Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
CVE-2022–30075 Tp-Link Authenticated RCE
https://cdn-images-1.medium.com/max/1280/1*TveYdprzzVRQlnpkmccoiA.jpeg
CVE-2022–30075
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
CVE-2022–30075 Tp-Link Authenticated RCE
https://cdn-images-1.medium.com/max/1280/1*TveYdprzzVRQlnpkmccoiA.jpeg
CVE-2022–30075
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2022–30075 Tp-Link Authenticated RCE
CVE-2022–30075
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Descoberta de Vulnerabilidade com direito a avaliação do meu currículo.
https://cdn-images-1.medium.com/max/720/1*nudx0delpceex7GlwbVEhA.jpeg
Iae meus amigos como vocês estão? espero que estejam bem. Trouxe hoje uma vulnerabilidade em uma Universidade que eu gostaria de contar…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Descoberta de Vulnerabilidade com direito a avaliação do meu currículo.
https://cdn-images-1.medium.com/max/720/1*nudx0delpceex7GlwbVEhA.jpeg
Iae meus amigos como vocês estão? espero que estejam bem. Trouxe hoje uma vulnerabilidade em uma Universidade que eu gostaria de contar…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Descoberta de Vulnerabilidade com direito a avaliação do meu currículo.
Iae meus amigos como vocês estão? espero que estejam bem. Trouxe hoje uma vulnerabilidade em uma Universidade que eu gostaria de contar…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Одна слабая транзакция в ECDSA в блокчейне Биткоина и с помощью Lattice Attack мы получили Private…
Что мы знаем про решетчатую атаку?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Одна слабая транзакция в ECDSA в блокчейне Биткоина и с помощью Lattice Attack мы получили Private…
Что мы знаем про решетчатую атаку?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Одна слабая транзакция в ECDSA в блокчейне Биткоина и с помощью Lattice Attack мы получили Private…
Что мы знаем про решетчатую атаку?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack the Box: Shocker — Writeup
https://cdn-images-1.medium.com/max/1222/1*o7z1-fVFpvX9rAoT4Sthmw.png
Shocker is an easy-rated retired Hack the Box machine that is vulnerable to CVE-2014–6271 (Shellshock). Shellshock (also known as…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hack the Box: Shocker — Writeup
https://cdn-images-1.medium.com/max/1222/1*o7z1-fVFpvX9rAoT4Sthmw.png
Shocker is an easy-rated retired Hack the Box machine that is vulnerable to CVE-2014–6271 (Shellshock). Shellshock (also known as…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack the Box: Shocker — Writeup
Shocker is an easy-rated retired Hack the Box machine that is vulnerable to CVE-2014–6271 (Shellshock). Shellshock (also known as…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Drone Hack: Cómo deshacerse de zonas restringida en drones DJI
https://cdn-images-1.medium.com/max/950/1*kQ2xM79t06goj11LRBc7HA.jpeg
El certificado de drone-hacks.com desbloquea altitud y NFZ.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Drone Hack: Cómo deshacerse de zonas restringida en drones DJI
https://cdn-images-1.medium.com/max/950/1*kQ2xM79t06goj11LRBc7HA.jpeg
El certificado de drone-hacks.com desbloquea altitud y NFZ.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Drone Hack: Cómo deshacerse de zonas restringida en drones DJI
El certificado de drone-hacks.com desbloquea altitud y NFZ.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nueva variante de Emotet que roba la información de la tarjeta de crédito de los usuarios de Google…
https://cdn-images-1.medium.com/max/1254/0*xUm_aVmhudRYsaY2
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nueva variante de Emotet que roba la información de la tarjeta de crédito de los usuarios de Google…
https://cdn-images-1.medium.com/max/1254/0*xUm_aVmhudRYsaY2
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nueva variante de Emotet que roba la información de la tarjeta de crédito de los usuarios de Google Chrome
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Incluso las amenazas más avanzadas se basan en sistemas sin parches
https://cdn-images-1.medium.com/max/1591/0*eADM7-rsmwNkLXET
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Incluso las amenazas más avanzadas se basan en sistemas sin parches
https://cdn-images-1.medium.com/max/1591/0*eADM7-rsmwNkLXET
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Incluso las amenazas más avanzadas se basan en sistemas sin parches
PUBLICADO EN 9 JUNIO, 2022POR EHACKING
How does one manage to write an exploit?
