I have 1% chance to hack this company
https://infosecwriteups.com/i-have-1-chance-to-hack-this-company-1044879f41a9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/i-have-1-chance-to-hack-this-company-1044879f41a9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
I have 1% chance to hack this company
Today I will share with you the first vulnerability I found on SerpApi, LLC.
Today I will share with you the first vulnerability I found on SerpApi, LLC.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/i-have-1-chance-to-hack-this-company-1044879f41a9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
I have 1% chance to hack this company
Today I will share with you the first vulnerability I found on SerpApi, LLC.
You should put scope over exploits! Or should you?
https://thexssrat.medium.com/you-should-put-scope-over-exploits-or-should-you-e7a083538e25?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://thexssrat.medium.com/you-should-put-scope-over-exploits-or-should-you-e7a083538e25?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
You should put scope over exploits! Or should you?
Through my time pentesting and working with other people, I have picked up a few valuable lessons that I hope to imprint on your brain. Today’s lesson is all about where your priorities should lay…
Continue reading on Medium » (https://thexssrat.medium.com/you-should-put-scope-over-exploits-or-should-you-e7a083538e25?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
You should put scope over exploits! Or should you?
Through my time pentesting and working with other people, I have picked up a few valuable lessons that I hope to imprint on your brain. Today’s lesson is all about where your priorities should lay…
Dark Reading: Attacks/Breaches
Docker Under Siege: Cybercriminals Compromise Honeypots to Ramp Up Attacks
Cloud containers are increasingly part of the cybercrime playbook, with researchers flagging ongoing scanning for Docker weaknesses along with rapid exploitation to infect systems with coin-miners, denial-of-service tools, and ransomware.
Docker Under Siege: Cybercriminals Compromise Honeypots to Ramp Up Attacks
Cloud containers are increasingly part of the cybercrime playbook, with researchers flagging ongoing scanning for Docker weaknesses along with rapid exploitation to infect systems with coin-miners, denial-of-service tools, and ransomware.
The curious case of mavinject.exe
https://www.reddit.com/r/redteamsec/comments/uizb40/the_curious_case_of_mavinjectexe/
submitted by /u/sciencestudent99 (https://www.reddit.com/user/sciencestudent99)
[link] (https://fourcore.io/blogs/mavinject-curious-process-injection) [comments] (https://www.reddit.com/r/redteamsec/comments/uizb40/the_curious_case_of_mavinjectexe/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/uizb40/the_curious_case_of_mavinjectexe/
submitted by /u/sciencestudent99 (https://www.reddit.com/user/sciencestudent99)
[link] (https://fourcore.io/blogs/mavinject-curious-process-injection) [comments] (https://www.reddit.com/r/redteamsec/comments/uizb40/the_curious_case_of_mavinjectexe/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: The curious case of mavinject.exe
Posted by u/sciencestudent99 - 11 votes and no comments
hacking: security in practice
Who here uses Rasberry Pi as a USB Rubber Ducky
So i programmed my rasberry pi to act like a rubber ducky.
Whenever i plug it into my laptop / computer it will disable volume change until the rickroll finishes.
submitted by /u/ncplayer5
[link] [comments]
Who here uses Rasberry Pi as a USB Rubber Ducky
So i programmed my rasberry pi to act like a rubber ducky.
Whenever i plug it into my laptop / computer it will disable volume change until the rickroll finishes.
submitted by /u/ncplayer5
[link] [comments]
reddit
Who here uses Rasberry Pi as a USB Rubber Ducky
So i programmed my rasberry pi to act like a rubber ducky. Whenever i plug it into my laptop / computer it will disable volume change until the...
hacking: security in practice
Is there a way I can get tor bridges to work on public wifi that blocks VPNs, tor, and its bridges?
I've tried obs4 bridges, no luck
submitted by /u/theonewithgeass
[link] [comments]
Is there a way I can get tor bridges to work on public wifi that blocks VPNs, tor, and its bridges?
I've tried obs4 bridges, no luck
submitted by /u/theonewithgeass
[link] [comments]
reddit
Is there a way I can get tor bridges to work on public wifi that...
I've tried obs4 bridges, no luck
hacking: security in practice
Hashcat gave me a password that doesn't work?
