sn1per – An Automated Penetration Testing Tool

0
[ad_1]
SN1PER

Sn1per is an automated scanner that can automate the process of collecting data for exploration and penetration testing.

In their work sn1per involves such well-known tools like: amap, arachni, amap, cisco-torch, dnsenum, enum4linux, golismero, hydra, metasploit-framework, nbtscan, nmap smtp-user-enum, sqlmap, sslscan, theharvester, w3af, wapiti, whatweb, whois, nikto, wpscan.d during a penetration test to enumerate and scan for vulnerabilities.

FEATURES:

  • Automatically collects basic recon (ie. whois, ping, DNS, etc.)
  • Automatically launches Google hacking queries against a target domain
  • Automatically enumerates open ports
  • Automatically brute forces sub-domains and DNS info
  • Automatically checks for sub-domain hijacking
  • Automatically runs targeted NMap scripts against open ports
  • Automatically runs targeted Metasploit scan and exploit modules
  • Automatically scans all web applications for common vulnerabilities
  • Automatically brute forces all open services
  • Automatically exploit remote hosts to gain remote shell access
  • Performs high level enumeration of multiple hosts
  • Auto-pwn added for Metasploitable, ShellShock, MS08-067, Default Tomcat Creds
  • Automatically integrates with Metasploit Pro, MSFConsole and Zenmap for reporting
  • Create individual workspaces to store all scan output

MODES:

  • REPORT: Outputs all results to text in the loot directory for later reference. To enable reporting, append ‘report’ to any sniper mode or command.
  • STEALTH: Quickly enumerate single targets using mostly non-intrusive scans to avoid WAF/IPS blocking
  • DISCOVER: Parses all hosts on a subnet/CIDR (ie. 192.168.0.0/16) and initiates a sniper scan against each host. Useful for internal network scans.
  • PORT: Scans a specific port for vulnerabilities. Reporting is not currently available in this mode.
  • FULLPORTONLY: Performs a full detailed port scan and saves results to XML.
  • WEB: Adds full automatic web application scans to the results (port 80/tcp & 443/tcp only). Ideal for web applications but may increase scan time significantly.
  • NOBRUTE: Launches a full scan against a target host/domain without brute forcing services.
  • AIRSTRIKE: Quickly enumerates open ports/services on multiple hosts and performs basic fingerprinting. To use, specify the full location of the file which contains all hosts, IP’s that need to be scanned and run ./sn1per /full/path/to/targets.txt airstrike to begin scanning.
  • NUKE: Launch full audit of multiple hosts specified in text file of choice. Usage example: ./sniper /pentest/loot/targets.txt nuke.
  • LOOT: Automatically organizes and displays loot folder in your browser and opens Metasploit Pro and Zenmap GUI with all port scan results. To run, type ‘sniper loot’.

Detailed Demonstration – sn1per

Step 1:

Download the  Sniper clone Repository from Github . Extract it Zip file in the Desktop

#git clone https://github.com/1N3/Sn1per.git
sn1per

Step 2:

Install the sn1per using the install.sh file in sn1per folder .

#chmod +x install.sh

Step 3:

Install sn1per using this command .

#./install.sh

Step 4:

After successfully installed sn1per open the tool .

Step :5

After Successfully Open the Sn1per, Start Gathering the information from the Target

#sniper  facebook.com

Here you will get some information about the fingerprint of specfic Target .

Domain name lookup  service “who is information” to search the whois database for domain name registration information.

theHarvester

The objective of this program is to gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database.

This tool is intended to help Penetration testers in the early stages of the penetration test in order to understand the customer footprint on the Internet. It is also useful for anyone that wants to know what an attacker can see about their organization.

Here you will get some information about the DNS Information of specfic Target .

Sublist3r

Sublist3r is python tool that is designed to enumerate subdomains of websites through OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r enumerates subdomains using many search engines such as Google, Yahoo, Bing, Baidu, and Ask. Sublist3r also enumerates subdomains using Netcraft, Virustotal, ThreatCrowd, DNSdumpster and ReverseDNS.

wafw00f

Web Application firewalls are typically firewalls working on the application layer which monitors & modifies HTTP requests.

