Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Where Cybercriminals Go To Buy Your Stolen Data
Threaded  |  Newest First  |  Oldest First
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
12/4/2016 | 11:30:34 PM
Offensive Security by the Private Citizen
I'm curious after reading this about whether a private citizen can do anything at all to investigate potential stolen data and illegal activities associated with their finances or business.  In the past I'd had the opportunity to build a honeypot which I was excited about since I always wanted to test out some ideas, build a custom Tor, etc.  But then I got lots of feedback from techs that know about these things to not even touch the project.  Once you attach yourself to something that can be used for illegal activities you risk being implicated, especially due to (as noted in the article) the possibility of law enforcement monitoring various networks, websites and file access points.  I'm surprised, in fact, this article doesn't unequivocally state private citizens not associated with law enforcement should not even consider researching these places.  What's the real rule of thumb in this case?
.osiris
50%
50%
.osiris,
User Rank: Strategist
12/6/2016 | 1:27:29 AM
Re: Where Cybercriminals Go To Buy Your Stolen Data
You can also add Armada board. A feaw years ago Crutop forum was very popular amonth the underground webmasters, until theor owner RedEye got prisoned.
sasa23
50%
50%
sasa23,
User Rank: Apprentice
10/10/2017 | 9:46:04 PM
Re: Offensive Security by the Private Citizen
its so interesting, thanks
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
12/7/2016 | 8:05:06 AM
Identity theft
Well this just goes on to show how much of our data be it stored in our systems or browsing online is vulnerable and susceptible to being hacked or mistreated by malicious hands. Therefore it is always important to secure online footprints and privacy and what best way to do that than deploying secure vpn server like PureVPN which provides online encrypted connections. They have some deals going from what I read on my last visit to their website

www.purevpn.com/order
rayray2016
50%
50%
rayray2016,
User Rank: Apprentice
12/13/2016 | 12:55:28 PM
Twenty Motion
Awesome articles
amirshk
100%
0%
amirshk,
User Rank: Author
12/16/2016 | 10:44:39 AM
Very interesting
Very interesting review of the marketplace


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises Are Assessing Cybersecurity Risk in Today's Environment
The adoption of cloud services spurred by the COVID-19 pandemic has resulted in pressure on cyber-risk professionals to focus on vulnerabilities and new exposures that stem from pandemic-driven changes. Many cybersecurity pros expect fundamental, long-term changes to their organization's computing and data security due to the shift to more remote work and accelerated cloud adoption. Download this report from Dark Reading to learn more about their challenges and concerns.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-46204
PUBLISHED: 2022-01-19
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via taocms\include\Model\Article.php.
CVE-2022-0274
PUBLISHED: 2022-01-19
Cross-site Scripting (XSS) - Stored in NPM cypress-orchardcore prior to 1.2.2.
CVE-2021-33912
PUBLISHED: 2022-01-19
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand...
CVE-2021-33913
PUBLISHED: 2022-01-19
libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of SPF_record_expand_data in spf_expand.c. The amount of overflowed data dep...
CVE-2021-42810
PUBLISHED: 2022-01-19
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.