Information Source Code Disclosure Directory .git — MNC Play
https://dandyrafliansyah.medium.com/information-source-code-disclosure-directory-git-mnc-play-149ad9851741?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://dandyrafliansyah.medium.com/information-source-code-disclosure-directory-git-mnc-play-149ad9851741?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Source Code Disclosure Directory .git — MNC Play
Pada tanggal 15 Oktober 2020 saya menemukan BUG SQL Injection di payment.mncplay.id tetapi tidak ada respons dari pihak MNC Play.
Pada tanggal 15 Oktober 2020 saya menemukan BUG SQL Injection di payment.mncplay.id tetapi tidak ada respons dari pihak MNC Play.Continue reading on Medium » (https://dandyrafliansyah.medium.com/information-source-code-disclosure-directory-git-mnc-play-149ad9851741?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Information Source Code Disclosure Directory .git — MNC Play
Pada tanggal 15 Oktober 2020 saya menemukan BUG SQL Injection di payment.mncplay.id tetapi tidak ada respons dari pihak MNC Play.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
OpenSSL Update is in Severe Conditions due to Implications in its Service
https://cdn-images-1.medium.com/max/640/0*Jg4TYjcNQRFBapFX.jpg
OpenSSL Update
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
OpenSSL Update is in Severe Conditions due to Implications in its Service
https://cdn-images-1.medium.com/max/640/0*Jg4TYjcNQRFBapFX.jpg
OpenSSL Update
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
OpenSSL Update is in Severe Conditions due to Implications in its Service
OpenSSL Update
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Росія у кібервійні
Фокуси хакерів;
Хакерські атаки на інші країни світу;
Хто стоїть за хакерськими атаками?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Росія у кібервійні
Фокуси хакерів;
Хакерські атаки на інші країни світу;
Хто стоїть за хакерськими атаками?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Росія у кібервійні
Фокуси хакерів; Хакерські атаки на інші країни світу; Хто стоїть за хакерськими атаками?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
बेस्ट साइबर सिक्योरिटी कोर्स इन हिंदी 2022
https://cdn-images-1.medium.com/max/770/0*y5MBVjiks7j0Ohmv.png
CYBER SECURITY CYBER SECURITY AWARENESS ETHICAL HACKER ETHICAL HACKING ETHICAL HACKING COURSE NEAR ME ETHICAL HACKING COURSE ONLINE…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
बेस्ट साइबर सिक्योरिटी कोर्स इन हिंदी 2022
https://cdn-images-1.medium.com/max/770/0*y5MBVjiks7j0Ohmv.png
CYBER SECURITY CYBER SECURITY AWARENESS ETHICAL HACKER ETHICAL HACKING ETHICAL HACKING COURSE NEAR ME ETHICAL HACKING COURSE ONLINE…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
बेस्ट साइबर सिक्योरिटी कोर्स इन हिंदी 2022
CYBER SECURITY CYBER SECURITY AWARENESS ETHICAL HACKER ETHICAL HACKING ETHICAL HACKING COURSE NEAR ME ETHICAL HACKING COURSE ONLINE…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
https://cdn-images-1.medium.com/max/640/0*vzL2HLY1d60vGeG8.png
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
https://cdn-images-1.medium.com/max/640/0*vzL2HLY1d60vGeG8.png
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
Poison Proxy-Bypass HTTPS and VPN to Hacking Yur Online Identity
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Danish DPA bans Google Workspace for municipalities
https://external-preview.redd.it/ynLvCMk6YurHERS1H7VT_XdV07IyK1qnqaFHWBIX3GY.jpg?width=640&crop=smart&auto=webp&s=85a682b06c757e494667093db09e7a35366315b7 submitted by /u/DonutAccomplished422
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Danish DPA bans Google Workspace for municipalities
https://external-preview.redd.it/ynLvCMk6YurHERS1H7VT_XdV07IyK1qnqaFHWBIX3GY.jpg?width=640&crop=smart&auto=webp&s=85a682b06c757e494667093db09e7a35366315b7 submitted by /u/DonutAccomplished422
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Danish DPA bans Google Workspace for municipalities
Posted in r/hacking by u/DonutAccomplished422 • 1 point and 0 comments
How I spammed a Google meet (But for good)
Hacking isn’t always about account takeover, authentication bypass, or authorization abuse. Sometimes it’s about functionality abuse and…Continue reading on Medium »
Read more...
Hacking isn’t always about account takeover, authentication bypass, or authorization abuse. Sometimes it’s about functionality abuse and…Continue reading on Medium »
Read more...
Ability to login as google staff in Google Cloud Community
-Gaurav Bhatia (Bug Hunter, CTF Player)Continue reading on Medium »
Read more...
-Gaurav Bhatia (Bug Hunter, CTF Player)Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature
Microsoft Teams security vulnerability left users open to XSS via flawed stickers featurePost Views: 10 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A security researcher has found that attackers could abuse the popular sticker feature in Microsoft Teams to conduct cross-site scripting (XSS) attacks.
Microsoft Teams, alongside comparable teleconferencing services including Zoom, have experienced a surge in popularity over the past few years.
The Covid-19 pandemic forced organizations to adopt work-from-home models whenever possible. In the aftermath, employees have often been given the option of either staying remote or going hybrid.
With so many users, any vulnerability in Microsoft Teams could have widespread impact. As such, cybersecurity researchers, including Gais Cyber Security’s senior cybersecurity specialist Numan Turle, have examined the software for potential flaws. Sticky subjectIn 2021, Turle uncovered CVE-2021-24114. Issued a CVSS score of 5.7, the bug was discovered in the preview process of images sent via Teams to leak Skype tokens (PDF) and trigger an account takeover vulnerability in Teams iOS.