The key difference is that WAFs work on Layer 7 – Application Layer of the OSI Model. Basically all WAFs protect against different HTTP attacks & queries like SQLi & XSS

Wafw00f is simply a python tool which automates a set of procedures used in finding a WAF. Wafw00f simply queries a web server with a set of HTTP requests & methods. It analyses the responses from them & detects the firewall in place.

XST

the “XS” in XST evokes similarity to XSS (Cross-Site Scripting) which has the consequence of leading people to mistake XST as a method for injecting JavaScript.

Nikto

Running Nikto yourself is not overly difficult. you will be able to start your web server testing with one of the most well known website / server testing tools. This the same tool we use on our online nikto scanner page.

INURLBR

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation junction for each target / url found.

MassBleed

MassBleed  is a SSL Vulnerability Scanner .main functions with the ability to proxy all connections:

  • To mass scan any CIDR range for OpenSSL vulnerabilities via port 443/tcp (https) (example: sh massbleed.sh 192.168.0.0/16)
  • To scan any CIDR range for OpenSSL vulnerabilities via any custom port specified (example: sh massbleed.sh 192.168.0.0/16 port 8443)
  • To individual scan every port (1-10000) on a single system for vulnerable versions of OpenSSL (example: sh massbleed.sh 127.0.0.1 single)
  • To scan every open port on every host in a single class C subnet for OpenSSL vulnerabilities (example: sh massbleed.sh 192.168.0. subnet)

Yasuo

Yasuo is a ruby script that scans for vulnerable 3rd-party web applications.

While working on a network security assessment (internal, external, redteam gigs etc.), we often come across vulnerable 3rd-party web applications or web front-ends that allow us to compromise the remote server by exploiting publicly known vulnerabilities.

Some of the common & favorite applications are Apache Tomcat administrative interface, JBoss jmx-console, Hudson Jenkins and so on.

BruteX

Automatically brute force all services running on a target .

  • Open ports
  • DNS domains
  • Usernames
  • Passwords

so collection of advanced information gathering and scanning tools are playing their role with Sn1per and Distribute  the Exact information and scanning result from a specific target.

You can also learn the complete YouTube videos here for all the Sn1per pentesting module training.

Also Read :


[ad_2]
Source link

How to set up two-factor authentication on Twitter using a hardware key

0
[ad_1]

We explain how to to enable hardware key authentication on Twitter.

If you use text based authentication as an additional level of security for your Twitter account, you may be aware that this option will be reserved for paying Twitter Blue subscribers come mid-March. This post explains how to enable hardware key authentication instead.

Enabling a hardware security key

1. While logged in, navigate to Settings and Support > Settings and Privacy > Security and account access > Security > Two-factor authentication.

2. Click Security key. You can then either insert the key into the USB port of your computer, or sync it over your computer’s Bluetooth or NFC. You should also name your key, which makes it easier for you to keep track of multiple security keys.

3. Click Get started. It’s worth noting here that many types of hardware keys work with mobile devices. You don’t necessarily need to insert keys into your phone, because they’ll authenticate via NFC or Bluetooth instead.

Protect your account

4. Insert the key into your device or sync with a phone via NFC or Bluetooth. Click Add key. Touch the key to add it to your account.Add your key 

Yubikey

5. You’ll be asked if you want to allow Twitter.com to start using a security key to sign in. The message may differ slightly from the below image.

Authorise key

6. Give the key a name and press Next. Save the backup code in case you lose access to your device or your authentication method.

Name your key

All set

Your Twitter account is now significantly more secure than it once was. The hardware key means phish attacks won’t work, as there’s no text or application code which can be stolen by phishing or SIM-swap attacks. This should be everything you need to keep your account safe.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

One UI 5.1 released for Galaxy Z Fold 2 and Galaxy A73 5G

0
[ad_1]

Samsung‘s One UI 5.1 update has reached the Galaxy Z Fold 2 and Galaxy A73 5G. The former is getting the update in Europe, while the rollout for the latter has begun in Asia. The company should push the new One UI version to the two phones globally over the next few days.

As of this writing, the Galaxy Z Fold 2 is getting the One UI 5.1 update in Germany. The new firmware build number for the second-gen Samsung foldable in Europe is F916BXXU2JWB5. The update should soon reach other European countries and also cross boundaries to global markets, including the US. The firmware version may vary slightly depending on your carrier and market, but the content will mostly remain unchanged.

The same goes for the Galaxy A73 5G as well. While this phone wasn’t released in the US, Samsung sold it in most other markets. The company has begun seeding One UI 5.1 to the premium mid-ranger in Malaysia. It is picking up the update with firmware version A736BXXU3CWB7 (via). Galaxy A73 5G users in Europe, Africa, Latin America, and other regions can also expect to receive the new One UI version soon.

Samsung’s Galaxy Z Fold 2 and Galaxy A73 5G get One UI 5.1

The Galaxy Z Fold 2 and Galaxy A73 5G are getting the February 2023 Android security patch with this update. The latest SMR (Security Maintenance Release) contains more than 50 vulnerability patches, including a handful of critical ones. But the update is primarily about One UI 5.1 rather than the latest security release. The new version of Samsung’s custom Android software brings a host of new features and improvements.

The Korean smartphone giant has improved its stock camera app with new presets for selfie effects. It has also added a Shared Family Album to the Gallery app so families can easily share photos and videos of their vacations. New gestures and DeX improvements make multitasking more efficient, while Samsung Notes now lets you remotely collaborate while you’re on a Google Meet call. Bixby text Call can also now transcribe your audio calls in English. Improved widgets, smart settings suggestions, and activity-based wallpapers are some other highlights of One UI 5.1.

If you’re using either of these Samsung smartphones, most of these new features will be available to you shortly. One UI 5.1 has also been rolled out to the Galaxy S22, Galaxy S21, Galaxy S20, Galaxy Note 20, and all of the recent Galaxy foldables, as well as the Galaxy A53 5G and Galaxy A33 5G. If you haven’t already updated, go to Settings > Software update and tap on Download and install to check for updates manually.


[ad_2]
Source link

A $3.7 billion case against Facebook has been put on hold

0
[ad_1]

Once again, Facebook gets dragged to court, but this time for a $3.7 billion case. The case in question went before a London tribunal, and Facebook will get some breathing space. After hearing the case, the tribunal gave the plaintiff time to file more evidence against the defendant.

This ruling will cut Facebook some slack and give the plaintiff time to gather more evidence. Facebook previously referred to this case as being “without merit” and they welcome the court’s decision. The court will look into this case again in the next six months after the plaintiff must have prepared more evidence to back up their case.

Well, Meta and its companies are not new to court cases of various kinds. But what exactly is Facebook being dragged for this time? The plaintiff is accusing Facebook of abusing its position and misusing millions of users’ data for profit.

Mass action lands in a $3.7 billion case against Facebook over handling of user data

The $3.7 billion case against Facebook was filed by Liza Lovdahl Gormsen over concerns about how the company handles user data. She accuses Facebook of abusing its position and monetizing user personal data. This is a mass action case, which means it is on behalf of 45 million Facebook users in Britain.

Liza says that Facebook demands more data from users than it needs to operate. In addition, users then receive less than they are meant to from the economic value that Facebook generates. This she says is a form of exploitation of millions of users around the world.

Liza Lovdahl Gormsen also says that this action is an abuse of the position Facebook holds in their industry. This case was taken before the Competition Appeal Tribunal in the fourth quarter of last year. By the end of January 2023, the tribunal sat and heard the case against social media giants Facebook.

Finally, the tribunal has come up with a verdict and will put the case on hold. The Competition Appeal Tribunal has given Liza Lovdahl Gormsen’s lawyers six months to strengthen their allegations. According to the tribunal, a “root-and-branch re-evaluation” is needed to establish any losses Facebook users have faced concerning this case.

Both parties will return before the tribunal in six months for a final verdict on the case. Liza Lovdahl Gormsen and her lawyers will use this time to get more evidence to win the $3.7 billion case against Facebook. Until then, Meta will continue improving the services on their social media platforms.


