Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Master_Librarian : A Tool To Audit Unix/*BSD/Linux System Libraries To Find Public Security Vulnerabilities Master_Librarian is a simple tool to audit Unix/*BSD/Linux system libraries to find public security vulnerabilities. To install…
8.39
ruby-2.7 2.7.0
glib-2.0 2.64.6
gnome-system-tools 3.0.0
xinerama 1.1.4
nunit 2.6.3
gmp 6.2.0
libevent 2.1.11-stable
xbuild12 12.0
xorg-sgml-doctools 1.11
presentproto 1.2
gdk-pixbuf-2.0 2.40.0
inputproto 2.3.2
libssl 1.1.1f
xcb-shm 1.14
gdk-2.0 2.24.32
libpng16 1.6.37
bigreqsproto 1.1.2
icu-io 66.1
xextproto 7.3.0
libthai 0.1.28
libbsd-overlay 0.10.0
mount 2.34.0
gio-2.0 2.64.6
adwaita-icon-theme 3.36.1
fontconfig 2.13.1
xrandr 1.5.2
monosgen-2 6.8.0.105
mono 6.8.0.105
xf86dgaproto 2.1
dri3proto 1.2
libpcre 8.39
pangoxft 1.44.7
blkid 2.34.0
libsepol 3.0
libevent_openssl 2.1.11-stable
uuid 2.34.0
gmodule-2.0 2.64.6
graphite2 3.0.1
libfl 2.6.4
zlib 1.2.11
cairo-pdf 1.16.0
ruby 2.7.0
Addressable is an alternative implementation to the URI implementation that is part of Ruby’s standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected. The vulnerability is patched in version 2.8.0. As a workaround, only create Template objects from trusted sources that have been validated not to produce catastrophic backtracking.
https://nvd.nist.gov/vuln/detail/CVE-2021-32740
5.0 MEDIUM
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.
https://nvd.nist.gov/vuln/detail/CVE-2020-10933
5.0 MEDIUM
libevent_extra 2.1.11-stable
system.web.mvc3 3.0.0.0
libstartup-notification-1.0 0.12
mono-2 6.8.0.105
mono-nunit 2.6.3
gobject-2.0 2.64.6
glproto 1.4.17
cairo-ft 1.16.0
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit’s fastMalloc, leading to an application crash with a “free(): invalid pointer” error.
https://nvd.nist.gov/vuln/detail/CVE-2018-19876
4.3 MEDIUM
xcb 1.14
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application’s unrestricted use of the render method and providing a .. (dot dot) in a pathname.
https://nvd.nist.gov/vuln/detail/CVE-2016-0752
5.0 MEDIUM
fribidi 1.0.8
xtrans 1.4.0
cairo-xlib-xrender 1.16.0
mono-lineeditor 0.2.1
xcmiscproto 1.2.2
gmodule-no-export-2.0 2.64.6
dri2proto 2.8
python3-embed 3.8
libpcre32 8.39
system.web.mvc2 2.0.0.0
dotnet 6.8.0.105
iso-codes 4.4
fontutil 1.3.1
xbitmaps 1.1.1
system.web.extensions_1.0 1.0.61025.0
recordproto 1.14.2
resourceproto 1.2.0
mobile-broadband-provider-info 20190618
videoproto 2.3.3
libevent_core 2.1.11-stable
fontsproto 2.1.3
xsp-4 4.2
python3 3.8
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.
https://nvd.nist.gov/vuln/detail/CVE-2020-15801
7.5 HIGH
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue C[...]
___________________________
@hacking_Attack
@Hacking_Video
ruby-2.7 2.7.0
glib-2.0 2.64.6
gnome-system-tools 3.0.0
xinerama 1.1.4
nunit 2.6.3
gmp 6.2.0
libevent 2.1.11-stable
xbuild12 12.0
xorg-sgml-doctools 1.11
presentproto 1.2
gdk-pixbuf-2.0 2.40.0
inputproto 2.3.2
libssl 1.1.1f
xcb-shm 1.14
gdk-2.0 2.24.32
libpng16 1.6.37
bigreqsproto 1.1.2
icu-io 66.1
xextproto 7.3.0
libthai 0.1.28
libbsd-overlay 0.10.0
mount 2.34.0
gio-2.0 2.64.6
adwaita-icon-theme 3.36.1
fontconfig 2.13.1
xrandr 1.5.2
monosgen-2 6.8.0.105
mono 6.8.0.105
xf86dgaproto 2.1
dri3proto 1.2
libpcre 8.39
pangoxft 1.44.7
blkid 2.34.0
libsepol 3.0
libevent_openssl 2.1.11-stable
uuid 2.34.0
gmodule-2.0 2.64.6
graphite2 3.0.1
libfl 2.6.4
zlib 1.2.11
cairo-pdf 1.16.0
ruby 2.7.0
Addressable is an alternative implementation to the URI implementation that is part of Ruby’s standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected. The vulnerability is patched in version 2.8.0. As a workaround, only create Template objects from trusted sources that have been validated not to produce catastrophic backtracking.
