Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ludo Supreme Gold Download & Get 1500 RS. Daily…
https://cdn-images-1.medium.com/max/1920/1*s8eseoYheJPmTB_RJgwfGQ.png
CLICK HERE — https://bit.ly/3i2kXcr
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ludo Supreme Gold Download & Get 1500 RS. Daily…
https://cdn-images-1.medium.com/max/1920/1*s8eseoYheJPmTB_RJgwfGQ.png
CLICK HERE — https://bit.ly/3i2kXcr
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ludo Supreme Gold Download & Get 1500 RS. Daily…
CLICK HERE — https://bit.ly/3i2kXcr
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CoinSwitch Kuber Download Bitcoin Unlimited…
https://cdn-images-1.medium.com/max/1920/1*N8gWgybns9u8Mwdx-69Bxw.png
- Title: COINSWITCH
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CoinSwitch Kuber Download Bitcoin Unlimited…
https://cdn-images-1.medium.com/max/1920/1*N8gWgybns9u8Mwdx-69Bxw.png
- Title: COINSWITCH
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CoinSwitch Kuber Download Bitcoin Unlimited…
- Title: COINSWITCH
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ThinkPHP 5.0.24 RCE POP Gadget Chain
https://cdn-images-1.medium.com/max/932/1*eG4p83RQySSFcnI_eV5VCg.png
CTF: 0CTF 2021 Finals
Team: More Smoked Leet Chicken
Team member: kemmio
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
ThinkPHP 5.0.24 RCE POP Gadget Chain
https://cdn-images-1.medium.com/max/932/1*eG4p83RQySSFcnI_eV5VCg.png
CTF: 0CTF 2021 Finals
Team: More Smoked Leet Chicken
Team member: kemmio
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
ThinkPHP 5.0.24 RCE POP Gadget Chain
CTF: 0CTF 2021 Finals
Team: More Smoked Leet Chicken
Team member: kemmio
Team: More Smoked Leet Chicken
Team member: kemmio
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to create a HTTPS server with one-liner of code
https://cdn-images-1.medium.com/max/1169/1*Kb33IXYfE-eGPVvRjfEL6A.png
During a pen-test engagement, we are all guilty of using this command python -m SimpleHTTPServer 80 to host and share our files. At a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to create a HTTPS server with one-liner of code
https://cdn-images-1.medium.com/max/1169/1*Kb33IXYfE-eGPVvRjfEL6A.png
During a pen-test engagement, we are all guilty of using this command python -m SimpleHTTPServer 80 to host and share our files. At a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to create a HTTPS server with one-liner of code
During a pen-test engagement, we are all guilty of using this command python -m SimpleHTTPServer 80 to host and share our files. At a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Backdooring windows ISO
https://cdn-images-1.medium.com/max/1063/1*2APx2pC6qSa7ZfdCBWswXA.png
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Backdooring windows ISO
https://cdn-images-1.medium.com/max/1063/1*2APx2pC6qSa7ZfdCBWswXA.png
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Backdooring windows ISO
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
https://cdn-images-1.medium.com/max/1386/0*MaD5d5AoCUSDH3l-
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
https://cdn-images-1.medium.com/max/1386/0*MaD5d5AoCUSDH3l-
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Validation: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*ds9sa4p_EybvbDRWRzKh9w.png
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box — Validation: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*ds9sa4p_EybvbDRWRzKh9w.png
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box — Validation: Walkthrough (without Metasploit)
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hello Neighbor
https://cdn-images-1.medium.com/max/1049/1*bPyvd9r_tYZFH-H31CgJvw.png
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
Hello Neighbor
https://cdn-images-1.medium.com/max/1049/1*bPyvd9r_tYZFH-H31CgJvw.png
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hello Neighbor
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress TranslatePress 2.0.8 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
WordPress TranslatePress plugin version 2.0.8 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress TranslatePress 2.0.8 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
WordPress TranslatePress plugin version 2.0.8 suffers from a persistent cross site scripting vulnerability.
MD5 |
cb0dfac0cf52af1f4c77f09caf67ea09Download
# Exploit Title: WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Date: 06-08-2021
# Exploit Author: Nosa Shandy (Apapedulimu)
# Vendor Homepage: https://translatepress.com/
# Software Link: https://wordpress.org/plugins/translatepress-multilingual/
# Reference: https://wpscan.com/vulnerability/b87fcc2f-c2eb-4e23-9757-d1c590f26d3f
# Version: 2.0.6
# Tested on: macOS 11.4
# CVE : CVE-2021-24610
Description:
The plugin does not implement a proper filter on the 'translated' parameter when input to the database. The 'trp_sanitize_string' function only check the "" with the preg_replace, the attacker can use the HTML Tag to execute javascript.
Step To Reproduce:
1. Go to http://localhost:8888/wordpress/?trp-edit-translation=true
2. Input Gettext String
3. Input the payload such as x
4. Save, The payload will be executed.
5. Look on the homepage will be affected.
Video : https://drive.google.com/file/d/1PnvjHuKCvjmom6xz_sxNLBu3jixCiHy_/view?usp=sharing
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress TranslatePress 2.0.8 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Contact Form 1.7.14 Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WordPress Contact Form plugin version 1.7.14 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Contact Form 1.7.14 Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WordPress Contact Form plugin version 1.7.14 suffers from a cross site scripting vulnerability.
MD5 |
ad3b8c07914e764e78a039113f3ce4a9Download
# Exploit Title: WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
# Date: 3/28/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/contact-form-by-supsystic/
# Version: 1.7.14
# Tested on: Windows 10
# CVE: CVE-2021-24276
1. Description:
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
2. Proof of Concept:
/wp-admin/admin.php?page=contact-form-supsystic&tab="+style=animation-name:rotation+onanimationstart=alert(/XSS/)//
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Contact Form 1.7.14 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.