[ad_2]
Source link

Florida Attorney General wants to warn iOS, Android users which apps are foreign-owned

0
[ad_1]
Worried about national security risks, Republican Florida Attorney General Ashley Moody proposes that Apple and Google flag apps developed and/or owned by foreign companies. Moody sent letters (via AppleInsider) to Google CEO Sundar Pichai and Apple CEO Tim Cook suggesting that a special icon or designation accompany Android and iOS apps that are created or owned by a company located outside of the states.

Moody’s letter naturally pointed out the one foreign-owned app that many are fearful of, TikTok. The short-form video app is always among the top titles getting installed on Android and iOS devices each year. It is owned by a Chinese company called ByteDance and Moody notes that the app has “been flagged by national security experts as posing a risk to both privacy and user information.”

There are concerns that TikTok can track the keystrokes that users type on its in-app keyboard allowing ByteDance to steal users’ personal information related to the TikTok app. In her letter to Apple and Google, Moody mentions the high-altitude spy balloons from China recently shot out of the skies by the U.S. military. She says that events like that underscore the need to add additional protections to mobile applications.

AG Moody writes, “We must ensure that consumers have the information needed to make informed decisions about their data privacy and security. The existing lack of transparency in app stores can create a significant risk for American citizens and could cause their personal information to be exploited by foreign entities of concern.” She added, “Further, it is alarming that out of the top apps in Apple’s App Store [and Google’s Play Store], the top three are China-based, thus equating to hundreds of millions of downloads domestically and billions worldwide.”

States such as Maryland, Texas, South Dakota, and Oklahoma have banned TikTok on government devices and The House of Representatives has ordered the removal of TikTok on phones used by lawmakers and staff. Another incident that scares Moody is the discovery of code from Russian company Pushwoosh that was found in thousands of App Store apps including ones from The Centers for Disease Control and Prevention (CDC), and the U.S. Army.

Moody’s letter added that “Consumers deserve the highest level of transparency when choosing to download an application to their phones. This can be achieved by adding a foreign-owned and/or developed designation to applications related to these countries.”


[ad_2]
Source link

Multilingual skimmer fingerprints ‘secret shoppers’ via Cloudflare endpoint API

0
[ad_1]

Magecart threat actors continue to go after e-commerce sites while also collecting data points from fake customers.

One important aspect of data theft in criminal markets revolves around the authenticity of the data that is being resold. There are different services that exist to vet such things as credit card numbers so that buyers can purchase with confidence.

Criminals are also very aware that anyone and in particular security researchers may want to interfere with their operations. Filling up phishing pages with junk data is a sport of its own, although it may also be counterproductive at times. Using special cards for tracing purposes can also be used by defenders to follow the money.

We recently spotted a Magecart skimmer that collects the current victim’s IP address and browser user-agent in addition to their email, address, phone number and credit card data. Because the victim already filled in their home address, we believe this is a fingerprinting effort much like what is done in traditional malware campaigns.

Skimmer targets various geolocations

The skimmer uses iframes that are loaded if the current page is the checkout and if the browser’s local storage does not include a font item (this is equivalent to using cookies to detect returning visitors).

Figure 1: Skimmer checking for address bar and inserting iframe

The final rendering is identical to official payment platforms and does not give anything away:

Figure 2: Fake payment forms injected by skimmer

Fingerprinting via Cloudflare API

The underlying code will scrape everything from the customer’s contact and payment forms. This is something that is often overlooked when talking about digital skimmers but yet is extremely important. While financial institutions can reissue you a new card in the mail, the information the criminals have collected is equivalent to a data breach and can be reused for other types of fraud later on.

Figure 3: Skimmer data collection and fingerprinting

One thing we noticed that was a little unusual, is code that queries the legitimate Cloudflare endpoint API and parses out the results specifically for two things: the user’s current IP address and browser’s user-agent. A user-agent string might look something like this:

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36

From this you can determine the user is running Windows 10 (64 bit version) with Chrome version 110.

