Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Broward Health reports a 1.3 million people data breach
https://cdn-images-1.medium.com/max/1384/1*g6Q1do7My4hDdPby_JlEtQ.jpeg
A massive data theft affecting 1,357,879 people has been discovered by the Broward Health public health system. Broward Health is a…
Continue reading on Medium »
Broward Health reports a 1.3 million people data breach
https://cdn-images-1.medium.com/max/1384/1*g6Q1do7My4hDdPby_JlEtQ.jpeg
A massive data theft affecting 1,357,879 people has been discovered by the Broward Health public health system. Broward Health is a…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
GAARA — Offensive Security PG Play
https://cdn-images-1.medium.com/max/2600/1*1bXSXOYw_2GI1P9UvUwR3g.jpeg
“Long time, No see…. NARUTO!!..”
Continue reading on Medium »
GAARA — Offensive Security PG Play
https://cdn-images-1.medium.com/max/2600/1*1bXSXOYw_2GI1P9UvUwR3g.jpeg
“Long time, No see…. NARUTO!!..”
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Simulating the Log4j Exploit to Hack a Server
https://cdn-images-1.medium.com/max/2600/1*owXEaRJGtAEHRFa-Jaa7Xw.jpeg
This proof of concept provides a window into tools like netcat, Docker, and VirtualBox.
Continue reading on Medium »
Simulating the Log4j Exploit to Hack a Server
https://cdn-images-1.medium.com/max/2600/1*owXEaRJGtAEHRFa-Jaa7Xw.jpeg
This proof of concept provides a window into tools like netcat, Docker, and VirtualBox.
Continue reading on Medium »
Accessing GoDaddy internal instance through an email logic bug.
Hey All,Continue reading on Medium »
Read more...
Hey All,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Projeqtor 9.3.1 Cross Site Scripting
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
Projeqtor version 9.3.1 suffers from a persistent cross site scripting vulnerability leveraging an svg file.
MD5 |
Download
# Exploit Title: Projeqtor v9.3.1 Stored XSS / Privilege Escalation
# Exploit Author: Oscar Gutierrez (m4xp0w3r)
# Date: January 4, 2021
# Vendor Homepage: https://www.projeqtor.org/en/
# Software Link: https://www.projeqtor.org/en/product-en/downloads
# Tested on: Ubuntu, LAAMP
# Vendor: Projeqtor
# Version: v9.3.1
# Exploit Description:
Projeqtor version 9.3.1 suffers from a stored XSS vulnerability via SVG file upload. A low level user can upload svg images that contain malicious Javascript. In this way an attacker can escalate privileges and upload a malicious plugin which results in arbitrary code execution in the server hosting the application.
# Steps to reproduce:
Upload the following XML code as an SVG file and change the xlink for a location that you control. Once the administrator user opens the attachment, the Javascript code hosted by the attacker will execute.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Projeqtor 9.3.1 Cross Site Scripting
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
Projeqtor version 9.3.1 suffers from a persistent cross site scripting vulnerability leveraging an svg file.
MD5 |
a0504e54b3a4143120a1026a0d2895d5Download
# Exploit Title: Projeqtor v9.3.1 Stored XSS / Privilege Escalation
# Exploit Author: Oscar Gutierrez (m4xp0w3r)
# Date: January 4, 2021
# Vendor Homepage: https://www.projeqtor.org/en/
# Software Link: https://www.projeqtor.org/en/product-en/downloads
# Tested on: Ubuntu, LAAMP
# Vendor: Projeqtor
# Version: v9.3.1
# Exploit Description:
Projeqtor version 9.3.1 suffers from a stored XSS vulnerability via SVG file upload. A low level user can upload svg images that contain malicious Javascript. In this way an attacker can escalate privileges and upload a malicious plugin which results in arbitrary code execution in the server hosting the application.
# Steps to reproduce:
Upload the following XML code as an SVG file and change the xlink for a location that you control. Once the administrator user opens the attachment, the Javascript code hosted by the attacker will execute.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Projeqtor 9.3.1 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Accessing GoDaddy internal instance through an email logic bug.
https://hector0x.medium.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hector0x.medium.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Accessing GoDaddy internal instance through an email logic bug.
Hey All,
Hey All,Continue reading on Medium » (https://hector0x.medium.com/accessing-godaddy-internal-instance-through-an-email-logic-bug-fdbea7b23542?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Accessing GoDaddy internal instance through an email logic bug.
Hey All,
https://a.thumbs.redditmedia.com/cYpNlfVVdTkrl8n-dBs9bKqW2gcLSwN6jHtOsAq3kv4.jpg I've been trying to change the name of an application's name in the task manager but how do I do it? I've tried doing it with resource hacker, and also I've tried doing it with visual studio code, but it still displays like this. Also is there any program or app that can do this?
https://preview.redd.it/e0j73c5ojp981.png?width=294&format=png&auto=webp&s=c8592f5dde3af51212f043ad6492fd99a89f3516
submitted by /u/BenDahGreat
[link] [comments]
https://preview.redd.it/e0j73c5ojp981.png?width=294&format=png&auto=webp&s=c8592f5dde3af51212f043ad6492fd99a89f3516
submitted by /u/BenDahGreat
[link] [comments]
hacking: security in practice
Software to wardrive for CCTV networks?
For work, I want to map out as many CCTV coverage areas as I can around town. I know many of the residential cameras such as Arlo, Ring and Nest utilize their own wifi network and broadcast the ssid.
I have WiFi Wiggle and it is recording all the networks but is like to be able to filter them out on a map for only the CCTV networks.
Anyone know if this is possible?
submitted by /u/SkippyBoJangles
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Software to wardrive for CCTV networks?
For work, I want to map out as many CCTV coverage areas as I can around town. I know many of the residential cameras such as Arlo, Ring and Nest utilize their own wifi network and broadcast the ssid.
I have WiFi Wiggle and it is recording all the networks but is like to be able to filter them out on a map for only the CCTV networks.
Anyone know if this is possible?
submitted by /u/SkippyBoJangles
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Software to wardrive for CCTV networks?
For work, I want to map out as many CCTV coverage areas as I can around town. I know many of the residential cameras such as Arlo, Ring and Nest...