Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Red Team vs Blue Team vs Purple Team.
https://cdn-images-1.medium.com/max/991/0*8HKfmR8b7rYht0J4.png
PUBLICADO EN 6 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
Red Team vs Blue Team vs Purple Team.
https://cdn-images-1.medium.com/max/991/0*8HKfmR8b7rYht0J4.png
PUBLICADO EN 6 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BASIC PENTEST — (CTF) TRY HACK ME
https://cdn-images-1.medium.com/max/634/1*YIgW8SajVZlgOppPRAb_-A.png
Hoje, como primeiro post, vim trazer uma máquina do try hack me, uma plataforma exclusiva para hackers que treinam e buscam conhecimento…
Continue reading on Medium »
BASIC PENTEST — (CTF) TRY HACK ME
https://cdn-images-1.medium.com/max/634/1*YIgW8SajVZlgOppPRAb_-A.png
Hoje, como primeiro post, vim trazer uma máquina do try hack me, uma plataforma exclusiva para hackers que treinam e buscam conhecimento…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Penetration Testing: Phishing & Adherence
https://cdn-images-1.medium.com/max/1920/1*Nf0Y1ZCY8WYxhTQRoe00Tw.jpeg
Before jumping right in there are a couple of things we need to understand. First, pen-testing is not beginner-friendly, it takes years of…
Continue reading on CodeX »
Penetration Testing: Phishing & Adherence
https://cdn-images-1.medium.com/max/1920/1*Nf0Y1ZCY8WYxhTQRoe00Tw.jpeg
Before jumping right in there are a couple of things we need to understand. First, pen-testing is not beginner-friendly, it takes years of…
Continue reading on CodeX »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to stay safe and anonymous online in 2021
https://cdn-images-1.medium.com/max/848/0*FwEKcN6XzRklcqq7.jpg
Hi everyone! falkensmaze here and in this blog post, I’ll teach you everything you need to know to keep hackers and governments stay out…
Continue reading on Medium »
How to stay safe and anonymous online in 2021
https://cdn-images-1.medium.com/max/848/0*FwEKcN6XzRklcqq7.jpg
Hi everyone! falkensmaze here and in this blog post, I’ll teach you everything you need to know to keep hackers and governments stay out…
Continue reading on Medium »
Raze Network Testnet Bounty Program Update
https://raze-net.medium.com/raze-network-testnet-bounty-program-update-ceb14ba9ba01?source=rss------bug_bounty-5
https://raze-net.medium.com/raze-network-testnet-bounty-program-update-ceb14ba9ba01?source=rss------bug_bounty-5
Dear Razers,Continue reading on Medium » (https://raze-net.medium.com/raze-network-testnet-bounty-program-update-ceb14ba9ba01?source=rss------bug_bounty-5)
Introducing: Single Staking Option Vaults (SSOV)
We are proud to announce the official launch of DPX Single Staking Option Vaults on the Dopex Testnet.Continue reading on Dopex »
Read more...
We are proud to announce the official launch of DPX Single Staking Option Vaults on the Dopex Testnet.Continue reading on Dopex »
Read more...
Introducing: Single Staking Option Vaults (SSOV)
https://blog.dopex.io/introducing-single-staking-option-vaults-ssov-b90bbb0a9ae5?source=rss------bug_bounty-5
https://blog.dopex.io/introducing-single-staking-option-vaults-ssov-b90bbb0a9ae5?source=rss------bug_bounty-5
We are proud to announce the official launch of DPX Single Staking Option Vaults on the Dopex Testnet.Continue reading on Dopex » (https://blog.dopex.io/introducing-single-staking-option-vaults-ssov-b90bbb0a9ae5?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bus Pass Management System 1.0 Insecure Direct Object Reference
https://3.bp.blogspot.com/-5Gol6ncjvHU/WWlu6JXhP1I/AAAAAAAAIJU/-rw4_xI3A9E9PcOGmPlkULl4C62j1nBBwCLcBGAs/s1600/h108.png
Bus Pass Management System version 1.0 suffers from an insecure direct object reference vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Bus Pass Management System 1.0 Insecure Direct Object Reference
https://3.bp.blogspot.com/-5Gol6ncjvHU/WWlu6JXhP1I/AAAAAAAAIJU/-rw4_xI3A9E9PcOGmPlkULl4C62j1nBBwCLcBGAs/s1600/h108.png
Bus Pass Management System version 1.0 suffers from an insecure direct object reference vulnerability.
MD5 |
e267ca8087f792dc662cac3d05dcc33eDownload
# Exploit Title: Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
# Date: 2021-09-05
# Exploit Author: sudoninja
# Vendor Homepage: https://phpgurukul.com/bus-pass-management-system-using-php-and-mysql
# Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
# Version: 1.0
# Tested on: Windows 10 - XAMPP Server
# Vulnerable page :
http://localhost/buspassms/admin/view-pass-detail.php?viewid=4
# Vulnerable paramater :
The viewid paramater is Vulnerable to Insecure direct object references (IDOR)
# Proof Of Concept :
# 1 . Download And install [ bus-pass-management-system ]
# 2 . Go to /admin/index.php and Enter Username & Password
# 3 . Navigate to search >> search pass
# 4 . Click on the view and enter the change viewid into the Url
Use :
http://localhost/buspassms/admin/view-pass-detail.php?viewid=[change id]
Source:packetstormsecurity.com