How I was able to find 50+ Cross site scripting(XSS) Security Vulnerabilities on Bugcrowd Public…
https://medium.com/@takshalpentester/how-i-was-able-to-find-50-cross-site-scripting-xss-security-vulnerabilities-on-bugcrowd-public-ba33db2b0ab1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@takshalpentester/how-i-was-able-to-find-50-cross-site-scripting-xss-security-vulnerabilities-on-bugcrowd-public-ba33db2b0ab1?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to find 50+ Cross site scripting(XSS) Security Vulnerabilities on Bugcrowd Public Program?
Hello everyone, I hope by the grace of God everyone who is reading this blog post is doing well and their families during this pandemic…
Hello everyone, I hope by the grace of God everyone who is reading this blog post is doing well and their families during this pandemic…Continue reading on Medium » (https://medium.com/@takshalpentester/how-i-was-able-to-find-50-cross-site-scripting-xss-security-vulnerabilities-on-bugcrowd-public-ba33db2b0ab1?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I was able to find 50+ Cross site scripting(XSS) Security Vulnerabilities on Bugcrowd Public Program?
Hello everyone, I hope by the grace of God everyone who is reading this blog post is doing well and their families during this pandemic…
hacking: security in practice
Hello
Recently a great Australian cricketer Shane Warne died at at young 52 from a heart attack, all over Australian instagram accounts a disgusting person with the name @shanewarnedeservesdeathhaha is mocking his death, I’m just wondering if anyone is able to get his IP address and leak his address or fuck up his internet. Cheers the account
submitted by /u/RevolutionSouthern34
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hello
Recently a great Australian cricketer Shane Warne died at at young 52 from a heart attack, all over Australian instagram accounts a disgusting person with the name @shanewarnedeservesdeathhaha is mocking his death, I’m just wondering if anyone is able to get his IP address and leak his address or fuck up his internet. Cheers the account
submitted by /u/RevolutionSouthern34
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hello
Recently a great Australian cricketer Shane Warne died at at young 52 from a heart attack, all over Australian instagram accounts a disgusting...
hacking: security in practice
How do I update ruby to 2.7+ on kali Linux
Every time I try find a tutorial it’s on everything except kali, macOS, windows legit anything but kali
Anyone know how
submitted by /u/retro_Ztro
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do I update ruby to 2.7+ on kali Linux
Every time I try find a tutorial it’s on everything except kali, macOS, windows legit anything but kali
Anyone know how
submitted by /u/retro_Ztro
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do I update ruby to 2.7+ on kali Linux
Every time I try find a tutorial it’s on everything except kali, macOS, windows legit anything but kali Anyone know how
hacking: security in practice
we can beat putin by trolling him
submitted by /u/throwawaypersec117
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
we can beat putin by trolling him
submitted by /u/throwawaypersec117
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
we can beat putin by trolling him
Posted in r/hacking by u/throwawaypersec117 • 1 point and 0 comments
Hacking on Medium
Termux-Torrent : Download Torrent Movies and Files with Termux
https://cdn-images-1.medium.com/max/600/0*whwaI9HtblsyLqPT
HomeUseful-Tools Termux-Torrent : Download Torrent Movies and Files with Termux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Termux-Torrent : Download Torrent Movies and Files with Termux
https://cdn-images-1.medium.com/max/600/0*whwaI9HtblsyLqPT
HomeUseful-Tools Termux-Torrent : Download Torrent Movies and Files with Termux
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Termux-Torrent : Download Torrent Movies and Files with Termux
HomeUseful-Tools Termux-Torrent : Download Torrent Movies and Files with Termux
Hacking on Medium
Stepping in the Unknown
https://cdn-images-1.medium.com/max/1201/1*GBBIBK8mVeng1xvLQv5iZw.png
There is a say in Cyber security “To stop a hacker, one needs to think like one” and penetration testing is what is all about thinking the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Stepping in the Unknown
https://cdn-images-1.medium.com/max/1201/1*GBBIBK8mVeng1xvLQv5iZw.png
There is a say in Cyber security “To stop a hacker, one needs to think like one” and penetration testing is what is all about thinking the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Stepping in the Unknown
There is a say in Cyber security “To stop a hacker, one needs to think like one” and penetration testing is what is all about thinking the…
Hacking on Medium
How can I determine who owns a domain name
https://cdn-images-1.medium.com/max/602/0*7RNy374ze3OnWEhn
Ever found yourself wondering who owns a particular domain name?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How can I determine who owns a domain name
https://cdn-images-1.medium.com/max/602/0*7RNy374ze3OnWEhn
Ever found yourself wondering who owns a particular domain name?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How can I determine who owns a domain name
Ever found yourself wondering who owns a particular domain name?
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
WMEye - A Post Exploitation Tool That Uses WMI Event Filter And MSBuild Execution For Lateral Movement
https://blogger.googleusercontent.com/img/a/AVvXsEhVUekhyfl8R_dEBxNFTNHCKXteQuSz2CZGIC7roLiaceI5LUkDHclvk838hosVEk0q2SXI9T9Q5gFnMlM3S-ObW5x1a36hEWjplBkb53XCqAm9XzTNmF0nl4JmTVRLhN0Ec5o1gyhG4K3qkxdAvGaRajrCMx2G6V3_CNOqQKjMgl-AtB5EvVwIi7W8=w640-h232
WMEye is an experimental tool that was developed when exploring about Windows WMI. The tool is developed for performing Lateral Movement using WMI and remote MSBuild Execution. It uploads the encoded/encrypted shellcode into remote targets WMI Class Property, create an event filter that when triggered writes an MSBuild based Payload using a special WMI Class called LogFileEventConsumer and finally executes the payload remotely.