Cracking some old af '97 ppt files that have a PW on them. Hashcat gave me passwords, but they don't work.
My Hashcat cmd:
According to this: https://hashcat.net/forum/thread-7643.html
I have a collision because we're only using the first 40 bytes of a salt+digest. So, my passwords, 2*\9{~ and t;m\PU should work, but they do not.
submitted by /u/TheSlenderman871
[link] [comments]
Hashcat gave me a password that doesn't work?
Cracking some old af '97 ppt files that have a PW on them. Hashcat gave me passwords, but they don't work.
$oldoffice$3*ae0092f1e451d0e3fae35f43aa65bcd7*2a2f489f9dad13b0b20fb94b1edf0848*b9a799f47c4ed7a0d80c2ddf3610a3a0be6db596:2*\9{~ $oldoffice$3*85491defe7e3dc6b98ceef5286a1e55e*cbf532f91bd6f8a7afc1e853dcae7786*a113b0d70d02b3d7b1a1a7fa09ef690ac81c2c51:t;m\PU My Hashcat cmd:
hashcat -m 9800 -a 3 dumb.txt -i ?a?a?a?a?a?a?a?a?a?a? According to this: https://hashcat.net/forum/thread-7643.html
I have a collision because we're only using the first 40 bytes of a salt+digest. So, my passwords, 2*\9{~ and t;m\PU should work, but they do not.
submitted by /u/TheSlenderman871
[link] [comments]
reddit
Hashcat gave me a password that doesn't work?
Cracking some old af '97 ppt files that have a PW on them. Hashcat gave me passwords, but they don't work. ...
hacking: security in practice
Is it realistic of me to try and get CEH certification?
Hi, I wanted to ask for your advice on rather or not I should try and take the course.
I have no formal experience in cyber security (no certifications)
What I do have: - C, C++ - python-only on syntax level, no libraries except selenium - studied linux for the pass couple of years as a hubby. - for the pass five months I have been experiencing with vulnhub machines ctf and wifi attacks using kali.
I will add that im currently pursuing a degree in cs and on a vacation for 6 months.
Do you guys/gals think it’s realistic for me to try and pass the course in 6 months?
submitted by /u/guykehat
[link] [comments]
Is it realistic of me to try and get CEH certification?
Hi, I wanted to ask for your advice on rather or not I should try and take the course.
I have no formal experience in cyber security (no certifications)
What I do have: - C, C++ - python-only on syntax level, no libraries except selenium - studied linux for the pass couple of years as a hubby. - for the pass five months I have been experiencing with vulnhub machines ctf and wifi attacks using kali.
I will add that im currently pursuing a degree in cs and on a vacation for 6 months.
Do you guys/gals think it’s realistic for me to try and pass the course in 6 months?
submitted by /u/guykehat
[link] [comments]
reddit
Is it realistic of me to try and get CEH certification?
Hi, I wanted to ask for your advice on rather or not I should try and take the course. I have no formal experience in cyber security (no...
Remote Code Execution Web Application Vulnerability : Code Injection Part
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium »
Read more...
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.
The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend✅ - Enabled by Default
⚠️ - Disabled by Default
❌ - No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38
✅
⚠️
❌
❌
⚠️
⚠️
✅ graphql-php 37
✅
⚠️
⚠️
❌
✅
⚠️
⚠️ Apollo 34
✅
⚠️
⚠️
✅
✅
✅
✅ graphql-yoga 34
✅
⚠️
❌
❌
⚠️
⚠️
⚠️ graphene 34
✅
❌
❌
❌
✅
❌
⚠️ Ariadne 34
✅
⚠️
⚠️
❌
✅
⚠️
❌ Strawberry 34
✅
⚠️
❌
❌
✅
❌
❌ graphql-ruby 28
✅
❌
⚠️
⚠️
✅
❌
✅ Sangria 27
✅
⚠️
⚠️
❌
✅
❌
⚠️ Tartiflette 26
❌
❌
❌
❌
✅
❌
❌ graphql-java 26
✅
⚠️
⚠️
❌
✅
❌
⚠️ gqlgen 25
✅
❌
⚠️
⚠️
✅
⚠️
⚠️ Dgraph 25
✅
❌
❌
⚠️
✅
❌
❌ graphql-go 24
✅
❌
❌
❌
✅
⚠️
❌ juniper 24
❌
❌
❌
❌
✅
❌
⚠️ Diana.jl 10
✅
❌
❌
❌
✅
❌
❌ gql-dart/gql 9
✅
❌
❌
❌
✅
❌
❌ Agoo 0
❌
❌
❌
❌
✅
⚠️
❌ Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix
___________________________
@hacking_Attack
@Hacking_Video
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.
