Real world hacking expert OTW demonstrates SQL Injection attack from recent MOVEit hack. Discussion includes impact of OTW's work, ongoing hacks by CLOPS group, cybersecurity threats by Russian hackers, evolution of SQL Injection exploits, and upcoming hacking classes.
Hackers exploit SQL injection vulnerabilities in Moveit Transfer to extort companies for ransom.
Occupy the Web offers cybersecurity classes on advanced topics like SDR, Bitcoin forensics, and mobile systems vulnerabilities.
Deep dives
The Rise of CLOPS and Moveit's Compromised security
The hacking organization CLOPS has been executing numerous cyber attacks using a website on the dark web to track their targets, including prominent companies like Taiwan semiconductor, Siemens, UCLA, and more. More than 150 companies have fallen victim to these relentless attacks, which involve exploiting vulnerabilities in software like Moveit transfer, allowing unauthorized access to databases through SQL injection techniques.
CLOPS' Tactics and Motives in Ransomware Attacks
CLOPS, a Russian-speaking group, specifically targets companies in Britain and the US, aiming to extort money by threatening to expose sensitive data unless ransom is paid. Their attacks focus on large organizations using software like Moveit, manipulating vulnerabilities like poor SQL sanitization to gain admin privileges, exfiltrate data, and demand hefty sums for data decryption, often reaching millions of dollars.
The Complexity of Exploiting SQL Injection in Moveit Transfer
The proof of concept of the exploit in Moveit Transfer involves intricate SQL injection techniques, where attackers insert themselves into the authorized user database, manipulate tokens, and whitelist their IP addresses to gain access. By leveraging multiple vulnerabilities like improper SQL sanitization, attackers are able to execute complex insert and update statements in the database, demonstrating sophisticated hacking skills.
Educational Opportunities and Future Cybersecurity Classes
Occupy the Web discusses upcoming cybersecurity classes, including SDR for hackers, AI for cybersecurity, Bitcoin forensics, Android hacking, and building femto cells and stingrays. These classes aim to delve into cutting-edge topics like intercepting signals, Bitcoin tracing, and analyzing SS7 flaws in mobile systems, offering insights into advanced cybersecurity techniques and real-world hacking scenarios.
This is a real world demonstration of the SQL Injection attack used in the recent MOVEit hack. This is real world - not just a simple SQL attack.
Big thank you to Juniper Networks for supporting the community and making training free. Go to https://juniper.net/davidbombal to get lots of training and also learn how to get certified for $50 (Associate Level).
// Mr Robot Playlist //
• Mr Robot
// Proof of Concept //
Horizon3: https://www.horizon3.ai/moveit-transf...
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube:
/ davidbombal
// Occupy The Web social //
Twitter: https://twitter.com/three_cube
// OTW classes //
Hacker's Arise Pro Subscription:
https://hackers-arise.com/online-stor...
Get 3 year's access to all live courses:
https://hackers-arise.com/online-stor...
// Occupy The Web books //
Linux Basics for Hackers: https://amzn.to/3JlAQXe
Getting Started Becoming a Master Hacker: https://amzn.to/3qCQbvh
Top Hacking Books you need to read:
• Top Hacking Books...
// Other books //
The Linux Command Line: https://amzn.to/3ihGP3j
How Linux Works: https://amzn.to/3qeCHoY
The Car Hacker’s Handbook by Craig Smith: https://amzn.to/3pBESSM
Hacking Connected Cars by Alissa Knight: https://amzn.to/3dDUZN8
// Occupy The Web Website / Hackers Arise Website //
Website: https://www.hackers-arise.com/?afmc=1d
OTW Mr Robot series: https://www.hackers-arise.com/mr-robot
Want to learn more from Occupy the Web? You can join his classes using these links:
Hacker's Arise Pro Subscription"
https://hackers-arise.com/online-stor...
Get 3 year's access to all live courses:
https://hackers-arise.com/online-stor...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
00:00 - Coming Up
00:55 - Juniper Free Training (Sponsored segment)
01:51 - OccupyTheWeb books and new books
03:57 - The MOVEit breach explained
05:20 - Clop website // Companies affected
08:52 - The two different vulnerabilities
10:26 - The truth about SQL Injection
12:21 - Using Shodan
14:05 - Proof of concept of the exploit
16:18 - SQL Injection example
20:35 - MOVEit hack analysis / How it was done
28:57 - CVE-2023-35708 SQL Injection vulnerability explained
30:36 - What is Taiwan Semi-Conductor (TSMC) and why they got hacked
31:01 - SQL Injection hack in the real world
32:45 - OccupyTheWeb online classes
33:46 - Union statement // Stacking queries demo
37:02 - Upcoming OccupyTheWeb courses and classes
39:50 - Conclusion
MOVEit
sql
sql injection
hack
hacking
hacker
pegasus
cybersecurity
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#hacking #cybersecurity #sql
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode