Showing posts with label Hacker. Show all posts
Showing posts with label Hacker. Show all posts

AI #Privacy & security concerns

Harmonic Security studio highlighted several security concerns regarding companies and users (USA & GB) sharing sensitives company data on AI platforms like source code, engineering documentation, financial reports, legal contracts, personal data and merging and acquisition documents.

About these platform DeepSeek (reported in 85% incidents) followed Kimi Moonshot & Qwen.

This on line tools provide enhanced features and immediate access but they do not guarantee transparency or control over the future use of the uploaded data, leaving companies exposed to serious risks of breach of confidentiality, loss of intellectual property, and regulatory non-compliance.

https://www.securityinfo.it/2025/07/25/generative-ai-cinesi-i-rischi-delladozione-incontrollata-nelle-aziende/

Hacker #PerfektBlue Bluetooth Vulnerabilities #several Millions of vechicles impacted

Four security flaws in OpenSynergy's BlueSDK Bluetooth stack discovered, few days ago, that, if successfully exploited, could allow remote code execution on millions of transport vehicles from different vendors.

More details:

https://thehackernews.com/2025/07/perfektblue-bluetooth-vulnerabilities.html

https://www.securityinfo.it/2025/07/11/vulnerabilita-in-bluesdk-milioni-di-veicoli-a-rischio-di-attacco/

Security #Global protect Portal hacker on going scanning activity

Researchers have detected a scanning activity targeting Palo Alto Networks’ GlobalProtect VPN portals

During last 30 about 24,000 unique IP addresses have attempted to access these critical security gateways

Here you can find complete article:

https://cybersecuritynews.com/hackers-scanning-palo-alto-networks-portals/




Security #February 2025 Deadline related KB5014754 and Certificate-based authentication changes on Windows domain controllers

Microsoft released, several months ago this important bulletin.

The key point is that, after February 2025 patch installation Windows domain controller certificate-based authentication will change (due to security reasons) to Full Enforcement mode. However, you can move back to Compatibility mode until September 2025.

There are several CA checks to be done to be sure that no problem will affect your organization.

One compatibility doubt that it might arise it could be related to organization that have no longer supported O.S. (like 2008 or older)

I think that working in compatibility mode might help to check, on internet, after February 2025 if any customer had some issues and find relative fixes/workarounds

In any case here they are essential checks that you should consider before enable “full enforcement mode”:

  1. Common Name (CN) and Subject Alternative Name (SAN): Must match the users or devices in Active Directory.
  2. Certificate Authority (CA): Certificates must be issued by a trusted and recognized CA.
  3. Certificate Chain: The certificate chain (including intermediate and root CA certificates) must be complete and valid.
  4. Revocation: It is necessary to check that the certificates have not been revoked.
  5. Time Validity: It must be verified that the certificates have not expired


KB5014754: Certificate-based authentication changes on Windows domain controllers

https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16 

https://admin.microsoft.com/AdminPortal/home?#/MessageCenter/:/messages/MC894351


Security - WhatsApp how to enable two-step verification settings

Security, IT side, often is underestimate.

Due to this reason and, considering that whatsApp is very used chatting app I am taking note, on blog, about procedure, necessary, to enable two-step verification settings

https://faq.whatsapp.com/1920866721452534?helpref=faq_content

Meanwhile you can review review your linked devices in WhatsApp and unlink any device that you do not recognize.



Cisco - ISE password recovery/Reset

I am taking note, on blog, about Cisco ISE procedure that is necessary, to be followed, in case admin password expired/do not work properly

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200568-ISE-Password-Recovery-Mechanisms.html

Consider that you should, proceed to https Ise Admin password account reset too.

Application reset-passwd ise admin

After Cisco ISE Server reboot, through vmware/HyperVisore console, you should check that all services are up and running, using this command

Show application status ise

Finally, after password reset, you should save Cisco ISE running config.

Copy running-config startup-config


Hacker/Security - UPnP security concerns

About UPnP there are several security concerns that people majority are not aware.

Here it is an article that well explain concepts and security problems that you might face:

Security - Wipe Tools

On blog was already published, some articles, mentioning several wipe tools:

Programma - HardWipe bonificare un Hard disk e cancellare i propri dati

USB Live - Creare una USB autoavviante per fare il WIPE di un Hard Disk 

Privacy - Two tools to completely wipe data and create USB/CD Live 


An alternative wipe tool could be using ABAN 

(ABAN’s name is inspired by Darik’s Boot and Nuke, an older (and unfortunately no longer maintained) program that does something very similar. But but other than that, it's completely unrelated.)

https://aban.derobert.net/

https://gitlab.com/derobert/aban

You can burn it using RUFUS

Here it is an old blog article (that mentioned RUFUS too):

https://www.alessandromazzanti.com/2015/04/microsoft-free-download-link-windows-81.html

Firewall/Security - IPS ( Intrusion Prevention Systems ) overview

I am taking note on blog about article related to IPS (Intrusion Prevention Systems) overview and relative comperazation to IDS:

"Unlike its predecessor the intrusion detection system (IDS) – which is a passive system that scans traffic and reports back on threats – the IPS is placed inline, directly in the flow of network traffic between the source and destination. Usually sitting right behind the firewall, the solution is actively analyzing and taking automated actions on all traffic flows that enter the network. These actions can include:

  • Sending an alarm to the administrator (as would be seen in an IDS)
  • Dropping the malicious packets
  • Blocking traffic from the source address
  • Resetting the connection
  • Configuring firewalls to prevent future attacks"



[Original Articles]


Hacker - Banking trojans

Zimperium recently published report about 10 most diffused home banking trojans, on Android OS, affecting more than 600 home banking apps.