The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend✅ - Enabled by Default
⚠️ - Disabled by Default
❌ - No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38
✅
⚠️
❌
❌
⚠️
⚠️
✅ graphql-php 37
✅
⚠️
⚠️
❌
✅
⚠️
⚠️ Apollo 34
✅
⚠️
⚠️
✅
✅
✅
✅ graphql-yoga 34
✅
⚠️
❌
❌
⚠️
⚠️
⚠️ graphene 34
✅
❌
❌
❌
✅
❌
⚠️ Ariadne 34
✅
⚠️
⚠️
❌
✅
⚠️
❌ Strawberry 34
✅
⚠️
❌
❌
✅
❌
❌ graphql-ruby 28
✅
❌
⚠️
⚠️
✅
❌
✅ Sangria 27
✅
⚠️
⚠️
❌
✅
❌
⚠️ Tartiflette 26
❌
❌
❌
❌
✅
❌
❌ graphql-java 26
✅
⚠️
⚠️
❌
✅
❌
⚠️ gqlgen 25
✅
❌
⚠️
⚠️
✅
⚠️
⚠️ Dgraph 25
✅
❌
❌
⚠️
✅
❌
❌ graphql-go 24
✅
❌
❌
❌
✅
⚠️
❌ juniper 24
❌
❌
❌
❌
✅
❌
⚠️ Diana.jl 10
✅
❌
❌
❌
✅
❌
❌ gql-dart/gql 9
✅
❌
❌
❌
✅
❌
❌ Agoo 0
❌
❌
❌
❌
✅
⚠️
❌ Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
Remote Code Execution Web Application Vulnerability : Code Injection Part
https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Remote Code Execution Web Application Vulnerability : Code Injection Part
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium » (https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Remote Code Execution Web Application Vulnerability : Code Injection Part
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.
SHA-256 |
683da3b4055369ad271be51cb81dbf94818591a437064ded4119628be26cc697Download
# Exploit Title: PHProjekt (PhpSimplyGest / MyProjects, 1.3.0) - Stored XSS (Cross-Site Scripting)
# Date: 2022-05-05
# Exploit Author: Andrea Intilangelo
# Vendor Homepage: http://www.phprojekt.altervista.org (removed demo was at http://phprojekt.altervista.org/phpsimplygest130)
# Software Link: https://github.com/robyfofo/MyProjects (original PhpSimplyGest https://github.com/robyfofo/PhpSimplyGest now merged/renamed into MyProjects)
# Version: 1.3
# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 100.0, Microsoft Edge 101.0.1210.32)
# CVE: CVE-2022-27308
Description:
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 (and related products from same vendor, like "MyProjects") allows
attacker to execute arbitrary web scripts or HTML.
Injecting persistent javascript code inside the title description (or content) while creating a project, todo, timecard, estimates, report or finding,
it will be triggered once page gets loaded.
Steps to reproduce:
Click on Projects and add or edit an existing one,
Insert the following PoC inside the Title
Click on 'Send'.
If a user visits the website dashboard, as well as project summary page, the javascript code will be rendered.
Timeline:
2022-01-08: Vulnerability discovered.
2022-01-08: Vendor contacted.
2022-02-09: No reply, vendor contacted for 2nd time.
2022-02-18: Request for CVE reservation.
2022-04-27: Assigned CVE number 2022-27308.
2022-05-02: No reply, vendor contacted for 3rd time.
2022-05-05: Public disclosure.
PoC Screenshots:
https://imagebin.ca/v/6g5OFET1pyZB
https://imagebin.ca/v/6g6qLRC3X5ky
https://postimg.cc/qgc19rg0
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.