Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Broken — Access Control Vulnerability
https://cdn-images-1.medium.com/max/780/0*Yy_ASQccsjXZNFWk.jpg
Overview
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Broken — Access Control Vulnerability
https://cdn-images-1.medium.com/max/780/0*Yy_ASQccsjXZNFWk.jpg
Overview
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Broken — Access Control Vulnerability
Overview
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
picoCTF write up: information
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Question: Files can always be changed in a secret way. Can you find the flag?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
picoCTF write up: information
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Question: Files can always be changed in a secret way. Can you find the flag?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
picoCTF write up: information
Question: Files can always be changed in a secret way. Can you find the flag?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
picoCTF write up: Nice netcat…
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Question: There is a nice program that you can talk to by using this command in a shell: $ nc mercury.picoctf.net 49039, but it doesn't…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
picoCTF write up: Nice netcat…
https://cdn-images-1.medium.com/max/600/1*KlGimrIDTFUJqDXnARmz1w.jpeg
Question: There is a nice program that you can talk to by using this command in a shell: $ nc mercury.picoctf.net 49039, but it doesn't…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
picoCTF write up: Nice netcat…
Question: There is a nice program that you can talk to by using this command in a shell: $ nc mercury.picoctf.net 49039, but it doesn't…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers que utilizan cuentas de Google Cloud comprometidas para extraer criptomonedas
https://cdn-images-1.medium.com/max/1547/0*nWiCIAL6IItqqdT9
PUBLICADO EN 29 NOVIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers que utilizan cuentas de Google Cloud comprometidas para extraer criptomonedas
https://cdn-images-1.medium.com/max/1547/0*nWiCIAL6IItqqdT9
PUBLICADO EN 29 NOVIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers que utilizan cuentas de Google Cloud comprometidas para extraer criptomonedas
PUBLICADO EN 29 NOVIEMBRE, 2021 POR DPAB
Learn Red Teaming & Malware Development for this year's Advent Of Code
https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly bite sized challenges to get into red teaming & hacking for those that already have some pentesting/security experience: https://github.com/fumamatar/Red-Team-Advent-of-Code If anyone wants to join, feel free. Maybe this can motivate someone to get into this awesome sector of it security. submitted by /u/sorhinco (https://www.reddit.com/user/sorhinco)
[link] (https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/) [comments] (https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly bite sized challenges to get into red teaming & hacking for those that already have some pentesting/security experience: https://github.com/fumamatar/Red-Team-Advent-of-Code If anyone wants to join, feel free. Maybe this can motivate someone to get into this awesome sector of it security. submitted by /u/sorhinco (https://www.reddit.com/user/sorhinco)
[link] (https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/) [comments] (https://www.reddit.com/r/redteamsec/comments/r5474n/learn_red_teaming_malware_development_for_this/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Learn Red Teaming & Malware Development for this year's Advent Of Code
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly...
hacking: security in practice
Nice site to buy breeched databases?
Any recommendations?
submitted by /u/CrownOfIce
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Nice site to buy breeched databases?
Any recommendations?
submitted by /u/CrownOfIce
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Nice site to buy breeched databases?
Any recommendations?
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
AutoRDPwn - The Shadow Attack Framework
https://gitlab.com/JoelGMSec/AutoRDPwn
AutoRDPwn is a post-exploitation framework created in Powershell, designed primarily to automate the Shadow attack on Microsoft Windows computers. This vulnerability (listed as a feature by Microsoft) allows a remote attacker to view his victim's desktop without his consent, and even control it on demand, using tools native to the operating system itself.
Thanks to the additional modules, it is possible to obtain a remote shell through Netcat, dump system hashes with Mimikatz, load a remote keylogger and much more. All this, Through a completely intuitive menu in seven different languages.
Additionally, it is possible to use it in a reverse shell through a series of parameters that are described in the usage section.
submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
AutoRDPwn - The Shadow Attack Framework
https://gitlab.com/JoelGMSec/AutoRDPwn
AutoRDPwn is a post-exploitation framework created in Powershell, designed primarily to automate the Shadow attack on Microsoft Windows computers. This vulnerability (listed as a feature by Microsoft) allows a remote attacker to view his victim's desktop without his consent, and even control it on demand, using tools native to the operating system itself.
Thanks to the additional modules, it is possible to obtain a remote shell through Netcat, dump system hashes with Mimikatz, load a remote keylogger and much more. All this, Through a completely intuitive menu in seven different languages.
