Cyber Security and Ethical Hacking Notes!
If you want to be updated and ahead of other Security Professionals, this directory is for you.
Notes cover various security approaches, attack techniques, and discoveries about security system vulnerabilities and breaches.
Using these resources boost your security operations handling, hunting, incident response skills, and much more.
Link:
https://t.co/gAzg2bln8A
Follow @ZabihullahAtal it's all about Empowering You.
It's officially been 4 years since I started https://t.co/LXHWsPXate !! as a one-off special, use the coupon "BUSINESSVERSARY" for 25% off, or log a ticket here https://t.co/umJVUmQmaa to upgrade to something by paying the difference (for 25% less)
Please repost!
#aws#cloud
EXPLOITING THE VULNERABILITY IN IPHONE AND ANDROID
As a penetration tester and security researcher, I want to talk about SS7; a vulnerability that exist in iPhones and android. People don’t know about it.
It can’t be patched. I don’t need to install malware on your phone before I collect data. Your phone number is enough. This is a form of radio penetration testing.
SS7, or Signaling System 7, is a set of telecommunication protocols used worldwide for handling phone calls and text messages. While SS7 serves a critical role in telecommunications, it has been known to have vulnerabilities that security researchers and malicious actors have exploited.
Governments and intelligence agencies had the power to intercept calls and exploit the power of SS7; but now individuals with powerful tools have the capabilities to do that.
Hackers can read text messages, listen to phone calls and track mobile phone users’ locations with just the knowledge of their phone number using a vulnerability in the worldwide mobile phone network infrastructure.
The exploit centres on a global system that connects mobile phone networks, and can give hackers, governments or anyone else with access to it remote surveillance powers that the user cannot do anything about.
Here's some information on SS7 vulnerabilities, how they can be exploited, and steps to mitigate these risks:
Exploiting SS7 Vulnerabilities
1. SMS Interception: One significant vulnerability is SMS interception. Malicious actors can exploit SS7 to intercept and read SMS messages sent to a target's phone number. This can lead to privacy breaches and unauthorized access to sensitive information like two-factor authentication codes.
2. Call Interception: Another vulnerability allows attackers to intercept phone calls and listen in on conversations. This is a significant concern for privacy and security.
3. Location Tracking: SS7 can be exploited to track the physical location of a mobile device, potentially enabling stalking or unauthorized surveillance.
4. Call and Message Spoofing: Attackers can use SS7 to spoof phone numbers, making it appear as though calls or messages are coming from a trusted source.
5. Denial of Service (DoS): While less common, SS7 networks can be targeted with DoS attacks, disrupting telecommunications services and causing inconvenience or financial losses.
6. Fraudulent Activities: Criminals can use SS7 attacks to commit fraud, such as bypassing international call charges, making premium-rate calls, or conducting fraudulent financial transactions.
Hackers can transparently forward calls, giving them the ability to record or listen in to them. They can also read SMS messages sent between phones, and track the location of a phone using the same system that the phone networks use to help keep a constant service available and deliver phone calls, texts and data.
The tools to perform this attack is sold on the open market today.
The problem with ss7 attack is, while targeting only one phone number, you will end up collecting data from thousands of phone numbers in seconds.
While is fun to play with ss7, make sure you have the permission to perform the exploit if you’re not researching.
The good thing it can be used to perform investigations and help bodies counter terrorism and fraud.
#CyberSecurityAwareness #cybersecurity #pentesting #ss7
Matt Mochary is a Silicon Valley legend.
He's coached the founders of OpenAI, Notion, Rippling, Robinhood, Coinbase, Reddit, @naval, and many others.
His entire course is open-sourced, even the templates. Here's a link 👇
https://t.co/deeeu5WmCj
I agree!
Unfortunately, studying medicine isn’t the best leverage for your intelligence.
You are more likely to get better returns in an even shorter timeframe if you use it in other fields!
If you need FREE learning and robust resources for the following:
-Coding
-Excel
-Project Management Cert.
-Video Editing
-Graphic Design
-Scrum
-Data Analysis
-Business Analysis
-Copyrighting
-Cyber Security
-Web Dev & more
RT. Check this drive: https://t.co/CltydOFRDg
When you call electrical company and they said they will charge you $140 a piece go change two breakers. Buy it on Amazon for $30 and replace it yourself… DIY. Taking risk is part of life
When you call electrical company and they said they will charge you $140 a piece go change two breakers. Buy it on Amazon for $30 and replace it yourself… DIY. Taking risk is part of life
It is not the basic things we have issues with. Have you been asked to buy baby apple, pear and banana puree, but you got the apple puree instead because you can't find the combo? To women, it is different. For me, apple is a part of the initial ask, so I chose that.
I’ve been doing market runs since I was 10.
Yes, and I mean going to Oja-Oba from Muslim all by myself. What’s wrong with you men? How did you survive till now if you can’t buy basic things?