https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/
Ok, this might be a really dumb and broad question and is just for satisfying my curiosity. How does one actually end up writing an exploit? For example, I am reading through CVE-2019-11231 (https://vulmon.com/vulnerabilitydetails?qid=CVE-2019-11231&scoretype=cvssv3). The code can be found here (https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/getsimplecms_unauth_code_exec.rb). I understand how this exploit works and how it does what it does. What I don't understand is how the author managed to find the vulnerability in this app. Is it far-fetched to assume that they read the source code of the GetSimpleCMS, checked all the other web components (Appache, PHP, etc...) and managed to figure out everything that is written in the exploit? Are there any of you who write their own exploits? If so, could you please give me more insight on how you manage to do it? It's just that I am very impressed on how somebody is this skilled and the whole procedure of designing an exploit looks like total black magic to me. :D submitted by /u/valjeanjean1 (https://www.reddit.com/user/valjeanjean1)
[link] (https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/) [comments] (https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/
Ok, this might be a really dumb and broad question and is just for satisfying my curiosity. How does one actually end up writing an exploit? For example, I am reading through CVE-2019-11231 (https://vulmon.com/vulnerabilitydetails?qid=CVE-2019-11231&scoretype=cvssv3). The code can be found here (https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/getsimplecms_unauth_code_exec.rb). I understand how this exploit works and how it does what it does. What I don't understand is how the author managed to find the vulnerability in this app. Is it far-fetched to assume that they read the source code of the GetSimpleCMS, checked all the other web components (Appache, PHP, etc...) and managed to figure out everything that is written in the exploit? Are there any of you who write their own exploits? If so, could you please give me more insight on how you manage to do it? It's just that I am very impressed on how somebody is this skilled and the whole procedure of designing an exploit looks like total black magic to me. :D submitted by /u/valjeanjean1 (https://www.reddit.com/user/valjeanjean1)
[link] (https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/) [comments] (https://www.reddit.com/r/Pentesting/comments/v9fdug/how_does_one_manage_to_write_an_exploit/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How does one manage to write an exploit?
Ok, this might be a really dumb and broad question and is just for satisfying my curiosity. How does one actually end up writing an exploit? For...
hacking: security in practice
Uploads directory discovery techniques
I'm currently doing a CTF style lab. I'm certain that there's a vulnerability with the upload picture feature of this bespoke vulnerable web app so I've been trying to find where the files get uploaded to but I've been at it over 24 hours (with sleep and plenty of breaks to reset) and really a at a loss, so I'm looking for ideas on techniques to help me find the upload directory.
The machine you've given for the lab is a Kali machine with GoBuster and dirb, but all of the wordlists included have a maximum of 200 entries, even rockyou.txt has been truncated.
Also, when you upload a picture you just get a 302 back to the profile page, no images change and there's no working gallery. So I'm kind of uploading blindly which is making it harder.
Here's a few things I've tried:
* Used all of the wordlists with dirb and gobuster
* Guessing for typical upload directories
* Changed the file name of the uploaded file to things like /var/www/html/test.jpg, ../../../../var/www/html/test/jpg etc
* Searched all the known pages for clues as to where the file might go
* Probably some other stuff that I've forgotten
Pulling my hair out over this one so would welcome your thoughts.
submitted by /u/ItchehBoy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Uploads directory discovery techniques
I'm currently doing a CTF style lab. I'm certain that there's a vulnerability with the upload picture feature of this bespoke vulnerable web app so I've been trying to find where the files get uploaded to but I've been at it over 24 hours (with sleep and plenty of breaks to reset) and really a at a loss, so I'm looking for ideas on techniques to help me find the upload directory.
The machine you've given for the lab is a Kali machine with GoBuster and dirb, but all of the wordlists included have a maximum of 200 entries, even rockyou.txt has been truncated.
Also, when you upload a picture you just get a 302 back to the profile page, no images change and there's no working gallery. So I'm kind of uploading blindly which is making it harder.
