CVE-2021–36543
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.UnlockDocument.php #…Continue reading on Medium »
Read more...
# Exploit Title: SeedDMS v5.1.x<5.1.23 and v6.0.x<6.0.16 is affected by cross-site request forgery (CSRF) in /op/op.UnlockDocument.php #…Continue reading on Medium »
Read more...
hacking: security in practice
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
submitted by /u/ZoneZeus123
[link] [comments]
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
submitted by /u/ZoneZeus123
[link] [comments]
reddit
I am doxing Awkward Turtle
I am fucking mad at him I will post his location here when I find it
hacking: security in practice
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned. Now i dont know how logging onto the wifi works, but im guessing its not like a normal wifi logon and each person's traffic can be individually monitored.
So here is what I was thinking: I have two laptops that run windows 10. One however, is a burner laptop. the other, i do work on and it a powerful laptop. I was thinking that i can connect to the wifi on the burner laptop, and then setup a hotspot on that burner laptop, and then connect to that on my work laptop and use a vpn on the work laptop. Would they be able to see the vpn even through the hotspot?
I do not know too much about networking but it seems like it would be really difficult to catch without a wifi sniffer, am I right?
submitted by /u/man_wif-waluigi-hed
[link] [comments]
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned. Now i dont know how logging onto the wifi works, but im guessing its not like a normal wifi logon and each person's traffic can be individually monitored.
So here is what I was thinking: I have two laptops that run windows 10. One however, is a burner laptop. the other, i do work on and it a powerful laptop. I was thinking that i can connect to the wifi on the burner laptop, and then setup a hotspot on that burner laptop, and then connect to that on my work laptop and use a vpn on the work laptop. Would they be able to see the vpn even through the hotspot?
I do not know too much about networking but it seems like it would be really difficult to catch without a wifi sniffer, am I right?
submitted by /u/man_wif-waluigi-hed
[link] [comments]
reddit
Could this be a workable exploit?
So im not gonna lie, im a mischievous kid. So in a year im going to be going to college, and im guessing that vpns and their usage will be banned....
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet)
A 16k stars project, used in, I can imagine game engines, UI, Android/iOS/embedded. Used in another 30k stars project and 11k from even Google (also possibly not fixed). OpenCV 55k stars seems to be also affected (new branch only). Attack vector through malicious font. Buy me a beer if you will get bounty on it and also initial fuzzing person https://github.com/nothings/stb/issues/618
Per Developer library was not intended to work with untrusted data.
Be careful when using it, consider a replacement. This is a PSA.
Thanks,
P.S Full thread here: https://twitter.com/marcinguy/status/1421740689516339200?s=19
submitted by /u/marcinguy
[link] [comments]
Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet)
A 16k stars project, used in, I can imagine game engines, UI, Android/iOS/embedded. Used in another 30k stars project and 11k from even Google (also possibly not fixed). OpenCV 55k stars seems to be also affected (new branch only). Attack vector through malicious font. Buy me a beer if you will get bounty on it and also initial fuzzing person https://github.com/nothings/stb/issues/618
Per Developer library was not intended to work with untrusted data.
Be careful when using it, consider a replacement. This is a PSA.
Thanks,
P.S Full thread here: https://twitter.com/marcinguy/status/1421740689516339200?s=19
submitted by /u/marcinguy
[link] [comments]
hacking: security in practice
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should I enter in the socket.connect (which IP )? Thanks
submitted by /u/Mx_Mlr
[link] [comments]
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should I enter in the socket.connect (which IP )? Thanks
submitted by /u/Mx_Mlr
[link] [comments]
reddit
Make a RAT Trojan (in python) ?
Hello, I made a RAT Trojan in python and it works well but of course when I test it on multi network it’s not working. How it works ? What should...
