In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.Continue reading on Medium » (https://corneacristian.medium.com/top-25-subdomain-takeover-bug-bounty-reports-f6e386ba4413?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 25 Subdomain Takeover Bug Bounty Reports
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Coding C2 Bind Shell Channel with C# and Powershell
https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/
https://www.youtube.com/watch?v=9CX7muqkjtQ submitted by /u/luzunov (https://www.reddit.com/user/luzunov)
[link] (https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/) [comments] (https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/
https://www.youtube.com/watch?v=9CX7muqkjtQ submitted by /u/luzunov (https://www.reddit.com/user/luzunov)
[link] (https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/) [comments] (https://www.reddit.com/r/redteamsec/comments/tets6e/coding_c2_bind_shell_channel_with_c_and_powershell/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Coding C2 Bind Shell Channel with C# and Powershell
[https://www.youtube.com/watch?v=9CX7muqkjtQ](https://www.youtube.com/watch?v=9CX7muqkjtQ)
hacking: security in practice
Are key loggers still important and strongly used now a days?
I have a background in the field but haven’t really been in touch due to personal issues but I was jumping back into it and seeing what’s the new tools everyone uses and if key loggers are still a thing. I’m curious to start up again and anything helps. Message me for anything personal!
submitted by /u/Guilty-Following9582
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are key loggers still important and strongly used now a days?
I have a background in the field but haven’t really been in touch due to personal issues but I was jumping back into it and seeing what’s the new tools everyone uses and if key loggers are still a thing. I’m curious to start up again and anything helps. Message me for anything personal!
submitted by /u/Guilty-Following9582
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are key loggers still important and strongly used now a days?
I have a background in the field but haven’t really been in touch due to personal issues but I was jumping back into it and seeing what’s the...
Hacking on Medium
Top 25 Subdomain Takeover Bug Bounty Reports
https://cdn-images-1.medium.com/max/1920/1*GE8U3baA4Y15QSMygJYt6w.png
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 25 Subdomain Takeover Bug Bounty Reports
https://cdn-images-1.medium.com/max/1920/1*GE8U3baA4Y15QSMygJYt6w.png
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 25 Subdomain Takeover Bug Bounty Reports
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Hacking on Medium
Bounty Hacker Tryhackme
https://cdn-images-1.medium.com/max/2600/0*js1nt9cVrM3ibq8-
CTF Writeup
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Bounty Hacker Tryhackme
https://cdn-images-1.medium.com/max/2600/0*js1nt9cVrM3ibq8-
CTF Writeup
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bounty Hacker Tryhackme
CTF Writeup
Hacking on Medium
Yes, your podcast does need a website
https://cdn-images-1.medium.com/max/1600/1*2q4TA1YQftn_0ibJf9R7Og.png
How to stand out from the hobbyists
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Yes, your podcast does need a website
https://cdn-images-1.medium.com/max/1600/1*2q4TA1YQftn_0ibJf9R7Og.png
How to stand out from the hobbyists
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Yes, your podcast does need a website
How to stand out from the hobbyists
Hacking on Medium
TryHackMe ‘Ignite’ Room Walkthrough
https://cdn-images-1.medium.com/max/877/1*j0rUxUSbWiA5s5oqAL4ZYg.png
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe ‘Ignite’ Room Walkthrough
https://cdn-images-1.medium.com/max/877/1*j0rUxUSbWiA5s5oqAL4ZYg.png
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe ‘Ignite’ Room Walkthrough
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Hacking on Medium
HTB: Poison Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/800/0*gw220D_f4gAIvS-l
Let’s skip the introduction and jump right into the writeup.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
HTB: Poison Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/800/0*gw220D_f4gAIvS-l
Let’s skip the introduction and jump right into the writeup.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTB: Poison Writeup w/o Metasploit
Let’s skip the introduction and jump right into the writeup.
Hacking on Medium
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
https://cdn-images-1.medium.com/max/1755/0*QVsP7IsIpwJOmo_W
PUBLICADO EN 15 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
https://cdn-images-1.medium.com/max/1755/0*QVsP7IsIpwJOmo_W
PUBLICADO EN 15 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
PUBLICADO EN 15 MARZO, 2022POR EHACKING
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
How I managed to trigger XSS automatically to get critical account takeover
https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium » (https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
0d24d3675c92cd6b4566d20cd36be0d8Download
# Exploit Title: College Website Management System 1.0 - SQL Injection
# Date: 12/03/2022
# Exploit Author: Mr Empy
# Software Link:
https://www.sourcecodester.com/php/15203/college-website-content-management-system-phpoop-free-source-code.html
# Version: 1.0
# Tested on: Linux
Title:
================
College Website Management System 1.0 - SQL Injection
Summary:
================
The College Website Management System application in version 1.0 is
vulnerable to SQL injection allowing the attacker to make requests to the
database.
Severity Level:
================
9.1 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Product:
================
College Website Management System v1.0
Steps to Reproduce:
================
1. Open your browser and go to
http://target/cwms/admin/?page=articles/view_article&id=1.
2. In the "id" parameter add the following payload:
' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc
After that, the server will only respond after 10 seconds have passed.
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=articles/view_article&id=1' AND (SELECT 2016 FROM
(SELECT(SLEEP(5)))kbJu) AND 'SfwZ'='SfwZ
---
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
College Website Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
1228b251a7f271fd7da635499b0bd342Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Laravel Media Library Pro 2.1.6 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.