Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 10 android hacking application’s
1. WiFi Kill
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Top 10 android hacking application’s
1. WiFi Kill
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 10 android hacking application’s
1. WiFi Kill
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The In-depth Look into SQL Vulnerabilities
https://cdn-images-1.medium.com/max/600/0*eHAo-NNMAtij3Ykx.png
What is SQL Injection , lets come to that point but before that lets come to the point of what is SQL is it a database or just a query …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The In-depth Look into SQL Vulnerabilities
https://cdn-images-1.medium.com/max/600/0*eHAo-NNMAtij3Ykx.png
What is SQL Injection , lets come to that point but before that lets come to the point of what is SQL is it a database or just a query …
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The In-depth Look into SQL Vulnerabilities
What is SQL Injection , lets come to that point but before that lets come to the point of what is SQL is it a database or just a query …
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BYPASS BYPASS WAF WITH SORONG6ETAR TAMPER SCRIPT
https://cdn-images-1.medium.com/max/1290/1*15OJeS4g9lWTrTZKIFkWKw.png
Heyy comback with me Rexha.. this time i will share tamper script for bypass Web Application Firewall (WAF). Feature :
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BYPASS BYPASS WAF WITH SORONG6ETAR TAMPER SCRIPT
https://cdn-images-1.medium.com/max/1290/1*15OJeS4g9lWTrTZKIFkWKw.png
Heyy comback with me Rexha.. this time i will share tamper script for bypass Web Application Firewall (WAF). Feature :
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BYPASS WAF WITH SORONG6ETAR TAMPER SCRIPT
Heyy comback with me Rexha.. this time i will share tamper script for bypass Web Application Firewall (WAF). Feature :
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vulnerabilidad de autenticación en el servicio de Kubernetes de AWS
https://cdn-images-1.medium.com/max/1656/0*prj_hAo1Vd0TSH_J
PUBLICADO EN 18 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilidad de autenticación en el servicio de Kubernetes de AWS
https://cdn-images-1.medium.com/max/1656/0*prj_hAo1Vd0TSH_J
PUBLICADO EN 18 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerabilidad de autenticación en el servicio de Kubernetes de AWS
PUBLICADO EN 18 JULIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
A Deep Dive Into ALPHV/BlackCat Ransomware
https://external-preview.redd.it/HfakifJn0_tUPEZ-_BxSVi2RCpIIhr02iPuJWGbaA8w.jpg?width=640&crop=smart&auto=webp&s=afe208df64aed3cc79cf59b1ae0e5cb4824bd929 submitted by /u/CyberMasterV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
A Deep Dive Into ALPHV/BlackCat Ransomware
https://external-preview.redd.it/HfakifJn0_tUPEZ-_BxSVi2RCpIIhr02iPuJWGbaA8w.jpg?width=640&crop=smart&auto=webp&s=afe208df64aed3cc79cf59b1ae0e5cb4824bd929 submitted by /u/CyberMasterV
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
A Deep Dive Into ALPHV/BlackCat Ransomware
Posted in r/hacking by u/CyberMasterV • 1 point and 0 comments
https://b.thumbs.redditmedia.com/ZjLfBGJ_hlIjoNnEcxK3sL758hcy1UNB0QMh-B_aEFc.jpg Hey all, I should provide some context before asking my question. So I am currently researching and trying to find a vulnerability in an IoT device, it's pretty secure and sandboxed quite well. The only potential attack vector i have found is a JavaScript Injection vulnerability which I have explored and messed around with tons, but nothing crazy outside of getting more information on the device. However, I have deployed this JS payload (which is supposed to spawn a reverse shell, i generated this payload from using JSshell, however it really only opens a TCP connection and not a shell environment):
Jsshell payload used
And after listening on the host and port 4848, I get the incoming connection:
Incoming connection from IoT device > me
This looks good, except I would like to spawn a shell through JS, not just the TCP connection, is there anything I can do to leverage this into a shell environment using JS? Lots of research points me toward using Node.js however Node runs server side and tends to only open a shell on the server and not the client (the IoT device), and obviously in this case I would like a shell on the client and not the server. Any help/Ideas is greatly appreciated!
submitted by /u/dxrk-kali
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Jsshell payload used
And after listening on the host and port 4848, I get the incoming connection:
Incoming connection from IoT device > me
This looks good, except I would like to spawn a shell through JS, not just the TCP connection, is there anything I can do to leverage this into a shell environment using JS? Lots of research points me toward using Node.js however Node runs server side and tends to only open a shell on the server and not the client (the IoT device), and obviously in this case I would like a shell on the client and not the server. Any help/Ideas is greatly appreciated!
