Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Current Book 1.0.1 Cross Site Scripting

https://1.bp.blogspot.com/-f08tQl4ET7w/WWlvRxSI6FI/AAAAAAAAINU/PQjq5zhIC6AFgb3OPDnJIpwa9KgUsaunwCLcBGAs/s1600/h37.png
WordPress Current Book plugin version 1.0.1 suffers from a persistent cross site scripting vulnerability.

MD5 | 9e6e35a0f251dadb33e65deae120dd38

Download
# Exploit Title: WordPress Plugin Current Book 1.0.1 - 'Book Title and Author field' Stored Cross-Site Scripting (XSS)
# Date: 14/07/2021
# Exploit Author: Vikas Srivastava
# Vendor Homepage:
# Software Link: https://wordpress.org/plugins/current-book/
# Version: 1.0.1
# Category: Web Application

How to Reproduce this Vulnerability:

1. Install WordPress 5.7.2
2. Install and activate Custom Book
3. Navigate to Tools >> Current Book and enter the XSS payload into the Book and Author input field.
4. Click Update Options
5. You will observe that the payload successfully got stored into the database and when you are triggering the same functionality at that time JavaScript payload is executing successfully and we are getting a pop-up.


Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Ipa-Medit : Memory Search And Patch Tool For Resigned Ipa Without Jailbreak

Ipa-medit is a memory search and patch tool for resigned ipa without jailbreak. It was created for mobile game security testing. Motivation Memory modification is the easiest way to cheat in games, it is one of the items to be checked in the security test. There are also cheat tools that can be used casually […]

The post Ipa-Medit : Memory Search And Patch Tool For Resigned Ipa Without Jailbreak appeared first on Kali Linux Tutorials.
Over the past few weeks, I have spun up and torn down my fair share of AWS Lambdas using Terraform — these are some bugs I found.Continue reading on Medium » (https://onelharrison.medium.com/bug-hunt-1-orphaned-amazon-s3-event-notifications-for-aws-lambda-functions-28cd5a2c8a73?source=rss------bug_bounty-5)
The BEST HACKING Certification for Beginners - eJPT / PTS
https://www.reddit.com/r/Pentesting/comments/okbabl/the_best_hacking_certification_for_beginners_ejpt/

<!-- SC_OFF -->Hey everyone! I just posted a video talking about my experience with the eJPT exam and it's official learning path (PTS). Here's the link for the vídeo if you want to check it out 😊 🎥 https://www.youtube.com/watch?v=Dz1uA8gyDd4 🎥 Thank you so much! ❤️ #cybersecurity #hacking #pentesting #infosec <!-- SC_ON --> submitted by /u/exploitc0sm0s (https://www.reddit.com/user/exploitc0sm0s)
[link] (https://www.reddit.com/r/Pentesting/comments/okbabl/the_best_hacking_certification_for_beginners_ejpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/okbabl/the_best_hacking_certification_for_beginners_ejpt/)
Wpscvn - Wpscvn Is A Tool For Pentesters, Website Owner To Test If Their Websites Had Some Vulnerable Plugins Or Themes

wpscvn is a tool for pentesters, website owner to test if their websites had some vulnerable plugins or themesThe author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent is illegal and punished by law. requires : Python 3 usage : python3 script.py http://site\n Download Wpscvn
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Urls shared by harmful twitch bots

Sometimes a huge horde of bot accounts start spamming some shady and weird looking url on big twitch streamers' chat (hasanabi's in that case) very rapidly. As far as i know you can't get hacked from clicking an url right ? Well i still don't want to risk it. What's the purpose of those bots and what could those links be ?

thats the message they share: https://imgur.com/a/063lMz3

submitted by /u/Korayzzz
[link] [comments]
Wpscvn - Wpscvn Is A Tool For Pentesters, Website Owner To Test If Their Websites Had Some Vulnerable Plugins Or Themes
http://www.kitploit.com/2021/07/wpscvn-wpscvn-is-tool-for-pentesters.html
wpscvn is a tool for pentesters, website (https://www.kitploit.com/search/label/Website) owner to test if their websites had some vulnerable (https://www.kitploit.com/search/label/Vulnerable) plugins or themes

The author does not hold any responsibility for the bad use of this tool, remember that attacking targets without prior consent is illegal and punished by law. requires : Python 3 usage : python3 script.py http://site\n (http://site%5Cn/)

Download Wpscvn (https://github.com/sabersebri/wpscvn)