https://nvd.nist.gov/vuln/detail/CVE-2021-32740
5.0 MEDIUM
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buffer, exception: false), the method resizes the buffer to fit the requested size, but no data is copied. Thus, the buffer string provides the previous value of the heap. This may expose possibly sensitive data from the interpreter.
https://nvd.nist.gov/vuln/detail/CVE-2020-10933
5.0 MEDIUM
libevent_extra 2.1.11-stable
system.web.mvc3 3.0.0.0
libstartup-notification-1.0 0.12
mono-2 6.8.0.105
mono-nunit 2.6.3
gobject-2.0 2.64.6
glproto 1.4.17
cairo-ft 1.16.0
cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit’s fastMalloc, leading to an application crash with a “free(): invalid pointer” error.
https://nvd.nist.gov/vuln/detail/CVE-2018-19876
4.3 MEDIUM
xcb 1.14
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application’s unrestricted use of the render method and providing a .. (dot dot) in a pathname.
https://nvd.nist.gov/vuln/detail/CVE-2016-0752
5.0 MEDIUM
fribidi 1.0.8
xtrans 1.4.0
cairo-xlib-xrender 1.16.0
mono-lineeditor 0.2.1
xcmiscproto 1.2.2
gmodule-no-export-2.0 2.64.6
dri2proto 2.8
python3-embed 3.8
libpcre32 8.39
system.web.mvc2 2.0.0.0
dotnet 6.8.0.105
iso-codes 4.4
fontutil 1.3.1
xbitmaps 1.1.1
system.web.extensions_1.0 1.0.61025.0
recordproto 1.14.2
resourceproto 1.2.0
mobile-broadband-provider-info 20190618
videoproto 2.3.3
libevent_core 2.1.11-stable
fontsproto 2.1.3
xsp-4 4.2
python3 3.8
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.
https://nvd.nist.gov/vuln/detail/CVE-2020-15801
7.5 HIGH
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue C[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
8.39 ruby-2.7 2.7.0 glib-2.0 2.64.6 gnome-system-tools 3.0.0 xinerama 1.1.4 nunit 2.6.3 gmp 6.2.0 libevent 2.1.11-stable xbuild12 12.0 xorg-sgml-doctools 1.11 presentproto 1.2 gdk-pixbuf-2.0 2.40.0 inputproto 2.3.2 libssl 1.1.1f xcb-shm 1.14 gdk-2.0 2.24.32…
ANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.
https://nvd.nist.gov/vuln/detail/CVE-2020-15523
6.9 MEDIUM
xineramaproto 1.2.1
xcb-render 1.14
libpcre2-32 10.34
libbsd-ctor 0.10.0
libbsd 0.10.0
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
https://nvd.nist.gov/vuln/detail/CVE-2019-20367
6.4 MEDIUM
xft 2.3.3
Tested in Ubuntu Linux, Fedora Linux and FreeBSD.
The purpose of this tool is to use in local pentest, take attention if you have a proper authorization before to use that. I do not have responsibility for your actions. You can use a hammer to construct a house or destroy it, choose the law path, don’t be a bad guy, remember. Download
___________________________
@hacking_Attack
@Hacking_Video
https://nvd.nist.gov/vuln/detail/CVE-2020-15523
6.9 MEDIUM
xineramaproto 1.2.1
xcb-render 1.14
libpcre2-32 10.34
libbsd-ctor 0.10.0
libbsd 0.10.0
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
https://nvd.nist.gov/vuln/detail/CVE-2019-20367
6.4 MEDIUM
xft 2.3.3
Tested in Ubuntu Linux, Fedora Linux and FreeBSD.
The purpose of this tool is to use in local pentest, take attention if you have a proper authorization before to use that. I do not have responsibility for your actions. You can use a hammer to construct a house or destroy it, choose the law path, don’t be a bad guy, remember. Download
___________________________
@hacking_Attack
@Hacking_Video
Hacking on Medium
TryHackMe: Kenobi
https://cdn-images-1.medium.com/max/600/1*_RwlH99OQZGZtCpRQsd0CA.jpeg
Task 1: Deploy the vulnerable machine
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Kenobi
https://cdn-images-1.medium.com/max/600/1*_RwlH99OQZGZtCpRQsd0CA.jpeg
Task 1: Deploy the vulnerable machine
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Kenobi
Task 1: Deploy the vulnerable machine
Hacking on Medium
IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles
https://cdn-images-1.medium.com/max/1335/1*txwAxko-DnEO37W3t8Z4FQ.png
Hello friends :)
I am happy to write a blog again after finding an Insecure Direct Object Reference Vulnerability in Drexel University…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles
https://cdn-images-1.medium.com/max/1335/1*txwAxko-DnEO37W3t8Z4FQ.png
Hello friends :)
I am happy to write a blog again after finding an Insecure Direct Object Reference Vulnerability in Drexel University…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
IDOR (Insecure Direct Object Reference) leads to listing all valid Users and edit their Profiles
Hello friends :) I am happy to write a blog again after finding an Insecure Direct Object Reference Vulnerability in Drexel University…
Hacking on Medium
Resources & Learning Paths collections (Part-2)
https://cdn-images-1.medium.com/max/1280/0*W3Z5B9Xsg9QGaJuJ
This is Part 2 where we talk about Github Repositories which helps you to know about the Cybersecurity and other stuffs.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Resources & Learning Paths collections (Part-2)
https://cdn-images-1.medium.com/max/1280/0*W3Z5B9Xsg9QGaJuJ
This is Part 2 where we talk about Github Repositories which helps you to know about the Cybersecurity and other stuffs.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Resources & Learning Paths collections (Part-2)
This is Part 2 where we talk about Github Repositories which helps you to know about the Cybersecurity and other stuffs.
