Java Application -Server Side Template Injection
https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application -Server Side Template Injection
Description:
Description:Continue reading on Medium » (https://medium.com/@Dhamuharker/java-application-server-side-template-injection-f2aa4d2bb41?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Java Application -Server Side Template Injection
Description:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails Hidden Behind Asterisks
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint analysts and security forces. It allows to intelligently predict, using Intelx leaks, which emails are related to the person we are looking for. It also allows you to automatically obtain information from emails for manual analysis through a CSV dataset that is generated with the results.
Example of email with asterisks on Twitter
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bp_XVCG2s7m1ThSYdzbW3hACICHhOWKSI7KWY92VCAa2GRl_M6LQUYxY8D_9JgkIoOppzgOcV2itjFNVFI4de_Bt2XRobuJH5ww4LXoEsm_f_FlFHrT9cbW3TCK59vNlhVSmAS0L8P6Z8Xm1bu61IVAAkT6nMQLEOHTtGBTtYlKqD2Lgi2tDNj_B/s578/email-asterisks.png
Installation
It’s necessary to install the intelx library for python
git clone https://github.com/Quantika14/email-prediction-asterisks
pip3 install -r requiriments.txt
git clone https://github.com/IntelligenceX/SDK
pip3 install SDK/Python
You must put your api key here
Directory: m/key.py
intelx = “HERE”
emailrep = “HERE”
Download
___________________________
@hacking_Attack
@Hacking_Video
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails Hidden Behind Asterisks
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint analysts and security forces. It allows to intelligently predict, using Intelx leaks, which emails are related to the person we are looking for. It also allows you to automatically obtain information from emails for manual analysis through a CSV dataset that is generated with the results.
Example of email with asterisks on Twitter
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Bp_XVCG2s7m1ThSYdzbW3hACICHhOWKSI7KWY92VCAa2GRl_M6LQUYxY8D_9JgkIoOppzgOcV2itjFNVFI4de_Bt2XRobuJH5ww4LXoEsm_f_FlFHrT9cbW3TCK59vNlhVSmAS0L8P6Z8Xm1bu61IVAAkT6nMQLEOHTtGBTtYlKqD2Lgi2tDNj_B/s578/email-asterisks.png
Installation
It’s necessary to install the intelx library for python
git clone https://github.com/Quantika14/email-prediction-asterisks
pip3 install -r requiriments.txt
git clone https://github.com/IntelligenceX/SDK
pip3 install SDK/Python
You must put your api key here
Directory: m/key.py
intelx = “HERE”
emailrep = “HERE”
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Email-Prediction-Asterisks : Script That Allows You To Identify The Emails
Email prediction asterisks is a script that allows you to identify the emails hidden behind asterisks. It is a perfect application for osint
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PEzor-Docker : With The Help Of This Docker Image, You Can Easily Access PEzor On Your System!
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs. For instance, you can pack the “mimikatz” executable file with the help of PEzor and then run it against victim’s system for a full mem dump without any problem!
How to use
docker pull https://hub.docker.com/r/4d0niis/pezor_included_kali:1.0
docker run -it 4d0niis/pezor_included_kali:1.0 /bin/bash
PEzor
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVKYb2ABFihCTRrxGUk1IVlua59KA6uj3fy-4vVtCBqZUs91p2ircwz3pQhSd1C9f_77pE21lindU-avprjbMxN-PgpMoNkeKLhM0LM6i1JRz6qO8rnllekLFyFkEoAyeC5YktiIoxvDEcfnMUEL5de5T0d0tP05xWnOAZGdYZ4oI9uwh0atMKB8_c/s1263/PEzor_docker.png
Download
___________________________
@hacking_Attack
@Hacking_Video
PEzor-Docker : With The Help Of This Docker Image, You Can Easily Access PEzor On Your System!
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs. For instance, you can pack the “mimikatz” executable file with the help of PEzor and then run it against victim’s system for a full mem dump without any problem!
How to use
docker pull https://hub.docker.com/r/4d0niis/pezor_included_kali:1.0
docker run -it 4d0niis/pezor_included_kali:1.0 /bin/bash
PEzor
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVKYb2ABFihCTRrxGUk1IVlua59KA6uj3fy-4vVtCBqZUs91p2ircwz3pQhSd1C9f_77pE21lindU-avprjbMxN-PgpMoNkeKLhM0LM6i1JRz6qO8rnllekLFyFkEoAyeC5YktiIoxvDEcfnMUEL5de5T0d0tP05xWnOAZGdYZ4oI9uwh0atMKB8_c/s1263/PEzor_docker.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
PEzor-Docker : With The Help Of This Docker Image
PEzor-Docker, With the help of this incredible tool, you can create FUD malwares that are capable of bypassing most of the well-known AVs.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
GoSH : Golang Reverse/Bind Shell Generator
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host.
The shell binary can be compiled for multiple platforms, supports partial polymorphism (unique functions’ names) and can use UDP protocol instead of the default TCP. If you send a
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnC-WEYdeAt0x860SwaRAydrT_858TCdri7AEVI1139na9sYmabGz1Jj9Z4WG9_ZZ_Mzxgz1LkRdlHCWK1AFn3b7goCZqZSvag2N7XAu1OOY7l9ya1pBborH3Ndl0cJMeNX5Uc-qpWewNXUImUjbzo6756_pimTXJg69U7zw-D4X83JpT4nC3Ct_qV/s1920/screenshot.png
Download
___________________________
@hacking_Attack
@Hacking_Video
GoSH : Golang Reverse/Bind Shell Generator
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host.