Figure 4: Stolen data including IP address and user-agent string

It’s worth noting that this is done after credit card data has already been collected and not before. It is quite common to check the user-agent string upon visiting a web page to determine whether a particular victim fits the target profile or to adapt the content to a mobile or desktop experience.

Since the skimmer already grabbed the shopper’s city, postal code and country it’s unlikely that the IP address would be of much use beyond that. We believe the threat actors are likely collecting IP addresses and user-agent strings for quality checks and monitoring invalid users such as bots and security researchers.

Conclusion

We observe a number credit card skimmers targeting e-commerce platforms such as Magento and WordPress/WooCommerce. Online merchants need to be aware of this threat and take appropriate measures to not only be compliant but also to make it much harder to be compromised in the first place. Since we mentioned Cloudflare in this post, it’s worth noting that the company provides a service to businesses called Page Shield, that helps keep visitors safe through malicious third-party libraries.

We continue to track and report skimming infrastructure in order to protect our users via our Malwarebytes for consumers and businesses, as well as our Browser Guard extension.

Indicators of Compromise

gtag-analytics[.]com

gtag-analytics[.]com/analytics/15798/script.js?key=
gtag-analytics[.]com/analytics/18452/script.js?key=
gtag-analytics[.]com/analytics/25198/script.js?key=
gtag-analytics[.]com/analytics/31826/script.js?key=
gtag-analytics[.]com/analytics/32444/script.js?key=
gtag-analytics[.]com/analytics/34515/script.js?key=
gtag-analytics[.]com/analytics/65526/script.js?key=

gogletags[.]click


[ad_2]
Source link

iPhone 15 Lineup to Reportedly Feature RAM Improvements

0
[ad_1]

RAM Improvements

A recent report suggests that the forthcoming iPhone 15 series could feature slight RAM improvements over the current devices. 

Previously, Taiwanese research firm TrendForce claimed that Apple could release the iPhone 15 Pro models with 8GB RAM later this year. That’s a slight bump from the 6GB RAM on the current iPhone 14 Pro lineup. 

The report also noted that the standard iPhone 15 and iPhone 15 Plus would remain at 6GB of RAM. 

Now a new TrendForce press release doubles down on the previous claim. Besides bumping up the forthcoming iPhone 15 Pro’s RAM capacity, the latest report suggests that Apple could also increase the iPhone 15 models’ RAM specification. 

“Apple will bump up the capacity and specifications of the DRAM solutions featured in the next generation of the iPhone that is scheduled for release this year,” says TrendForce. 

So what do the RAM improvements mean for users? 

Effect of iPhone 15’s RAM Improvements on User Experience

The 8GB RAM will result in improved multitasking on the iPhone. Users should now be able to simultaneously run more apps in the background without worrying that the system might shut down. 

Despite not getting a bump in capacity, the iPhone 15 and 15 Plus models could get a specification boost to the faster LPDDR5 RAM. That’s the same spec as last year’s iPhone 14 Pro models. 

Expectedly, combining these RAM improvements with the rumored A17 Bionic chip could result in a significant performance boost over previous generations. This is especially true since Apple hasn’t announced a RAM bump since releasing the iPhone 12 Pro with 6GB RAM. 

Based on previous experiences, Apple should announce the iPhone 15 series later in September. 

Until then, several leaks already indicate slight design changes, such as thicker camera bumps, slimmer bezels, and curved edges. The reports further suggest that the forthcoming iPhone 15 lineup could include a USB Type-C charging port. 


[ad_2]
Source link

ASUS ROG Phone 6/6 Pro: Everything You Need To Know

0
[ad_1]

ASUS officially announced the ROG Phone 6 and ROG Phone 6 Pro on July 5. Introducing the mobile gaming world to the latest superpowered handset. While we have loved the ROG Phone 6 Pro and covered a lot about how the device performs in our review, there’s a lot more to actually know about the phone. So we’ll be covering that information here.

ASUS’s ROG Phone brand has come a long way since the days of the original phone. And although that particular device was among the best for mobile gaming even back then, ASUS has really added some spit and polish to its most recent offering. Quite simply, this is the best ASUS has ever produced and it finally feels like it can be a worthy daily driver for the majority of users.

