Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Have scraper bots outstayed their welcome on real estate listing sites?
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
Have scraper bots outstayed their welcome on real estate listing sites?
Continue reading on Netacea »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Have scraper bots outstayed their welcome on real estate listing sites?
Real estate is just one of many industries that was forced to quickly adapt to an increasingly online-first world in the wake of the COVID-19 pandemic. Virtual viewings are now the norm, and real…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HOW CAN I MONITOR SOMEONE’S WHATSAPP MESSAGES?
https://cdn-images-1.medium.com/max/768/0*hRjP5pIzHgVwlYme
How to Hack WhatsApp messages and read without Access To someone’s Phone
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HOW CAN I MONITOR SOMEONE’S WHATSAPP MESSAGES?
https://cdn-images-1.medium.com/max/768/0*hRjP5pIzHgVwlYme
How to Hack WhatsApp messages and read without Access To someone’s Phone
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HOW CAN I MONITOR SOMEONE’S WHATSAPP MESSAGES?
How to Hack WhatsApp messages and read without Access To someone’s Phone
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WebKit PointerCaptureController::processPendingPointerCapture Heap Use-After-Free
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
WebKit suffers from a heap use-after-free vulnerability in PointerCaptureController::processPendingPointerCapture.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WebKit PointerCaptureController::processPendingPointerCapture Heap Use-After-Free
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
WebKit suffers from a heap use-after-free vulnerability in PointerCaptureController::processPendingPointerCapture.
MD5 |
85982c0cc7c08c6c433738b10d8364c7Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WebKit PointerCaptureController::processPendingPointerCapture Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WebKit EventHandler::keyEvent Heap Use-After-Free
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
WebKit suffers from a heap use-after-free vulnerability in EventHandler::keyEvent.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WebKit EventHandler::keyEvent Heap Use-After-Free
https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
WebKit suffers from a heap use-after-free vulnerability in EventHandler::keyEvent.
MD5 |
0f7868eaf28b9a9f6b987cd467e31156Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WebKit EventHandler::keyEvent Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WebKit DOMWindow::open Heap Use-After-Free
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
WebKit suffers from a heap use-after-free vulnerability in DOMWindow::open.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WebKit DOMWindow::open Heap Use-After-Free
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
WebKit suffers from a heap use-after-free vulnerability in DOMWindow::open.
MD5 |
fcb529386a430d5c97cf9addb3eafc75Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WebKit DOMWindow::open Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Yellowfin Cross Site Scripting / Insecure Direct Object Reference
https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Yellowfin versions prior to 9.6.1 suffer from persistent cross site scripting and insecure direct object reference vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Yellowfin Cross Site Scripting / Insecure Direct Object Reference
https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Yellowfin versions prior to 9.6.1 suffer from persistent cross site scripting and insecure direct object reference vulnerabilities.
MD5 |
ca807ea57006fe0e0063b6d15f7fb00dDownload
YELLOWFIN < 9.6.1 MULTIPLE VULNERABILITIES
----------------------------------------------------
Vulnerability:
==============
Stored Cross-Site Scripting
Affected Products and Versions:
===============================
Yellowfin < 9.6.1
CVEID:
======
CVE-2021-36387
CVSSv3.1 Score:
===============
5.4 (Medium)
CVSSv3.1 Attack Vector:
=======================
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Short Description:
==================
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".
Remediation:
============
Update Yellowfin to the latest version available
Discoverer:
===========
Michele Di Bonaventura (cyberaz0r)
Reference:
==========
https://wiki.yellowfinbi.com/display/yfcurrent/Release+Notes+for+Yellowfin+9#ReleaseNotesforYellowfin9-Yellowfin9.6
----------------------------------------------------
Vulnerability:
==============
Insecure Direct Object Reference
Affected Products and Versions:
===============================
Yellowfin < 9.6.1
CVEID:
======
CVE-2021-36388
CVSSv3.1 Score:
===============
7.5 (High)
CVSSv3.1 Attack Vector:
=======================
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Short Description:
==================
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4".
