Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cyber Apocalypse CTF 2022 — HackTheBox
https://cdn-images-1.medium.com/max/1200/0*pCzUXZXZcLlwKo3d.jpg
Writeup 01: Web Challenges
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Cyber Apocalypse CTF 2022 — HackTheBox
https://cdn-images-1.medium.com/max/1200/0*pCzUXZXZcLlwKo3d.jpg
Writeup 01: Web Challenges
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Apocalypse CTF 2022 — HackTheBox
Writeup 01: Web Challenges
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking “Emdee five for life”
https://cdn-images-1.medium.com/max/600/1*kwCrm24QVY7WoFiEGP6XWg.png
Cyber Security Education
Level: Easy
Challenge: Emdee five for life by Hack the box (HTB)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking “Emdee five for life”
https://cdn-images-1.medium.com/max/600/1*kwCrm24QVY7WoFiEGP6XWg.png
Cyber Security Education
Level: Easy
Challenge: Emdee five for life by Hack the box (HTB)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking “Emdee five for life”
Cyber Security Education Level: Easy Challenge: Emdee five for life by Hack the box (HTB)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ways To Exploit JSON CSRF (Simple Explanation)
https://cdn-images-1.medium.com/max/1024/1*Jr4dcHyxVyeVHzjRKXdCbw.png
How JSON CSRF can be exploitable?
The JSON CSRF can be exploited in four ways depending on other factors that we will discuss:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ways To Exploit JSON CSRF (Simple Explanation)
https://cdn-images-1.medium.com/max/1024/1*Jr4dcHyxVyeVHzjRKXdCbw.png
How JSON CSRF can be exploitable?
The JSON CSRF can be exploited in four ways depending on other factors that we will discuss:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ways To Exploit JSON CSRF (Simple Explanation)
How JSON CSRF can be exploitable? The JSON CSRF can be exploited in four ways depending on other factors that we will discuss:
Cyber Apocalypse CTF 2022 — Intergalactic Chase Write up
https://infosecwriteups.com/cyber-apocalypse-ctf-2022-intergalactic-chase-write-up-6d2e89b1633e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/cyber-apocalypse-ctf-2022-intergalactic-chase-write-up-6d2e89b1633e?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Apocalypse CTF 2022 — Intergalactic Chase Write up
Hello everyone I am Hac and today we are doing Cyber Apocalypse CTF 2022 , Specifically this challenges :-
Hello everyone I am Hac and today we are doing Cyber Apocalypse CTF 2022 , Specifically this challenges :-Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cyber-apocalypse-ctf-2022-intergalactic-chase-write-up-6d2e89b1633e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Apocalypse CTF 2022 — Intergalactic Chase Write up
Hello everyone I am Hac and today we are doing Cyber Apocalypse CTF 2022 , Specifically this challenges :-
Hacking Web3: Introduction and How to Start
https://huntinex.medium.com/hacking-web3-introduction-and-how-to-start-88ae2c51f3ec?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://huntinex.medium.com/hacking-web3-introduction-and-how-to-start-88ae2c51f3ec?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Web3: Introduction and How to Start
Web3 is a newfound technology, and it’s claimed that it can greatly increase the security on the websites using it. In fact, web3 is a new…
Web3 is a newfound technology and it’s claimed that it can greatly increase the security on the websites using it. In fact web3 is a new…Continue reading on Medium » (https://huntinex.medium.com/hacking-web3-introduction-and-how-to-start-88ae2c51f3ec?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Web3: Introduction and How to Start
Web3 is a newfound technology, and it’s claimed that it can greatly increase the security on the websites using it. In fact, web3 is a new…
hacking: security in practice
Alternatives to bug bounties for blue teams/threat intel activities?
Hi everyone,
I was wondering if there are other platforms out there for blue team/threat intel/malware analysis activities (and that allow to make few bucks) like bug bounties programs do for "red team" activities. I am not referring to ctf/learning platforms as TryHackMe or HTB, I mean platforms in which you could be paid for your services.
submitted by /u/r3drush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Alternatives to bug bounties for blue teams/threat intel activities?
Hi everyone,
I was wondering if there are other platforms out there for blue team/threat intel/malware analysis activities (and that allow to make few bucks) like bug bounties programs do for "red team" activities. I am not referring to ctf/learning platforms as TryHackMe or HTB, I mean platforms in which you could be paid for your services.
submitted by /u/r3drush
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Alternatives to bug bounties for blue teams/threat intel activities?
Hi everyone, I was wondering if there are other platforms out there for blue team/threat intel/malware analysis activities (and that allow to...
hacking: security in practice
How recognised is EC-Council in the cyber security world ?
Is it a good certificate for getting a job in cyber security ?
submitted by /u/Bloodwolf6328
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How recognised is EC-Council in the cyber security world ?
Is it a good certificate for getting a job in cyber security ?
submitted by /u/Bloodwolf6328
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How recognised is EC-Council in the cyber security world ?
Is it a good certificate for getting a job in cyber security ?
hacking: security in practice
Assistance hacking Skynet.
Title says it all, I’m worried Skynet might kill us all.
submitted by /u/theboarrior
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Assistance hacking Skynet.
Title says it all, I’m worried Skynet might kill us all.
submitted by /u/theboarrior
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Assistance hacking Skynet.
Title says it all, I’m worried Skynet might kill us all.
hacking: security in practice
Fyasecurity
Just checking if anyone remembers the old-school 90s/early-00s fyasecurity.com hacking site/forum. Used to spend lots of time there. Purplehaze was the moderator/postmaster.
