Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AnyDesk 7.0.9 Arbitrary File Write / Denial Of Service

https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png AnyDesk version 7.0.9 suffers from an arbitrary file write vulnerability via a symlink attack.

SHA-256 | a24a864d0cf210e9aa4cf317353b4651dcf88793c38af3fcf86fc7d93525574aDownload # Exploit Title: AnyDesk allow arbitrary file write by symbolic link attack lead to denial-of-service attack on local machine
# Google Dork: [if applicable]
# Date: 24/5/2022
# Exploit Author: Erwin Chan
# Vendor Homepage: https://anydesk.com/en
# Software Link: https://anydesk.com/en
# Version: 7.0.9
# Tested on: Windows 11
It was found that AnyDesk (version 7.0.9) was vulnerable to arbitrary file
write by symbolic link attack leading to denial-of-service attack on local
machine. It was noted that two functions were affected.

*Affected function A*
When there was a remote connection come in, a directory under AppData of
current user (without admin privilege) and a "ad.trace" file (i.e.,
"C:\Users\
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacker Search Engines

A list of search engines useful during Penetration testing, vulnerability assessments, red team operations, bug bounty and moreContinue reading on Medium »
Read more...
XSS cheatsheet payloads

XSS PAYLOADSContinue reading on Medium »
Read more...
OpenSSH CVE-2018–15473 User Enumeration Vulnerability

Description:Continue reading on Medium »
Read more...
hacking: security in practice
Learning OT hacking

Hi all,

Good resources to learn about OT security?

Thanks.

submitted by /u/Morgue0xFF
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Critical Infrastructure for aviation?

Hello, I have a background as an avionics technician for the military and now a private company.

Gonna be pursuing a degree in Cyber Security/Critical Infrastructure. Was wondering if anyone on this subreddit had experience in the field and any advice they could offer me as far as career plans, education, general guidance, etc.

Thanks.

submitted by /u/CookiesNCraem
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Bypassing 403 Forbidden

Hey guys. I am facing a problem, the server does allow PUT method, but Apache Tomcat on version 7.0.14 gives me 403 Forbidden after using burpsuite and trying to use PUT method on it. Any ideas how to bypass that?

submitted by /u/mirahacker
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Ransomware Volume Nearly Doubles 2021 Totals in a Single Quarter

Like a hydra, every time one ransomware gang drops out (REvil or Conti), plenty more step up to fill the void (Black Basta).