With all of that said, let’s dive a little more into the phone series. If you’re considering buying one, then it won’t hurt to know more about it.

When do the ROG Phone 6 and ROG Phone 6 Pro launch?

ASUS ROG Phone 6 Pro Review 4

ASUS hasn’t officially launched the phone yet but it did begin pre-orders on July 5, the day of its announcement. ASUS also noted that the device would ship to buyers “a few weeks later” which means it should be shipping out to those who pre-ordered sometime next week or the week after.

Right now the device is only available for pre-order in the UK, Europe, and Taiwan. With no official release time for the US. ASUS did officially launch the ROG Phone 5 in the US though, so its predecessor will eventually make it stateside as well.

It’s just a matter of time. That being said, the device will probably reach US consumers before the end of the year.

Update: September 9, 2022

The ROG Phone 6 and ROG Phone 6 Pro are now available for pre-order in the US via Amazon. They will be available for pre-order through the ASUS Store in the near future.

How much does the phone cost?

This will depend on where you buy it and what model you get. The ROG Phon 6 with 12GB of RAM and 256GB of storage is £899 in the UK and €999 in Europe. The ROG Phone 6 with 16GB of RAM and 512GB of storage increases the price to £999 in the UK and €1,149 in Europe.

And finally, the ROG Phone 6 Pro, which comes with 18GB of RAM and 512GB of storage, is £1,099 in the UK and €1,299 in Europe. As of right now there are no official prices for the US. And there likely won’t be any confirmed US prices until after ASUS officially announces when the US release date is. At which point it will probably open up pre-orders as well.

ASUS also lists an 8GB RAM model of the ROG Phone 6 on its US site, but no prices are listed and it does not seem to offer this model in the UK at all. So configuration availability is definitely subject to region.

Update: September 9, 2022

US pricing for the device starts at $999. This is for the 12GB RAM/256GB storage model. The 16GB RAM/512GB storage model retails for $1,099, and the ROG Phone 6 Pro, which comes with 18GB of RAM and 512GB of storage will retail for $1,299.

How many models of the ROG Phone 6 are there?

There are two models of the device, with a combined total of four configurations. This includes three configurations of the ROG Phone 6, and one configuration of the ROG Phone 6 Pro.

So this year ASUS has decided to cut things down. With the ROG Phone 5, it launched three different models. The 5, 5 Pro, and 5 Ultimate. Then it also ended up launching the 5s and 5s Pro. This year, ASUS has essentially packed everything that would have been in an Ultimate into the 6 Pro, and everything that would have been in a Pro and 5s models into the second configuration of the 6.

In our opinion, this makes everything way easier. And it’s less convoluted for the consumer. Having too many models to choose from just leads to indecision which can lead to no sale. ASUS appears to be trying to make things simpler here.

What are the full specs for the device?

The specs for the most part are the same across all four configurations that ASUS is offering. With the only changes being the amount of RAM, and how much storage you have. The ROG Phone 6 also doesn’t come with an LCD display on the back like the Pro model. And instead uses a customizable RGB pattern like on last year’s ROG Phone 5s. The rest of the specs however are the same. So here’s the breakdown of what you get.

  • Colorways – Phantom Black and Storm White for the ROG Phone 6, and Storm White for the ROG Phone 6 Pro
  • Processor – Snapdragon 8+ Gen 1 Mobile Platform with Adreno 730
  • Memory – 8GB/12GB/16GB for the ROG phone 6, and 18GB for the ROG Phone 6 Pro
  • Storage – 256GB and 512GB for the ROG Phone 6, and 512GB for the ROG Phone 6 Pro
  • Display – 6.78-inch Samsung AMOLED with 2448 x 1080 resolution and Corning Gorilla Glass Victus
  • Refresh rate – 165Hz
  • Rear camera – Main Sensor: Sony IMX766 50MP image sensor – plus 13MP ultrawide sensor and 5MP macro sensor
  • Front camera – 12MP sensor
  • Video – 8K UHD at 24fps, 4K UHD at 30fps and 60fps, 1080p FHD at 30fps and 60fps, 720p HD at 30fps and 60fps
  • Speakers – Dual front-facing stereo speakers with Dirac HD sound
  • SIM – Dual SIM card slots
  • Battery – 6,00mAh high-capacity battery with Quick Charge 5.0 support
  • Sensors – In-display fingerprint sensor, accelerometer, face recognition, e-compass, gyroscope, proximity sensor, ambient-light sensor, ultrasonic sensors for AirTrigger 6 and grip press
  • Power adapter – 65W USB-C power adapter
  • Water resistance – IPX4
  • Weight – 239g
  • Dimensions – 173 x 77 x 10.3 mm

Does the phone have expandable storage?

