Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BASIC PENTEST — (CTF) TRY HACK ME

https://cdn-images-1.medium.com/max/634/1*YIgW8SajVZlgOppPRAb_-A.png
Hoje, como primeiro post, vim trazer uma máquina do try hack me, uma plataforma exclusiva para hackers que treinam e buscam conhecimento…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Penetration Testing: Phishing & Adherence

https://cdn-images-1.medium.com/max/1920/1*Nf0Y1ZCY8WYxhTQRoe00Tw.jpeg
Before jumping right in there are a couple of things we need to understand. First, pen-testing is not beginner-friendly, it takes years of…

Continue reading on CodeX »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to stay safe and anonymous online in 2021

https://cdn-images-1.medium.com/max/848/0*FwEKcN6XzRklcqq7.jpg
Hi everyone! falkensmaze here and in this blog post, I’ll teach you everything you need to know to keep hackers and governments stay out…

Continue reading on Medium »
Raze Network Testnet Bounty Program Update

Dear Razers,Continue reading on Medium »
Read more...
Introducing: Single Staking Option Vaults (SSOV)

We are proud to announce the official launch of DPX Single Staking Option Vaults on the Dopex Testnet.Continue reading on Dopex »
Read more...
We are proud to announce the official launch of DPX Single Staking Option Vaults on the Dopex Testnet.Continue reading on Dopex » (https://blog.dopex.io/introducing-single-staking-option-vaults-ssov-b90bbb0a9ae5?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bus Pass Management System 1.0 Insecure Direct Object Reference

https://3.bp.blogspot.com/-5Gol6ncjvHU/WWlu6JXhP1I/AAAAAAAAIJU/-rw4_xI3A9E9PcOGmPlkULl4C62j1nBBwCLcBGAs/s1600/h108.png
Bus Pass Management System version 1.0 suffers from an insecure direct object reference vulnerability.

MD5 | e267ca8087f792dc662cac3d05dcc33e

Download
# Exploit Title: Bus Pass Management System 1.0 - 'viewid' Insecure direct object references (IDOR)
# Date: 2021-09-05
# Exploit Author: sudoninja
# Vendor Homepage: https://phpgurukul.com/bus-pass-management-system-using-php-and-mysql
# Software Link: https://phpgurukul.com/wp-content/uploads/2021/07/Bus-Pass-Management-System-Using-PHP-MySQL.zip
# Version: 1.0
# Tested on: Windows 10 - XAMPP Server

# Vulnerable page :

http://localhost/buspassms/admin/view-pass-detail.php?viewid=4

# Vulnerable paramater :

The viewid paramater is Vulnerable to Insecure direct object references (IDOR)

# Proof Of Concept :

# 1 . Download And install [ bus-pass-management-system ]
# 2 . Go to /admin/index.php and Enter Username & Password
# 3 . Navigate to search >> search pass
# 4 . Click on the view and enter the change viewid into the Url

Use :
http://localhost/buspassms/admin/view-pass-detail.php?viewid=[change id]

Source:packetstormsecurity.com