Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Realistic Mission 14
https://cdn-images-1.medium.com/max/600/0*-paUT8fFQVkxZutm.jpg
Alright so this mission unfortunately is broken, I played around for a bit on the website and couldn’t find anything easy to exploit.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Realistic Mission 14
https://cdn-images-1.medium.com/max/600/0*-paUT8fFQVkxZutm.jpg
Alright so this mission unfortunately is broken, I played around for a bit on the website and couldn’t find anything easy to exploit.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Realistic Mission 14
Alright so this mission unfortunately is broken, I played around for a bit on the website and couldn’t find anything easy to exploit. After…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Basic Mission 7
https://cdn-images-1.medium.com/max/700/0*-paUT8fFQVkxZutm.jpg
We are back hacking another one of Sam’s pages trying to obtain a password. This time his daughter wrote us a fancy calendar script that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Basic Mission 7
https://cdn-images-1.medium.com/max/700/0*-paUT8fFQVkxZutm.jpg
We are back hacking another one of Sam’s pages trying to obtain a password. This time his daughter wrote us a fancy calendar script that…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Basic Mission 7
We are back hacking another one of Sam’s pages trying to obtain a password. This time his daughter wrote us a fancy calendar script that…
HTML Injection On Trio App
Hey Hackers!!! I am back again! My name is Krishnadev P Melevila, To know more about me, Search on Google “ Who is Krishnadev P Melevila”!Continue reading on InfoSec Write-ups »
Read more...
Hey Hackers!!! I am back again! My name is Krishnadev P Melevila, To know more about me, Search on Google “ Who is Krishnadev P Melevila”!Continue reading on InfoSec Write-ups »
Read more...
Hi I'm completely new my manager asked me to do this. As a Cybersecurity Analyst, you have been asked to perform the security testing on given virtual machine and provide the brief documentation with all vulnerabilities along with mitigation approach for detected vulnerabilities
https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/
Can you tell me any sample presentation for it? submitted by /u/cybosri (https://www.reddit.com/user/cybosri)
[link] (https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/) [comments] (https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/
Can you tell me any sample presentation for it? submitted by /u/cybosri (https://www.reddit.com/user/cybosri)
[link] (https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/) [comments] (https://www.reddit.com/r/Pentesting/comments/v30qhi/hi_im_completely_new_my_manager_asked_me_to_do/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hi I'm completely new my manager asked me to do this. As a...
Can you tell me any sample presentation for it?
HTML Injection On Trio App
https://infosecwriteups.com/html-injection-on-trio-app-92f039c500a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/html-injection-on-trio-app-92f039c500a7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTML Injection On Trio App
Hey Hackers!!! I am back again! My name is Krishnadev P Melevila, To know more about me, Search on Google “ Who is Krishnadev P Melevila”!
Hey Hackers!!! I am back again! My name is Krishnadev P Melevila, To know more about me, Search on Google “ Who is Krishnadev P Melevila”!Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/html-injection-on-trio-app-92f039c500a7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
HTML Injection On Trio App
Hey Hackers!!! I am back again! My name is Krishnadev P Melevila, To know more about me, Search on Google “ Who is Krishnadev P Melevila”!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vulnhub: Escalate My Privileges 1
https://cdn-images-1.medium.com/max/940/1*pg-t10q4SW11zKNuOpT92w.png
Hi! this is Roshan aka 1mper1us. Here i am going to solve/crack a machine called “Escalate My Privileges 1”. Hope you guys will find it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnhub: Escalate My Privileges 1
https://cdn-images-1.medium.com/max/940/1*pg-t10q4SW11zKNuOpT92w.png
Hi! this is Roshan aka 1mper1us. Here i am going to solve/crack a machine called “Escalate My Privileges 1”. Hope you guys will find it…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnhub: Escalate My Privileges 1
Hi! this is Roshan aka 1mper1us. Here i am going to solve/crack a machine called “Escalate My Privileges 1”. Hope you guys will find it…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tryhackme: Wonderland writeup
https://cdn-images-1.medium.com/max/1962/1*b5daOFm9rHuSrIzmwvSP7w.jpeg
This is my first write-up, I will be going over https://tryhackme.com‘s Wonderland room. This box has a heavy emphasis on Linux privilege…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Tryhackme: Wonderland writeup
https://cdn-images-1.medium.com/max/1962/1*b5daOFm9rHuSrIzmwvSP7w.jpeg
This is my first write-up, I will be going over https://tryhackme.com‘s Wonderland room. This box has a heavy emphasis on Linux privilege…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme: Wonderland writeup
This is my first write-up, I will be going over https://tryhackme.com‘s Wonderland room. This box has a heavy emphasis on Linux privilege…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare
New Windows Search zero-day added to Microsoft protocol nightmarePost Views: 6
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
The security issue can be leveraged because Windows supports a URI protocol handler called ‘search-ms’ that allows applications and HTML links to launch customized searches on a device.
