Installation
- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- bash scarce.sh
or you can install in your system like this- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- sudo cp scarce.sh /usr/bin/scarce && sudo chmod +x /usr/bin/scarce
- $ scarce
Usage
Menu's Menu 1 is for scanning LFI Vulnerability (https://www.kitploit.com/search/label/LFI%20Vulnerability) from a provided file that contains the list of the target url or a provided single target url.Menu 2 is for scanning RCE Vulnerability from a provided file that contains the list of the target url or a provided single target url.Menu 3 is for Executing RCE from a provided single target url. This will work for the Maybe Vuln Results or sometimes with a 500 Error Response.URL Format Use http:// like http://example.com or https:// like https://example.com for the url formatting at Single Target usagesFor Url or IP that has been provided from a List, Don't Use the URL Formatting like eg: https://target.com (https://target.com/)http://hackerone.com (http://hackerone.com/)https://bugcrowd.com (https://bugcrowd.com/)
Requirements
curlbashgit
Credits
Thanks to:CVE-2021-41773 Reproduced (https://twitter.com/ptswarm/status/1445376079548624899) by @ptswarm (https://twitter.com/ptswarm)Executing RCE in CVE-2021-41773 (https://twitter.com/hackerfantastic/status/1445531829985968137) by @hackerfantastic (https://twitter.com/hackerfantastic)Removing 5xx Error when Running RCE (https://twitter.com/lukejahnke/status/1445560511270064138) by @lukejahnke (https://twitter.com/lukejahnke)
Download Scarce-Apache2 (https://github.com/HightechSec/scarce-apache2)
___________________________
@hacking_Attack
@Hacking_Video
- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- bash scarce.sh
or you can install in your system like this- git clone https://github.com/HightechSec/scarce-apache2
- cd scarce-apache2
- sudo cp scarce.sh /usr/bin/scarce && sudo chmod +x /usr/bin/scarce
- $ scarce
Usage
Menu's Menu 1 is for scanning LFI Vulnerability (https://www.kitploit.com/search/label/LFI%20Vulnerability) from a provided file that contains the list of the target url or a provided single target url.Menu 2 is for scanning RCE Vulnerability from a provided file that contains the list of the target url or a provided single target url.Menu 3 is for Executing RCE from a provided single target url. This will work for the Maybe Vuln Results or sometimes with a 500 Error Response.URL Format Use http:// like http://example.com or https:// like https://example.com for the url formatting at Single Target usagesFor Url or IP that has been provided from a List, Don't Use the URL Formatting like eg: https://target.com (https://target.com/)http://hackerone.com (http://hackerone.com/)https://bugcrowd.com (https://bugcrowd.com/)
Requirements
curlbashgit
Credits
Thanks to:CVE-2021-41773 Reproduced (https://twitter.com/ptswarm/status/1445376079548624899) by @ptswarm (https://twitter.com/ptswarm)Executing RCE in CVE-2021-41773 (https://twitter.com/hackerfantastic/status/1445531829985968137) by @hackerfantastic (https://twitter.com/hackerfantastic)Removing 5xx Error when Running RCE (https://twitter.com/lukejahnke/status/1445560511270064138) by @lukejahnke (https://twitter.com/lukejahnke)
Download Scarce-Apache2 (https://github.com/HightechSec/scarce-apache2)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - HightechSec/scarce-apache2: A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability…
A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public - HightechSec/scarce-apache2
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Russian National Accused of Role in Trickbot Is Extradited to US
Court documents say Vladimir Dunaev is alleged to have been a malware developer for the Trickbot Group.
___________________________
@hacking_Attack
@Hacking_Video
Russian National Accused of Role in Trickbot Is Extradited to US
Court documents say Vladimir Dunaev is alleged to have been a malware developer for the Trickbot Group.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Russian National Accused of Role in Trickbot Is Extradited to US
Court documents say Vladimir Dunaev is alleged to have been a malware developer for the Trickbot Group.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Snyk Agrees to Acquire CloudSkiff, Creators of driftctl
New capabilities allow Snyk Infrastructure as Code customers to more effectively detect infrastructure drift.
___________________________
@hacking_Attack
@Hacking_Video
Snyk Agrees to Acquire CloudSkiff, Creators of driftctl
New capabilities allow Snyk Infrastructure as Code customers to more effectively detect infrastructure drift.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Snyk Agrees to Acquire CloudSkiff, Creators of driftctl
New capabilities allow Snyk Infrastructure as Code customers to more effectively detect infrastructure drift.
hacking: security in practice
Locking down a PC/Laptop, unlocking only with a key.
