Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

12/3/2016
09:00 AM
Sean Martin
Sean Martin
Slideshows
Connect Directly
LinkedIn
RSS
E-Mail

Where Cybercriminals Go To Buy Your Stolen Data

What malicious sites provide both free and paid access to stolen credit cards, company databases, malware and more?
2 of 10

Bonus Source: Novice Cybercrime Communities

Social sites, communities, marketplaces and other places for people new to the cybercrime underground to learn their craft have become increasingly available, easy to find, and easy to use, even for the most novice user.

'The introduction of low cost-domains, the availability of cheap shared web hosting, and the large number of free-to-use open-source community platforms has enabled fraudsters to easily set up and run dark web communities in a matter of a few minutes,' says Tyler. 'This has led to a huge explosion in the number of communities that are accessible and available, even for those hunting for information via a search engine.'

Image Source: CSID

Bonus Source: Novice Cybercrime Communities

Social sites, communities, marketplaces and other places for people new to the cybercrime underground to learn their craft have become increasingly available, easy to find, and easy to use, even for the most novice user.

The introduction of low cost-domains, the availability of cheap shared web hosting, and the large number of free-to-use open-source community platforms has enabled fraudsters to easily set up and run dark web communities in a matter of a few minutes, says Tyler. This has led to a huge explosion in the number of communities that are accessible and available, even for those hunting for information via a search engine.

Image Source: CSID

2 of 10
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
sasa23
50%
50%
sasa23,
User Rank: Apprentice
10/10/2017 | 9:46:04 PM
Re: Offensive Security by the Private Citizen
its so interesting, thanks
amirshk
100%
0%
amirshk,
User Rank: Author
12/16/2016 | 10:44:39 AM
Very interesting
Very interesting review of the marketplace
rayray2016
50%
50%
rayray2016,
User Rank: Apprentice
12/13/2016 | 12:55:28 PM
Twenty Motion
Awesome articles
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
12/7/2016 | 8:05:06 AM
Identity theft
Well this just goes on to show how much of our data be it stored in our systems or browsing online is vulnerable and susceptible to being hacked or mistreated by malicious hands. Therefore it is always important to secure online footprints and privacy and what best way to do that than deploying secure vpn server like PureVPN which provides online encrypted connections. They have some deals going from what I read on my last visit to their website

www.purevpn.com/order
.osiris
50%
50%
.osiris,
User Rank: Apprentice
12/6/2016 | 1:27:29 AM
Re: .osiris
You can also add Armada board. A feaw years ago Crutop forum was very popular amonth the underground webmasters, until theor owner RedEye got prisoned.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
12/4/2016 | 11:30:34 PM
Offensive Security by the Private Citizen
I'm curious after reading this about whether a private citizen can do anything at all to investigate potential stolen data and illegal activities associated with their finances or business.  In the past I'd had the opportunity to build a honeypot which I was excited about since I always wanted to test out some ideas, build a custom Tor, etc.  But then I got lots of feedback from techs that know about these things to not even touch the project.  Once you attach yourself to something that can be used for illegal activities you risk being implicated, especially due to (as noted in the article) the possibility of law enforcement monitoring various networks, websites and file access points.  I'm surprised, in fact, this article doesn't unequivocally state private citizens not associated with law enforcement should not even consider researching these places.  What's the real rule of thumb in this case?
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5230
PUBLISHED: 2019-11-13
P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform...
CVE-2019-5231
PUBLISHED: 2019-11-13
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
CVE-2019-5233
PUBLISHED: 2019-11-13
Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.
CVE-2019-5246
PUBLISHED: 2019-11-13
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain par...
CVE-2010-4177
PUBLISHED: 2019-11-12
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.