HackTheBox - CCTV

IppSec·9.9K views · 1 month ago

00:00 - Introduction 00:40 - Start of nmap 03:00 - Logging into zoneminder with default credentials, flailing around trying to find the date this version was released 10:55 - Looking into the SQL Injection, lots of weird confusion around the date this was released... should of prepared more 13:30 - Getting this into SQLMap to test the injection, discovering it finds Time Based Blind which is really slow and unreliable 16:00 - Playing with the SQL Injection to get it to turn this into Boolean Based which is much better than time based 19:50 - Getting SQLMap to exploit this with boolean using prefix and suffix 24:10 - Cracking the password 30:00 - Got marks credentials, can login now 32:30 - Forwarding port 8765 back to us and accessing the MotionEye webserver, looking at configs and getting an admin password that lets us login 37:00 - RootPath1: Looking at public exploits, finding a command injection, testing it out and getting a shell 42:00 - RootPath2: Talk to the Web Control Port directly, poison that config and get command injection. Misspeak when i say camera, mean web control port 48:30 - Intended path to sa_mark, can tcpdump, capture packets get a credential and login 58:00 - Beyond Root: Using Claude to help me turn the blind injection into boolean.

Data BreachInfosecurity Magazine·1 month ago

CISA Details Incident Response to Exposed AWS GovCloud Keys

CISA has disclosed its incident response procedures following the exposure of AWS GovCloud credentials and internal data in a publicly accessible GitHub repository. The agency's detailed account provides insights into how a government cybersecurity organization handles the discovery and remediation of compromised cloud infrastructure access and sensitive information.

MalwareInfosecurity Magazine·1 month ago

Microsoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive Capabilities

Microsoft has identified a new malware called GigaWiper that functions as a multi-purpose backdoor capable of supporting both espionage and destructive operations. The malware's dual functionality allows attackers to conduct covert intelligence gathering before escalating to file-wiping attacks, combining reconnaissance and destructive capabilities in a single tool.

VulnerabilityZero Day Initiative·1 month ago

CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys

A remote code execution vulnerability in Windows HTTP.sys allows unauthenticated attackers to send specially crafted HTTP/1.x requests over TLS connections to trigger a kernel pool heap buffer overflow, potentially resulting in denial of service or arbitrary kernel-level code execution. The vulnerability stems from an integer overflow in the buffer reference array capacity field during HTTP header parsing, which can be exploited by encapsulating each header line in a separate TLS record to accumulate the required 65,536 buffer references. Microsoft patched this vulnerability in the June 2026 release cycle, and organizations can mitigate risk by keeping the MaxRequestBytes registry value at or below 65,535 bytes or deploying the vendor patch.

OtherInfosecurity Magazine·1 month ago

Anthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers Warn

Researchers from the AI Now Institute have developed a proof-of-concept exploit demonstrating that security tools from major AI providers could potentially be weaponized by attackers. The findings suggest that common AI-based security tools may inadvertently create new attack vectors when misused, raising concerns about the dual-use nature of these platforms.

RansomwareInfosecurity Magazine·1 month ago

New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections

GodDamn ransomware leverages a remote desktop application to covertly traverse networks and deploy the PoisonX kernel driver, which disables cybersecurity protections on targeted systems. This combination of lateral movement and driver-based defense evasion represents an escalation in ransomware sophistication, allowing attackers to bypass security controls before executing their encryption payloads.

LIVE AMA | Summer of CCNA | 07/09/2026

NetworkChuck·16K views · 1 month ago

Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!

Policy & LegalCloudflare Blog·1 month ago

Why we cannot wait for better post-quantum signature algorithms

NIST is advancing nine new post-quantum signature algorithms toward standardization, but their timeline remains uncertain. Cloudflare argues that organizations should adopt ML-DSA immediately rather than wait for future candidates, as it represents the most mature and practical option currently available for post-quantum cryptography deployment.

Policy & LegalInfosecurity Magazine·1 month ago

75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees Face

A survey by MetaCompliance reveals significant communication gaps between cybersecurity leaders and corporate boards, with three-quarters of CISOs concerned that executives lack understanding of the cyber risks threatening their workforce. The findings highlight a broader disconnect where many board members appear disengaged from the evolving nature of cybersecurity threats facing employees across their organizations.

OtherInfosecurity Magazine·1 month ago

Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests

Operation First Light 2026, a Chinese-government-funded Interpol initiative, has resulted in 5,811 arrests in a coordinated cybercrime crackdown. The operation demonstrates international law enforcement collaboration against cyber threats, with China providing financial backing for the large-scale enforcement action.

Policy & LegalInfosecurity Magazine·1 month ago

New AI Security Charter Backed by Over 70 Cyber Firms

Over 70 cybersecurity organizations have endorsed the CREST AI Charter, establishing guidelines for the responsible deployment of artificial intelligence in security operations. The charter represents industry consensus on best practices for leveraging AI capabilities while maintaining ethical standards and security integrity.

MalwareInfosecurity Magazine·1 month ago

RedWing Android Spyware Sold as a Service on Telegram

Zimperium has discovered RedWing, an Android spyware operation being monetized as a service through Telegram channels, primarily targeting banking applications. The malware-as-a-service model enables threat actors to purchase access to the spyware capabilities for financial fraud and data theft purposes.

Nation-StateInfosecurity Magazine·1 month ago

China-Linked APT Expands Proxy Network With New Malware

Cisco Talos has identified China-linked APT UAT-7810 expanding its infrastructure through the development of new malware designed to augment its proxy relay network. This expansion suggests the threat actor is strengthening its capabilities for obfuscating command-and-control communications and maintaining persistent access to compromised systems.

Load more