submitted by /u/dxrk-kali
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to leverage my current connection
Posted in r/hacking by u/dxrk-kali • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Popular vehicle GPS tracker gives hackers admin privileges over SMS
https://external-preview.redd.it/-f-vVzQkPmZwLNORqcl8vyalSAFQkcgg_yDPpw9wy6k.jpg?width=640&crop=smart&auto=webp&s=cd7c33001eebe33a8d29f12781bba5b684bf9583 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Popular vehicle GPS tracker gives hackers admin privileges over SMS
https://external-preview.redd.it/-f-vVzQkPmZwLNORqcl8vyalSAFQkcgg_yDPpw9wy6k.jpg?width=640&crop=smart&auto=webp&s=cd7c33001eebe33a8d29f12781bba5b684bf9583 submitted by /u/DrinkMoreCodeMore
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Popular vehicle GPS tracker gives hackers admin privileges over SMS
Posted in r/hacking by u/DrinkMoreCodeMore • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Asus GameSDK 1.0.0.4 Unquoted Service Path
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Asus GameSDK version 1.0.0.4 suffers from an unquoted service path vulnerability in GameSDK.exe.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Asus GameSDK 1.0.0.4 Unquoted Service Path
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Asus GameSDK version 1.0.0.4 suffers from an unquoted service path vulnerability in GameSDK.exe.
SHA-256 |
cd88ac76d033405e5a3e34567ef8fd43237dddbf5f9d43a3e92a2f447d70a461Download
# Exploit Title: Asus GameSDK v1.0.0.4 - 'GameSDK.exe' Unquoted Service Path (Privilege Escalation)
# Date: 07/14/2022
# Exploit Author: Angelo Pio Amirante
# Version: 1.0.0.4
# Tested on: Windows 10
# Patched version: 1.0.5.0
# CVE: CVE-2022-35899
# Step to discover the unquoted service path:
wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\" | findstr /i /v """
# Info on the service:
C:\>sc qc "GameSDK Service"
[SC] QueryServiceConfig OPERAZIONI RIUSCITE
NOME_SERVIZIO: GameSDK Service
TIPO : 10 WIN32_OWN_PROCESS
TIPO_AVVIO : 2 AUTO_START
CONTROLLO_ERRORE : 1 NORMAL
NOME_PERCORSO_BINARIO : C:\Program Files (x86)\ASUS\GameSDK Service\GameSDK.exe
GRUPPO_ORDINE_CARICAMENTO :
TAG : 0
NOME_VISUALIZZATO : GameSDK Service
DIPENDENZE :
SERVICE_START_NAME : LocalSystem
# Exploit
If an attacker had already compromised the system and the current user has the privileges to write in the "C:\Program Files (x86)\ASUS\" folder or in "C:\" , he could place his own "Program.exe" or "GameSDK.exe" files respectively, and when the service starts, it would launch the malicious file, rather than the original "GameSDK.exe".
# Impact
An attacker can elevate his privileges on the system and become NTAUTHORITY\SYSTEM.
# Poc Video
https://youtu.be/u_8JMIgn-5g
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Asus GameSDK 1.0.0.4 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Spryker Commerce OS Remote Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Spryker Commerce OS Remote Command Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Spryker Commerce OS Remote Command Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
My Essential Recon Commands
https://medium.com/@xsanjay/my-essential-recon-commands-93d37f4e1b91?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@xsanjay/my-essential-recon-commands-93d37f4e1b91?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Essential Recon Commands
Resolution
ResolutionContinue reading on Medium » (https://medium.com/@xsanjay/my-essential-recon-commands-93d37f4e1b91?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
My Essential Recon Commands
Resolution
The AMSI bypass i got from CRTP doesn't work, any help?
https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/
just signed for the CRTP and their AMSI bypass doesnt work on their lab, tried a bunch of bypasses from github as well and none worked, help ? submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/) [comments] (https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/
just signed for the CRTP and their AMSI bypass doesnt work on their lab, tried a bunch of bypasses from github as well and none worked, help ? submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/) [comments] (https://www.reddit.com/r/Pentesting/comments/w31wnt/the_amsi_bypass_i_got_from_crtp_doesnt_work_any/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
The AMSI bypass i got from CRTP doesn't work, any help?
just signed for the CRTP and their AMSI bypass doesnt work on their lab, tried a bunch of bypasses from github as well and none worked, help ?