Sunday, August 4, 2019

Thursday, January 25, 2018

Latest Google Dorks List Collection for SQL Injection – SQL Dorks 2018

Google helps you to find Vulnerable Websites that Indexed in Google Search Results. Here is the latest collection of Google SQL dorks. More than a million of people searching for google dorks for various purposes for database queries, SEO and for SQL injection.
SQL injection is a technique which attacker takes non-validated input vulnerabilities and inject SQL commands through web applications that are executed in the backend database.
Read More: GBHackers
A multi-platform APT CrossRAT Malware discovered with sophisticated surveillance operation that targeting Windows, OSX, and Linux computer globally both individuals and organizations.
It performed by Large-scale Dark Caracal cyber-espionage campaign and conducting advanced spying operation globally.
READ more at GBHackers

Wednesday, January 24, 2018

HNS IoT Botnet Compromised More than 14k Devices that Spreads from Asia to the United States

A new IoT Botnet dubbed HNS is growing phenomenally and spreads from Asia to the United States.The HNS IoT Botnet features a worm-like mechanism and embeds numerous commands such as data exfiltration, code execution and interference with a device’s operation.
The Bot was uncovered by Bitdefender Security researchers, they first spotted the bot by Jan. 10 and then it faded up and comes back significantly in more improved form by Jan. 20.
Read More: GBHackers

Tuesday, January 23, 2018

Firefox 58 Quantum Released with New Security Future & Faster for Windows, Linux and Mac

Firefox 58 Released(Quantum) with new privacy future and also much faster than old version along with this new Opt-in Tracking Protection future has been introduced with this release for high-speed browsing even in Tracking Protection mode.
Last November Firefox Quantum and began offering to users the option to turn on Tracking Protection all the time. 24-7. This new release enables users to browse Twice faster than the old version of Firefox and chrome.
Read More: GBhackers

Friday, January 12, 2018

WINSpect-Powershell based Windows Security Auditing Toolbox

WINSpect is the PowerShell based windows auditing tool to enumerate and identify security weaknesses with windows platform and results of this audit can be useful for further hardening.

Features of this script – Windows Auditing Tool

WINSpect script provides audit checks and enumeration
  • Installed security products
  • World-exposed local filesystem shares
  • Domain users and groups with local group membership
  • Registry autoruns
  • Local services that are configurable by Authenticated Users group member.
Read : GBHackers

Thursday, January 11, 2018

Oracle Weblogic Exploit to Deploy Monero Miner

Oracle WebLogic application server is vulnerable to cryptocurrency mining.The security researcher has found this exploit to mine monero coins in the compromised machine.
This critical bug allows hackers to run arbitrary commands with WebLogic server with user privileges.
The vulnerability (CVE 2017-10271) was present in the WebLogic Web Services component (wls-wsat) and due to lack of improperly user input sanitizing which allow an unauthenticated remote attacker to install and run crypto miners and hijacking their processing power to mine Monero coins makes the spike in CPU usage.
READ: GBHackers

macOS High Sierra’s App Store System Can be Unlocked by Any Password

New bug discovered in macOS High Sierra allows unlocking the App Store System Preferences by any password.
App Store System Preferences accept any password when system logged in with local admin Privilege.
This could be very dangerous if anyone already has your system permission and they can able to download any apps, modifying the apps store setting, also they can disable auto update for future macOS update.
Read : GBHackers

Security Flaws Identified in WhatsApp Could Allow Attackers to Spy on Group Chats

End-to-end encryption is the major security feature of secure instant messengers, among the most popular one is WhatsApp having more than one billion users.
Security researchers discovered vulnerabilities with Whatsapp and Signal which allows an attacker to add themselves to the group chat. But the risk associated with the attack is limited.