Download Spring4Shell-Poc (https://github.com/ckkok/spring4shell-poc)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - ckkok/spring4shell-poc
Contribute to ckkok/spring4shell-poc development by creating an account on GitHub.
Spring4Shell-Poc - Spring Core RCE 0-day Vulnerability
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. Go to the url to see the result of the shell command Download Spring4Shell-Poc
Read more...
Description of the vulnerability: https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html Construction of the POC: https://github.com/BobTheShoplifter/Spring4Shell-POC Steps to Build/Run Tested with JDK 11.0.14, Spring Boot 2.6.5, and Apache Tomcat 9.0.60 Run mvn clean package to build the application Rename demo-0.0.1-SNAPSHOT.war to spring-poc.war and copy this .war file to Tomcat's webapps directory Run python exp.py --url http://localhost:8080/spring-poc/greeting If successful, the message 漏洞存在,shell地址为:http://localhost:8080/spring-poc/tomcatwar.jsp?pwd=j&cmd=whoami will be logged. You should now see the file tomcatwar.jsp written to Tomcat's webapps/spring-poc directory. This directory can be changed by modifying exp.py. Go to the url to see the result of the shell command Download Spring4Shell-Poc
Read more...
ETH Amsterdam — Hats hits the road
https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium » (https://hatsfinance.medium.com/eth-amsterdam-hats-hits-the-road-6cf4ba1e7c9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…
ETH Amsterdam — Hats hits the road
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium »
Read more...
Seven years ago, Amsterdam hosted one of the first ever international Ethereum conferences. Our OG CTO, Shay Zluf, was a keynote speaker…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Type of phishing attacks with examples
https://cdn-images-1.medium.com/max/1200/1*wBa_HTQI9-n8QVPfpxXftA.jpeg
Hello buddies, I’m here with another handy tutorial and in this tutorial you will learn the most common phishing attacks which hackers use…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Type of phishing attacks with examples
https://cdn-images-1.medium.com/max/1200/1*wBa_HTQI9-n8QVPfpxXftA.jpeg
Hello buddies, I’m here with another handy tutorial and in this tutorial you will learn the most common phishing attacks which hackers use…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Type of phishing attacks with examples
Hello buddies, I’m here with another handy tutorial and in this tutorial you will learn the most common phishing attacks which hackers use…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Chasing Carders Part 2
So, yesterday my curiosity was peaked as to how these guys are able to still operate, and if they were how many are still around…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Chasing Carders Part 2
So, yesterday my curiosity was peaked as to how these guys are able to still operate, and if they were how many are still around…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Chasing Carders Part 2
So, yesterday my curiosity was peaked as to how these guys are able to still operate, and if they were how many are still around…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Can You Teach A Kid How To Hack?
https://cdn-images-1.medium.com/max/800/1*BbZLmujiFOktcgGfjRDBKA.png
Intro
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Can You Teach A Kid How To Hack?
https://cdn-images-1.medium.com/max/800/1*BbZLmujiFOktcgGfjRDBKA.png
Intro
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Can You Teach A Kid How To Hack?
Intro
hacking: security in practice
Is it possible to bypass NAT44 legally?
or any other option to expose ports for free (or with an small cost 1-2$)
submitted by /u/Sebasorova_YT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is it possible to bypass NAT44 legally?
or any other option to expose ports for free (or with an small cost 1-2$)
submitted by /u/Sebasorova_YT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is it possible to bypass NAT44 legally?
or any other option to expose ports for free (or with an small cost 1-2$)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Lincoln College to close after 157 years due ransomware attack
https://external-preview.redd.it/94UrK1NR5oGC6oyYvwV6kdwv1w-Rcwi3itdBs6Ndq6E.jpg?width=640&crop=smart&auto=webp&s=176a28531481113c20a36976344667f429790874 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Lincoln College to close after 157 years due ransomware attack
https://external-preview.redd.it/94UrK1NR5oGC6oyYvwV6kdwv1w-Rcwi3itdBs6Ndq6E.jpg?width=640&crop=smart&auto=webp&s=176a28531481113c20a36976344667f429790874 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Lincoln College to close after 157 years due ransomware attack
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
hacking: security in practice
Are there somethings we casually do to be avoided?
* Like visiting porn sites
* downloading pdf books
* downloading a apk
* downloading movies from torrent etc
Can those be the source of being hacked?
submitted by /u/BlueBuddhaNFT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are there somethings we casually do to be avoided?
* Like visiting porn sites
* downloading pdf books
* downloading a apk
* downloading movies from torrent etc
Can those be the source of being hacked?
submitted by /u/BlueBuddhaNFT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are there somethings we casually do to be avoided?
- Like visiting porn sites - downloading pdf books - downloading a apk - downloading movies from torrent etc Can those be the source of being hacked?
hacking: security in practice
hacked my professor and I feel extremely guilty about it
I usually get high scores in her class, I didn't need her exams, I just stole them for the thrill but she was nice to us (students) and did her best to educate us, I feel like trash and I want to apologize to her even though she doesn't know.
How do scammers continue living after tricking people?!
submitted by /u/Clichedfoil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
hacked my professor and I feel extremely guilty about it
I usually get high scores in her class, I didn't need her exams, I just stole them for the thrill but she was nice to us (students) and did her best to educate us, I feel like trash and I want to apologize to her even though she doesn't know.
How do scammers continue living after tricking people?!
submitted by /u/Clichedfoil
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
hacked my professor and I feel extremely guilty about it
I usually get high scores in her class, I didn't need her exams, I just stole them for the thrill but she was nice to us (students) and did her...
hacking: security in practice
cryprolocking scammers
I have been a fan of Jim Browning and the other folks fighting the good fight against the scammers out of India, and it occurred to me after watching the videos of their giant operation to play pranks on them just how much money these scammers make.
Seems to me, there is a perfect opportunity to take a scourge of the legitimate IT world and turn it on another of the world's biggest and worst entities. Has anyone considered using something like the SaaS versions of cryptolocker and using the core component of the scam (a remote connection) to let it loose on their network. Who cares if they pay, right? Whether they do or not, it means they are shut down for a while.
Any thoughts? I wouldn't know where to begin even trying to get a hold of the software for this, but you might.
submitted by /u/jc88usus
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
cryprolocking scammers
I have been a fan of Jim Browning and the other folks fighting the good fight against the scammers out of India, and it occurred to me after watching the videos of their giant operation to play pranks on them just how much money these scammers make.
Seems to me, there is a perfect opportunity to take a scourge of the legitimate IT world and turn it on another of the world's biggest and worst entities. Has anyone considered using something like the SaaS versions of cryptolocker and using the core component of the scam (a remote connection) to let it loose on their network. Who cares if they pay, right? Whether they do or not, it means they are shut down for a while.
Any thoughts? I wouldn't know where to begin even trying to get a hold of the software for this, but you might.
submitted by /u/jc88usus
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…