Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Composr 10.0.36 Shell Upload
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
Composr version 10.0.36 suffers from a remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Composr 10.0.36 Shell Upload
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
Composr version 10.0.36 suffers from a remote shell upload vulnerability.
MD5 |
735eb24f76261ce2e85c105910c3e39cDownload
# Exploit Title: Composr 10.0.36 - Remote Code Execution
# Date: 04/06/2021
# Exploit Author: Orion Hridoy
# Vendor Homepage: https://compo.sr/
# Software Link: https://compo.sr/download.htm
# Version: 10.0.36
# Tested on: Windows/Linux
# CVE : CVE-2021-30149
A RCE on Composr CMS has been discovered by BugsBD Private LTD. We have a galleries security issue which allows us to upload a PHP file. Whenever we upload an image from galleries, Composr allows us to upload only images. If we tried to upload a PHP file from galleries uploader it will say someone attempting hacking activities. But we have a security issue on the Upload In Bulk section. Whenever we check allowed extension in Upload in bulk function we can see PHP is completely prohibited. But whenever we tamper the request and change the extension we can see it will upload the PHP file without other or server side verification. This allows a user to upload malicious file even when they restricted it.
Steps To Reproduce:
1. Go to upload galleries.
2. Upload a image and tamper the request and change the extension from .jpg to .php
3. It will say hacking attempts, check the allowed extension and you can see it's not accepting PHP extension.
4. Now go to upload in bulk option.
5. Upload a image with PHP codes and tamper the request.
6. Change extension from .jpg to .php
7. It will get uploaded with the blocked PHP extension.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Handcuffs Over AI: Solving Security Challenges With Law Enforcement
We've tried everything else ... now it's time to make the prospect of getting caught -- and punished -- a real deterrent to cybercrime.
Handcuffs Over AI: Solving Security Challenges With Law Enforcement
We've tried everything else ... now it's time to make the prospect of getting caught -- and punished -- a real deterrent to cybercrime.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Kics : Find Security Vulnerabilities & Compliance Issues
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx. KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project. Supported Platforms Support of other solutions and additional cloud providers are on the roadmap. […]
The post Kics : Find Security Vulnerabilities & Compliance Issues appeared first on Kali Linux Tutorials.
Kics : Find Security Vulnerabilities & Compliance Issues
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx. KICS stands for Keeping Infrastructure as Code Secure, it is open source and is a must-have for any cloud native project. Supported Platforms Support of other solutions and additional cloud providers are on the roadmap. […]
The post Kics : Find Security Vulnerabilities & Compliance Issues appeared first on Kali Linux Tutorials.
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
HOW I GOT MY NAME IN BBC’S HALL OF FAME
https://cdn-images-1.medium.com/max/600/1*HQmIX9n4miVy5j8FTvtWsA.gif
Hi Everyone, Hope you all are doing well and hunting bugs ;)
Continue reading on Medium »
HOW I GOT MY NAME IN BBC’S HALL OF FAME
https://cdn-images-1.medium.com/max/600/1*HQmIX9n4miVy5j8FTvtWsA.gif
Hi Everyone, Hope you all are doing well and hunting bugs ;)
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Virtual Servers are vulnerable to exploitation
https://cdn-images-1.medium.com/max/1200/1*H880iByZ7oETOM_2y-IfpQ.jpeg
Companies are working with petabytes of data every day. This data is collected across thousands of inputs from questionnaires to cookies…
Continue reading on Shadowscape »
How Virtual Servers are vulnerable to exploitation
https://cdn-images-1.medium.com/max/1200/1*H880iByZ7oETOM_2y-IfpQ.jpeg
Companies are working with petabytes of data every day. This data is collected across thousands of inputs from questionnaires to cookies…
Continue reading on Shadowscape »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Algunas reflexiones sobre filosofía
https://cdn-images-1.medium.com/max/2600/1*UKXnPGs-jKN_HNztxx1XeA.jpeg
Artículo sobre algunas reflexiones de temas filosóficos como el tiempo, la muerte, el equilibrio, el poder y la libertad.