No. The ROG Phone 6 series does not come with expandable storage. Like many of today’s devices, you get what comes in the phone and that’s it. Luckily, with the ROG Phone 6 and ROG Phone 6 Pro, your options are 256GB or 512GB. Which is quite a lot and most people who would buy this device would probably struggle to use it all up.

That doesn’t mean it’ll be enough for everyone. But for a phone, it’s exceptionally easy to get by with ether of these amounts. Thanks to the advancement of cloud gaming and cloud storage. Which ultimately means you use up less room for storing games, apps, music, movies, photos, videos, documents and more.

Do the ROG Phone 6/6 Pro have any accessories?

ASUS ROG Phone 6 Pro Review 6

The ROG Phone 6 series has a few official accessories, and a relaunch of one accessory from last year. There’s the all-new AeroActive Cooler 6 which comes in the box, as well as a shell case in the box. There’s also an optional shell case, an optional protective case from Devil Case, and an optional tempered glass screen protector.

ASUS also re-released the ROG Kunai 3 gamepad in Storm White to match the new White color of both the ROG Phone 6 and ROG Phone 6 Pro. Lastly, ASUS is launching a new set of true wireless earbuds for the phone that can be transformed into a wired pair, and a phone clip for third-party controllers.

Is The ROG Phone 6 running on Android 12?

Yes. ASUS ships the ROG Phone 6 and ROG Phone 6 Pro with Android 12 out of the box. So there’s no need to update the software to be on the newest version of Android. Which makes sense given that the ROG Phone 5 received the Android 12 update officially well before the 6 and 6 Pro were announced.

Update: February 21, 2023

As of February 21, 2023 ASUS has begun pushing out the update for Android 13 to the ROG Phone 6 and ROG Phone 6 Pro. This means most or all ROG Phone 6 and ROG Phone 6 Pro owners should have Android 13 running on their devices by the end of the week.

Does the phone have good battery life?

ASUS ROG Phone 6 Pro Review 7

The phone has excellent battery life. After all, this isn’t too difficult to achieve when there’s a 6,000mAh high-capacity battery powering your experiences.

In short you can easily get by on two days of use with a single charge. Maybe more. That will naturally change based on how you use the phone. For example, if you sit down for a few hours of gaming with a graphically demanding game like Genshin Impact or Diablo Immortal, then your battery can certainly lose about 50% of its power in that time. Even then that doesn’t matter too much since the phone charges up very rapidly in a short amount of time.

There are some ways you can mitigate the battery drain though. For starters, utilize the phone’s different performance profiles in the Armoury Crate app. There’s X Mode, Dynamic Mode, and Ultra Durable. If you’re looking to conserve battery while still gaming, then set it to dynamic once you’re in your game of choice. You can do this by opening the Game Genie dashboard once the game is loaded up.

Secondly, make sure you tune the game’s graphics down. This will help the game use less power to function optimally. And should result in overall less power draw from the battery. You can also turn off anything that isn’t really necessary to the gaming experience. Like the LCD display and RGB lighting on the back of the phone. And finally, either stick with the speakers for audio or use wired headphones, and turn down the screen brightness as much as you’re willing to tolerate.

Does the ROG Phone 6 have a 3.5mm headphone jack?

Yes. ASUS is still implementing the use of a 3.5mm headphone jack on its latest gaming phones. So if you prefer the wired experience, you can plug in your favorite headset. Or you can try and snag ASUS’s snazzy new true wireless earbuds that come with a wired attachment. This way you can use them wireless for somethings and wired for others.

