Just Hacked On

Just Hacked On

Share

Hacking is a talent. You won't learn it at school.

Photos from Just Hacked On's post 02/11/2025

Completed a hands-on lab analyzing a malicious browser extension. Below are the concise technical observations.

URL obfuscation: Base64 encoding.

Exfiltration vector: element (new Image() β†’ src GET request`).

Sandbox/VM check (first trigger): navigator.plugins.length === 0.

Keystroke capture: document.addEventListener('keydown', ...) β†’ event.key.

Encryption used: AES (CryptoJS.AES.encrypt) with IV; result base64-encoded.

Credential access: FormData API to read submitted username/email and password; uses window.location.hostname for context.

Takeaway
Simple but effective evasion and exfiltration techniques β€” great exercise in threat-hunting and chain-of-evidence extraction.

10/08/2025

Steganography & RC4 Encryption – Hide Malware in PNG Like a Pro | Live Webinar | Team JustHackedOn

Ever wondered how hackers hide malicious code inside images? πŸ“‚πŸ–Ό
Join our live webinar where we’ll explore Steganography and RC4 Encryption with IDAT Chunks – a real-world technique used in cyber attacks.

πŸ’‘ What you’ll learn:

Steganography πŸ•΅οΈβ€β™‚οΈ

Using IDAT chunks in PNG files for data hiding

RC4 encryption for securing hidden payloads

Real-world ethical hacking use cases

πŸ“… Date: 13th August 2025
πŸ•˜ Time: 9:00 PM
πŸ“ Hosted by Just Hacked On – Security Just an Illusion

πŸš€ Don’t miss this chance to level up your cybersecurity skills!

Photos from Just Hacked On's post 07/08/2025

πŸ›‘οΈ Malware Analysis: Real-World Payload Hunting

Recently, I analyzed a suspicious network indicator pointing to a potential loader

πŸ“Œ Key Steps I Took:

Collected network artifacts (pcap/scripts)

Identified encoded PowerShell loaders and decoded them

Reconstructed the dropped .exe payload from hex strings inside the PowerShell script

Verified the SHA256 hash:

1eb7b02e18f67420f42b1d94e74f3b6289d92672a0fb1786c30c03d68e81d798

Uploaded the sample to VirusTotal to confirm it

Retrieved the Alibaba malware family label

πŸ“‚ Outcome:
β†’ Discovered the sample used fileless techniques and persistent ex*****on via scheduled tasks and VBScript
β†’ Learned how .jpg extensions can be abused to bypass basic filters

πŸ” This was a hands-on case study in:

Script deobfuscation

Payload reconstruction

Threat intelligence enrichment

🧠 Stay curious, analyze everything.

04/08/2025

Pros and Cons of Using Hydra Tool πŸ› οΈ

Evaluate Hydra tool use! Enjoy efficient testing and customizable options, but consider legal risks and ethical concerns. Perfect for cybersecurity pros! πŸ•΅οΈβ€β™‚οΈ

04/08/2025

Step-by-Step Web Login Brute Force with Hydra πŸšͺ

Follow the web login brute force process with Hydra! From specifying credentials to executing the attack, enhance your security testing skills. Get started! πŸ”

03/08/2025

Explore Hydra’s Versatility in Pe*******on Testing 🌐

Discover Hydra’s power in pe*******on testing across Telnet, FTP, SSH, HTTP, RDP, and SMB! Boost your cybersecurity expertise with versatile tools. Dive in! πŸ›‘οΈ

03/08/2025

Master Hydra Commands Configuration Guide πŸ’»

Learn to configure Hydra commands for single or multiple usernames and passwords! Enhance your pe*******on testing skills with this step-by-step guide. Start now! πŸ”§

02/08/2025

Brute-Force vs. Manual Testing: Which is Better? πŸ”

Compare brute-force and manual testing for login security! Brute-force is fast and parallel but detectable, while manual testing is slower yet less detectable. Choose wisely! πŸ›‘οΈ

02/08/2025

Bypass Firewalls with Nmap Techniques πŸ”₯

Learn Nmap firewall bypass techniques like packet fragmentation, MAC spoofing, decoy IPs, and random padding! Strengthen your ethical hacking skills today. πŸ›‘οΈ

Want your school to be the top-listed School/college in punjab?

Click here to claim your Sponsored Listing.

Location

Telephone

Address

Gujranwala
Punjab
52250