Build a SOC LAB
https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/
Hey guys! I have a project where i need to build a LAB for a SOC (security operation center) with infra as code (vagrant) and then launch some attacks on it and investigate their behavior's with Splunk. So i would like from peoples that already worked or have expérience in this, if you Can recommand some good ressources that will help me see some examples of SOC architectures that i Can deploy and some interesting attacks to investigate. Cheers submitted by /u/Adel_Maestro (https://www.reddit.com/user/Adel_Maestro)
[link] (https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/
Hey guys! I have a project where i need to build a LAB for a SOC (security operation center) with infra as code (vagrant) and then launch some attacks on it and investigate their behavior's with Splunk. So i would like from peoples that already worked or have expérience in this, if you Can recommand some good ressources that will help me see some examples of SOC architectures that i Can deploy and some interesting attacks to investigate. Cheers submitted by /u/Adel_Maestro (https://www.reddit.com/user/Adel_Maestro)
[link] (https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/u1x0bs/build_a_soc_lab/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Build a SOC LAB
Hey guys! I have a project where i need to build a LAB for a SOC (security operation center) with infra as code (vagrant) and then launch some...
XSS - The LocalStorage Robbery
https://shahjerry33.medium.com/xss-the-localstorage-robbery-d5fbf353c6b0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://shahjerry33.medium.com/xss-the-localstorage-robbery-d5fbf353c6b0?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS - The LocalStorage Robbery
Summary :
Summary :Continue reading on Medium » (https://shahjerry33.medium.com/xss-the-localstorage-robbery-d5fbf353c6b0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
XSS - The LocalStorage Robbery
Summary :
Immunefi Matching Bug Bounty Program: Renewal and Expansion
https://medium.com/nexus-mutual/immunefi-matching-bug-bounty-program-renewal-and-expansion-61f820a4275e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/nexus-mutual/immunefi-matching-bug-bounty-program-renewal-and-expansion-61f820a4275e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Immunefi Matching Bug Bounty Program: Renewal and Expansion
Nexus Mutants recently approved the renewal and expansion of the Immunefi matching bug bounty program by a unanimous vote. Funding for the…
Nexus Mutants recently approved the renewal and expansion of the Immunefi matching bug bounty program by a unanimous vote. Funding for the…Continue reading on Nexus Mutual » (https://medium.com/nexus-mutual/immunefi-matching-bug-bounty-program-renewal-and-expansion-61f820a4275e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Immunefi Matching Bug Bounty Program: Renewal and Expansion
Nexus Mutants recently approved the renewal and expansion of the Immunefi matching bug bounty program by a unanimous vote. Funding for the…
Nexus Mutual Community Renews Bounty Matching Program With $600k War Chest
https://medium.com/immunefi/nexus-mutual-community-renews-bounty-matching-program-with-600k-war-chest-1f4f4a5751d2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/immunefi/nexus-mutual-community-renews-bounty-matching-program-with-600k-war-chest-1f4f4a5751d2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nexus Mutual Community Renews Bounty Matching Program With $600k War Chest
The Nexus Mutual community has just voted to continue its bug bounty matching program with Immunefi and increase the size of the war chest…
The Nexus Mutual community has just voted to continue its bug bounty matching program with Immunefi and increase the size of the war chest…Continue reading on Immunefi » (https://medium.com/immunefi/nexus-mutual-community-renews-bounty-matching-program-with-600k-war-chest-1f4f4a5751d2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nexus Mutual Community Renews Bounty Matching Program With $600k War Chest
The Nexus Mutual community has just voted to continue its bug bounty matching program with Immunefi and increase the size of the war chest…
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 3
https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-3-ca2b8e79b918?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-3-ca2b8e79b918?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 3
Hello Medium folk, I hope you enjoyed our previous articles, so now on this article You’ll learn about Types of Cross-Site-Scripting…
Hello Medium folk, I hope you enjoyed our previous articles, so now on this article You’ll learn about Types of Cross-Site-Scripting…Continue reading on Medium » (https://as745591.medium.com/albussec-penetration-list-05-cross-site-scripting-xss-part-3-ca2b8e79b918?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
AlbusSec:- Penetration-List 05 Cross-Site-Scripting (XSS) — Part 3
Hello Medium folk, I hope you enjoyed our previous articles, so now on this article You’ll learn about Types of Cross-Site-Scripting…
CVE-2021–4034 Local privilege escalationContinue reading on Medium » (https://medium.com/@reconshell.com/cve-2021-4034-bd72d4aecfa2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2021–4034
CVE-2021–4034 Local privilege escalation