Here's a few things I've tried:
* Used all of the wordlists with dirb and gobuster
* Guessing for typical upload directories
* Changed the file name of the uploaded file to things like /var/www/html/test.jpg, ../../../../var/www/html/test/jpg etc
* Searched all the known pages for clues as to where the file might go
* Probably some other stuff that I've forgotten
Pulling my hair out over this one so would welcome your thoughts.
submitted by /u/ItchehBoy
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Uploads directory discovery techniques
I'm currently doing a CTF style lab. I'm certain that there's a vulnerability with the upload picture feature of this bespoke vulnerable web app...
hacking: security in practice
Hacking with Windows
Hi everyone,so i want to be an ethical hacker but i was wondering if you can start off as a hacker by only using Windows and not Linux(I have 2 main computers 1 that i use for ethical hacking and that i downloaded Linux on and the other one that is a Windows that i was wondering if i could use it aswell for ethical hacking without downloading Linux)
submitted by /u/Successful_Amount_72
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking with Windows
Hi everyone,so i want to be an ethical hacker but i was wondering if you can start off as a hacker by only using Windows and not Linux(I have 2 main computers 1 that i use for ethical hacking and that i downloaded Linux on and the other one that is a Windows that i was wondering if i could use it aswell for ethical hacking without downloading Linux)
submitted by /u/Successful_Amount_72
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking with Windows
Hi everyone,so i want to be an ethical hacker but i was wondering if you can start off as a hacker by only using Windows and not Linux(I have 2...
Jeeves - Time-Based Blind SQLInjection Finder
http://www.kitploit.com/2022/06/jeeves-time-based-blind-sqlinjection.html
http://www.kitploit.com/2022/06/jeeves-time-based-blind-sqlinjection.html
Jeeves is made for looking to Time-Based Blind SQLInjection through recon.
- Installation & Requirements: Installing Jeeves $ go install github.com/ferreiraklet/Jeeves@latest OR $ git clone https://github.com/ferreiraklet/Jeeves.git
$ cd Jeeves
$ go build jeeves.go
$ chmod +x jeeves
$ ./jeeves -h
- Usage & Explanation: In Your recon process, you may find endpoints (https://www.kitploit.com/search/label/Endpoints) that can be vulnerable (https://www.kitploit.com/search/label/Vulnerable) to sql injection, Ex: https://redacted.com/index.php?id=1 Single urls echo 'https://redacted.com/index.php?id=your_time_based_blind_payload_here' | jeeves -t payload_time
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves --payload-time 5
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(10)))v)" | jeeves -t 10 In --payload-time you must use the time mentioned in payload
From list cat targets | jeeves --payload-time 5 Adding Headers Pay attention to the syntax! Must be the same => echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 -H "Testing: testing;OtherHeader: Value;Other2: Value" Using proxy echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 --proxy "http://ip:port"
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 -p "http://ip:port"
Proxy + Headers (https://www.kitploit.com/search/label/Headers) => echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves --payload-time 5 --proxy "http://ip:port" -H "User-Agent: xxxx" Post Request Sending data through post request ( login (https://www.kitploit.com/search/label/Login) forms, etc ) Pay attention to the syntax! Must be equal! -> echo "https://example.com/Login.aspx" | jeeves -t 10 -d "user=(select(0)from(select(sleep(5)))v)&password=xxx"
echo "https://example.com/Login.aspx" | jeeves -t 10 -H "Header1: Value1" -d "username=admin&password='+(select*from(select(sleep(5)))a)+'" -p "http://yourproxy:port" Another ways of Usage You are able to use of Jeeves with other tools, such as gau, gauplus, waybackurls, qsreplace and bhedak, mastering his strenght
Command line flags: traffic to a proxy -c Set Concurrency, Default 25 -H, --headers Custom Headers -d, --data Sending Post request with data -h Show This Help Message"> Usage:
-t, --payload-time, The time from payload
-p, --proxy Send traffic to a proxy
-c Set Concurrency, Default 25
-H, --headers Custom Headers
-d, --data Sending Post request with data
-h Show This Help Message
