Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
I opened RDP on my firewall and this is what happened
https://cdn-images-1.medium.com/max/600/1*rd1MARPRk5Z8xAzlEYaaGw.jpeg
Working on ransomware attacks I continually see RDP being used as external access and being the attack vector in ransomware attacks. I…
Continue reading on Medium »
I opened RDP on my firewall and this is what happened
https://cdn-images-1.medium.com/max/600/1*rd1MARPRk5Z8xAzlEYaaGw.jpeg
Working on ransomware attacks I continually see RDP being used as external access and being the attack vector in ransomware attacks. I…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Dark Side of Crypto
https://cdn-images-1.medium.com/max/1280/1*4sBwdiog243bpj5Em4W0EQ.jpeg
All the Negatives of Cryptocurrency and the Ways it is Misused
Continue reading on Medium »
The Dark Side of Crypto
https://cdn-images-1.medium.com/max/1280/1*4sBwdiog243bpj5Em4W0EQ.jpeg
All the Negatives of Cryptocurrency and the Ways it is Misused
Continue reading on Medium »
XStream Vulnerabilities — Detection & Mitigation
https://blog.shiftleft.io/xstream-vulnerabilities-detection-mitigation-e468c152ca23?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://blog.shiftleft.io/xstream-vulnerabilities-detection-mitigation-e468c152ca23?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
XStream Vulnerabilities — Detection & Mitigation
Looking at RCEs in the XStream Java Library and How you can prevent them
Looking at RCEs in the XStream Java Library and How you can prevent themContinue reading on ShiftLeft Blog » (https://blog.shiftleft.io/xstream-vulnerabilities-detection-mitigation-e468c152ca23?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XStream Vulnerabilities — Detection & Mitigation
Looking at RCEs in the XStream Java Library and How you can prevent them
hacking: security in practice
How is my VM using john kicking my hosts ass that's using hashcat
I am doing a ctf which has you crack a sha256 hash using john the ripper but I am trying to learn hashcat more so have been making myself use that on my host machine. Today after my hashcat was running for ~1hr i figured I'd try JTR on my vm for shits and giggles. Well it cracked the hash instantly. Any explanations on why if I am using the same wordlist this would happen (full rockyou.txt as requested by the ctf)? I would think my vm regulated to 4 cores would be slower then the host with 8 cores, integrated graphics, and a 3060 running in parallel. My guess is operator error with hashcat?
hashcat cmd:`hashcat -m 1400 -a 3 -o OUTPUT HASH WORDLIST`
john cmd:`john HASH --wordlist=WORDLIST --format=RAW-SHA256`
submitted by /u/rltw_275
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How is my VM using john kicking my hosts ass that's using hashcat
I am doing a ctf which has you crack a sha256 hash using john the ripper but I am trying to learn hashcat more so have been making myself use that on my host machine. Today after my hashcat was running for ~1hr i figured I'd try JTR on my vm for shits and giggles. Well it cracked the hash instantly. Any explanations on why if I am using the same wordlist this would happen (full rockyou.txt as requested by the ctf)? I would think my vm regulated to 4 cores would be slower then the host with 8 cores, integrated graphics, and a 3060 running in parallel. My guess is operator error with hashcat?
hashcat cmd:`hashcat -m 1400 -a 3 -o OUTPUT HASH WORDLIST`
john cmd:`john HASH --wordlist=WORDLIST --format=RAW-SHA256`
submitted by /u/rltw_275
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How is my VM using john kicking my hosts ass that's using hashcat
I am doing a ctf which has you crack a sha256 hash using john the ripper but I am trying to learn hashcat more so have been making myself use that...
XLS Entanglement
https://www.reddit.com/r/redteamsec/comments/ok91wk/xls_entanglement/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.bc-security.org/post/xls-entanglement/) [comments] (https://www.reddit.com/r/redteamsec/comments/ok91wk/xls_entanglement/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ok91wk/xls_entanglement/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.bc-security.org/post/xls-entanglement/) [comments] (https://www.reddit.com/r/redteamsec/comments/ok91wk/xls_entanglement/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: XLS Entanglement
Posted by u/dmchell - 14 votes and no comments
[Help] Technical questions about penetration testing
https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/
<!-- SC_OFF -->Hi all, I am trying to make a Q&A about pentest for my forum. I would like to collect more technical questions about this topic. If you have any technical questions, can you comment bellow? I'd be so thankful :D <!-- SC_ON --> submitted by /u/myx_linh (https://www.reddit.com/user/myx_linh)
[link] (https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/)
https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/
<!-- SC_OFF -->Hi all, I am trying to make a Q&A about pentest for my forum. I would like to collect more technical questions about this topic. If you have any technical questions, can you comment bellow? I'd be so thankful :D <!-- SC_ON --> submitted by /u/myx_linh (https://www.reddit.com/user/myx_linh)
[link] (https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/ok9qzq/help_technical_questions_about_penetration_testing/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Invoice System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
Invoice System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Invoice System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
Invoice System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
ae515ca8430ebaf0b5e6780c40a79454Download
# Exploit Title: Invoice System 1.0 - 'Multiple' Stored Cross-Site Scripting (XSS)
# Date: 12 July 2021
# Exploit Author: Subhadip Nag (mrl0s3r)
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/14858/invoice-system-using-phpoop-free-source-code.html
# Tested on: Server: XAMPP
# Description #
Invoice System 1.0 is vulnerable to 'Multiple 'stored cross site scripting (xss) in the Settings option because of insufficient user supplied data.
When anyone visits any other option like(Dashboard,Invoice,Category,Service,Product and also Settings option, our payload will respond as well, and when anyone again Login as Admin the payload works the same as well.
# Proof of Concept (PoC) : Exploit #
1) Goto: http://localhost/simple_invoice/admin/login.php
2) Login: Login as a Admin for given credentials: admin | admin123
3) Goto: Settings option
4) In the System Name & Short Name, Enter the payload:
5) Click Update
6) our XSS attack fired and Stored
7) Wherever we are clicked in any options, noticed that our Payload responding us
8) Goto: http://localhost/simple_invoice/admin/?page=service
9) Click Create New
10) In the Name and Description field, enter the payload:
11) Our XSS attack Successful
12) Goto: http://localhost/simple_invoice/admin/?page=invoice
13) Click Create New
14) In the Customer Name, Unit, Remarks, enter the payload:
15) Our XSS attack Successful
# PoC image
1) https://ibb.co/JpYdZ4F
2) https://ibb.co/brm00dF
3) https://ibb.co/3crYLSZ
4) https://ibb.co/N9m6fy0
5) https://ibb.co/HGNSJDN
6) https://ibb.co/7tyFY1P
7) https://ibb.co/gZ0BvjB
8) https://ibb.co/2S9J6Xn
Source:packetstormsecurity.com