This trojans are injected through harmless apps available on google store.

After that these apps are installed on mobile phones, and succesfully infected mobile devices, they show, to end users, similar home banking websites and work to intercept, user, password and one time passwords.

Here they are original articles

https://www.hwupgrade.it/news/sicurezza-software/trojan-bancari-e-emergenza-i-10-piu-diffusi-prendono-di-mira-app-scaricate-un-miliardo-di-volte_107688.html

https://www.forbes.com/sites/daveywinder/2022/04/09/these-6-dangerous-phone-apps-need-to-be-deleted-immediately/

REMARK This is why I still use hardware home banking token :)


<============>

About other Security/Hacker articles please review below blog sections:

https://www.alessandromazzanti.com/search/label/Hacker

https://www.alessandromazzanti.com/search/label/Security

Security - Shodan

Major person does not have exactly perception about how much could be invasive technology, what it mean internet (World Wide LAN that interconnect all devices through internet) and how much security perception is lower than how much is dangerous.

Other than this aspect I am taking note about Shodan, that is a search engine, for internet-connected devices.

Here it is a presentation. There are other aspects, for which this website can be used but, due to security aspects/concerns, I would prefer to omit them. (to indicate them on blog)

https://help.shodan.io/the-basics/what-is-shodan

<============>

About other Security/Hacker articles please review below blog sections:

https://www.alessandromazzanti.com/search/label/Hacker

https://www.alessandromazzanti.com/search/label/Security

Security - 6 Security Tips

Person majority does not have exactly perception about how much it could be invasive technology, what it really means internet (*) and how much security perception is lower than how much it is dangerous and appliable to normal life activities.

Due to this reasons I am focusing, with this article, on some interesting aspects.

Consider that, in this article, there is a specific topic that explain effects that technology abuse might affects teenagers (italian language)

(*) World Wide WEB means that all devices are interconnected each other, through internet, it implies that all world devices are, theoretically, reachable from any users and from location. Security concerns should easily realized :-)

1) PASSWORD SHARING

This website permits to create weblinks containing PrivateText & Passwords (that could be securely shared with remote users).

https://privnote.com/

To strengten security there are furthers settings that we strongly suggest to use.

  • Password could be shown only "one time" (or extended up to 30 days deprecated)
  • You can add email address having real time notification (when weblink was effectively read)
  • You can create master password, about web link, that you should communicate, to end user, using different communication ways (SMS, by phone, by voice etc. etc.)

2) HAVE YOU POWNED

Here it is an old article that explains how to verify if, your email account, was  affected in any data breach (occurred on any websites where you registered)


3) VERIFY FILES/WEBLINKS/EMAIL/DOCUMENTS ON ALL ANTIVIRUS VENDORS

During these years I often had necessity to check files/emails/URLs understanding if they had any sort of infection (that was not yet discovered from latter antivirus definitions)

To get this result often I connect through this website that queries all majority AV versions and relative latter definitions.



4) PROXY BROWSER ON LINE

After virustotal checks if weblink is fine but you suspect that it could be a phishing targeted attack you might open weblink through a specific website (registration is for free for basic settings) and you might verify real contents and requests (withouth any risk on you pc/device):


5) PASSWORD TOOLS

Here they are some password tools from old blog article



6) HOW TO VIEW RDP HISTORY SCREENSHOTS

How to view RDP activities done on any Server/client


6.BIS) CYBERBULLISMO

Here it is an optional article that explain technology abuses that could occur on teenagers and persons (italian language only)



<============>

About other Security/Hacker articles please review below blog sections, there are several other aspects that are important to take awareness

https://www.alessandromazzanti.com/search/label/Hacker

https://www.alessandromazzanti.com/search/label/Security

[update 2022.01.04]

Privnote alternative

https://pwpush.com

Security - MFA override

Here it is mentioned, in italian language a way to override MFA when a proper phishing email is sent to user that will redirect him to a similar website page (a.e. web bank)

End user will insert user and password. Immediately crimes will insert user and password on original website (a.e. bank).

User will receive email with temporary code (true), that will be inserted in duplicated page. Crimes will use this latter code on original webpage having full access on user account (a.e. bank)

So attention to phishing emails must be improved.

https://www.hwupgrade.it/news/sicurezza-software/l-autenticazione-a-due-fattori-puo-essere-bucata-dall-italia-arriva-la-scoperta-ma-non-c-e-soluzione_106327.html

[Update 2022.06.27]

https://www.securityinfo.it/2022/06/27/phishing-supera-l2fa-con-app-microsoft-webview2/

Security - How to find domains that contain specific keyword

You might have necessity to check if you domain/company name, or any other term, is available on internet.

