Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Comprehensive Guide on HTML Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

Today, in this article, we’ll learn how such misconfigured HTML codes, open the gates for the attackers to manipulate the designed webpages and grabs up the sensitive data from the users.

🌐 What is HTML?
πŸ“˜ Introduction to HTML Injection
πŸ’₯ Impact of HTML Injection
βš”οΈ HTML Injection vs XSS
🧬 Types of Injection
πŸ’Ύ Stored HTML
πŸ” Reflected HTML
πŸ“₯ Reflected GET
πŸ“€ Reflected POST
πŸ”— Reflected Current URL
A Detailed Guide on OS Command Injection

πŸ”₯ Telegram: https://t.me/hackinarticles

In this article, we’ll learn about OS Command Injection, in which an attacker is able to trigger some arbitrary system shell commands on the hosted operating system via a vulnerable web-application.

πŸ“˜ Introduction to Command Injection
❓ How Command Injection Occurs?
πŸ”£ Metacharacters
πŸ“‚ Types of Command Injection
πŸ’₯ Impact of OS Command Injection
🧭 Steps to Exploit – OS Command Injection
πŸ› οΈ Manual Exploitation
πŸ“Ÿ Basic OS Command Injection
🚫 Bypass a Blacklist Implemented
πŸ€– Exploitation through Automated Tools
πŸ§ͺ Burp Suite
✍️ Manual
πŸŒͺ️ Fuzzing
🧬 Commix
🎯 Metasploit
πŸ‘οΈ Blind OS Command Injection
πŸ” Detection
πŸ’£ Exploitation
Wireless Penetration Testing: PMKID Attack

πŸ”₯ Telegram: https://t.me/hackinarticles

This attack targets WPA and WPA2 protocols effectively. However, recent studies show that WPA3 offers far greater resistance and shows little to no success against PMKID attacks.

πŸ”“ Open System Authentication
πŸ” Shared Key Authentication
πŸ“Ά WPA and WPA2 PSK
🀝 4-Way Handshake
🧠 PMK Caching and PMKID (in the RSN IE frame)
πŸ“– Explanation of Attack
🎯 Capturing PMKID using hcxdumptool
βš™οΈ Converting pcapng to hashcat file and Cracking Using Hashcat
🎯 Capturing Only a Single PMKID using hcxdumptool
πŸ”„ Converting pcapng to pcap and Cracking Using Aircrack-ng
πŸ› οΈ PMKID Capture and Attack Using Airgeddon
🌐 PMKID Capture Using Bettercap