A year on, the researcher decided to examine Microsoft Teams’ sticker function for new security issues. See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
When a sticker is sent via Teams, the platform converts it into an image and uploads the content as ‘RichText/HTML’ in the subsequent message.
Turle inspected the HTML request using Burp Suite and tried out typical attributes – to no avail, due to the protections offered by Microsoft’s Content Security Policy (CSP).
CSP is designed to mitigate a range of common web attacks, including XSS.
However, after plugging the CSP into Google’s CSP Evaluator tool, the researcher found a CSP defect – the script-src field was flagged as unsafe, which paved the way for potential HTML injection attacks against multiple domains. Trying a different angleMicrosoft had plugged these security holes via Azure domain changes. So, after digging deeper and inspecting Teams in-browser, Turle uncovered a JavaScript element, angular-jquery, that could be used as an alternative.
jQuery with Angular is a JavaScript framework for managing HTML and CSS interactions. However, this version was out of date and vulnerabilities in the outdated version (1.5.14) – could be utilized to bypass the CSP.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo
Trending: OSINT Tool: Pagodo
After crafting a malicious iframe with help from HTML encoding, the researcher was able to create a malicious payload, sent via the stickers function in Teams, to trigger XSS, obtained through user interaction.
Turle disclosed the XSS issue to Microsoft on January 6. The vulnerability was patched in March and the researcher was awarded a $6,000 bug bounty. The Daily Swighas reached out to Gais Cyber Security and Microsoft and we will update when we hear back.
Full details can be found in a technical blog post from Turle. Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a q[...]
Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature
Microsoft Teams security vulnerability left users open to XSS via flawed stickers featurePost Views: 10 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A security researcher has found that attackers could abuse the popular sticker feature in Microsoft Teams to conduct cross-site scripting (XSS) attacks.
Microsoft Teams, alongside comparable teleconferencing services including Zoom, have experienced a surge in popularity over the past few years.
The Covid-19 pandemic forced organizations to adopt work-from-home models whenever possible. In the aftermath, employees have often been given the option of either staying remote or going hybrid.
With so many users, any vulnerability in Microsoft Teams could have widespread impact. As such, cybersecurity researchers, including Gais Cyber Security’s senior cybersecurity specialist Numan Turle, have examined the software for potential flaws. Sticky subjectIn 2021, Turle uncovered CVE-2021-24114. Issued a CVSS score of 5.7, the bug was discovered in the preview process of images sent via Teams to leak Skype tokens (PDF) and trigger an account takeover vulnerability in Teams iOS.
A year on, the researcher decided to examine Microsoft Teams’ sticker function for new security issues. See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
When a sticker is sent via Teams, the platform converts it into an image and uploads the content as ‘RichText/HTML’ in the subsequent message.
Turle inspected the HTML request using Burp Suite and tried out typical attributes – to no avail, due to the protections offered by Microsoft’s Content Security Policy (CSP).
CSP is designed to mitigate a range of common web attacks, including XSS.
However, after plugging the CSP into Google’s CSP Evaluator tool, the researcher found a CSP defect – the script-src field was flagged as unsafe, which paved the way for potential HTML injection attacks against multiple domains. Trying a different angleMicrosoft had plugged these security holes via Azure domain changes. So, after digging deeper and inspecting Teams in-browser, Turle uncovered a JavaScript element, angular-jquery, that could be used as an alternative.
jQuery with Angular is a JavaScript framework for managing HTML and CSS interactions. However, this version was out of date and vulnerabilities in the outdated version (1.5.14) – could be utilized to bypass the CSP.
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo
Trending: OSINT Tool: Pagodo
After crafting a malicious iframe with help from HTML encoding, the researcher was able to create a malicious payload, sent via the stickers function in Teams, to trigger XSS, obtained through user interaction.
Turle disclosed the XSS issue to Microsoft on January 6. The vulnerability was patched in March and the researcher was awarded a $6,000 bug bounty. The Daily Swighas reached out to Gais Cyber Security and Microsoft and we will update when we hear back.
Full details can be found in a technical blog post from Turle. Trending: New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a q[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature Microsoft Teams security vulnerability left users open to XSS via flawed stickers featurePost Views: 10 Premium Contenthttps://www.blackha…
uote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Untitled-design-300x150.png Microsoft releases tweet-size exploit for macOS sandbox escape bugJuly 14, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature first appeared on Black Hat Ethical Hacking.
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Untitled-design-300x150.png Microsoft releases tweet-size exploit for macOS sandbox escape bugJuly 14, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images_for_the_Website_posts-300x150.png Microsoft fixes dozens of Azure Site Recovery privilege escalation bugsJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/FTDZNGKMCJPIDKR5RE7MSLIMB4-scaled-300x150.jpg News – new template postJuly 13, 2022
Reading Time: 4 minutes
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/remotelyunlock-honda-1-1-300x150.jpg Hackers Say They Can Unlock and Start Honda Cars RemotelyJuly 12, 2022
Reading Time: 4 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Microsoft Teams security vulnerability left users open to XSS via flawed stickers feature first appeared on Black Hat Ethical Hacking.
How I spammed a Google meet (But for good)
https://medium.com/@shaunak007/how-i-spammed-a-google-meet-but-for-good-8bc5b328f1bb?source=rss------bug_bounty-5
https://medium.com/@shaunak007/how-i-spammed-a-google-meet-but-for-good-8bc5b328f1bb?source=rss------bug_bounty-5