Additionally, it is possible to use it in a reverse shell through a series of parameters that are described in the usage section.
submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
AutoRDPwn - The Shadow Attack Framework
https://gitlab.com/JoelGMSec/AutoRDPwn **AutoRDPwn** is a post-exploitation framework created in Powershell, designed primarily to automate the...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Learn Red Teaming & Malware Development for Advent Of Code
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly bite sized challenges to get into red teaming & hacking for those that already have some pentesting/security experience:
https://github.com/fumamatar/Red-Team-Advent-of-Code
If anyone wants to join, feel free. Maybe this can motivate someone to get into this awesome sector of it security.
submitted by /u/sorhinco
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Learn Red Teaming & Malware Development for Advent Of Code
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly bite sized challenges to get into red teaming & hacking for those that already have some pentesting/security experience:
https://github.com/fumamatar/Red-Team-Advent-of-Code
If anyone wants to join, feel free. Maybe this can motivate someone to get into this awesome sector of it security.
submitted by /u/sorhinco
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Learn Red Teaming & Malware Development for Advent Of Code
Hey, I wanted to improve my red teaming and malware development skills this december, so I came up with these challenges, which should be fairly...
hacking: security in practice
Hacking with C#
Hello,
I have been creating hacks for some unity games, meaning that I am very proficient in C# but am struggling to move forward. Is C# used for hacking, and if so could you guys recommend some starter projects?
submitted by /u/David_8J
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking with C#
Hello,
I have been creating hacks for some unity games, meaning that I am very proficient in C# but am struggling to move forward. Is C# used for hacking, and if so could you guys recommend some starter projects?
submitted by /u/David_8J
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking with C#
Hello, I have been creating hacks for some unity games, meaning that I am very proficient in C# but am struggling to move forward. Is C# used for...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Nextar C472 POS DLL Hijacking
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Nextar C472 POS suffers from a dll hijacking vulnerability.
MD5 |
Download
/*
Description:
A vulnerability exists in windows that allows other applications dynamic link libraries
to execute malicious code without the users consent, in the privelage context of the targeted application.
Exploit Title: Nextar C472 POS DLL Hijacking Exploit (nxmm.dll - mdmdregistration.dll)
Date: 28/11/2021
Author: Yehia Elghaly
Vendor: https://www.nextar.com/
Software: https://download.nextar.com/latest/setup_nex_en.exe
Version: Latest Nextar C472 POS
Tested on: Windows 7 Pro x86 - Windows 10 x64
Vulnerable extensions: .htm .html
*/
/*
Instructions:
1. Create dll using msfvenom (sudo msfvenom --platform windows -p windows/messagebox TEXT="Nex POS Hacked - YME" -f dll > nxmm.dll) or compile the code
2. Replace nxmm.dll - mdmdregistration.dll or shcore.dll in Nex directory C:\Nex with your newly dll
3. Launch NexAdmin.exe
4. PoP UP MessageBox!
*/
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Nextar C472 POS DLL Hijacking
https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png
Nextar C472 POS suffers from a dll hijacking vulnerability.
MD5 |
042ade5bb6a561b509ee91f0791e6f7aDownload
/*
Description:
A vulnerability exists in windows that allows other applications dynamic link libraries
to execute malicious code without the users consent, in the privelage context of the targeted application.
Exploit Title: Nextar C472 POS DLL Hijacking Exploit (nxmm.dll - mdmdregistration.dll)
Date: 28/11/2021
Author: Yehia Elghaly
Vendor: https://www.nextar.com/
Software: https://download.nextar.com/latest/setup_nex_en.exe
Version: Latest Nextar C472 POS
Tested on: Windows 7 Pro x86 - Windows 10 x64
Vulnerable extensions: .htm .html
*/
/*
Instructions:
1. Create dll using msfvenom (sudo msfvenom --platform windows -p windows/messagebox TEXT="Nex POS Hacked - YME" -f dll > nxmm.dll) or compile the code
2. Replace nxmm.dll - mdmdregistration.dll or shcore.dll in Nex directory C:\Nex with your newly dll
3. Launch NexAdmin.exe
4. PoP UP MessageBox!
*/
#include
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Nextar C472 POS DLL Hijacking
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Polkit Authentication Bypass / Local Privilege Escalation
https://1.bp.blogspot.com/-5_4vnaEHtE4/WWlvOudg9oI/AAAAAAAAIMs/tPLG-GePmxgLMlPyiIuDfO-2MFfOtdhKQCLcBGAs/s1600/h26.png
This whitepaper provides an overview of a Polkit authentication bypass vulnerability that allows for local privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Polkit Authentication Bypass / Local Privilege Escalation
https://1.bp.blogspot.com/-5_4vnaEHtE4/WWlvOudg9oI/AAAAAAAAIMs/tPLG-GePmxgLMlPyiIuDfO-2MFfOtdhKQCLcBGAs/s1600/h26.png
This whitepaper provides an overview of a Polkit authentication bypass vulnerability that allows for local privilege escalation.
MD5 |
67a1833abd27b15afafc5374cc1c064fDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit Authentication Bypass / Local Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
This document aims at explaining some recent vulnerabilities in Apache HTTP Server that leads to attacks like path traversal and remote code execution.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
This document aims at explaining some recent vulnerabilities in Apache HTTP Server that leads to attacks like path traversal and remote code execution.
MD5 |
feda936f15f34e868bc723af3bf3cca5Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache HTTP Server 2.4.50 CVE-2021-42013 Exploitation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.