Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Detailed Analysis of the LockBit Ransomware
https://external-preview.redd.it/ksdYq2E9x2eeNMu5_p8mas5l8JQs0NDIOUlVOOlYEPI.jpg?width=640&crop=smart&auto=webp&s=70abb3a23535e46dd63813cc3ea8cfeed5ba0aa7 submitted by /u/CyberMasterV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Detailed Analysis of the LockBit Ransomware
https://external-preview.redd.it/ksdYq2E9x2eeNMu5_p8mas5l8JQs0NDIOUlVOOlYEPI.jpg?width=640&crop=smart&auto=webp&s=70abb3a23535e46dd63813cc3ea8cfeed5ba0aa7 submitted by /u/CyberMasterV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
A Detailed Analysis of the LockBit Ransomware : r/hacking
2.6M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploits…
Looking for a seasoned red team pro to red team ops.
https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/
submitted by /u/OverField9702 (https://www.reddit.com/user/OverField9702)
[link] (https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/) [comments] (https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/
submitted by /u/OverField9702 (https://www.reddit.com/user/OverField9702)
[link] (https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/) [comments] (https://www.reddit.com/r/redteamsec/comments/umg52x/looking_for_a_seasoned_red_team_pro_to_red_team/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Looking for a seasoned red team pro to red team ops.
Posted by u/OverField9702 - No votes and no comments
Spring4Shell-POC - Dockerized Spring4Shell (CVE-2022-22965) PoC Application And Exploit
http://www.kitploit.com/2022/05/spring4shell-poc-dockerized.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/spring4shell-poc-dockerized.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Spring4Shell-POC - Dockerized Spring4Shell (CVE-2022-22965) PoC Application And Exploit
This is a dockerized application that is vulnerable (https://www.kitploit.com/search/label/Vulnerable) to the Spring4Shell vulnerability (https://www.kitploit.com/search/label/Vulnerability) (CVE-2022-22965). Full Java source for the war is provided and modifiable, the war will get re-built whenever the docker image is built. The built WAR will then be loaded by Tomcat. There is nothing special about this application, it's a simple hello world that's based off Spring tutorials (https://spring.io/guides/gs/handling-form-submission/). Details: https://www.lunasec.io/docs/blog/spring-rce-vulnerabilitiesHaving issues with the POC? Check out the LunaSec fork at: https://github.com/lunasec-io/Spring4Shell-POC, it's more actively maintained. Requirements Docker Python3 + requests library Instructions Clone the repository Build and run the container: docker build . -t spring4shell && docker run -p 8080:8080 spring4shell App should now be available at http://localhost:8080/helloworld/greeting
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Run the exploit.py script: python exploit.py --url "http://localhost:8080/helloworld/greeting"
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Visit the created webshell! Modify the cmd GET parameter for your commands. (http://localhost:8080/shell.jsp by default)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Notes Fixed! As of this writing, the container (https://www.kitploit.com/search/label/Container) (possibly just Tomcat) must be restarted between exploitations. I'm actively trying to resolve this. Re-running the exploit will create an extra artifact file of {old_filename}_.jsp. PRs/DMs @Rezn0k (https://twitter.com/rezn0k) are welcome for improvements! Credits @esheavyind (https://twitter.com/esheavyind) for help on building a PoC. Check out their writeup at: https://gist.github.com/esell/c9731a7e2c5404af7716a6810dc33e1a @LunaSecIO (https://twitter.com/LunaSecIO) for improving the documentation and exploit @rwincey (https://twitter.com/rwincey) for making the exploit replayable without requiring a Tomcat (https://www.kitploit.com/search/label/Tomcat) restart
Download Spring4Shell-POC (https://github.com/reznok/Spring4Shell-POC)
___________________________
@hacking_Attack
@Hacking_Video
Download Spring4Shell-POC (https://github.com/reznok/Spring4Shell-POC)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Business Logic Vulnerabilities (easy hit) Bug-Bounty
Hello Cybersecurity Researchers,Continue reading on Medium »
Read more...
Hello Cybersecurity Researchers,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Find Out Who Has Viewed Your WhatsApp Profile
You may have seen your WhatsApp status views and wondered how to find out who viewed your profile as well.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Find Out Who Has Viewed Your WhatsApp Profile
You may have seen your WhatsApp status views and wondered how to find out who viewed your profile as well.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Out Who Has Viewed Your WhatsApp Profile
You may have seen your WhatsApp status views and wondered how to find out who viewed your profile as well. If this is something you’ve been…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How To Hack Any Website [ Part — 1]
https://cdn-images-1.medium.com/max/1200/0*XTSCzIwjG7oHpMYO.jpeg
— -|- Satyam Pathania
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How To Hack Any Website [ Part — 1]
https://cdn-images-1.medium.com/max/1200/0*XTSCzIwjG7oHpMYO.jpeg
— -|- Satyam Pathania
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How To Hack Any Website [ Part — 1]
— -|- Satyam Pathania
hacking: security in practice
How to spoof caller ID to custom number?
