Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Remote Code Execution Web Application Vulnerability : Code Injection Part

Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations

https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.

The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend - Enabled by Default

⚠️ - Disabled by Default

- No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38


⚠️





⚠️

⚠️

graphql-php 37


⚠️

⚠️





⚠️

⚠️ Apollo 34


⚠️

⚠️







graphql-yoga 34


⚠️





⚠️

⚠️

⚠️ graphene 34












⚠️ Ariadne 34


⚠️

⚠️





⚠️

Strawberry 34


⚠️









graphql-ruby 28




⚠️

⚠️





Sangria 27


⚠️

⚠️







⚠️ Tartiflette 26












graphql-java 26


⚠️

⚠️







⚠️ gqlgen 25




⚠️

⚠️



⚠️

⚠️ Dgraph 25






⚠️





graphql-go 24










⚠️

juniper 24












⚠️ Diana.jl 10












gql-dart/gql 9












Agoo 0










⚠️

Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting

https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.

SHA-256 | 683da3b4055369ad271be51cb81dbf94818591a437064ded4119628be26cc697

Download
# Exploit Title: PHProjekt (PhpSimplyGest / MyProjects, 1.3.0) - Stored XSS (Cross-Site Scripting)
# Date: 2022-05-05
# Exploit Author: Andrea Intilangelo
# Vendor Homepage: http://www.phprojekt.altervista.org (removed demo was at http://phprojekt.altervista.org/phpsimplygest130)
# Software Link: https://github.com/robyfofo/MyProjects (original PhpSimplyGest https://github.com/robyfofo/PhpSimplyGest now merged/renamed into MyProjects)
# Version: 1.3
# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 100.0, Microsoft Edge 101.0.1210.32)
# CVE: CVE-2022-27308
Description:

A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 (and related products from same vendor, like "MyProjects") allows
attacker to execute arbitrary web scripts or HTML.

Injecting persistent javascript code inside the title description (or content) while creating a project, todo, timecard, estimates, report or finding,
it will be triggered once page gets loaded.
Steps to reproduce:

Click on Projects and add or edit an existing one,

Insert the following PoC inside the Title
Click on 'Send'.

If a user visits the website dashboard, as well as project summary page, the javascript code will be rendered.
Timeline:

2022-01-08: Vulnerability discovered.
2022-01-08: Vendor contacted.
2022-02-09: No reply, vendor contacted for 2nd time.
2022-02-18: Request for CVE reservation.
2022-04-27: Assigned CVE number 2022-27308.
2022-05-02: No reply, vendor contacted for 3rd time.
2022-05-05: Public disclosure.
PoC Screenshots:

https://imagebin.ca/v/6g5OFET1pyZB
https://imagebin.ca/v/6g6qLRC3X5ky
https://postimg.cc/qgc19rg0

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
1,000+ Attacks in 2 Years: How the SideWinder APT Sheds Its Skin

Researcher to reveal fresh details at Black Hat Asia on a tenacious cyber-espionage group attacking specific military, law enforcement, aviation, and other entities in Central and South Asia.
What's everyone's favorite phishing framework/tool?
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/

I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Critical Cisco VM-Escape Bug Threatens Host Takeover

The vendor also disclosed two other security vulnerabilities that would allow remote, unauthenticated attackers to inject commands as root and snoop on sensitive user information.
Dark Reading: Attacks/Breaches
FBI: Bank Losses From BEC Attacks Top $43B

Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.

___________________________
@hacking_Attack
@Hacking_Video