Internet archive was early beginning then so no index available.
Just a nostalgia question which you can ignore
submitted by /u/dcflatline
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Fyasecurity
Just checking if anyone remembers the old-school 90s/early-00s fyasecurity.com hacking site/forum. Used to spend lots of time there. Purplehaze was the moderator/postmaster.
Internet archive was early beginning then so no index available.
Just a nostalgia question which you can ignore
submitted by /u/dcflatline
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Fyasecurity
Just checking if anyone remembers the old-school 90s/early-00s [fyasecurity.com](https://fyasecurity.com) hacking site/forum. Used to spend lots...
hacking: security in practice
Anyone want to start a CTF team?
Saw the popular post about joining a CTF team, but missed the boat on that group, so I figured there is probably enough interest to get another group going. I haven't done too many CTFs, but have been studying pentesting and cyber security for a couple years, and I think it would be a good opportunity to sharpen my skills. Will primarily be discord based, at least to start, could move to a more secure platform later on. Hopefully we can get a good mix of skill levels, DM me or post here if interested!
submitted by /u/SpartanJAH
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Anyone want to start a CTF team?
Saw the popular post about joining a CTF team, but missed the boat on that group, so I figured there is probably enough interest to get another group going. I haven't done too many CTFs, but have been studying pentesting and cyber security for a couple years, and I think it would be a good opportunity to sharpen my skills. Will primarily be discord based, at least to start, could move to a more secure platform later on. Hopefully we can get a good mix of skill levels, DM me or post here if interested!
submitted by /u/SpartanJAH
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Anyone want to start a CTF team?
Saw the popular post about joining a CTF team, but missed the boat on that group, so I figured there is probably enough interest to get another...
hacking: security in practice
best way i can stay secure??
i don’t know anything about hacking and stuff but there’s alot of doxxers around in groupchats on social medias and idk how could i protect myself
submitted by /u/Any_Blacksmith_7638
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
best way i can stay secure??
i don’t know anything about hacking and stuff but there’s alot of doxxers around in groupchats on social medias and idk how could i protect myself
submitted by /u/Any_Blacksmith_7638
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
best way i can stay secure??
i don’t know anything about hacking and stuff but there’s alot of doxxers around in groupchats on social medias and idk how could i protect myself
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
LiquidFiles 3.4.15 Cross Site Scripting
https://4.bp.blogspot.com/-4tZE0Y76jWM/WWlvMNv2FRI/AAAAAAAAIMQ/Di9LOyWyOssTbh7urhFnaBV0oE1qNf8CgCLcBGAs/s1600/h19.png
LiquidFiles version 3.4.15 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
LiquidFiles 3.4.15 Cross Site Scripting
https://4.bp.blogspot.com/-4tZE0Y76jWM/WWlvMNv2FRI/AAAAAAAAIMQ/Di9LOyWyOssTbh7urhFnaBV0oE1qNf8CgCLcBGAs/s1600/h19.png
LiquidFiles version 3.4.15 suffers from a cross site scripting vulnerability.
SHA-256 |
64fb0fffa85d330dbc47f539a594fa8fcad4c9362b419983c93474d08ba4e151Download
=====[ Tempest Security Intelligence - ADV-12/2021
]==========================
LiquidFiles - 3.4.15
Author: Rodolfo Tavares
Tempest Security Intelligence - Recife, Pernambuco - Brazil
=====[ Table of Contents]==================================================
* Overview
* Detailed description
* Timeline of disclosure
* Thanks & Acknowledgements
* References
=====[ Vulnerability
Information]=============================================
* Class: Improper Neutralization of Input During Web Page Generation
('Cross-site Scripting') [CWE-79]
* CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
=====[ Overview]========================================================
* System affected : LiquidFiles
* Software Version : Version - 3.4.15
* Impacts :
* XSS: LiquidFiles 3.4.15 has stored XSS through the "send email"
functionality when sending a file via email to an administrator. When a
file has no extension and contains malicious HTML / JavaScript content
(such as SVG with HTML content), the payload is executed upon a click. This
is fixed in 3.5.
=====[ Detailed
description]=================================================
* Stored XSS at [http://localhost:8080/message/new]:
* Steps to reproduce
1 - Create a file without extension, with the content below inside
```
```
2 - With an external user send an email with that file (without any
extension) to admin or someone.
3 - With the admin account go to the menu click on "Data", inside the
"Data" menu click at "Messages", and select the message that you sent at
step 2. At the table click on the filename row over your file, the
javascript code will be executed.
=====[ Timeline of
disclosure]===============================================
11/Jan/2021 - Responsible disclosure was initiated with the vendor.
12/Jan/2021 - LiquidFiles Support confirmed the issue;
18/Fev/2021 - The vendor fixed the vulnerability the second stored XSS's
06/Apr/2021 - CVEs was assigned and reserved as CVE-2021-30140
=====[ Thanks & Acknowledgements]========================================
* Tempest Security Intelligence [5]
=====[ References ]=====================================================
[1][ [
https://cwe.mitre.org/data/definitions/79.html]|https://cwe.mitre.org/data/definitions/79.html
]]
[2][ [https://gist.github.com/rodnt/9f7d368fac38cafa7334598ec94fb167]]
[3][ [https://www.tempest.com.br|
https://www.tempest.com.br/]|https://www.tempest.com.br/]
=====[ EOF ]===========================================================
--
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
LiquidFiles 3.4.15 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.