Is there a way I can use a specific number to call someone else? Nothing malicious just wanted to do a light prank calling a friend as another friend.
submitted by /u/Jcon_Josh
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to spoof caller ID to custom number?
Is there a way I can use a specific number to call someone else? Nothing malicious just wanted to do a light prank calling a friend as another friend.
submitted by /u/Jcon_Josh
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
software distribution sites that check for malware?
Hi all!
I am working on a small hotkey counter program to be the enhanced version of DCSB by being configurable to multiple keys and increment multiple text files
Since this requires use of a global key listener, my guess is it would be flagged by malware software (idk that works really I’m just assuming)? Is there a reputable site that you can upload your software to, where they’ll scan and approve it so your average user can be comfortable downloading and running it?
submitted by /u/PartySquidGaming
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
software distribution sites that check for malware?
Hi all!
I am working on a small hotkey counter program to be the enhanced version of DCSB by being configurable to multiple keys and increment multiple text files
Since this requires use of a global key listener, my guess is it would be flagged by malware software (idk that works really I’m just assuming)? Is there a reputable site that you can upload your software to, where they’ll scan and approve it so your average user can be comfortable downloading and running it?
submitted by /u/PartySquidGaming
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
software distribution sites that check for malware?
Hi all! I am working on a small hotkey counter program to be the enhanced version of DCSB by being configurable to multiple keys and increment...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring4Shell-POC - Dockerized Spring4Shell (CVE-2022-22965) PoC Application And Exploit
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaq3n6pTYJadYNCpjVegHxZFc8ZwiZUtKbPgpxPlbSd7vQgjUEfKFw0cO8jrAjpHsv_tzZAG_chVh9Mwrrh9UpIHbkniKAjKptmjj-rJ2uOjSxvBrPfVn3H2AZpIjCO-1Lrt4HnOxh7SS5SrMbbIttLpUzw7xDtIat1yKhbVk_0JgC8RDhwEXTMEuY/w640-h308/Spring4Shell.png This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965). Full Java source for the war is provided and modifiable, the war will get re-built whenever the docker image is built. The built WAR will then be loaded by Tomcat. There is nothing special about this application, it's a simple hello world that's based off Spring tutorials.
Details: https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities
Having issues with the POC? Check out the LunaSec fork at: https://github.com/lunasec-io/Spring4Shell-POC, it's more actively maintained. Requirements1. Docker
2. Python3 + requests library Instructions1. Clone the repository
2. Build and run the container:
Re-running the exploit will create an extra artifact file of {old_filename}_.jsp.
PRs/DMs @Rezn0k are welcome for improvements! Credits* @esheavyind for help on building a PoC. Check out their writeup at: https://gist.github.com/esell/c9731a7e2c5404af7716a6810dc33e1a
* @LunaSecIO for improving the documentation and exploit
* @rwincey for making the exploit replayable without requiring a Tomcat restart Download Spring4Shell-POC
___________________________
@hacking_Attack
@Hacking_Video
Spring4Shell-POC - Dockerized Spring4Shell (CVE-2022-22965) PoC Application And Exploit
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaq3n6pTYJadYNCpjVegHxZFc8ZwiZUtKbPgpxPlbSd7vQgjUEfKFw0cO8jrAjpHsv_tzZAG_chVh9Mwrrh9UpIHbkniKAjKptmjj-rJ2uOjSxvBrPfVn3H2AZpIjCO-1Lrt4HnOxh7SS5SrMbbIttLpUzw7xDtIat1yKhbVk_0JgC8RDhwEXTMEuY/w640-h308/Spring4Shell.png This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965). Full Java source for the war is provided and modifiable, the war will get re-built whenever the docker image is built. The built WAR will then be loaded by Tomcat. There is nothing special about this application, it's a simple hello world that's based off Spring tutorials.
