Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cibele Thinfinity VirtualUI 2.5.41.0 User Enumeration
https://2.bp.blogspot.com/-y5QhCp_hFKM/WWlvahEOH0I/AAAAAAAAIPA/Q0VQ49Z0hVw4skegRDdSXm3Bk15Ptyg5wCLcBGAs/s1600/h70.png
Cibele Thinfinity VirtualUI version 2.5.41.0 suffers from a user enumeration vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Cibele Thinfinity VirtualUI 2.5.41.0 User Enumeration
https://2.bp.blogspot.com/-y5QhCp_hFKM/WWlvahEOH0I/AAAAAAAAIPA/Q0VQ49Z0hVw4skegRDdSXm3Bk15Ptyg5wCLcBGAs/s1600/h70.png
Cibele Thinfinity VirtualUI version 2.5.41.0 suffers from a user enumeration vulnerability.
MD5 |
075e1c749825a41f790a7703ee3dc388Download
# Exploit Title: Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
# Date: 13/12/2021
# Exploit Author: Daniel Morales, IT Security Team - ARHS Spikeseed
# Vendor Homepage: https://www.cybelesoft.com
# Software Link: https://www.cybelesoft.com/thinfinity/virtualui/
# Version: vulnerable < v3.0
# Tested on: Microsoft Windows
# CVE: CVE-2021-44848
How it works: By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest...
Payload: The vulnerable vector is "https://example.com/changePassword?username=USERNAME" where "USERNAME" need to be brute-forced.
Reference: https://github.com/cybelesoft/virtualui/issues/1
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Cibele Thinfinity VirtualUI 2.5.41.0 User Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome blink::NativeIOFile::DoRead Heap Use-After-Free
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
Chrome suffers from a heap use-after-free vulnerability in blink::NativeIOFile::DoRead.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome blink::NativeIOFile::DoRead Heap Use-After-Free
https://1.bp.blogspot.com/-9u0QXe9ybeo/WWlvU_DnejI/AAAAAAAAIN0/BUl-HrIsuwE3sKywG67Nuv_wLRABID6oQCLcBGAs/s1600/h45.png
Chrome suffers from a heap use-after-free vulnerability in blink::NativeIOFile::DoRead.
MD5 |
e51b3f4d20f95cd97c31e2cfc01a4df7Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome blink::NativeIOFile::DoRead Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome ThreadedIconLoader::DecodeAndResizeImageOnBackgroundThread Heap Use-After-Free
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Chrome suffers from a heap use-after-free vulnerability in ThreadedIconLoader::DecodeAndResizeImageOnBackgroundThread.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome ThreadedIconLoader::DecodeAndResizeImageOnBackgroundThread Heap Use-After-Free
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Chrome suffers from a heap use-after-free vulnerability in ThreadedIconLoader::DecodeAndResizeImageOnBackgroundThread.
MD5 |
970ce6283c7d9f02e474b4ef93003566Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome ThreadedIconLoader::DecodeAndResizeImageOnBackgroundThread Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome NavigationPreloadRequest Site Isolation Bypass
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Chrome suffers from a site isolation bypass vulnerability in NavigationPreloadRequest.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome NavigationPreloadRequest Site Isolation Bypass
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Chrome suffers from a site isolation bypass vulnerability in NavigationPreloadRequest.