The shell binary can be compiled for multiple platforms, supports partial polymorphism (unique functions’ names) and can use UDP protocol instead of the default TCP. If you send a
DELETEcommand over the established connection, the shell binary removes itself from the host it was executed on.https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhnC-WEYdeAt0x860SwaRAydrT_858TCdri7AEVI1139na9sYmabGz1Jj9Z4WG9_ZZ_Mzxgz1LkRdlHCWK1AFn3b7goCZqZSvag2N7XAu1OOY7l9ya1pBborH3Ndl0cJMeNX5Uc-qpWewNXUImUjbzo6756_pimTXJg69U7zw-D4X83JpT4nC3Ct_qV/s1920/screenshot.png
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
GoSH : Golang Reverse/Bind Shell Generator !!! Kali Linux
GoSH is a tool that generates a Go binary that launches a shell of the desired type on the targeted host. The shell binary can be compiled .
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
CVE-Tracker : With The Help Of This Automated Script, You Will Never Lose Track Of Recently Released CVEs
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do is exactly running the Microsoft Edge at system startup, navigate to 2 URLs ,and then put the browser in to full screen mode.
As ethical hackers, it’s vital that we keep track of the recently released CVEs in order to be fully aware of new threats or vulnerabilities out there in the Internet. Actually, it’s a routine task in our day to day lives. So why don’t we just automate the whole procedure of opening a browser and navigate to our sources for cheking the new CVEs? The purpose of this tool is to basically, automate the mentioned procedure with the help of powershell scripting.
Among all the online sources that are available which publish new CVEs, I’ve chosen the following 2 URLs and leveraged them in the script.
URLshttps://cvetrends.com/https://cve.circl.lu/
If you want to change these URLs to your desired ones, you can simply open the cve.ps1 file with an editor and change the URLs there! Also remember that you can even add more URLs to the file.
Usage
Download the zip file and unzip it on your system
If you haven’t bypassed the script execution on your system, please do so with the command “Set-ExecutionPolicy -ExecutionPolicy Bypass”
[Note: it needs to be run as administrator]
.\CVE_Track.ps1
Also, keep in mind the changes that are made to your system can easily be undone, by running the command
Technical Analysis
At first, when you run the script, it will create a *.bat file (CVE_Track.bat) in the following directory that literally allows the automation procedure that we aim for. C:\Users\.
Also the file “cv.ps1” is coppied to the directory C:\Users\and every time the system starts, it will be executed.
Download
___________________________
@hacking_Attack
@Hacking_Video
CVE-Tracker : With The Help Of This Automated Script, You Will Never Lose Track Of Recently Released CVEs
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do is exactly running the Microsoft Edge at system startup, navigate to 2 URLs ,and then put the browser in to full screen mode.
As ethical hackers, it’s vital that we keep track of the recently released CVEs in order to be fully aware of new threats or vulnerabilities out there in the Internet. Actually, it’s a routine task in our day to day lives. So why don’t we just automate the whole procedure of opening a browser and navigate to our sources for cheking the new CVEs? The purpose of this tool is to basically, automate the mentioned procedure with the help of powershell scripting.
Among all the online sources that are available which publish new CVEs, I’ve chosen the following 2 URLs and leveraged them in the script.
URLshttps://cvetrends.com/https://cve.circl.lu/
If you want to change these URLs to your desired ones, you can simply open the cve.ps1 file with an editor and change the URLs there! Also remember that you can even add more URLs to the file.
Usage
Download the zip file and unzip it on your system
If you haven’t bypassed the script execution on your system, please do so with the command “Set-ExecutionPolicy -ExecutionPolicy Bypass”
[Note: it needs to be run as administrator]
.\CVE_Track.ps1
Also, keep in mind the changes that are made to your system can easily be undone, by running the command
.\undo.ps1Technical Analysis
At first, when you run the script, it will create a *.bat file (CVE_Track.bat) in the following directory that literally allows the automation procedure that we aim for. C:\Users\.
Also the file “cv.ps1” is coppied to the directory C:\Users\and every time the system starts, it will be executed.
Download
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
CVE-Tracker : With The Help Of This Automated ScriptYou Will Never Lose
CVE-Tracker, With the help of this automated script, you will never lose track of newly released CVEs. What does this powershell script do.
I Found IDOR In Private Program Via API
https://medium.com/@mydudehello91/i-found-idor-in-private-program-via-api-875da81d4a54?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@mydudehello91/i-found-idor-in-private-program-via-api-875da81d4a54?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHOAMI:
WHOAMI:
WHOAMI:Continue reading on Medium » (https://medium.com/@mydudehello91/i-found-idor-in-private-program-via-api-875da81d4a54?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
WHOAMI:
WHOAMI:
Telangana, Andhra Pradesh, Karnataka, Himachal Pradesh & Kerala — All Government bus services were…
https://infosecwriteups.com/telangana-andhra-pradesh-karnataka-himachal-pradesh-kerala-all-government-bus-services-were-885b44c21a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://infosecwriteups.com/telangana-andhra-pradesh-karnataka-himachal-pradesh-kerala-all-government-bus-services-were-885b44c21a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Telangana, Andhra Pradesh, Karnataka, Himachal Pradesh & Kerala — All Government bus services were hacked
Hi Hackers! Welcome back to my new write-up. My name is Krishnadev P Melevila. I am a 20-Year-old Self-Learned Ethical Hacker.
Hi Hackers! Welcome back to my new write-up. My name is Krishnadev P Melevila. I am a 20-Year-old Self-Learned Ethical Hacker.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/telangana-andhra-pradesh-karnataka-himachal-pradesh-kerala-all-government-bus-services-were-885b44c21a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Telangana, Andhra Pradesh, Karnataka, Himachal Pradesh & Kerala — All Government bus services were hacked
Hi Hackers! Welcome back to my new write-up. My name is Krishnadev P Melevila. I am a 20-Year-old Self-Learned Ethical Hacker.