Continue reading on Medium »
Algunas reflexiones sobre filosofía
https://cdn-images-1.medium.com/max/2600/1*UKXnPGs-jKN_HNztxx1XeA.jpeg
Artículo sobre algunas reflexiones de temas filosóficos como el tiempo, la muerte, el equilibrio, el poder y la libertad.
Continue reading on Medium »
Iran’s APT34 Returns with an Updated Arsenal
https://www.reddit.com/r/redteamsec/comments/mmz48y/irans_apt34_returns_with_an_updated_arsenal/
submitted by /u/malware_bender (https://www.reddit.com/user/malware_bender)
[link] (https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/) [comments] (https://www.reddit.com/r/redteamsec/comments/mmz48y/irans_apt34_returns_with_an_updated_arsenal/)
https://www.reddit.com/r/redteamsec/comments/mmz48y/irans_apt34_returns_with_an_updated_arsenal/
submitted by /u/malware_bender (https://www.reddit.com/user/malware_bender)
[link] (https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/) [comments] (https://www.reddit.com/r/redteamsec/comments/mmz48y/irans_apt34_returns_with_an_updated_arsenal/)
Deep Web
forex trader
Does anyone know a forum link, community on the deepweb about forex trader?
submitted by /u/Trader_Kamikaze
[link] [comments]
forex trader
Does anyone know a forum link, community on the deepweb about forex trader?
submitted by /u/Trader_Kamikaze
[link] [comments]
reddit
forex trader
**Does anyone know a forum link, community on the deepweb about forex trader?**
hacking: security in practice
I would like to scrape all posts in a subreddit?
I’d like to compile all the “Jim Cramer does xxxxxxx xxx” comments in /gme
Reason: pure gold comments
This is my first hack, I am inspired
P.S, Jim Cramer eats cereal with water instead of milk.
Please halp.
submitted by /u/SasquatchAquatica
[link] [comments]
I would like to scrape all posts in a subreddit?
I’d like to compile all the “Jim Cramer does xxxxxxx xxx” comments in /gme
Reason: pure gold comments
This is my first hack, I am inspired
P.S, Jim Cramer eats cereal with water instead of milk.
Please halp.
submitted by /u/SasquatchAquatica
[link] [comments]
reddit
I would like to scrape all posts in a subreddit?
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
Wifi Deauth
I’m sorry if this is a dumb question but let’s say I know the password of Wifi-A but not Wifi-B. Can I use a deauth attack via Kali Linux on both Wifi-A and Wifi-B or just Wifi-A?
Basically do I need to be connected to the wifi that I want to kick devices off of?
submitted by /u/Imamassivedickhead
[link] [comments]
Wifi Deauth
I’m sorry if this is a dumb question but let’s say I know the password of Wifi-A but not Wifi-B. Can I use a deauth attack via Kali Linux on both Wifi-A and Wifi-B or just Wifi-A?
Basically do I need to be connected to the wifi that I want to kick devices off of?
submitted by /u/Imamassivedickhead
[link] [comments]
reddit
Wifi Deauth
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
hacking: security in practice
If You Had $300 to $400 To Burn What Learning Stuff Would You Spend It On?
I have about $400 to burn on learning material. What would you spend it on?
So far I am going to get HackTheBox membership and TryHackMe subscription.
submitted by /u/jrosend963
[link] [comments]
If You Had $300 to $400 To Burn What Learning Stuff Would You Spend It On?
I have about $400 to burn on learning material. What would you spend it on?
So far I am going to get HackTheBox membership and TryHackMe subscription.
submitted by /u/jrosend963
[link] [comments]
reddit
If You Had $300 to $400 To Burn What Learning Stuff Would You...
A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits, industry standards, grey and white hat...
Max - Maximizing BloodHound
http://www.kitploit.com/2021/04/max-maximizing-bloodhound.html
http://www.kitploit.com/2021/04/max-maximizing-bloodhound.html