Remediation:
============
Update Yellowfin to the latest version available
Discoverer:
===========
Michele Di Bonaventura (cyberaz0r)
Reference:
==========
https://wiki.yellowfinbi.com/display/yfcurrent/Release+Notes+for+Yellowfin+9#ReleaseNotesforYellowfin9-Yellowfin9.6
----------------------------------------------------
Vulnerability:
==============
Insecure Direct Object Reference
Affected Products and Versions:
===============================
Yellowfin < 9.6.1
CVEID:
======
CVE-2021-36389
CVSSv3.1 Score:
===============
7.5 (High)
CVSSv3.1 Attack Vector:
=======================
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Short Description:
==================
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".
Remediation:
============
Update Yellowfin to the latest version available
Discoverer:
===========
Michele Di Bonaventura (cyberaz0r)
Reference:
==========
https://wiki.yellowfinbi.com/display/yfcurrent/Release+Notes+for+Yellowfin+9#ReleaseNotesforYellowfin9-Yellowfin9.6
----------------------------------------------------
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Yellowfin Cross Site Scripting / Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TextPattern CMS 4.8.7 Shell Upload
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
TextPattern CMS version 4.8.7 suffers from an authenticated remote shell upload vulnerability.
MD5 |
Download
# Exploit Title: TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated)
# Date: 2021/09/06
# Exploit Author: Mert Daş merterpreter@gmail.com
# Software Link: https://textpattern.com/file_download/113/textpattern-4.8.7.zip
# Software web: https://textpattern.com/
# Tested on: Server: Xampp
First of all we should use file upload section to upload our shell.
Our shell contains this malicious code:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
TextPattern CMS 4.8.7 Shell Upload
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
TextPattern CMS version 4.8.7 suffers from an authenticated remote shell upload vulnerability.
MD5 |
a48c73645293b99b6fbcfeb552bf7cc4Download
# Exploit Title: TextPattern CMS 4.8.7 - Remote Command Execution (RCE) (Authenticated)
# Date: 2021/09/06
# Exploit Author: Mert Daş merterpreter@gmail.com
# Software Link: https://textpattern.com/file_download/113/textpattern-4.8.7.zip
# Software web: https://textpattern.com/
# Tested on: Server: Xampp
First of all we should use file upload section to upload our shell.
Our shell contains this malicious code:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TextPattern CMS 4.8.7 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
SolarWinds Kiwi CatTools 3.11.8 Unquoted Service Path
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
SolarWinds Kiwi CatTools version 3.11.8 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
SolarWinds Kiwi CatTools 3.11.8 Unquoted Service Path
https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
SolarWinds Kiwi CatTools version 3.11.8 suffers from an unquoted service path vulnerability.
MD5 |
acc6ac66fedd5db07765a9c5c1fc9e3cDownload
# Exploit Title: SolarWinds Kiwi CatTools 3.11.8 - Unquoted Service Path
# Exploit Author: Mert DAŞ
# Version: 3.11.8
# Date: 14.10.2021
# Vendor Homepage: https://www.solarwinds.com/
# Tested on: Windows 10
# Step to discover Unquoted Service Path :
--------------------------------------
C:\Users\Mert>sc qc CatTools
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: CatTools
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\CatTools3\nssm.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : CatTools
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
---------------------------------------------
Or:
-------------------------
C:\Users\Mert>wmic service get name,displayname,pathname,startmode |findstr
/i "auto" |findstr /i /v "c:\windows\\" |findstr /i /v """
----------------------
#Exploit:
A successful attempt would require the local user to be able to insert
their code in the system root path undetected by the OS or other security
applications where it could potentially be executed during application
startup or reboot. If successful, the local user's code would execute with
the elevated privileges of the application.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
SolarWinds Kiwi CatTools 3.11.8 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
IFSC Code Finder Project 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
IFSC Code Finder Project 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
IFSC Code Finder Project 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Dark Reading: Attacks/Breaches
Open Source Security Foundation Raises $10M
Industry leaders from technology, financial services, telecom, and cybersecurity sectors respond to Biden's executive order and commit to a more secure future for software.
___________________________
@hacking_Attack
@Hacking_Video
Open Source Security Foundation Raises $10M
Industry leaders from technology, financial services, telecom, and cybersecurity sectors respond to Biden's executive order and commit to a more secure future for software.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Open Source Security Foundation Raises $10M
Industry leaders from technology, financial services, telecom, and cybersecurity sectors respond to Biden's executive order and commit to a more secure future for software.