UseCase
Fileless Lateral Movement using WMI, can be used with Cobalt Strike's Execute-Assembly
Note: This is still in experimental stage and no where near to be used in a real engagement.
Current Working
* Creates a Remote WMI Class
* Writes Shellcode as property value to the above created Fake WMI Class
* Creates a WMI Event Filter to trigger on powershell.exe process creation
* On Event Trigger, it Uploads MSBuild Payload into remote system using LogFileEventConsumer (A WMI Consumer type to write Log Files)
* Finally Invoke
The MSBuild Payload fetches encoded shellcode from WMI Class Property, decodes and executes it.
Upcoming Features
* Replace WIN32_Process Create method of invocation with something better
* Add GZIP Compression for Shellcode and XML File Bytes
* Add NTLM PTH Support
* Add CleanUp Functions for removing event filter after the logfileeventconsumer finished writing the MSBuild Payload
Whats Unique in this Project ?
* Uploads the encoded/encrypted shellcode to remote machines WMI property on a Created Fake Class (can maybe tweak to write shellcode into existing class's Property)
* Uses LogFileEventConsumer to upload MSBuild File , instead of relying in spawning Powershell.exe using win32_process Create
Credits
https://www.fireeye.de/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf
Download WMEye
___________________________
@hacking_Attack
@Hacking_Video
WMEye - A Post Exploitation Tool That Uses WMI Event Filter And MSBuild Execution For Lateral Movement
https://blogger.googleusercontent.com/img/a/AVvXsEhVUekhyfl8R_dEBxNFTNHCKXteQuSz2CZGIC7roLiaceI5LUkDHclvk838hosVEk0q2SXI9T9Q5gFnMlM3S-ObW5x1a36hEWjplBkb53XCqAm9XzTNmF0nl4JmTVRLhN0Ec5o1gyhG4K3qkxdAvGaRajrCMx2G6V3_CNOqQKjMgl-AtB5EvVwIi7W8=w640-h232
WMEye is an experimental tool that was developed when exploring about Windows WMI. The tool is developed for performing Lateral Movement using WMI and remote MSBuild Execution. It uploads the encoded/encrypted shellcode into remote targets WMI Class Property, create an event filter that when triggered writes an MSBuild based Payload using a special WMI Class called LogFileEventConsumer and finally executes the payload remotely.
UseCase
Fileless Lateral Movement using WMI, can be used with Cobalt Strike's Execute-Assembly
Note: This is still in experimental stage and no where near to be used in a real engagement.
Current Working
* Creates a Remote WMI Class
* Writes Shellcode as property value to the above created Fake WMI Class
* Creates a WMI Event Filter to trigger on powershell.exe process creation
* On Event Trigger, it Uploads MSBuild Payload into remote system using LogFileEventConsumer (A WMI Consumer type to write Log Files)
* Finally Invoke
Win32_Process Createto call MSbuild remotelyThe MSBuild Payload fetches encoded shellcode from WMI Class Property, decodes and executes it.
Upcoming Features
* Replace WIN32_Process Create method of invocation with something better
* Add GZIP Compression for Shellcode and XML File Bytes
* Add NTLM PTH Support
* Add CleanUp Functions for removing event filter after the logfileeventconsumer finished writing the MSBuild Payload
Whats Unique in this Project ?
* Uploads the encoded/encrypted shellcode to remote machines WMI property on a Created Fake Class (can maybe tweak to write shellcode into existing class's Property)
* Uses LogFileEventConsumer to upload MSBuild File , instead of relying in spawning Powershell.exe using win32_process Create
Credits
https://www.fireeye.de/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf
Download WMEye
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
WMEye - A Post Exploitation Tool That Uses WMI Event Filter And MSBuild Execution For Lateral Movement
Hats Finance Opens New Bug Bounty Program with Fuji DAO
About Fuji DAOContinue reading on Medium »
Read more...
About Fuji DAOContinue reading on Medium »
Read more...
Hats Finance Opens New Bug Bounty Program with Fuji DAO
https://hatsfinance.medium.com/hats-finance-opens-new-bug-bounty-program-with-fuji-dao-7578b1ef5511?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/hats-finance-opens-new-bug-bounty-program-with-fuji-dao-7578b1ef5511?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hats Finance Opens New Bug Bounty Program with Fuji DAO
About Fuji DAO
About Fuji DAOContinue reading on Medium » (https://hatsfinance.medium.com/hats-finance-opens-new-bug-bounty-program-with-fuji-dao-7578b1ef5511?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hats Finance Opens New Bug Bounty Program with Fuji DAO
About Fuji DAO
Optimism Infinite Money Duplication Bugfix Review
https://medium.com/immunefi/optimism-infinite-money-duplication-bugfix-review-daa6597146a0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/optimism-infinite-money-duplication-bugfix-review-daa6597146a0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Optimism Infinite Money Duplication Bugfix Review
Summary
SummaryContinue reading on Immunefi » (https://medium.com/immunefi/optimism-infinite-money-duplication-bugfix-review-daa6597146a0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Optimism Infinite Money Duplication Bugfix Review
Summary