Details: https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities
Having issues with the POC? Check out the LunaSec fork at: https://github.com/lunasec-io/Spring4Shell-POC, it's more actively maintained. Requirements1. Docker
2. Python3 + requests library Instructions1. Clone the repository
2. Build and run the container:
docker build . -t spring4shell && docker run -p 8080:8080 spring4shell3. App should now be available at http://localhost:8080/helloworld/greeting https://blogger.googleusercontent.com/img/a/AVvXsEgiSKKOBdAf-H6x6nvFmF2wHQ0WkAKdimGQcO3ortF_UVrOhKDkUDmIr4gxFzpaEaodNjEbpOo2z05EuGygz6K7atd6sXZYvXGfs60tMvLY5ZPxKOwuFrODicy7AbrL7kskqnDMETdZ2FPvJ1mD0gw2LxfG-qch-LSC8tBo7hIW-JM4Jj9jGhkehhhD=w640-h124 1. Run the exploit.py script: python exploit.py --url "http://localhost:8080/helloworld/greeting"https://blogger.googleusercontent.com/img/a/AVvXsEhXbcvigqvcJMzQzqHzuPqv8kDD2hEASz5zefNLhrnslPL6PVh8EdqWR0NFrOVdonBf7kBvzydhbiiPpBmFXSQun215RFALW4ijb3ucOIgmJKqELuISNRn59h8q-FHSlsEeoc594Ns_vIAkKrrogsoVbif_ufTU9Udrr2Umykdeyz9b0o3y5DkRXVhj=w640-h50 1. Visit the created webshell! Modify the cmdGET parameter for your commands. (http://localhost:8080/shell.jsp by default) https://blogger.googleusercontent.com/img/a/AVvXsEgTxfQevfT3YeenETl-w22eGNM_pdTzRn-0Nr0fwMbrmE7CLOkf33fpWA0N4zEloY3M1qI7ja7sQ-MziwLKY0FoiMoJ1e1kPhHSTMnyCU8L358ZRZTXcLmZDM7U9FHf7YuvY_3Nu3l17zdYcxQC4C9UgkypJ82wWMrgZt1jZ1cS_-2kOH7GfPdZgu6F=w640-h118 NotesFixed! As of this writing, the container (possibly just Tomcat) must be restarted between exploitations. I'm actively trying to resolve this.Re-running the exploit will create an extra artifact file of {old_filename}_.jsp.
PRs/DMs @Rezn0k are welcome for improvements! Credits* @esheavyind for help on building a PoC. Check out their writeup at: https://gist.github.com/esell/c9731a7e2c5404af7716a6810dc33e1a
* @LunaSecIO for improving the documentation and exploit
* @rwincey for making the exploit replayable without requiring a Tomcat restart Download Spring4Shell-POC
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Spring4Shell-POC - Dockerized Spring4Shell (CVE-2022-22965) PoC Application And Exploit
Business Logic Vulnerabilities (easy hit) Bug-Bounty
https://medium.com/@gandhim373/business-logic-vulnerabilities-easy-hit-bug-bounty-8cbfbb5af9eb?source=rss------bug_bounty-5
Hello Cybersecurity Researchers,Continue reading on Medium » (https://medium.com/@gandhim373/business-logic-vulnerabilities-easy-hit-bug-bounty-8cbfbb5af9eb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@gandhim373/business-logic-vulnerabilities-easy-hit-bug-bounty-8cbfbb5af9eb?source=rss------bug_bounty-5
Hello Cybersecurity Researchers,Continue reading on Medium » (https://medium.com/@gandhim373/business-logic-vulnerabilities-easy-hit-bug-bounty-8cbfbb5af9eb?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Business Logic Vulnerabilities (easy hit) Bug-Bounty
Hello Cybersecurity Researchers,
Building your own app
https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/
Hello, I have to build for my master's degree my own application in pen testing... I'm extremely lost and confused, in all fairness I don't know where to start, and I'm also not thinking of doing anything impressive. I wanted to ask you guys if anyone could kindly refer me any materials in order to build something from scratch. I would be complacent even with the simplest thing that a student can make. Thank you submitted by /u/Kiddas (https://www.reddit.com/user/Kiddas)
[link] (https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/) [comments] (https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/
Hello, I have to build for my master's degree my own application in pen testing... I'm extremely lost and confused, in all fairness I don't know where to start, and I'm also not thinking of doing anything impressive. I wanted to ask you guys if anyone could kindly refer me any materials in order to build something from scratch. I would be complacent even with the simplest thing that a student can make. Thank you submitted by /u/Kiddas (https://www.reddit.com/user/Kiddas)
[link] (https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/) [comments] (https://www.reddit.com/r/Pentesting/comments/umj285/building_your_own_app/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Building your own app
Hello, I have to build for my master's degree my own application in pen testing... I'm extremely lost and confused, in all fairness I don't know...