Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Printix 1.3.1106.0 Privilege Escalation

https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the creation of the Installer's temp.ini file.

SHA-256 | 962985a116482c4dadbf77096ef08deaadaf5eff443d79735b06e3812d725e3e

Download
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Printix 1.3.1106.0 Privileged API Abuse

https://3.bp.blogspot.com/-ZdpKmdYlHbY/WWlu_uhv-yI/AAAAAAAAIKA/GrhbPhfNXpolamaXsSLRo9Cb0FKriXUgQCLcBGAs/s1600/h12.png
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe in Printix's "Printix Secure Cloud Print Management" versions 1.3.1106.0 and below allows a local or remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.

SHA-256 | e26119f8d98f860e7ac7059a0d25e15dfc9acdbc0d49faa1f612da8efaf64cdc

Download
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Mastering the New CISO Playbook

How can you safeguard your organization amid global conflict and uncertainty?
Dark Reading: Attacks/Breaches
5-Buck DCRat Malware Foretells a Worrying Cyber Future

The Dark Crystal remote access Trojan (aka DCRat) breaks a few stereotypes, with coding done by a solo developer, using an obscure Web language and offering it at a frighteningly low price.
How to best get started with pentesting both learning and with tooling and setting up a suite
https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/

I’ve done like one or two of the easier hackthebox machines and feel like I was definitely a bit over my head. I also have heard that it is best practice to not run any of the tools directly on your OS. I’m curious what the standard practices are. Should I make a kali bootable usb, or a VM, or something else? Also, I want to learn pentesting for both offensive and defensive purposes. I’d like to host my own webapp but want to be aware of potential attack vectors. I know this is a lot but I figured there might be some professionals in this sub with some advice. submitted by /u/regular_guy_anon (https://www.reddit.com/user/regular_guy_anon)
[link] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/) [comments] (https://www.reddit.com/r/Pentesting/comments/umka8w/how_to_best_get_started_with_pentesting_both/)

___________________________
@hacking_Attack
@Hacking_Video