Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
What's the point of XSS attack when you can only inject the script from the computer that has opened the target website ?

I'm just a beginner web developer and not a hacker. I watched several videos about XSS. Live attacks etc, but in all of them the hacker was injecting the script from the computer he was visiting the website and "stealing" the password and username he has entered on that same webpage. What's the point then ?

submitted by /u/lotsofhugszerofucks
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Intelbras ATA 200 Cross Site Scripting

https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Intelbras ATA 200 with firmware version 74.19.10.21 suffers from a persistent cross site scripting vulnerability.

SHA-256 | e356bd5406aa48762a1618d1a835ba31ee602d213580bd449699352c7cdfb239

Download
# Exploit Title: Intelbras ATA 200 Authenticated Stored XSS
# Date: 17/01/2022
# Exploit Author: Leonardo Goncalves
# Vendor Homepage: https://www.intelbras.com/pt-br/adaptador-ip-para-telefones-analogicos-ata-200
# Version: Firmware 74.19.10.21

1) Log in the equipment via your web browser
2) Go to Management > Syslog
3) In the "Field Server Address" inject the payload "-prompt("XSS")-"
4) Click Save
5) Exploit

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Fiberhome AN5506-02-B Cross Site Scripting

https://3.bp.blogspot.com/-_lYy5AwzHPI/WWlvAVk_lrI/AAAAAAAAIKU/HsTDdKCabVkkHkFsXQw08U72hOmjap5rACLcBGAs/s1600/h121.png
Fiberhome AN5506-02-B with firmware version RP2521 suffers from a persistent cross site scripting vulnerability.

SHA-256 | 6468873259d857e4b7cda7bf2ece5a2b2508ecd08b9330bef4207248417b9146

Download
# Exploit Title: FiberHome - AN5506-02-B - RP2521 - Authenticated Stored XSS
# Date: 10/08/2022
# Exploit Author: Leonardo Goncalves
# Version: Firmware RP2521

1) Log in the equipment via your web browser
2) Go to Network > auth_settings
3) In the "sncfg_loid" inject the payload ""
4) Click Save
5) Exploit!

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
How to works the use of free browser by hackers?
https://www.reddit.com/r/Pentesting/comments/wm2ec4/how_to_works_the_use_of_free_browser_by_hackers/

Reading this report about Thieflow and Yanluowang Group - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/yanluowang-ransomware-attacks-continue I came across with two lines: Other tools used include ProxifierPE, which can be used to proxy connections back to attacker-controlled infrastructure, and the free, Chromium-based Cent web browser.Thieflow attacks:Use of free browsers, such as s3browser and Cent browser How that works? The hacker install on machine victim a free browser in hidden mode and use to exfiltration, for what ? submitted by /u/huge_cock_123 (https://www.reddit.com/user/huge_cock_123)
[link] (https://www.reddit.com/r/Pentesting/comments/wm2ec4/how_to_works_the_use_of_free_browser_by_hackers/) [comments] (https://www.reddit.com/r/Pentesting/comments/wm2ec4/how_to_works_the_use_of_free_browser_by_hackers/)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Supply-Chain Security Startup Phylum Wins the First Black Hat Innovation Spotlight

Up-and-coming companies shoot their shot in a new feature introduced at the 25th annual cybersecurity conference.
Dark Reading: Attacks/Breaches
After Colonial Pipeline, Critical Infrastructure Operators Remain Blind to Cyber-Risks

In her keynote address at Black Hat USA 2022, Kim Zetter gives a scathing rebuke of Colonial Pipeline for not foreseeing the attack.
Dark Reading: Attacks/Breaches
Krebs: Taiwan, Geopolitical Headwinds Loom Large

During a keynote at Black Hat 2022, former CISA director Chris Krebs outlined the biggest risk areas for the public and private sectors for the next few years.