Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
<!-- SC_OFF -->Corporate networks overlap with home networks in the remote work era, and sensitive information abounds behind consumer-grade routers. But these devices might not be designed with security as a priority. Get ready for our research team's top investigation on routers this Friday at DefCon. https://faradaysec.com/blog-new-research-from-faraday-goes-to-def-con/ "A preliminary Shodan search revealed over 60,000 vulnerable routers with their admin panel exposed worldwide." "This is often the problem with IoT devices and especially with OEM since vendors do not always plan long-term maintenance, and security becomes a responsibility of the end-user." This Friday at 3 pm at Defcon, more details will be revealed. https://forum.defcon.org/node/241835 https://defcon.org/html/defcon-30/dc-30-schedule.html https://preview.redd.it/e2riym17q4h91.png?width=760&format=png&auto=webp&s=942612ced9781eb6f61787042488aadd1cd5928f <!-- SC_ON --> submitted by /u/Faradaysecurity (https://www.reddit.com/user/Faradaysecurity)
[link] (https://www.reddit.com/r/Pentesting/comments/wlyub5/new_research_findings_from_faraday_goes_to_def_con/) [comments] (https://www.reddit.com/r/Pentesting/comments/wlyub5/new_research_findings_from_faraday_goes_to_def_con/)
hacking: security in practice
What's the point of XSS attack when you can only inject the script from the computer that has opened the target website ?

I'm just a beginner web developer and not a hacker. I watched several videos about XSS. Live attacks etc, but in all of them the hacker was injecting the script from the computer he was visiting the website and "stealing" the password and username he has entered on that same webpage. What's the point then ?

submitted by /u/lotsofhugszerofucks
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Intelbras ATA 200 Cross Site Scripting

https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Intelbras ATA 200 with firmware version 74.19.10.21 suffers from a persistent cross site scripting vulnerability.

SHA-256 | e356bd5406aa48762a1618d1a835ba31ee602d213580bd449699352c7cdfb239

Download
# Exploit Title: Intelbras ATA 200 Authenticated Stored XSS
# Date: 17/01/2022
# Exploit Author: Leonardo Goncalves
# Vendor Homepage: https://www.intelbras.com/pt-br/adaptador-ip-para-telefones-analogicos-ata-200
# Version: Firmware 74.19.10.21

1) Log in the equipment via your web browser
2) Go to Management > Syslog
3) In the "Field Server Address" inject the payload "-prompt("XSS")-"
4) Click Save
5) Exploit

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Fiberhome AN5506-02-B Cross Site Scripting

https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
Fiberhome AN5506-02-B with firmware version RP2521 suffers from a persistent cross site scripting vulnerability.

SHA-256 | 6468873259d857e4b7cda7bf2ece5a2b2508ecd08b9330bef4207248417b9146

Download
# Exploit Title: FiberHome - AN5506-02-B - RP2521 - Authenticated Stored XSS
# Date: 10/08/2022
# Exploit Author: Leonardo Goncalves
# Version: Firmware RP2521

1) Log in the equipment via your web browser
2) Go to Network > auth_settings
3) In the "sncfg_loid" inject the payload ""
4) Click Save
5) Exploit!

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video