Greetings,
I'm using my laptop frequently (alongside with my PC, but that's not so important in this story) in a workplace park, which is a little bit outside of our building. Many times I had to run for some papers inside the building, and I had to let my laptop outside, and I'm afraid one day someone will just randomly take it (since... that place is visited by many tourists and people). I'm more productive outside, the laptop doesn't costs so much, but still I wouldn't waste like 10 days of work just to get another laptop. Is there a way, IN CASE (hopefully never) someone takes my laptop, to lock it from my PC (whatever, home PC or office PC), and so that the only way for them to unlock is is to put the password in (and maybe show a message or something).
Why I don't want to use the Windows default password thingy? I hate waiting at every login, startup to input my password, cuz as I said, I frequently just leave it like that, and I don't need security 24/7, I would like to activate that password thing just when I access it from another PC.
TLDR: A remote software that locks your PC, and can only be unlocked when the user inputs a password
Thanks!
submitted by /u/D1stRU3T0R
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Locking down a PC/Laptop, unlocking only with a key.
Greetings,
I'm using my laptop frequently (alongside with my PC, but that's not so important in this story) in a workplace park, which is a little bit outside of our building. Many times I had to run for some papers inside the building, and I had to let my laptop outside, and I'm afraid one day someone will just randomly take it (since... that place is visited by many tourists and people). I'm more productive outside, the laptop doesn't costs so much, but still I wouldn't waste like 10 days of work just to get another laptop. Is there a way, IN CASE (hopefully never) someone takes my laptop, to lock it from my PC (whatever, home PC or office PC), and so that the only way for them to unlock is is to put the password in (and maybe show a message or something).
Why I don't want to use the Windows default password thingy? I hate waiting at every login, startup to input my password, cuz as I said, I frequently just leave it like that, and I don't need security 24/7, I would like to activate that password thing just when I access it from another PC.
TLDR: A remote software that locks your PC, and can only be unlocked when the user inputs a password
Thanks!
submitted by /u/D1stRU3T0R
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Locking down a PC/Laptop, unlocking only with a key.
Greetings, I'm using my laptop frequently (alongside with my PC, but that's not so important in this story) in a workplace park, which...
hacking: security in practice
IP address of a scammer
Hi all,
Someone scammed me out of a lot of money but I was able to get their IP address, what can i do with it? Can I spoof them, report them, send them crap . any insight is appreciated
submitted by /u/wayfaringnomad
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
IP address of a scammer
Hi all,
Someone scammed me out of a lot of money but I was able to get their IP address, what can i do with it? Can I spoof them, report them, send them crap . any insight is appreciated
submitted by /u/wayfaringnomad
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
IP address of a scammer
Hi all, Someone scammed me out of a lot of money but I was able to get their IP address, what can i do with it? Can I spoof them, report them,...
hacking: security in practice
programming in python
i spent 2 months learning basics of python so what do i do now like should i remember all codes or start another language
( i want to become white hat hacker and historian )
submitted by /u/AdEducational9877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
programming in python
i spent 2 months learning basics of python so what do i do now like should i remember all codes or start another language
( i want to become white hat hacker and historian )
submitted by /u/AdEducational9877
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
programming in python
i spent 2 months learning basics of python so what do i do now like should i remember all codes or start another language ( i want to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 10 Free Ethical Hacking Tools online
https://cdn-images-1.medium.com/max/2000/1*5q0M97G9gtNYYlugP9U_Vg.jpeg
Looking for a new tool to help you get the most out of your Ethical Hacking Tools online processes? Read on for some great choices.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 10 Free Ethical Hacking Tools online
https://cdn-images-1.medium.com/max/2000/1*5q0M97G9gtNYYlugP9U_Vg.jpeg
Looking for a new tool to help you get the most out of your Ethical Hacking Tools online processes? Read on for some great choices.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 10 Free Ethical Hacking Tools online
Looking for a new tool to help you get the most out of your Ethical Hacking Tools online processes? Read on for some great choices.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Los ataques a APIs están dejando expuestas vulnerabilidades en la seguridad de empresas
https://cdn-images-1.medium.com/max/1500/0*SCcIfOyp3ti84k5T
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Los ataques a APIs están dejando expuestas vulnerabilidades en la seguridad de empresas
https://cdn-images-1.medium.com/max/1500/0*SCcIfOyp3ti84k5T
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Los ataques a APIs están dejando expuestas vulnerabilidades en la seguridad de empresas
PUBLICADO EN 29 OCTUBRE, 2021POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
One misconfiguration to rule them all
https://cdn-images-1.medium.com/max/2600/0*rL9QNfnE1QOazLVN
How a small misconfiguration led to exposed secrets, access to production data, and employee PII.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
One misconfiguration to rule them all
https://cdn-images-1.medium.com/max/2600/0*rL9QNfnE1QOazLVN
How a small misconfiguration led to exposed secrets, access to production data, and employee PII.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
One misconfiguration to rule them all
How a small misconfiguration led to exposed secrets, access to production data, and employee PII.
