hacking: security in practice
Crypto & DeFi Security Subreddit
Howdy security fam, for those who might be interested in Crypto/DeFi/Chain security related topics, we've started a subreddit:
/r/DeFiSecurity - Decentralized Finance (DeFi) and Crypto Cybersecurity related Conversations
If this is an area of interest, please drop in, join and add to the conversations...thanks!
submitted by /u/rfhacker
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Crypto & DeFi Security Subreddit
Howdy security fam, for those who might be interested in Crypto/DeFi/Chain security related topics, we've started a subreddit:
/r/DeFiSecurity - Decentralized Finance (DeFi) and Crypto Cybersecurity related Conversations
If this is an area of interest, please drop in, join and add to the conversations...thanks!
submitted by /u/rfhacker
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Crypto & DeFi Security Subreddit
Howdy security fam, for those who might be interested in Crypto/DeFi/Chain security related topics, we've started a subreddit: /r/DeFiSecurity \-...
hacking: security in practice
Anyone ordered from Dc207.org?
I’m looking at building a pwnagotchi and for some reason getting all the components in Germany is insanely expensive everywhere I’ve looked. It looks like I can buy a completed pownagotchi from Dc207.org for less than the price of components here. Has anyone ordered from them before?
submitted by /u/Traditional_Couple90
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anyone ordered from Dc207.org?
I’m looking at building a pwnagotchi and for some reason getting all the components in Germany is insanely expensive everywhere I’ve looked. It looks like I can buy a completed pownagotchi from Dc207.org for less than the price of components here. Has anyone ordered from them before?
submitted by /u/Traditional_Couple90
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anyone ordered from Dc207.org?
I’m looking at building a pwnagotchi and for some reason getting all the components in Germany is insanely expensive everywhere I’ve looked. It...
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgydikjQTzuAjAZQNo1Hcrj_Rew0WSbhEeC2dz5FhHgK2HAVBBKkwvLmXBd5K-r8vDoH1MuAKG_N8zJD78VAigXz6W2a9iz8SoMQDA-he8xVWYMwhZjkSrRpyG-PSskP--fKR2nzg2YnGruFCXj4VJ7npFI3KpYoRgNb1RkZwUN_pDfUy0e7A1XQf9s/w640-h334/Spring4Shell.jpg
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html
Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC
Steps to Build/Run
Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60
* Run
* Rename
* Run
* If successful, the message
* You should now see the file
* https://github.com/ckkok/spring4shell-poc/raw/master/images/01-log-message.png
* Go to the url to see the result of the shell command
* https://github.com/ckkok/spring4shell-poc/raw/master/images/02-running-the-payload.png
Download Spring4Shell-Poc
___________________________
@hacking_Attack
@Hacking_Video
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgydikjQTzuAjAZQNo1Hcrj_Rew0WSbhEeC2dz5FhHgK2HAVBBKkwvLmXBd5K-r8vDoH1MuAKG_N8zJD78VAigXz6W2a9iz8SoMQDA-he8xVWYMwhZjkSrRpyG-PSskP--fKR2nzg2YnGruFCXj4VJ7npFI3KpYoRgNb1RkZwUN_pDfUy0e7A1XQf9s/w640-h334/Spring4Shell.jpg
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html
Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC
Steps to Build/Run
Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60
* Run
mvn clean packageto build the application* Rename
demo-0.0.1-SNAPSHOT.warto spring-poc.warand copy this .war file to Tomcat's webapps directory* Run
python exp.py --url http://localhost:8080/spring-poc/greeting* If successful, the message
漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoamiwill be logged.* You should now see the file
tomcatwar.jspwritten to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. * https://github.com/ckkok/spring4shell-poc/raw/master/images/01-log-message.png
* Go to the url to see the result of the shell command
* https://github.com/ckkok/spring4shell-poc/raw/master/images/02-running-the-payload.png
Download Spring4Shell-Poc
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
https://b.thumbs.redditmedia.com/crAxQ2yiPRCZbLnKueJKoB8k56kzz-E_HtSsC8oUJVc.jpg I'm looking for ad fraud bots I need this or something similar thanks.
https://preview.redd.it/dcejmsgtvpy81.png?width=625&format=png&auto=webp&s=c633219e3aa6eee29793d70ac63548cfdc117a07
submitted by /u/Ricochetox
[link] [comments]
https://preview.redd.it/dcejmsgtvpy81.png?width=625&format=png&auto=webp&s=c633219e3aa6eee29793d70ac63548cfdc117a07
submitted by /u/Ricochetox
[link] [comments]
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
http://www.kitploit.com/2022/05/spring4shell-poc-spring-core-rce-0-day.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/05/spring4shell-poc-spring-core-rce-0-day.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot (https://www.kitploit.com/search/label/Spring%20Boot) 2.6.5, and Apache (https://www.kitploit.com/search/label/Apache) Tomcat (https://www.kitploit.com/search/label/Tomcat) 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory (https://www.kitploit.com/search/label/Directory) can be changed by modifying exp.py.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Cyber Kendra
SpringShell: Spring Core RCE 0-day Vulnerability
Spring4Shell: Spring core RCE vulnerability
Go to the url to see the result of the shell command
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Download Spring4Shell-Poc (https://github.com/ckkok/spring4shell-poc)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - ckkok/spring4shell-poc
Contribute to ckkok/spring4shell-poc development by creating an account on GitHub.
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. Go to the url to see the result of the shell command Download Spring4Shell-Poc
Read more...
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. Go to the url to see the result of the shell command Download Spring4Shell-Poc
Read more...
ETH Amsterdam — Hats hits the road
https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium » (https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium »
Read more...
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium »
Read more...