Basically to intercept any phishing, website cloning with similar FQDN

There is a specific website that easily help you on these searches.

https://dnslytics.com/domain-search

You can use:

  1. ^keyword to search all domains that starts with keyword term
  2. keyword$ to search all domains that ends with keyword term

Security - RemotePotato0 0-Day vulnerability

There is 0-day a vulnerability that affect all Windows versions permitting to gain Domain Admin permissions.

This attack use NTLM (old authentication protocol that was substituted by Kerberos), Microsoft suggest to disable NTLM (or configure servers to block NTLM relay). For the moment no patches are available (and it is not clear if Microsoft will never release it)

Meanwhile you can create 0patch account and install their patches.

Consider that O.S./SW no longer supported could benefits 0Patch platform patches/fixes

 https://blog.0patch.com/2022/01/free-micropatches-for-remotepotato0.html

[original article]

https://www.hwupgrade.it/news/sistemi-operativi/falla-0-day-remotepotato0-su-windows-cos-e-e-come-risolvere-temporaneamente_103969.html

https://www.securityinfo.it/2022/01/14/microsoft-non-si-muove-patch-ufficiosa-per-la-falla-remote-potato0

Security - Are you part of an online data breach ?

There are some methods that I found checking if your email account is affected in any data breach.

  1. You can visit below websites, insert your emails, and verify which websites faced any data breach.

    https://haveibeenpwned.com/ 

    https://www.avast.com/hackcheck & https://www.f-secure.com/en/home/free-tools/identity-theft-checker (in this case you will receive an email report on your account)

    https://monitor.firefox.com/ (in this case you will receive real time emails when data breach will occur on your accounts. PREREQUISITE be aware that firefox email account creation is necessary)



  2. Alternatively, to have constantly your emails accounts monitored, you can install Avast Antivirus on your your mobile devices (there is a section where put your emails accounts to be monitored)

    ANDROID
    https://play.google.com/store/apps/details?id=com.avast.android.mobilesecurity

    IOS/IPHONE/IPAD
    https://www.avast.com/it-it/free-ios-security#pc

Security - Exchange Zero Date Vulnerability #CVE-2021-26855

These vulnerabilities permits to access, without any authentication, to all Exchange mailboxes contents.

This is possible on all Exchange servers that are published, on internet, through OWA (attacker need onlty to know user account name)

Afterward attackers created several backdoors, through aspx webshell, creating AD credentials dump. (having horizontal attacks possibility)

There are two scenarios:

  1. Standalone: require single user (SID) (more difficult)
  2. Cluster (DAG) only end user email name is required.

Attack is possibile only if you know server FQDN (but this is easy to be knwon sending an http post call to Exchange Web Services)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-26855

Patches are here available: (for Exchange 2010 too)

https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b

Other articles:

https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-2016-and-the-end-of-mainstream-support/ba-p/1574110

https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/

https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2021-exchange-server-security-updates/ba-p/2175901

https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/

https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

https://docs.microsoft.com/en-us/exchange/troubleshoot/client-connectivity/exchange-security-update-issues

[original articles]

https://www.windowserver.it/2021/03/exchange-server-sotto-attacco-cosa-sta-succedendo/

https://www.wired.it/internet/web/2021/03/05/microsoft-exchange-hacker-cina/


[update 2021.03.19]

Automatic on-premises Exchange Server mitigation now in Microsoft Defender Antivirus

https://www.microsoft.com/security/blog/2021/03/18/automatic-on-premises-exchange-server-mitigation-now-in-microsoft-defender-antivirus/

[update 2021.03.24]

https://edge9.hwupgrade.it/news/security/attacco-ad-exchange-server-anche-tim-business-colpita-e-intanto-microsoft-teme-la-fuga-di-notizie-interna_96269.html

[update 2021.03.29]

How to Recover Exchange Server after Black KingDom Ransomware Attack?

https://www.stellarinfo.com/blog/recover-exchange-server-after-black-kingdom-ransomware-attack/


Security - VMSA-2021-0002 Vmware 6.5/6.7/7.0 Vulnerability Severity 9.8

VMware vCenter Server updates address remote code execution vulnerability in the vSphere Client (CVE-2021-21972)

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Known Attack Vectors

A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. 

Resolution

To remediate CVE-2021-21972 apply the updates listed in the 'Fixed Version' column of the 'Response Matrix' below to affected deployments.

Workarounds

Workarounds for CVE-2021-21972 have been listed in the 'Workarounds' column of the 'Response Matrix' below.

More details here

https://www.vmware.com/security/advisories/VMSA-2021-0002.html

https://edge9.hwupgrade.it/news/security/gli-hacker-vanno-alla-ricerca-dei-server-vmware-non-patchati-una-grave-falla-permette-agli-attaccanti-di-violarli-facilmente_95865.html