TGViewer
Channel Public Channel
📜 Чтиво 📜

📜 Чтиво 📜

@chtivvvo

Канал начал своё существование здесь https://t.me/chtivvvo/4

Начало личных постов
https://t.me/chtivvvo/356
Subscribers
137
Photos
319
Videos
6
Links
581
Recent Posts 20 shown
Post #1466 342
Novel phishing campaign uses corrupted Word documents to evade security

A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but still be recoverable by the application.

https://www.bleepingcomputer.com/news/security/novel-phishing-campaign-uses-corrupted-word-documents-to-evade-security/
BleepingComputer Novel phishing campaign uses corrupted Word documents to evade security A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but still be recoverable by the application.
  • 👍 3
Post #1465 164
Phishing emails increasingly use SVG attachments to evade detection

Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection.

Most images on the web are JPG or PNG files, which are made of grids of tiny squares called pixels. Each pixel has a specific color value, and together, these pixels form the entire image.

SVG, or Scalable Vector Graphics, displays images differently, as instead of using pixels, the images are created through lines, shapes, and text described in textual mathematical formulas in the code.

https://www.bleepingcomputer.com/news/security/phishing-emails-increasingly-use-svg-attachments-to-evade-detection/
BleepingComputer Phishing emails increasingly use SVG attachments to evade detection Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection.
  • 👍 1
Post #1464 140
https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/



The malicious network, made up almost entirely of TP-Link routers, was first documented in October 2023 by a researcher who named it Botnet-7777. The geographically dispersed collection of more than 16,000 compromised devices at its peak got its name because it exposes its malicious malware on port 7777.


In July and again in August of this year, security researchers from Serbia and Team Cymru reported the botnet was still operational. All three reports said that Botnet-7777 was being used to skillfully perform password spraying, a form of attack that sends large numbers of login attempts from many different IP addresses. Because each individual device limits the login attempts, the carefully coordinated account-takeover campaign is hard to detect by the targeted service.
Ars Technica Thousands of hacked TP-Link routers used in yearslong account takeover attacks The botnet is being skillfully used to launch "highly evasive" password-spraying attacks.
  • 👍 1
Post #1455 211
Post #1453 177
What did I say to make you stop talking to me?

[...] Attackers are interested in attempting to detect honeypots; over the years, we have seen various ways to do so. But so far, we have not done much to prevent this. We randomize some fo the parameters, but overall, we just run a "stock" cowrie install. There is however a relatively easy method to find out what gave the honeypot away after the attacker connected.

Most attackers will immediately disconnect after they realize they have found a honeypot. So as a simple method, you just find out what the last command was an attacker executed. I just did this for some of our larger honeypots, investigating about 10 million cowrie sessions. [...]
  • 👍 2
Post #1452 140

Forwarded from Proxy Bar

Lenovo X1 Carbon Bitlocker Key Sniffing
круто, 42.9 секунды
  • 👍 3
Post #1450 212
https://www.theregister.com/2023/12/20/credentialstealing_malware_infects_50k_banking/

When the requested banking page "contains a certain keyword and a login button with a specific ID present, new malicious content is injected," Langus explained. "Credential theft is executed by adding event listeners to this button, with an option to steal a one-time password (OTP) token with it."

The script is fairly smart: it communicates with a remote command-and-control (C2) server, and removes itself from the DOM tree – deletes itself from the login page, basically – once it's done its thing, which makes it tricky to detect and analyze.

The malware can perform a series of nefarious actions, and these are based on an "mlink" flag the C2 sends. In total, there are nine different actions that the malware can perform depending on the "mlink" value, we're told.

These include injecting a prompt for the user's phone number or two-factor authentication token, which the miscreants can use with the intercepted username and password to access the victim's bank account and steal their cash.
  • 👍 3
Post #1449 209
Decoupling for Security

In the last few years, a slew of ideas old and new have converged to reveal a path out of this morass, but they haven’t been widely recognized, combined, or used. These ideas, which we’ll refer to in the aggregate as “decoupling,” allow us to rethink both security and privacy.

Here's the gist. The less someone knows, the less they can put you and your data at risk. In security this is called Least Privilege. The decoupling principle applies that idea to cloud services by making sure systems know as little as possible while doing their jobs. It states that we gain security and privacy by separating private data that today is unnecessarily concentrated.
  • 👍 1
Post #1448 184
What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)

Local recursive resolvers are usually configured via DHCP. Your ISP, or the network you connect to, will usually advertise one or two IP addresses to use as your resolver. As far as I know, DHCP cannot configure an encrypted resolver. But earlier today, @⁤HQuest on X pointed out that iOS 17 implemented a new protocol, "Discovery of Designated Resolvers (DDR)". [1]

The idea is that a resolver you have already configured via traditional means like DHCP may advertise that it is also reachable via DoH/Q/T. Cloudflare stated that they implemented experimental support for DDR in March of 2022, but my tests today did not get the expected response [2].
SANS Internet Storm Center What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR) What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR), Author: Johannes Ullrich
  • 👍 2
Post #1447 145
Malware Dropped Through a ZPAQ Archive

[...]

The file was called "Purchase Order pdf.zpaq" (SHA256:1c33eef0d22dc54bb2a41af485070612cd4579529e31b63be2141c4be9183eb6). The fact that the archive is using an "exotic" compress algorithm, the VT score is null! I tried the classic tools on a stock Windows operating systems, including 7Zip and no one was able to decompress the archive. This is a strange because it reduces the number of potential victims! On Windows, you can use PeaZip.
  • 🔥 2
Post #1446 171

Forwarded from RUH8

Вымогатели тоже пользуются конфлюенсом. И этим не повезло...
  • 😁 2
  • 👍 1
Post #1445 168
CVE-2023-38545: curl SOCKS5 oversized hostname vulnerability. How bad is it?

The vulnerability is a heap-based buffer overflow, which may lead to arbitrary code execution. Modern operating systems should make exploitation of heap-based buffer overflows more difficult, but exploitation is possible.

To exploit this vulnerability, the attacker has to be able to supply an oversized hostname to curl. Host names passed to curl should be validated, and I do not believe such an oversized hostname would pass input validation. Sure, an attacker can run "curl" on the command line, but if they can do so, they already have code execution capabilities. A valid exploit would require an attacker to trigger code execution by, for example, passing a hostname to a web app that would trigger the code execution in curl.

Next, the exploit only exists if curl is used to connect to a SOCKS5 proxy. This is another dependency, making exploitation less likely.
Older posts →

About this channel

How can I read @chtivvvo without a Telegram account?
TGViewer shows the public web preview Telegram publishes for 📜 Чтиво 📜: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does 📜 Чтиво 📜 have?
📜 Чтиво 📜 (@chtivvvo) has 137 subscribers on Telegram, refreshed roughly every 30 minutes.
Does 📜 Чтиво 📜 know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →