Ethical Hacker Philippines - EHPH

Ethical Hacker Philippines - EHPH Official page of EHPH group
Founded: September 06, 2022

08/05/2024
๐—ฅ๐—ฒ๐—ฑ๐—ง๐—ฒ๐—ฎ๐—บ ๐—ง๐—ผ๐—ผ๐—น๐˜€ : ๐—” ๐—–๐—ผ๐—น๐—น๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐—ฅ๐—ฒ๐—ฑ ๐—ง๐—ฒ๐—ฎ๐—บ๐—ถ๐—ป๐—ด/๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ผ๐—ผ๐—น๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—พ๐˜‚๐—ฒ๐˜€https://github.com/A-poc/RedTeam-Too...
08/05/2024

๐—ฅ๐—ฒ๐—ฑ๐—ง๐—ฒ๐—ฎ๐—บ ๐—ง๐—ผ๐—ผ๐—น๐˜€ : ๐—” ๐—–๐—ผ๐—น๐—น๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐—ฅ๐—ฒ๐—ฑ ๐—ง๐—ฒ๐—ฎ๐—บ๐—ถ๐—ป๐—ด/๐—ฃ๐—ฒ๐—ป๐—ฒ๐˜๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ง๐—ผ๐—ผ๐—น๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—พ๐˜‚๐—ฒ๐˜€

https://github.com/A-poc/RedTeam-Tools



๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต๐—ฆ๐—ฝ๐˜† : ๐—œ๐—ป๐—ถ๐˜๐—ถ๐—ฎ๐—น ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐—ผ๐˜€๐˜-๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ผ๐—ผ๐—น ๐—ณ๐—ผ๐—ฟ ๐—”๐—”๐—— ๐—ฎ๐—ป๐—ฑ ๐—ข๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ฏ๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—š๐—จ๐—œhttps://github.com/RedByte...
08/05/2024

๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต๐—ฆ๐—ฝ๐˜† : ๐—œ๐—ป๐—ถ๐˜๐—ถ๐—ฎ๐—น ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฎ๐—ป๐—ฑ ๐—ฃ๐—ผ๐˜€๐˜-๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ง๐—ผ๐—ผ๐—น ๐—ณ๐—ผ๐—ฟ ๐—”๐—”๐—— ๐—ฎ๐—ป๐—ฑ ๐—ข๐Ÿฏ๐Ÿฒ๐Ÿฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ฏ๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—š๐—จ๐—œ

https://github.com/RedByte1337/GraphSpy



๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด-๐—˜๐——๐—ฅ-๐—ฎ๐—ป๐—ฑ-๐—˜๐——๐—ฅ_๐—˜๐˜ƒ๐—ฎ๐˜€๐—ถ๐—ผ๐—ปhttps://github.com/reveng007/Learning-EDR-and-EDR_Evasion
08/05/2024

๐—Ÿ๐—ฒ๐—ฎ๐—ฟ๐—ป๐—ถ๐—ป๐—ด-๐—˜๐——๐—ฅ-๐—ฎ๐—ป๐—ฑ-๐—˜๐——๐—ฅ_๐—˜๐˜ƒ๐—ฎ๐˜€๐—ถ๐—ผ๐—ป

https://github.com/reveng007/Learning-EDR-and-EDR_Evasion



๐—ช๐—ฒ๐—ฎ๐—ธ๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ฎ ๐—ฐ๐—ผ๐—น๐—น๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐˜๐—ผ๐—ผ๐—น๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—ฏ๐—ฟ๐˜‚๐˜๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ต๐—ฎ๐˜€๐—ต๐—ฐ๐—ฟ๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ดBetter than rockyou 2024๐——๐—ถ๐—ฐ๐—ฎ๐˜€๐˜€๐—ฎ๐˜€๐˜€๐—ถ๐—ป32.91 GB tar23,109,038,...
03/05/2024

๐—ช๐—ฒ๐—ฎ๐—ธ๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ฎ ๐—ฐ๐—ผ๐—น๐—น๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป ๐—ผ๐—ณ ๐˜๐—ผ๐—ผ๐—น๐˜€ ๐—ณ๐—ผ๐—ฟ ๐—ฏ๐—ฟ๐˜‚๐˜๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ ๐—ฎ๐—ป๐—ฑ ๐—ต๐—ฎ๐˜€๐—ต๐—ฐ๐—ฟ๐—ฎ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด

Better than rockyou 2024

๐——๐—ถ๐—ฐ๐—ฎ๐˜€๐˜€๐—ฎ๐˜€๐˜€๐—ถ๐—ป
32.91 GB tar
23,109,038,633 lists
https://weakpass.com
https://weakpass.com/wordlist/1946



๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ฒ๐—ฟ ๐˜๐—ผ ๐—จ๐—ป๐˜ƒ๐—ฒ๐—ถ๐—น ๐Ÿฐ ๐—ข๐—ฝ๐—ฒ๐—ป๐—ฉ๐—ฃ๐—ก ๐—ญ๐—ฒ๐—ฟ๐—ผ-๐——๐—ฎ๐˜† ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฎ๐˜ ๐—•๐—น๐—ฎ๐—ฐ๐—ธ ๐—›๐—ฎ๐˜ ๐—จ๐—ฆ๐—” ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฐhttps://securityonline.info/micro...
03/05/2024

๐— ๐—ถ๐—ฐ๐—ฟ๐—ผ๐˜€๐—ผ๐—ณ๐˜ ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต๐—ฒ๐—ฟ ๐˜๐—ผ ๐—จ๐—ป๐˜ƒ๐—ฒ๐—ถ๐—น ๐Ÿฐ ๐—ข๐—ฝ๐—ฒ๐—ป๐—ฉ๐—ฃ๐—ก ๐—ญ๐—ฒ๐—ฟ๐—ผ-๐——๐—ฎ๐˜† ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฎ๐˜ ๐—•๐—น๐—ฎ๐—ฐ๐—ธ ๐—›๐—ฎ๐˜ ๐—จ๐—ฆ๐—” ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฐ

https://securityonline.info/microsoft-researcher-to-unveil-4-openvpn-zero-day-vulnerabilities-at-black-hat-usa-2024/



The ๐—Ÿ๐—ฎ๐˜‡๐—ฎ๐—ฟ๐˜‚๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ was caught impersonating Fenbushi Capital on LinkedIn to launch their phishing campaign. They are also...
29/04/2024

The ๐—Ÿ๐—ฎ๐˜‡๐—ฎ๐—ฟ๐˜‚๐˜€ ๐—š๐—ฟ๐—ผ๐˜‚๐—ฝ was caught impersonating Fenbushi Capital on LinkedIn to launch their phishing campaign. They are also targeting blockchain developers to spread their malware by initiating fake recruiting.

IoC
https://pastebin.com/2pz1iQFm



26/04/2024

๐Ÿšจ ๐—ข๐—ฟ๐—ฎ๐—ฐ๐—น๐—ฒ ๐—ฉ๐—ถ๐—ฟ๐˜๐˜‚๐—ฎ๐—น๐—•๐—ผ๐˜… ๐Ÿณ.๐Ÿฌ.๐Ÿญ๐Ÿฒ ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜๐—ผ ๐—Ÿ๐—ฃ๐—˜ ๐Ÿšจ

Oracle VirtualBox Prior to 7.0.16 is vulnerable to Local Privilege Escalation via Symbolic Link Following leading to Arbitrary File Delete and Arbitrary File Move.

PoC
https://github.com/mansk1es/CVE-2024-21111

Sploitscan
https://github.com/xaitax/SploitScan
$ python3 sploitscan.py CVE-2024-21111 -e JSON



๐— ๐—ฎ๐—น๐˜„๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฒ๐˜„ : ๐—ฎ ๐—ณ๐—ถ๐—ฟ๐˜€๐˜ ๐—ฟ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ ๐˜๐—ผ๐—ผ๐—น ๐˜‚๐˜€๐—ฒ๐—ฑ ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ต๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ณ๐—ณ๐—ฒ๐—ฟ๐˜€ ๐—ถ๐—ป๐˜๐—ฒ๐—น ๐—ถ๐—ป๐—ณ๐—ผ๐—ฟ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฉ๐—ถ๐—ฟ๐˜‚๐˜€ ๐—ง๐—ผ๐˜๐—ฎ๐—น, ๐—›๐˜†๐—ฏ๐—ฟ๐—ถ๐—ฑ ๐—”๐—ป๐—ฎ๐—น๐˜†...
23/04/2024

