Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress W-DALIL 2.0 Cross Site Scripting

https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
WordPress W-DALIL plugin version 2.0 suffers from a persistent cross site scripting vulnerability.

SHA-256 | 3d149a791c07c7cfc468c60b80fc0a429d771a83d5713a156f35ef0f03df6cc5

Download
# Exploit Title: WordPress Plugin W-DALIL - Stored Cross Site Scripting
# Date: 27-06-2022
# Exploit Author: Mariam Tariq - HunterSherlock
# Vendor Homepage: https://wordpress.org/plugins/w-dalil/
# Version: 2.0
# Tested on: Firefox
# Contact me: mariamtariq404@gmail.com

#Vulnerable Code:

```

placeholder="

```

#Steps To Reproduce :

1 - First Install the plugin "*w-dalil*" and activate it.
2 - Go to Dalil —> Add New Dalil item
3 - Inside the “*Dalil item address*” enter XSS payload “*>
onerror=alert(1)>*" and hit enter.

#Poc Image :

https://imgur.com/JPG97oh

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mailhog 1.0.1 Cross Site Scripting

https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Mailhog version 1.0.1 suffers from a persistent cross site scripting vulnerability.

SHA-256 | c6d4443c876d720bb306b68d688651b623465386c426966caee9a17a0fcf1d8a

Download
# Exploit Title: Mailhog 1.0.1 - Stored Cross-Site Scripting (XSS)
# Google Dork: https://www.shodan.io/search?query=mailhog ( > 3500)
# Date: 06.18.2022
# Exploit Author: Vulnz
# Vendor Homepage: https://github.com/mailhog/MailHog
# Software Link: https://github.com/mailhog/MailHog
# Version: 1.0.1
# Tested on: Windows,Linux,Docker
# CVE : N/A

Explanation:
Malicious users have the ability to send API requests to localhost and this request will be executed without any additional checks. As long as CSRF exists and unrestricted API calls as well, XSS could lead any API calls including email deletion, sending, reading or any other call.

Steps to reproduce:
1. Create malicious attachment with payloads stated below
2. Attach malicious file to email with payload (XSS)
3. Send email
4. Wait for victim to open email
5. Receive data, get control of victim browser using Beef framework, or manipulate with API data
Proof of Concept:

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Simple Page Transition 1.4.1 Cross Site Scripting

https://4.bp.blogspot.com/-mkcU-A73eZ4/WWlu7eKaHEI/AAAAAAAAIJY/m_4841aOwNcKGKR9ykgWprFWjwy04TKNACLcBGAs/s1600/h11.png
WordPress Simple Page Transition plugin version 1.4.1 suffers from a persistent cross site scripting vulnerability.

SHA-256 | 6add737b61d202a5e1a60dba7f03322ef6b69ca1cb41cb65fe52abe7e5145de6

Download
# Exploit Title: WordPress Plugin ‘Simple Page Transition’ - Stored Cross
Site Scripting
# Date: 27-06-2022
# Exploit Author: Mariam Tariq - HunterSherlock
# Vendor Homepage: https://wordpress.org/plugins/simple-page-transition/
# Version: 1.4.1
# Tested on: Firefox
# Contact me: mariamtariq404@gmail.com
*#Vulnerable code*:

```

name="simple_page_transition_ignored" value="**" />
```
*#POC:*

1- Install the plugin ‘simple page transition’ & activate it.
2- Navigate towards the “ignored download links”
3- Enter the XSS payload ` *“>x *`

*#POC image:*

https://imgur.com/yzaTkhi

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Understand the Attacker’s Approach and Mindset behind Pentesting Modern-Day Android Applications :DContinue reading on Medium » (https://kunalkhubchandani.medium.com/modern-day-android-application-pentesting-approach-for-bugbounties-assessments-kunal-b09154b522d?source=rss------bug_bounty-5)
The Modern-Day Android Application Pentesting Approach for BugBounties/Assessments

Understand the Attacker’s Approach and Mindset behind Pentesting Modern-Day Android Applications :DContinue reading on Medium »
Read more...
Dark Reading: Attacks/Breaches
Shadow IT Spurs 1 in 3 Cyberattacks

Cerby platform emerges from stealth mode to let users automate security for applications outside of the standard IT purview.
Dark Reading: Attacks/Breaches
Federal, State Agencies' Aid Programs Face Synthetic Identity Fraud

Balancing public service with fraud prevention requires rule revisions and public trust.
Looking for a partner
https://www.reddit.com/r/Pentesting/comments/vm9hwj/looking_for_a_partner/

Hello, I guess that majority of the FOSS, Linux, hacker community struggle when it comes to meeting partners especially on the dating sites. And because I appreciate not only open source and privacy but also my time I decided to write “looking for a partner” post in few different places on the net. About me: I am female in late 20s, living in Europe, looking for something serious, marriage oriented. I’m NOT poly. I consider myself leftist, open minded person, supporting minority groups. I use Linux and I’m FOSS enthusiast, working as a developer but leaning more towards pen-testing jobs lately. Yes, I have nerdy side, but also entrepreneurial spirit and I want to start a company in future. Looking for: I don’t have exact image. If I find someone with same interests, similar views would be super great. I’m Sapiosexual and don’t mind age gap. But it’s important that person have serious intentions and it’s honest. I have I hectic life (work related) so I don’t want to spend lots of time texting, I prefer meeting asap. Like I mentioned - I’m from Europe. Distance don’t bother me if you are wiling to travel or relocate in future. It’s also possible for me to relocate. But in general I prefer that you are from Europe. I know that this post is super straight forward but I think it can be good way to meet someone. Because whats is the chance that I meet someone that special, when I’m drinking caffe in local bar? ;)) Great dating life to you all :) submitted by /u/LinuxCaffes (https://www.reddit.com/user/LinuxCaffes)
[link] (https://www.reddit.com/r/Pentesting/comments/vm9hwj/looking_for_a_partner/) [comments] (https://www.reddit.com/r/Pentesting/comments/vm9hwj/looking_for_a_partner/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Freshie looking to get into all things IT

Hi I am a highschool freshman looking to get into cyber security or some sort of IT and I’m sure “hacking” could be a hobby and help me along the way so if you’d like to help let me tell you about my situation. I’m going into sophomore year and I’ve transitioned to online school and I’m going to get a computer to obviously attend lol but well what do I do to start, what videos do I watch, what books do I read, what apps or programs do I download to see if this is even something I’d be interested in

submitted by /u/Cryptic6127
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Break into my website for fun!

I have been trying to get someone/s to break into my website with whatever means, and to program it to whatever they want. I figured someone here would have taken the challenge and created something fun, weird etc.

So, here is my website. Hackmywebsite.net

Show me what you got!! No strings attached. Only this domain is available to be messed with.

submitted by /u/Matt6247
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Add on for auto HDR in Windows 10?

So, I love how HDR looks. Though, I hate how Windows 10 "supports" it, as all SDR content just looks... Awful, to say the least. I know Windows 11 supports HDR. But fuck Windows 11, my next OS is gonna be Steam OS for multiple reasons.

Now that this is said, how do I hack Windows 10 to have proper HDR support? Because right now my screen is doing the work "HDR-ize" my screen, and it looks better than pretty much anything Windows 10 has to offer with it's "HDR" mode (my ass, it ruins everything else).

submitted by /u/3-Valdion
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video