Does the phone still have AirTriggers?

Absolutely. These are a staple of the ROG Phone series and ASUS likely plans on never getting rid of them. And rightfully so. They’re an easy way to implement extra controls for gamers without having to actually add on physical controls. That being said, there are some differences this year.

The new AirTriggers actually do more than the ones on last year’s ROG Phone 5 series devices. With the AirTriggers 6 offering up to 9 different gestures. However, there are no longer any back ultrasonic triggers on the back like there were on the ROG Phone 5 Ultimate. Instead ASUS seems to have incorporated the functions of those into the AirTriggers on the top.

How is the camera quality?

ASUS ROG Phone 6 Pro Review 3

Chances are if you’re buying a gaming phone, you’re buying it mostly for the gaming prowess. You may be less concerned with how it performs in the picture taking department. But, that doesn’t mean you won’t use the camera at all, right? This is after all likely to be your main phone. Unless you’re a user who has more than one device, and use this strictly for gaming, this will be your only device and thus the only phone camera you have at your disposal.

So you probably want the camera to perform at least decently. We can say that the camera performs admirably. It won’t be the best phone camera on the market, but it will provide you with pretty good pictures in this day and age.

Especially if you’re coming from a phone that’s at least two or three years older. As long as you’re aware that the camera on the ROG Phone 6 and ROG Phone 6 Pro won’t outdo the likes of the Pixel 6 Pro, iPhone 13 Pro Max, and Samsung Galaxy S22 Ultra, then you should be pretty happy with it. Then again, some of this might be subjective and you may find that the camera in your own opinion, is just as good.

Does the ROG Phone 6 stay cool when gaming?

The short answer is yes and no. The phone does stay cool (to a point) during gaming sessions. But it can still get warm to the touch the longer you play and if the game is more graphically demanding. In those cases, ASUS recommends using the AeroActive Cooler 6 that comes with the phone.

Specifically it recommends using this attachment if you plan to play longer than one hour. Temperatures are also lower compared to last year’s ROG Phone 5 series. So all-in-all, the phone can stay cool while you game and ASUS has managed to lower the temps from its previous model. That’s a win in our book. However, just know you need to temper your expectations.

The phone will not be completely cool to the point that you won’t notice the heat being put out by the CPU and GPU. And again it all depends on the game you’re playing. For example, playing a game like Alto’s Odyssey for two or three hours straight isn’t going to increase the phone temperatures too much. So keep that in mind.


[ad_2]
Source link

This might be the first ever AI-generated phishing scam

0
[ad_1]

AI does a lot of stuff nowadays, and every day, it seems that there’s a new thing that it can do. Well, did you anticipate that it’d be able to scam you? That’s right! A new LinkedIn phishing scam might be the first-ever AI-generated phishing scam.

Obviously, there isn’t some rogue AI out there trying to scam users into giving up their information. The brain behind the scam is very much flesh and blood. Rather, it looks like the materials that make up the scam have been generated using AI.

This could be the first-ever AI-generated phishing scam

According to TechRadar, researchers at SafeGuard Security uncovered this phishing scam recently. It was an ad on the platform that shills a whitepaper for businesses to help them close more deals. The only thing is that the image used to promote it shows the telltale sign of an AI-generated image.

On the bottom right of DALL-E images, there is a succession of colored squares. They’re seen on the bottom of every image generated by the platform. Below, there’s an example.

Dall e image squares

Along with that, there are other red flags that set off the alarms. For starters, the LinkedIn profile was another major tell. The profile was pretty barebones. That should be the first clue that things aren’t on the up and up. Also, it has probably the most generic name for an account, Sales Intelligence.

The profile is empty, and the website link led to a jewelry store on Amazon. That’s an odd website for a profile offering a whitepaper.

When you follow the link in the ad, you’d then put in your personal information (again, another red flag) in exchange for access to the whitepaper. Suffice it to say, there is no whitepaper. Instead, the information that the user gave up will be used for the phishing scam.

If you see an ad for a whitepaper, see an ad with an AI-generated image, or see an account that’s empty, you’ll want to pass it up.


[ad_2]
Source link