๐— ๐—ฎ๐—น๐˜„๐—ผ๐˜ƒ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฒ๐˜„ : ๐—ฎ ๐—ณ๐—ถ๐—ฟ๐˜€๐˜ ๐—ฟ๐—ฒ๐˜€๐—ฝ๐—ผ๐—ป๐˜€๐—ฒ ๐˜๐—ผ๐—ผ๐—น ๐˜‚๐˜€๐—ฒ๐—ฑ ๐—ณ๐—ผ๐—ฟ ๐˜๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ต๐˜‚๐—ป๐˜๐—ถ๐—ป๐—ด ๐—ฎ๐—ป๐—ฑ ๐—ผ๐—ณ๐—ณ๐—ฒ๐—ฟ๐˜€ ๐—ถ๐—ป๐˜๐—ฒ๐—น ๐—ถ๐—ป๐—ณ๐—ผ๐—ฟ๐—บ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฉ๐—ถ๐—ฟ๐˜‚๐˜€ ๐—ง๐—ผ๐˜๐—ฎ๐—น, ๐—›๐˜†๐—ฏ๐—ฟ๐—ถ๐—ฑ ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€, ๐—จ๐—ฅ๐—Ÿ๐—›๐—ฎ๐˜‚๐˜€, ๐—ฃ๐—ผ๐—น๐˜†๐˜€๐˜„๐—ฎ๐—ฟ๐—บ, ๐— ๐—ฎ๐—น๐˜€๐—ต๐—ฎ๐—ฟ๐—ฒ, ๐—”๐—น๐—ถ๐—ฒ๐—ป ๐—ฉ๐—ฎ๐˜‚๐—น๐˜, ๐— ๐—ฎ๐—น๐—ฝ๐—ฒ๐—ฑ๐—ถ๐—ฎ, ๐— ๐—ฎ๐—น๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—•๐—ฎ๐˜‡๐—ฎ๐—ฎ๐—ฟ, ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜๐—™๐—ผ๐˜…, ๐—ง๐—ฟ๐—ถ๐—ฎ๐—ด๐—ฒ, ๐—œ๐—ป๐—ค๐˜‚๐—ฒ๐˜€๐˜ ๐—ฎ๐—ป๐—ฑ ๐—ถ๐˜ ๐—ถ๐˜€ ๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜๐—ผ ๐˜€๐—ฐ๐—ฎ๐—ป ๐—”๐—ป๐—ฑ๐—ฟ๐—ผ๐—ถ๐—ฑ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ ๐—ฎ๐—ด๐—ฎ๐—ถ๐—ป๐˜€๐˜ ๐—ฉ๐—ง.

Malwoverview performs an initial and quick triage of malware samples, URLs, IP addresses, domains, malware families, IOCs and hashes. Additionally, Malwoverview is able to get dynamic and static behavior reports, submit and download samples from several endpoints. In few words, it works as a client to main existing sandboxes.

1. Determine similar executable malware samples (PE/PE+) according to the import table (imphash) and group them by different colors (pay attention to the second column from output). Thus, colors matter!

2. Show hash information on Virus Total, Hybrid Analysis, Malshare, Polyswarm, URLhaus, Alien Vault, Malpedia and ThreatCrowd engines.

3. Determining whether the malware samples contain overlay and, if you want, extract it.

4. Check suspect files on Virus Total, Hybrid Analysis and Polyswarm.

5. Check URLs on Virus Total, Malshare, Polyswarm, URLhaus engines and Alien Vault.

6. Download malware samples from Hybrid Analysis, Malshare, URLHaus, Polyswarm and Malpedia engines.

7. Submit malware samples to VirusTotal, Hybrid Analysis and Polyswarm.

8. List last suspected URLs from URLHaus.

9. List last payloads from URLHaus.

10. Search for specific payloads on the Malshare.

https://github.com/alexandreborges/malwoverview



๐Ÿšจ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—”๐—น๐—ฒ๐—ฟ๐˜ ๐Ÿšจ : A threat actor is currently selling a new zero-day (LPE) Local Privilege Escalation exploit...
20/04/2024

๐Ÿšจ ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—–๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—”๐—น๐—ฒ๐—ฟ๐˜ ๐Ÿšจ : A threat actor is currently selling a new zero-day (LPE) Local Privilege Escalation exploit affecting all Windows systems. It was priced at $250,000 yesterday but now dropped to $150,000. The threat actor also claims that the vulnerability is not linked to any CVE.

LPE is a security flaw exploited by threat actors to gain higher privileges. They can then install malware, access sensitive data, modify system settings, and do lateral movement to compromise other networks.

Reference:
https://gbhackers.com/windows-lpe-zero-day/



Address

Cebu
Cebu City

Website

Alerts

Be the first to know and let us send you an email when Ethical Hacker Philippines - EHPH posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Organization

Send a message to Ethical Hacker Philippines - EHPH:

Share