While most Windows searches will look on the local device’s index, it is also possible to force Windows Search to query file shares on remote hosts and use a custom title for the search window.
For example, the popular Sysinternals toolset allows you to remotely mount live.sysinternals.com as a network share to launch their utilities. To search this remote share and list only files matching a particular name, you could use the following ‘search-ms’ URI:
A customized search window will appear when this command is executed from a Run dialog or web browser address bar on Windows 7, Windows 10, and Windows 11, as shown below.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/search-ms-protocol-handler/search-ms-sysinternals.jpg
Microsoft Office takes it to the next levelThis week, researchers discovered that threat actors were utilizing a new Windows zero-day vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT). To exploit it, threat actors created malicious Word documents that launched the ‘ms-msdt’ URI protocol handler to execute PowerShell commands simply by opening the document.
Identified as CVE-2022-30190, the flaw makes it possible to modify Microsoft Office documents to bypass Protected View and launch URI protocol handlers without interaction by users, which will only lead to further abuse of protocol handlers.
This was seen yesterday when Hickey converted existing Microsoft Word MSDT exploits to use the search-ms protocol handler we described earlier[...]
___________________________
@hacking_Attack
@Hacking_Video
New Windows Search zero-day added to Microsoft protocol nightmare
New Windows Search zero-day added to Microsoft protocol nightmarePost Views: 6
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
The security issue can be leveraged because Windows supports a URI protocol handler called ‘search-ms’ that allows applications and HTML links to launch customized searches on a device.
While most Windows searches will look on the local device’s index, it is also possible to force Windows Search to query file shares on remote hosts and use a custom title for the search window.
For example, the popular Sysinternals toolset allows you to remotely mount live.sysinternals.com as a network share to launch their utilities. To search this remote share and list only files matching a particular name, you could use the following ‘search-ms’ URI:
search-ms:query=proc&crumb=location:%5C%5Clive.sysinternals.com&displayname=Searching%20SysinternalsAs you can see from the command above, the search-ms ‘crumb’ variable specifies the location to search, and the ‘displayname’ variable specifies the search title.A customized search window will appear when this command is executed from a Run dialog or web browser address bar on Windows 7, Windows 10, and Windows 11, as shown below.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/search-ms-protocol-handler/search-ms-sysinternals.jpg
Microsoft Office takes it to the next levelThis week, researchers discovered that threat actors were utilizing a new Windows zero-day vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT). To exploit it, threat actors created malicious Word documents that launched the ‘ms-msdt’ URI protocol handler to execute PowerShell commands simply by opening the document.
Identified as CVE-2022-30190, the flaw makes it possible to modify Microsoft Office documents to bypass Protected View and launch URI protocol handlers without interaction by users, which will only lead to further abuse of protocol handlers.
This was seen yesterday when Hickey converted existing Microsoft Word MSDT exploits to use the search-ms protocol handler we described earlier[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare | Black Hat Ethical Hacking
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare
___________________________
@hacking_Attack
@Hacking_Video
New Windows Search zero-day added to Microsoft protocol nightmare
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare | Black Hat Ethical Hacking
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
Reverse Engineering Discord’s Party Mode
https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reverse Engineering Discord’s Party Mode
If you haven’t noticed yet, Discord added a ‘Party Mode’ because they are celebrating their 7th birthday. When a friend convinced me to enable it, I did the first few challenges, but quickly noticed…
Continue reading on Medium » (https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reverse Engineering Discord’s Party Mode
If you haven’t noticed yet, Discord added a ‘Party Mode’ because they are celebrating their 7th birthday. When a friend convinced me to enable it, I did the first few challenges, but quickly noticed…
How I Mass hunt for Admin Panel Access…
https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Mass hunt for Admin Panel Access…🤩
Hello All,🙂