet


Phishing by Venezuelan government puts activists and internet users at risk.
https://vesinfiltro.com/noticias/Phishing_by_Venezuelan_government_targets_activists/
#hackerstuff #HackThePlanet


2019-02-18 Random Interesting Shit

Categories Hacker Shit, News Feed Stuff, Random Musings, Security Stuff, Stuff To Learn

Today’s Principle to Follow:
Principle #33: Learn to Practice Effectively for More Efficient Learning.
   To really learn a skill we have to practice it. To learn even faster and more effectively, we have to know what to focus on when we practice. It help to have an expert around who can guide us and give feedback. Usually, what they will do is tell us the most crucial parts of the task that need to be met before anything else can be accomplished. For example, in typing it is critical to have your hands in the right position so you hit the keys you are supposed to. In piano, you should be aware of the hand positioning for a song as well as maintaining a relaxed posture – being relaxed helps to move the fingers more fluidly and to avoid injuries.
   
   Often times when we practice something over and over, we see patterns and find that we have weaknesses. Many people will avoid their weak areas because it is a good challenge. They will instead practice what they are good at, so they feel better. As you might guess, it is actually a better use of our time to focus on improving our weak areas when we practice a new skill. In doing this, you can advance more quickly. To practice effectively we should identify the most essential parts of the task, begin practice, identify our weaknesses, practice some more, and continue to seek feedback from experts. As you get better you may create something new. In that case, you can get feedback from an audience as well. Do not forget that the quality of your practice is much more important than the quantity. With focus, you will not need to practice as much to reach mastery



Popular Torrent Uploader ‘CracksNow’ Caught Spreading Ransomware
https://thehackernews.com/2019/02/malware-torrent-download.html
#hackerstuff #HackThePlanet


How to Hack Facebook Accounts? Just Ask Your Targets to Open a Link
https://thehackernews.com/2019/02/hack-facebook-account-password.html
#hackerstuff #HackThePlanet


Blockchain Digital Identity Management | Empowering Individual Data Ownership
https://blockchain.oodles.io/blog/blockchain-digital-identity-management/
#hackerstuff #HackThePlanet


Electrohunt Part 1: Hunting for the phishing campaigns on the Electrum network
https://blog.coinbase.com/electrohunt-part-1-hunting-for-the-phishing-campaigns-on-the-electrum-network-b10529162e63
#hackerstuff #HackThePlanet


Tracking the trackers. Draw connections between scripts and domains on website.
https://hackernoon.com/tracking-the-trackers-draw-connections-between-scripts-and-domains-on-website-360bc6a306df
#hackerstuff #HackThePlanet


PDF – REST-ler: Automatic Intelligent REST API Fuzzing
https://www.microsoft.com/en-us/research/uploads/prod/2018/04/restler.pdf
#hackerstuff #HackThePlanet


Hack The Box – Giddy – Write-up by 0xRick
https://0xrick.github.io/hack-the-box/giddy/
#hackerstuff #HackThePlanet


Unveiling Amazon S3 bucket names
https://medium.com/@localh0t/unveiling-amazon-s3-bucket-names-e1420ceaf4fa
#hackerstuff #HackThePlanet