Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.
The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend✅ - Enabled by Default
⚠️ - Disabled by Default
❌ - No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38
✅
⚠️
❌
❌
⚠️
⚠️
✅ graphql-php 37
✅
⚠️
⚠️
❌
✅
⚠️
⚠️ Apollo 34
✅
⚠️
⚠️
✅
✅
✅
✅ graphql-yoga 34
✅
⚠️
❌
❌
⚠️
⚠️
⚠️ graphene 34
✅
❌
❌
❌
✅
❌
⚠️ Ariadne 34
✅
⚠️
⚠️
❌
✅
⚠️
❌ Strawberry 34
✅
⚠️
❌
❌
✅
❌
❌ graphql-ruby 28
✅
❌
⚠️
⚠️
✅
❌
✅ Sangria 27
✅
⚠️
⚠️
❌
✅
❌
⚠️ Tartiflette 26
❌
❌
❌
❌
✅
❌
❌ graphql-java 26
✅
⚠️
⚠️
❌
✅
❌
⚠️ gqlgen 25
✅
❌
⚠️
⚠️
✅
⚠️
⚠️ Dgraph 25
✅
❌
❌
⚠️
✅
❌
❌ graphql-go 24
✅
❌
❌
❌
✅
⚠️
❌ juniper 24
❌
❌
❌
❌
✅
❌
⚠️ Diana.jl 10
✅
❌
❌
❌
✅
❌
❌ gql-dart/gql 9
✅
❌
❌
❌
✅
❌
❌ Agoo 0
❌
❌
❌
❌
✅
⚠️
❌ Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix
___________________________
@hacking_Attack
@Hacking_Video
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
https://blogger.googleusercontent.com/img/a/AVvXsEjct_YmCLc-18AnApBUspPpG3TqJm6idF8kXXzhip6ehKOT6BfkPAmSl5giOn-9YO41mRxa2ob3NpNTpGXMABoNhKw0JstsaRZ3T1geeh-tAfUjm8ZGP37g1AXeTCjWlmatsSLJ1BcN1C4jAoJ6lEWukj_LI46xtJeoKe6jz4kQKlJyminP3SofY7CK=w640-h284 Why graphql-threat-matrix?graphql-threat-matrix was built for bug bounty hunters, security researchers and hackers to assist with uncovering vulnerabilities across multiple GraphQL implementations.
The differences in how GraphQL implementations interpret and conform to the GraphQL specification may lead to security gaps and unique attack vectors. By analyzing and comparing the factors that drive the security risks across different implementations the GraphQL ecosystem can make safer deployment decisions as well as collectively advance the security maturity of all implementations. Legend✅ - Enabled by Default
⚠️ - Disabled by Default
❌ - No Support
Implementation Validations Field Suggestions Query Depth limit Query Cost Analysis Automatic Persisted Queries Introspection Debug Mode Batch Requests wp-graphql 38
✅
⚠️
❌
❌
⚠️
⚠️
✅ graphql-php 37
✅
⚠️
⚠️
❌
✅
⚠️
⚠️ Apollo 34
✅
⚠️
⚠️
✅
✅
✅
✅ graphql-yoga 34
✅
⚠️
❌
❌
⚠️
⚠️
⚠️ graphene 34
✅
❌
❌
❌
✅
❌
⚠️ Ariadne 34
✅
⚠️
⚠️
❌
✅
⚠️
❌ Strawberry 34
✅
⚠️
❌
❌
✅
❌
❌ graphql-ruby 28
✅
❌
⚠️
⚠️
✅
❌
✅ Sangria 27
✅
⚠️
⚠️
❌
✅
❌
⚠️ Tartiflette 26
❌
❌
❌
❌
✅
❌
❌ graphql-java 26
✅
⚠️
⚠️
❌
✅
❌
⚠️ gqlgen 25
✅
❌
⚠️
⚠️
✅
⚠️
⚠️ Dgraph 25
✅
❌
❌
⚠️
✅
❌
❌ graphql-go 24
✅
❌
❌
❌
✅
⚠️
❌ juniper 24
❌
❌
❌
❌
✅
❌
⚠️ Diana.jl 10
✅
❌
❌
❌
✅
❌
❌ gql-dart/gql 9
✅
❌
❌
❌
✅
❌
❌ Agoo 0
❌
❌
❌
❌
✅
⚠️
❌ Want to provide a submission (or correction)?Interested in contributing? Found a discrepancy? Please create a GitHub issue or PR with your details. Contributors & Maintainers* Nick Aleks
* Dolev Farhi Download Graphql-Threat-Matrix
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Graphql-Threat-Matrix - GraphQL Threat Framework Used By Security Professionals To Research Security Gaps In GraphQL Implementations
Remote Code Execution Web Application Vulnerability : Code Injection Part
https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Remote Code Execution Web Application Vulnerability : Code Injection Part
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…Continue reading on Medium » (https://medium.com/@arshiadev/remote-code-execution-web-application-vulnerability-code-injection-part-da295445f30e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Remote Code Execution Web Application Vulnerability : Code Injection Part
Remote code execution (RCE) occurs when an attacker can execute arbitrary code on a target machine because of a vulnerability or…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
PHProjekt PhpSimplyGest and MyProjects version 1.3.0 suffer from a cross site scripting vulnerability.
SHA-256 |
683da3b4055369ad271be51cb81dbf94818591a437064ded4119628be26cc697Download
# Exploit Title: PHProjekt (PhpSimplyGest / MyProjects, 1.3.0) - Stored XSS (Cross-Site Scripting)
# Date: 2022-05-05
# Exploit Author: Andrea Intilangelo
# Vendor Homepage: http://www.phprojekt.altervista.org (removed demo was at http://phprojekt.altervista.org/phpsimplygest130)
# Software Link: https://github.com/robyfofo/MyProjects (original PhpSimplyGest https://github.com/robyfofo/PhpSimplyGest now merged/renamed into MyProjects)
# Version: 1.3
# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 100.0, Microsoft Edge 101.0.1210.32)
# CVE: CVE-2022-27308
Description:
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 (and related products from same vendor, like "MyProjects") allows
attacker to execute arbitrary web scripts or HTML.
Injecting persistent javascript code inside the title description (or content) while creating a project, todo, timecard, estimates, report or finding,
it will be triggered once page gets loaded.
Steps to reproduce:
Click on Projects and add or edit an existing one,
Insert the following PoC inside the Title
Click on 'Send'.
If a user visits the website dashboard, as well as project summary page, the javascript code will be rendered.
Timeline:
2022-01-08: Vulnerability discovered.
2022-01-08: Vendor contacted.
2022-02-09: No reply, vendor contacted for 2nd time.
2022-02-18: Request for CVE reservation.
2022-04-27: Assigned CVE number 2022-27308.
2022-05-02: No reply, vendor contacted for 3rd time.
2022-05-05: Public disclosure.
PoC Screenshots:
https://imagebin.ca/v/6g5OFET1pyZB
https://imagebin.ca/v/6g6qLRC3X5ky
https://postimg.cc/qgc19rg0
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
PHProjekt PhpSimplyGest / MyProjects 1.3.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
ZoneMinder Language Settings Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
ZoneMinder Language Settings Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ZoneMinder Language Settings Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Multichannel Phishing Concerns Cybersecurity Leaders in 2022
With 80% of companies using cloud collaboration tools, cybercriminals are using multichannel phishing attacks to exploit security gaps in the hybrid work model.
___________________________
@hacking_Attack
@Hacking_Video
Multichannel Phishing Concerns Cybersecurity Leaders in 2022
With 80% of companies using cloud collaboration tools, cybercriminals are using multichannel phishing attacks to exploit security gaps in the hybrid work model.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Multichannel Phishing Concerns Cybersecurity Leaders in 2022
With 80% of companies using cloud collaboration tools, cybercriminals are using multichannel phishing attacks to exploit security gaps in the hybrid work model.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
___________________________
@hacking_Attack
@Hacking_Video
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
Cisco Announces Cloud Controls Framework Is Now Available to Public
The Cisco CCF helps save resources by enabling organizations to achieve cloud security certifications more efficiently.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
___________________________
@hacking_Attack
@Hacking_Video
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Magnet Forensics Acquires Cybersecurity Software Firm Comae Technologies
The company will continue the development of Comae’s memory analysis platform and seek to incorporate its capabilities into existing solutions
What's everyone's favorite phishing framework/tool?
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/
I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/
I think GoPhish is the most popular. I'm going to be playing around with as many as I find over the weekend. I wanted to get some feedback on any favorites you may have used; pros & cons; etc. Thanks in advance for any feedback! submitted by /u/offftherecordz (https://www.reddit.com/user/offftherecordz)
[link] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/) [comments] (https://www.reddit.com/r/redteamsec/comments/uj43zm/whats_everyones_favorite_phishing_frameworktool/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the redteamsec community on Reddit
Explore this post and more from the redteamsec community
Dark Reading: Attacks/Breaches
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
___________________________
@hacking_Attack
@Hacking_Video
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
___________________________
@hacking_Attack
@Hacking_Video
Darkreading
FBI: Bank Losses From BEC Attacks Top $43B
Law enforcement attributes a recent 65% spike in BEC attack losses to COVID-19 restrictions and the ongoing reality of a remote workforce.
hacking: security in practice
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
submitted by /u/TheRealTengri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
submitted by /u/TheRealTengri
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is a good certification that will make you good at hacking?
I keep hearing people talk bad about the CEH certification, which I have. If that isn't good, what is a good certification?
AMB Bridge: bug bounty program
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem »
Read more...
As you may already know, we have recently launched the AMB bridge on the Ambrosus testnet!Continue reading on Ambrosus Ecosystem »
Read more...