Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is cryptography?
https://cdn-images-1.medium.com/max/600/0*bXtsOi2N7fhou65H.jpg
Cryptography is a method of protecting information and communications through the use of codes so that only those for whom the information…
Continue reading on Medium »
What is cryptography?
https://cdn-images-1.medium.com/max/600/0*bXtsOi2N7fhou65H.jpg
Cryptography is a method of protecting information and communications through the use of codes so that only those for whom the information…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The dynamism of One Time Password (OTP) Authentication
https://cdn-images-1.medium.com/max/1000/0*EipyE8hVDgT6LIlm.jpg
While making shopping online on Amazon Indian portal — I was to log in and follow through with Two Factor Authentication (TFA) process. In…
Continue reading on Medium »
The dynamism of One Time Password (OTP) Authentication
https://cdn-images-1.medium.com/max/1000/0*EipyE8hVDgT6LIlm.jpg
While making shopping online on Amazon Indian portal — I was to log in and follow through with Two Factor Authentication (TFA) process. In…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Broward Health reports a 1.3 million people data breach
https://cdn-images-1.medium.com/max/1384/1*g6Q1do7My4hDdPby_JlEtQ.jpeg
A massive data theft affecting 1,357,879 people has been discovered by the Broward Health public health system. Broward Health is a…
Continue reading on Medium »
Broward Health reports a 1.3 million people data breach
https://cdn-images-1.medium.com/max/1384/1*g6Q1do7My4hDdPby_JlEtQ.jpeg
A massive data theft affecting 1,357,879 people has been discovered by the Broward Health public health system. Broward Health is a…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
GAARA — Offensive Security PG Play
https://cdn-images-1.medium.com/max/2600/1*1bXSXOYw_2GI1P9UvUwR3g.jpeg
“Long time, No see…. NARUTO!!..”
Continue reading on Medium »
GAARA — Offensive Security PG Play
https://cdn-images-1.medium.com/max/2600/1*1bXSXOYw_2GI1P9UvUwR3g.jpeg
“Long time, No see…. NARUTO!!..”
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Simulating the Log4j Exploit to Hack a Server
https://cdn-images-1.medium.com/max/2600/1*owXEaRJGtAEHRFa-Jaa7Xw.jpeg
This proof of concept provides a window into tools like netcat, Docker, and VirtualBox.
Continue reading on Medium »
Simulating the Log4j Exploit to Hack a Server
https://cdn-images-1.medium.com/max/2600/1*owXEaRJGtAEHRFa-Jaa7Xw.jpeg
This proof of concept provides a window into tools like netcat, Docker, and VirtualBox.
Continue reading on Medium »
Accessing GoDaddy internal instance through an email logic bug.
Hey All,Continue reading on Medium »
Read more...
Hey All,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Projeqtor 9.3.1 Cross Site Scripting
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
Projeqtor version 9.3.1 suffers from a persistent cross site scripting vulnerability leveraging an svg file.
MD5 |
Download
# Exploit Title: Projeqtor v9.3.1 Stored XSS / Privilege Escalation
# Exploit Author: Oscar Gutierrez (m4xp0w3r)
# Date: January 4, 2021
# Vendor Homepage: https://www.projeqtor.org/en/
# Software Link: https://www.projeqtor.org/en/product-en/downloads
# Tested on: Ubuntu, LAAMP
# Vendor: Projeqtor
# Version: v9.3.1
# Exploit Description:
Projeqtor version 9.3.1 suffers from a stored XSS vulnerability via SVG file upload. A low level user can upload svg images that contain malicious Javascript. In this way an attacker can escalate privileges and upload a malicious plugin which results in arbitrary code execution in the server hosting the application.
# Steps to reproduce:
Upload the following XML code as an SVG file and change the xlink for a location that you control. Once the administrator user opens the attachment, the Javascript code hosted by the attacker will execute.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Projeqtor 9.3.1 Cross Site Scripting
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
Projeqtor version 9.3.1 suffers from a persistent cross site scripting vulnerability leveraging an svg file.
MD5 |
a0504e54b3a4143120a1026a0d2895d5Download
# Exploit Title: Projeqtor v9.3.1 Stored XSS / Privilege Escalation
# Exploit Author: Oscar Gutierrez (m4xp0w3r)
# Date: January 4, 2021
# Vendor Homepage: https://www.projeqtor.org/en/
# Software Link: https://www.projeqtor.org/en/product-en/downloads
# Tested on: Ubuntu, LAAMP
# Vendor: Projeqtor
# Version: v9.3.1
# Exploit Description:
Projeqtor version 9.3.1 suffers from a stored XSS vulnerability via SVG file upload. A low level user can upload svg images that contain malicious Javascript. In this way an attacker can escalate privileges and upload a malicious plugin which results in arbitrary code execution in the server hosting the application.
# Steps to reproduce:
Upload the following XML code as an SVG file and change the xlink for a location that you control. Once the administrator user opens the attachment, the Javascript code hosted by the attacker will execute.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Projeqtor 9.3.1 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Accessing GoDaddy internal instance through an email logic bug.
https://hector0x.medium.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hector0x.medium.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Accessing GoDaddy internal instance through an email logic bug.
Hey All,