hacking: security in practice
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice
submitted by /u/starknight23Yt
[link] [comments]
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice
submitted by /u/starknight23Yt
[link] [comments]
reddit
Is it legal to IP track a hacker after getting hacked
I'm only asking because I lost my Steam account to a hacker and was wondering if I could IP tracking and bring them to Justice
hacking: security in practice
hackerbot.net
is it legit or is it fake
submitted by /u/ELMate1234
[link] [comments]
hackerbot.net
is it legit or is it fake
submitted by /u/ELMate1234
[link] [comments]
reddit
hackerbot.net
is it legit or is it fake
ASC War Games Filtration Phase 2021
https://abd11atarek.medium.com/asc-war-games-filtration-phase-2021-7286d70bc2ab?source=rss------bug_bounty-5
https://abd11atarek.medium.com/asc-war-games-filtration-phase-2021-7286d70bc2ab?source=rss------bug_bounty-5
Hi, I’m abda11atarek, our team got 2nd place in the qualification phase (FireFall) and here is my write-up for web challenges. See you at…Continue reading on Medium » (https://abd11atarek.medium.com/asc-war-games-filtration-phase-2021-7286d70bc2ab?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
PowerShellArmoury - A PowerShell Armoury For Security Guys And Girls
http://2.bp.blogspot.com/-HCBmPFBkMDU/YP8bS1r9z9I/AAAAAAAAoZQ/NDFQo5mSEXQ2ExgCjfl_januYaXVu-VugCK4BGAYYCw/w285-h400/PowerShellArmoury_1-793052.png The PowerShell Armoury is meant for pentesters, "insert-color-here"-teamers and everyone else who uses a variety of PowerShell tools during their engagements. It allows you to download and store all of your favourite PowerShell scripts in a single, encrypted file.
You do not have to hassle with updating Rubeus, PowerView, ... manually. Just create a configuration file once or use the default one included with the tool. From now on, you just have to run "New-PSArmoury" before you head to the next engagement. In addition, your new and shiny armoury is encrypted and includes a bypass for AMSI, so you dont have to worry about AV.
Note: you have to provide a valid github account as well as a personal access token, so the script can properly use the github API. Do not use username/password since this will not work anyway if you have MFA enabled (and you should enable MFA). Also accessing the API with basic username/password is deprecated. Follow this guide to create a personal access token. Config referenceThe config file needs to be a valid json that consists of a single array with one or more objects, where every object is interpreted as a single script source. Every object has the following attributes
Name (Mandatory)
A name of your choice to identify the script included in this object. This is just meant as a reference for yourself.
URL (Mandatory)
The location to get the script content from. This can be a URL to a web resource (https://) or a local path (C:) or a network resource (\...). The URL is thrown into Net.Webclient or Powershells Get-Item respectively. So basically every format that one of those two can handle by default should work.
Type (Mandatory)
This gives a hint about the script location to the armoury creator. There are three valid types:
* GitHub
* Will prompt for credentials so we can authenticate against the github API. Will also try to distinguish between a "raw" URL that directly poins to a file or a URL that points to a repository. If the URL points to a repository, the script will automatically search all Powershell files in that repository and include them. Like "https://github.com/cfalta/PoshRandom"
* WebDownloadSimple
* Means a file that can be downloaded without authentication or stuff using an HTTP GET. Like "http://mywebserver.com/file.ps1"
* LocalFile
* A file on disk like "C:\temp\test.ps1". If the path points to a directory, all files (recursive) with the extension ".ps1" will be included.
FileInclusionFilter (Optional)
Will only be interpreted in an object of type "GitHub". Will be matched with Powershells "like" comparison operator against the whole filename so keep in mind that you need to include the wildcards yourself. Don't forget to include a star (*) if you want to match part of a filename. "*.ps1" means all files that end with ".ps1" but ".ps1" just means ".ps1".
You don't have to include a filter but if you do, you have to use it. An empty InclusionFilter means no files.
FileExclusionFilter (Optional)
Like the InclusionFilter but obviously the other way round. Exclusion takes precedence. ArgumentsSee inline Powershell help (man -full New-PSArmoury) for more details.
-Path
The path to your new armoury file. The default ist ".\MyArmoury.ps1"
-FromFile
Load your Powershell scripts directly from a local folder or file and you don't have to provide a config file.
-Config
The path to your JSON-config file. Have a look at the sample that comes with this script for ideas.
-Password
The password that will be used to encrypt your armoury. If you do not provide a[...]
PowerShellArmoury - A PowerShell Armoury For Security Guys And Girls
http://2.bp.blogspot.com/-HCBmPFBkMDU/YP8bS1r9z9I/AAAAAAAAoZQ/NDFQo5mSEXQ2ExgCjfl_januYaXVu-VugCK4BGAYYCw/w285-h400/PowerShellArmoury_1-793052.png The PowerShell Armoury is meant for pentesters, "insert-color-here"-teamers and everyone else who uses a variety of PowerShell tools during their engagements. It allows you to download and store all of your favourite PowerShell scripts in a single, encrypted file.
