Exploit Collector
Zyxel Firewall ZTP Unauthenticated Command Injection
___________________________
@hacking_Attack
@Hacking_Video
Zyxel Firewall ZTP Unauthenticated Command Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zyxel Firewall ZTP Unauthenticated Command Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome 100 extensions::ExtensionApiFrameIdMap::GetFrameId Heap Use-After-Free
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
A use-after-free issue exists in Chrome 100 and earlier versions. A malicious extension can achieve arbitrary code execution in the browser process.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome 100 extensions::ExtensionApiFrameIdMap::GetFrameId Heap Use-After-Free
https://4.bp.blogspot.com/-hp3wB9AXd0k/WWlvDY5V44I/AAAAAAAAIKs/ScSIhWVAvDAhjeMkIwqbNby9r3gKQvOEgCLcBGAs/s1600/h128.png
A use-after-free issue exists in Chrome 100 and earlier versions. A malicious extension can achieve arbitrary code execution in the browser process.
SHA-256 |
595428413ed6af41648e85f12bfacfc4d3b4b659dea62dab16b66777c9ddb014Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome 100 extensions::ExtensionApiFrameIdMap::GetFrameId Heap Use-After-Free
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
IpMatcher 1.0.4.1 Server-Side Request Forgery
___________________________
@hacking_Attack
@Hacking_Video
IpMatcher 1.0.4.1 Server-Side Request Forgery
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
IpMatcher 1.0.4.1 Server-Side Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
HighCMS/HighPortal 12.x SQL Injection
https://3.bp.blogspot.com/-4JQvP0m8T2k/WWlu48OEwdI/AAAAAAAAII8/Zf-K1JUBYisUlMBEUhCPF3Gl3BdQ2zG_gCLcBGAs/s1600/h103.png
HighCMS/HighPortal version 12.x appears to suffer from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
HighCMS/HighPortal 12.x SQL Injection
https://3.bp.blogspot.com/-4JQvP0m8T2k/WWlu48OEwdI/AAAAAAAAII8/Zf-K1JUBYisUlMBEUhCPF3Gl3BdQ2zG_gCLcBGAs/s1600/h103.png
HighCMS/HighPortal version 12.x appears to suffer from a remote SQL injection vulnerability.
SHA-256 |
11e531f865e4da1f04161aa0a4cb5e11bbe807e029d3818481e6c9fa1d18a1e6Download
# Exploit Title: HighCMS/HighPortal v12.x SQL Inj
# Type : WEBAPPS "HighCMS/HighPortal"
# Platform : ASP.NET
# Date : 4/23/2022
# Exploit Author : E1.Coders
# Software Link : https://aryanic.com/page/portal
# Version : v12.x
# Category : Webapps
# Tested on: Linux/Windows
# Google Dork: inurl:index.jsp?siteid=1&fkeyid=&siteid=1&pageid=
# Google Dork: <©2022
Step 1: Enter the address of the "page" that has the problem of sql injection attacks
http: //TARGET/index.jsp? Siteid = 1 & fkeyid = & siteid = 1 & pageid = 6528 Default credentials. ( is True )
STEP 2 : Send the following request "
or
Use sqlmap : python sqlmap.py -u "https://example.ir/index.jsp?siteid=1&fkeyid=&siteid=1&pageid=11211"
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
HighCMS/HighPortal 12.x SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Bug Bounty от Meta Pool
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…Continue reading on Meta Pool Russia »
Read more...
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…Continue reading on Meta Pool Russia »
Read more...
How do you make writing reports more pleasant?
https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We write the vulnerabilities with Mark Down, render with pandoc into a word file, then take it and merge it with the word template. Then validate and make corrections and export it to PDF. The good part with is that we don't have to fix styles when writing it, but I'm sure there must be a better way to do it. I've researched few options but can't find a good one. I'm thinking about creating web app with a DB containing all the vulnerabilities that were used in the reports, so it will be easier to import them. Some of them for example for missing headers will only have an option to import an image with the proof of concept with previously prepared static text containing information. In other vulnerabilities that need additional writing there will be placeholders. Somehow I think my idea will take way too long, any ideas or tips will be highly appreciated. Ps. I've notice taking trashy notes slows down additionally my Reporting process. Can you suggest me on editors like one note(including images) but which you can use on both Windows and Linux? Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/) [comments] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We write the vulnerabilities with Mark Down, render with pandoc into a word file, then take it and merge it with the word template. Then validate and make corrections and export it to PDF. The good part with is that we don't have to fix styles when writing it, but I'm sure there must be a better way to do it. I've researched few options but can't find a good one. I'm thinking about creating web app with a DB containing all the vulnerabilities that were used in the reports, so it will be easier to import them. Some of them for example for missing headers will only have an option to import an image with the proof of concept with previously prepared static text containing information. In other vulnerabilities that need additional writing there will be placeholders. Somehow I think my idea will take way too long, any ideas or tips will be highly appreciated. Ps. I've notice taking trashy notes slows down additionally my Reporting process. Can you suggest me on editors like one note(including images) but which you can use on both Windows and Linux? Thanks! submitted by /u/tryingtoworkatm (https://www.reddit.com/user/tryingtoworkatm)
[link] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/) [comments] (https://www.reddit.com/r/Pentesting/comments/uqyer1/how_do_you_make_writing_reports_more_pleasant/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do you make writing reports more pleasant?
Hi, I've been writing reports for a while now but I'm struggling big time. Our methodology is pretty complicated and I want to automate it. We...
Bug Bounty от Meta Pool
https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty от Meta Pool
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…Continue reading on Meta Pool Russia » (https://medium.com/meta-pool-russia/bug-bounty-%D0%BE%D1%82-meta-pool-c6dd3dcc405e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Bounty от Meta Pool
Meta Pool опубликовал в своем gitBook программу Bug Bounty, в которой может участвовать любой, кто обнаружит ошибку или уязвимость в…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
___________________________
@hacking_Attack
@Hacking_Video
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Critical Zyxel Firewall Bug Under Active Attack After PoC Exploit Debut
Just one day after disclosure, cyberattackers are actively going after the command-injection/code-execution vulnerability in Zyxel's gear.
Free Microsoft Certification Exam with Microsoft Build Cloud Skills Challenge
https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://cybersochacklabproject.blogspot.com/2022/05/free-microsoft-certification-exam-with.html) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://cybersochacklabproject.blogspot.com/2022/05/free-microsoft-certification-exam-with.html) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0efp/free_microsoft_certification_exam_with_microsoft/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Free Microsoft Certification Exam with Microsoft Build Cloud Skills Challenge
Posted by u/cybersocdm - 1 vote and no comments
API Security Offence and Defence: Introduction to API
https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=5EMkuG7QMOM&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/watch?v=5EMkuG7QMOM&feature=share) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0foj/api_security_offence_and_defence_introduction_to/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: API Security Offence and Defence: Introduction to API
Posted by u/cybersocdm - 2 votes and no comments
Open Source Intelligence (OSINT)
https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/playlist?list=PLHveG9B0-uTW7w0iWIrToTvthlN7eIrVU) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/
submitted by /u/cybersocdm (https://www.reddit.com/user/cybersocdm)
[link] (https://youtube.com/playlist?list=PLHveG9B0-uTW7w0iWIrToTvthlN7eIrVU) [comments] (https://www.reddit.com/r/redteamsec/comments/ur0hgh/open_source_intelligence_osint/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: Open Source Intelligence (OSINT)
Posted by u/cybersocdm - 3 votes and no comments