Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Zen Cart 1.5.7 Cross Site Scripting

https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
Zen Cart version 1.5.7 suffers from a cross site scripting vulnerability.

MD5 | df30607df6a72933aa69d11199808bb8

Download
Information
--------------------
Advisory by Netsparker
Name: Cross-Site Scripting Vulnerability in Zen Cart 1.5.7
Affected Software: Zen Cart
Affected Versions: 1.5.7
Homepage: https://www.zen-cart.com/
Vulnerability: Cross-Site Scripting
Severity: High
Status: Fixed
CVSS Score (3.0): AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Netsparker Advisory Reference: NS-21-002

Technical Details
--------------------

Zen Cart 1.5.7 was improperly sanitizing user input in HTTP GET parameter
names, which led to a Cross-Site Scripting (XSS) vulnerability in the admin
area. The impact of this vulnerability is lessened due to the fact that the
name of the admin panel must be set to a random or user-supplied name.

Resolution: The vulnerability is fixed in Zen Cart v1.5.7c.
Scope: It affected only users of Zen Cart v1.5.7, v1.5.7a, and v1.5.7b.
Fix: Users can consult the release announcement for guidance on applying
the patched files related to upgrading to v1.5.7c

For more information on cross-site scripting vulnerabilities read the
article Cross-site Scripting (XSS).

For more information:
https://www.netsparker.com/web-applications-advisories/ns-21-002-cross-site-scripting-in-zen-cart/

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Pen Test Report Writing Tool
https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/

I'm working on a side project of trying to build a web-based tool for managing and helping me generate pen-testing reports. The idea is to define some attributes, such as the company you're doing the work for, dates, etc., and then drag-and-drop blocks of the report into place. For example, an executive summary, scope, various issues found. All would come in customized already with the various known attributes, and then you can tweak/modify each section as needed. You can then also save your blocks to re-use later. This might be particularly handy for various vulnerabilities since we tend to find the same things over and over again. I'd be curious to hear from as many people as possible regarding what features they would want in a web-based report writer, and I'm also looking for sample reports. Anything redacted or open-source would be fine, but please nothing confidential. I've started this Workflowy list to try and capture the requirements: https://workflowy.com/s/penetration-report-w/h1fcj6ru5b3ca4r7 Any help is appreciated. Happy to share the final result with you, if it ever comes into being. If I build it, I will likely charge a monthly or annual fee for it, but anyone who helps will get a large discount and/or some extended trial period (3 months +?). submitted by /u/ltmodcs (https://www.reddit.com/user/ltmodcs)
[link] (https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/) [comments] (https://www.reddit.com/r/Pentesting/comments/nln3ee/pen_test_report_writing_tool/)

___________________________
@hacking_Attack
@Hacking_Video
Cmd injection
https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/

<!-- SC_OFF -->Really struggling to do a command injection on a server that I am told, is vulnerable for cmd injection on an application port. The application does not have UI so no URL to use tools like burp, commix etc. I know it’s too generic but is there a way command injections can be done checking with Linux level commands from external server like trying to write files in target server etc ? Any help would be appreciated. TIA. <!-- SC_ON --> submitted by /u/Pamelaxyz (https://www.reddit.com/user/Pamelaxyz)
[link] (https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/) [comments] (https://www.reddit.com/r/Pentesting/comments/nlquki/cmd_injection/)
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol

Multi-platform toolkit for an interactive C2C DNS shell, by using DNS-Black-Cat, you will be able to execute system commands in shell mode over a fully encrypted covert channel.Server ported as a python script, which acts as DNS server with required functionalities to provide interactive shell command interface. Client ported as the following file formats Windows 32/64 executable (exe) Linux 32/64 executable (ELF) Powershell Script (ps1) Dynamic Link Library (DLL) MacOS Darwin x86_64 Highlights The agent supports multi-platforms. built-in feature with 0xsp-mongoose RED. Available as win32/64 executable, Powershell script, Linux ELF. Encrypted and encoded DNS Queries. Traffic Segmentation. Speed and stability. Stealth and undetectable. Releases System Supported Windows (EXE) YES Windows (PS) YES Windows (DLL) YES Linux YES MacOS YES BSD Still Android Still Support Support the project for continuous development (ETH 0xf340c15c5e669a4ababab856e9f2bccd659d6e42) Wiki ? https://0xsp.com/security%20research%20&%20development%20(SRD)/covert-dns-cc-for-red-teaming-ops Download Dns-Black-Cat
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol

https://1.bp.blogspot.com/-LJ3lpMgEgkk/YKryYpKcThI/AAAAAAAAWRA/uVqHfzIDYfcZWqyp2dbUpRpUs_t6A8_twCNcBGAsYHQ/w640-h508/dns-black-cat_1_DNS-Cat.png
Multi-platform toolkit for an interactive C2C DNS shell, by using DNS-Black-Cat, you will be able to execute system commands in shell mode over a fully encrypted covert channel.
Server

ported as a python script, which acts as DNS server with required functionalities to provide interactive shell command interface.

Client

ported as the following file formats

* Windows 32/64 executable (exe)
* Linux 32/64 executable (ELF)
* Powershell Script (ps1)
* Dynamic Link Library (DLL)
* MacOS Darwin x86_64

Highlights

* The agent supports multi-platforms.
* built-in feature with 0xsp-mongoose RED.
* Available as win32/64 executable, Powershell script, Linux ELF.
* Encrypted and encoded DNS Queries.
* Traffic Segmentation.
* Speed and stability.
* Stealth and undetectable.

Releases
System Supported Windows (EXE) YES Windows (PS) YES Windows (DLL) YES Linux YES MacOS YES BSD Still Android Still
Support

Support the project for continuous development (ETH 0xf340c15c5e669a4ababab856e9f2bccd659d6e42)

Wiki ?

https://0xsp.com/security%20research%20&%20development%20(SRD)/covert-dns-cc-for-red-teaming-ops
Download Dns-Black-Cat

___________________________
@hacking_Attack
@Hacking_Video
DNS-Black-Cat(DBC) - Multi Platform Toolkit For An Interactive DNS Shell Commands Exfiltration, By Using DNS-Cat You Will Be Able To Execute System Commands In Shell Mode Over DNS Protocol
http://www.kitploit.com/2021/05/dns-black-catdbc-multi-platform-toolkit.html

___________________________
@hacking_Attack
@Hacking_Video