You do not have to hassle with updating Rubeus, PowerView, ... manually. Just create a configuration file once or use the default one included with the tool. From now on, you just have to run "New-PSArmoury" before you head to the next engagement. In addition, your new and shiny armoury is encrypted and includes a bypass for AMSI, so you dont have to worry about AV.
Note: you have to provide a valid github account as well as a personal access token, so the script can properly use the github API. Do not use username/password since this will not work anyway if you have MFA enabled (and you should enable MFA). Also accessing the API with basic username/password is deprecated. Follow this guide to create a personal access token. Config referenceThe config file needs to be a valid json that consists of a single array with one or more objects, where every object is interpreted as a single script source. Every object has the following attributes
Name (Mandatory)
A name of your choice to identify the script included in this object. This is just meant as a reference for yourself.
URL (Mandatory)
The location to get the script content from. This can be a URL to a web resource (https://) or a local path (C:) or a network resource (\...). The URL is thrown into Net.Webclient or Powershells Get-Item respectively. So basically every format that one of those two can handle by default should work.
Type (Mandatory)
This gives a hint about the script location to the armoury creator. There are three valid types:
* GitHub
* Will prompt for credentials so we can authenticate against the github API. Will also try to distinguish between a "raw" URL that directly poins to a file or a URL that points to a repository. If the URL points to a repository, the script will automatically search all Powershell files in that repository and include them. Like "https://github.com/cfalta/PoshRandom"
* WebDownloadSimple
* Means a file that can be downloaded without authentication or stuff using an HTTP GET. Like "http://mywebserver.com/file.ps1"
* LocalFile
* A file on disk like "C:\temp\test.ps1". If the path points to a directory, all files (recursive) with the extension ".ps1" will be included.
FileInclusionFilter (Optional)
Will only be interpreted in an object of type "GitHub". Will be matched with Powershells "like" comparison operator against the whole filename so keep in mind that you need to include the wildcards yourself. Don't forget to include a star (*) if you want to match part of a filename. "*.ps1" means all files that end with ".ps1" but ".ps1" just means ".ps1".
You don't have to include a filter but if you do, you have to use it. An empty InclusionFilter means no files.
FileExclusionFilter (Optional)
Like the InclusionFilter but obviously the other way round. Exclusion takes precedence. ArgumentsSee inline Powershell help (man -full New-PSArmoury) for more details.
-Path
The path to your new armoury file. The default ist ".\MyArmoury.ps1"
-FromFile
Load your Powershell scripts directly from a local folder or file and you don't have to provide a config file.
-Config
The path to your JSON-config file. Have a look at the sample that comes with this script for ideas.
-Password
The password that will be used to encrypt your armoury. If you do not provide a[...]
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! PowerShellArmoury - A PowerShell Armoury For Security Guys And Girls http://2.bp.blogspot.com/-HCBmPFBkMDU/YP8bS1r9z9I/AAAAAAAAoZQ/NDFQo5mSEXQ2ExgCjfl_januYaXVu-VugCK4BGAYYCw/w285-h400/PowerShellArmoury_1-793052.png The PowerShell…
password, the script will generate a random one.
Please note: the main goal of encryption in this script is to circumvent anti-virus. If confidentiality is important to you, use the "-OmitPassword" switch. Otherwise your password and salt will be stored in your armoury in PLAINTEXT!
-Salt
The salt that will be used together with your password to generate an AES encryption key. If you do not provide a salt, the script will generate a random one.
Please note: the main goal of encryption in this script is to circumvent anti-virus. If confidentiality is important to you, use the "-OmitPassword" switch. Otherwise your password and salt will be stored in your armoury in PLAINTEXT!
-OmitPassword
This switch will remove the plaintext password from the final armoury script. Use this if confidentiality is important to you.
-ValidateOnly
Use this together with "-Config" to let the script validate the basic syntax of your JSON config file without executing it.
-Use3DES
Encrypts with 3DES instead of AES.
-EnhancedArmour
Instructs your armoury to require a protectecd PowerShell process. Therefore on first execution, your armoury will not load but spawn a new PowerShell that is set to run with BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON process mitigation. This prevents non-microsoft DLLs (e.g. AV/EDR products) to load into PowerShell. Shamelessly copied from the great @_rastamouse: https://gist.github.com/rasta-mouse/af009f49229c856dc26e3a243db185ec Example usageYou can find a very brief introduction below. Also have a look a these two blog posts here and here.