Using with sql payloads wordlist cat sql_wordlist.txt | while read payload;do echo http://testphp.vulnweb.com/artists.php?artist= | qsreplace $payload | jeeves -t 5;done Testing in headers echo "https://target.com" | jeeves -H "User-Agent: 'XOR(if(now()=sysdate(),sleep(5*2),0))OR'" -t 10
echo "https://target.com" | jeeves -H "X-Forwarded-For: 'XOR(if(now()=sysdate(),sleep(5*2),0))OR'" -t 10
Payload credit: https://github.com/rohit0x5 OBS: Does not follow redirects, If the Status Code is diferent than 200, it returns "Need Manual Analisys" Jeeves does not http probing, he is not able to do requests to urls that does not contain protocol ( http://, https:// )
This project is for educational and bug bounty porposes only! I do not support any illegal activities!. If any error in the program, talk to me immediatly. Please, also check these =>
- Installation & Requirements: Installing Jeeves $ go install github.com/ferreiraklet/Jeeves@latest OR $ git clone https://github.com/ferreiraklet/Jeeves.git
$ cd Jeeves
$ go build jeeves.go
$ chmod +x jeeves
$ ./jeeves -h
- Usage & Explanation: In Your recon process, you may find endpoints (https://www.kitploit.com/search/label/Endpoints) that can be vulnerable (https://www.kitploit.com/search/label/Vulnerable) to sql injection, Ex: https://redacted.com/index.php?id=1 Single urls echo 'https://redacted.com/index.php?id=your_time_based_blind_payload_here' | jeeves -t payload_time
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves --payload-time 5
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(10)))v)" | jeeves -t 10 In --payload-time you must use the time mentioned in payload
From list cat targets | jeeves --payload-time 5 Adding Headers Pay attention to the syntax! Must be the same => echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 -H "Testing: testing;OtherHeader: Value;Other2: Value" Using proxy echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 --proxy "http://ip:port"
echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves -t 5 -p "http://ip:port"
Proxy + Headers (https://www.kitploit.com/search/label/Headers) => echo "http://testphp.vulnweb.com/artists.php?artist=" | qsreplace "(select(0)from(select(sleep(5)))v)" | jeeves --payload-time 5 --proxy "http://ip:port" -H "User-Agent: xxxx" Post Request Sending data through post request ( login (https://www.kitploit.com/search/label/Login) forms, etc ) Pay attention to the syntax! Must be equal! -> echo "https://example.com/Login.aspx" | jeeves -t 10 -d "user=(select(0)from(select(sleep(5)))v)&password=xxx"
echo "https://example.com/Login.aspx" | jeeves -t 10 -H "Header1: Value1" -d "username=admin&password='+(select*from(select(sleep(5)))a)+'" -p "http://yourproxy:port" Another ways of Usage You are able to use of Jeeves with other tools, such as gau, gauplus, waybackurls, qsreplace and bhedak, mastering his strenght
Command line flags: traffic to a proxy -c Set Concurrency, Default 25 -H, --headers Custom Headers -d, --data Sending Post request with data -h Show This Help Message"> Usage:
-t, --payload-time, The time from payload
-p, --proxy Send traffic to a proxy
-c Set Concurrency, Default 25
-H, --headers Custom Headers
-d, --data Sending Post request with data
-h Show This Help Message
Using with sql payloads wordlist cat sql_wordlist.txt | while read payload;do echo http://testphp.vulnweb.com/artists.php?artist= | qsreplace $payload | jeeves -t 5;done Testing in headers echo "https://target.com" | jeeves -H "User-Agent: 'XOR(if(now()=sysdate(),sleep(5*2),0))OR'" -t 10
echo "https://target.com" | jeeves -H "X-Forwarded-For: 'XOR(if(now()=sysdate(),sleep(5*2),0))OR'" -t 10
Payload credit: https://github.com/rohit0x5 OBS: Does not follow redirects, If the Status Code is diferent than 200, it returns "Need Manual Analisys" Jeeves does not http probing, he is not able to do requests to urls that does not contain protocol ( http://, https:// )
This project is for educational and bug bounty porposes only! I do not support any illegal activities!. If any error in the program, talk to me immediatly. Please, also check these =>
Nilo (https://github.com/ferreiraklet/nilo) - Checks if URL has status 200 SQLMAP (https://github.com/sqlmapproject/sqlmap) Blisqy (https://github.com/JohnTroony/Blisqy) Header time based SQLI
Download Jeeves (https://github.com/ferreiraklet/Jeeves)
Download Jeeves (https://github.com/ferreiraklet/Jeeves)