MD5 |
79cec0e9bbab06da069bc3e1a41127e4Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome NavigationPreloadRequest Site Isolation Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
HTTP VERB TAMPERING:
https://haxor8595.medium.com/http-verb-tampering-ec69d91c7d5b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://haxor8595.medium.com/http-verb-tampering-ec69d91c7d5b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTTP VERB TAMPERING:
HTTP Verb Altering is an assault that misuses vulnerabilities in HTTP verb (too known as HTTP strategy) verification and gets to control…
HTTP Verb Altering is an assault that misuses vulnerabilities in HTTP verb (too known as HTTP strategy) verification and gets to control…Continue reading on Medium » (https://haxor8595.medium.com/http-verb-tampering-ec69d91c7d5b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTTP VERB TAMPERING:
HTTP Verb Altering is an assault that misuses vulnerabilities in HTTP verb (too known as HTTP strategy) verification and gets to control…
User Enumeration- Forgot Password #VDP
https://haxor8595.medium.com/user-enumeration-forgot-password-vdp-1f073875634e?source=rss------bug_bounty-5
User Enumeration:Continue reading on Medium » (https://haxor8595.medium.com/user-enumeration-forgot-password-vdp-1f073875634e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://haxor8595.medium.com/user-enumeration-forgot-password-vdp-1f073875634e?source=rss------bug_bounty-5
User Enumeration:Continue reading on Medium » (https://haxor8595.medium.com/user-enumeration-forgot-password-vdp-1f073875634e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
User Enumeration- Forgot Password #VDP
User Enumeration:
Intro to Cryptography and Signatures in Ethereum
Everyone who has ever dealt with a blockchain system like Ethereum knows what blockchain consists of, such as blocks, transactions, and…Continue reading on Immunefi »
Read more...
Everyone who has ever dealt with a blockchain system like Ethereum knows what blockchain consists of, such as blocks, transactions, and…Continue reading on Immunefi »
Read more...
HTTP VERB TAMPERING:
HTTP Verb Altering is an assault that misuses vulnerabilities in HTTP verb (too known as HTTP strategy) verification and gets to control…Continue reading on Medium »
Read more...
HTTP Verb Altering is an assault that misuses vulnerabilities in HTTP verb (too known as HTTP strategy) verification and gets to control…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Un nuevo malware sin archivos utiliza el registro de Windows como almacenamiento para evadir la…
https://cdn-images-1.medium.com/max/1123/0*cFmUshgZ7prwpFsM
PUBLICADO EN 16 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Un nuevo malware sin archivos utiliza el registro de Windows como almacenamiento para evadir la…
https://cdn-images-1.medium.com/max/1123/0*cFmUshgZ7prwpFsM
PUBLICADO EN 16 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Un nuevo malware sin archivos utiliza el registro de Windows como almacenamiento para evadir la detección
PUBLICADO EN 16 DICIEMBRE, 2021POR DPAB
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Testing Cloud (AWS & Azure) WAF Capabilities Against log4shell(CVE-2021–44228)
https://cdn-images-1.medium.com/max/1962/1*FbYV2McEMnatKRxYCubhaA.png
Log4j shell or Log4Shell or LogJam[CVE-2021–44228] is a zero day that allows hackers to execute remote code execution(RCE). It exploits…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Testing Cloud (AWS & Azure) WAF Capabilities Against log4shell(CVE-2021–44228)
https://cdn-images-1.medium.com/max/1962/1*FbYV2McEMnatKRxYCubhaA.png
Log4j shell or Log4Shell or LogJam[CVE-2021–44228] is a zero day that allows hackers to execute remote code execution(RCE). It exploits…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Testing Cloud (AWS & Azure) WAF Capabilities Against log4shell(CVE-2021–44228)
Log4j shell or Log4Shell or LogJam[CVE-2021–44228] is a zero day that allows hackers to execute remote code execution(RCE). It exploits…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
eJPT Review
https://cdn-images-1.medium.com/max/1200/1*8EfM03QNO2wBnBNApUraEA.png
Course
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
eJPT Review
https://cdn-images-1.medium.com/max/1200/1*8EfM03QNO2wBnBNApUraEA.png
Course
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
eJPT Review
Course
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internal — OSCP Offensive security proving grounds (practice, easy)
This is a walkthrough for Offensive Security’s internal box on their paid subscription service, Proving Grounds.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internal — OSCP Offensive security proving grounds (practice, easy)
This is a walkthrough for Offensive Security’s internal box on their paid subscription service, Proving Grounds.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internal — OSCP Offensive security proving grounds (practice, easy)
This is a walkthrough for Offensive Security’s internal box on their paid subscription service, Proving Grounds.