Use the following commands to create an armoury with all default settings. You can start with the sample config file in this repository for inspiration.
You can load the armoury into your current session by using
* Load all encrypted powershell functions into the current session as part of an array
* Disable AMSI
* Disable console history (can help prevent detection)
* Decrypt everything and pipe into iex
After that, all powershell code you put in the armoury will be available. Just invoke the cmdlets as usual like this
Please note: the main goal of encryption in this script is to circumvent anti-virus. If confidentiality is important to you, use the "-OmitPassword" switch. Otherwise your password and salt will be stored in your armoury in PLAINTEXT!
-Salt
The salt that will be used together with your password to generate an AES encryption key. If you do not provide a salt, the script will generate a random one.
Please note: the main goal of encryption in this script is to circumvent anti-virus. If confidentiality is important to you, use the "-OmitPassword" switch. Otherwise your password and salt will be stored in your armoury in PLAINTEXT!
-OmitPassword
This switch will remove the plaintext password from the final armoury script. Use this if confidentiality is important to you.
-ValidateOnly
Use this together with "-Config" to let the script validate the basic syntax of your JSON config file without executing it.
-Use3DES
Encrypts with 3DES instead of AES.
-EnhancedArmour
Instructs your armoury to require a protectecd PowerShell process. Therefore on first execution, your armoury will not load but spawn a new PowerShell that is set to run with BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON process mitigation. This prevents non-microsoft DLLs (e.g. AV/EDR products) to load into PowerShell. Shamelessly copied from the great @_rastamouse: https://gist.github.com/rasta-mouse/af009f49229c856dc26e3a243db185ec Example usageYou can find a very brief introduction below. Also have a look a these two blog posts here and here.
Use the following commands to create an armoury with all default settings. You can start with the sample config file in this repository for inspiration.
. .\New-PSArmoury.ps1
New-PSArmoury -Config .\PSArmoury.jsonThis will create an encrypted .ps1 file called "MyArmoury.ps1" in the current working directory. Password and salt for encryption are randomly generated and included in cleartext in the file. (note that we use encryption only to prevent detection on disk and not for confidentiality)You can load the armoury into your current session by using
cat -raw .\MyArmoury.ps1 | iexLoading your armoury invokes the following steps:* Load all encrypted powershell functions into the current session as part of an array
* Disable AMSI
* Disable console history (can help prevent detection)
* Decrypt everything and pipe into iex
After that, all powershell code you put in the armoury will be available. Just invoke the cmdlets as usual like this
Invoke-Rubeus -Command "kerberoast /stats"
Invoke-Bloodhound
Get-DomainGroupMember -Identity "Domain Admins" -RecurseIf it happens that you don't remember what you put inside the armoury, just load it and call the inventory :-) Get-PSArmouryDownload PowerShellArmoury
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe - Sweettooth Inc. (non port forward method)
https://cdn-images-1.medium.com/max/1744/0*uUgGmI_zQUDTJNqc.jpeg
Hello everyone, this one is going to be the write-up for the Sweettooth Inc. room on TryHackMe. In this room, we’ll have to first…
Continue reading on Medium »
TryHackMe - Sweettooth Inc. (non port forward method)
https://cdn-images-1.medium.com/max/1744/0*uUgGmI_zQUDTJNqc.jpeg
Hello everyone, this one is going to be the write-up for the Sweettooth Inc. room on TryHackMe. In this room, we’ll have to first…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
Capture The Flag (CTF)
https://cdn-images-1.medium.com/max/646/1*PmnXg9LknftoBZexoKcAZQ.gif
The Ultimate way to learn and practice Hacking!
Continue reading on Medium »
Capture The Flag (CTF)
https://cdn-images-1.medium.com/max/646/1*PmnXg9LknftoBZexoKcAZQ.gif
The Ultimate way to learn and practice Hacking!
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Facebook Mod Apk Download Latest Version
Facebook Mod Apk Download Here is a Brief Guide on This What Is Facebook, How to Download This, How To Install This, Facebook Information…
Continue reading on Medium »
Facebook Mod Apk Download Latest Version
Facebook Mod Apk Download Here is a Brief Guide on This What Is Facebook, How to Download This, How To Install This, Facebook Information…
Continue reading on Medium »