hacking: security in practice
Text now number
Is it possible to find out who is behind a fake app number like a text now number.
submitted by /u/KiwiSea2189
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Text now number
Is it possible to find out who is behind a fake app number like a text now number.
submitted by /u/KiwiSea2189
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Text now number
Is it possible to find out who is behind a fake app number like a text now number.
hacking: security in practice
how long have you been “hacking “ for
just asking pretty curious could you tell me what you’ve learnt and what’s possible?
submitted by /u/Its_squidward
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
how long have you been “hacking “ for
just asking pretty curious could you tell me what you’ve learnt and what’s possible?
submitted by /u/Its_squidward
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
how long have you been “hacking “ for
just asking pretty curious could you tell me what you’ve learnt and what’s possible?
hacking: security in practice
How to decrypt this pdf file?
downloaded pdf but I'm unable to open it...this pdf I can use Only after login in site but can't able to download pdf... however I have managed to download but still unable to open..
{"response":true,"url":"https://vcdn.spayee.in/spees/w/o/5e05e061e4b07876042d20c2/v/611e29ee0cf2272a293b1a96/u/616ed9af0cf216a8e6359508/p/assets/pdfs/2021/08/19/611e29ee0cf2272a293b1a96/file.pdf. ","p":"9f34072186edfc9a5f0e32dfa753e75eatAsU3Rh90PI81AcACIkcwfL5RjjeagmiXW1OzlbPvoY8f9JKMh08T+1nkuLyZcofdc6be512d1aa17feec4627eb2477db5","allowDownload":false,"allowWatermark":true}
This is what I got...I don't know how to decrypt.
submitted by /u/ASHWATTHMA
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to decrypt this pdf file?
downloaded pdf but I'm unable to open it...this pdf I can use Only after login in site but can't able to download pdf... however I have managed to download but still unable to open..
{"response":true,"url":"https://vcdn.spayee.in/spees/w/o/5e05e061e4b07876042d20c2/v/611e29ee0cf2272a293b1a96/u/616ed9af0cf216a8e6359508/p/assets/pdfs/2021/08/19/611e29ee0cf2272a293b1a96/file.pdf. ","p":"9f34072186edfc9a5f0e32dfa753e75eatAsU3Rh90PI81AcACIkcwfL5RjjeagmiXW1OzlbPvoY8f9JKMh08T+1nkuLyZcofdc6be512d1aa17feec4627eb2477db5","allowDownload":false,"allowWatermark":true}
This is what I got...I don't know how to decrypt.
submitted by /u/ASHWATTHMA
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to decrypt this pdf file?
downloaded pdf but I'm unable to open it...this pdf I can use Only after login in site but can't able to download pdf... however I have managed to...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hack The Box - Holiday - Source Code Analysis
https://external-preview.redd.it/ppVzM8rByVbqirOQNpu3WEmRFDEgY5KlHNr9A9hSCuA.jpg?width=640&crop=smart&auto=webp&s=650109dd548b4da0f773659421af0b90d17bd6b1 submitted by /u/pythonpsycho1337
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hack The Box - Holiday - Source Code Analysis
https://external-preview.redd.it/ppVzM8rByVbqirOQNpu3WEmRFDEgY5KlHNr9A9hSCuA.jpg?width=640&crop=smart&auto=webp&s=650109dd548b4da0f773659421af0b90d17bd6b1 submitted by /u/pythonpsycho1337
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hack The Box - Holiday - Source Code Analysis
Posted in r/hacking by u/pythonpsycho1337 • 2 points and 0 comments
hacking: security in practice
Can I trace out dev's running bad code?
Hi,
So there are some dev's in my environment and they are running API request and everything.
What should I be looking out for as the sysadmin? Can I grab any of the data being run on their code in Wireshark or anything like that?
What's the risk of someone running an API request?
submitted by /u/onequestion1168
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can I trace out dev's running bad code?
Hi,
So there are some dev's in my environment and they are running API request and everything.
What should I be looking out for as the sysadmin? Can I grab any of the data being run on their code in Wireshark or anything like that?
What's the risk of someone running an API request?
submitted by /u/onequestion1168
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can I trace out dev's running bad code?
Hi, So there are some dev's in my environment and they are running API request and everything. What should I be looking out...