Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Insecure Comments

Hi All,Continue reading on Medium »
Read more...
Pico CTF 2021 (Web Exploitation) — Part 1

GET aHEAD (20 Points)Continue reading on System Weakness »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Joomla Vik Booking 1.15.0 Cross Site Scripting

https://2.bp.blogspot.com/-4wIBcK0z7y4/WWlvHXARtRI/AAAAAAAAILc/wzdKaT4lYrUxiztYZaNra08YExR9F67-wCLcBGAs/s1600/h14.png Joomla Vik Booking extension version 1.15.0 suffers from a cross site scripting vulnerability.

SHA-256 | dd42bf74f375195161af098783436d265cf1dca658bad8cf5c833c3115d343bdDownload ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘

┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : extensions.joomla.org │
│ Vendor : e4j Extensions for Joomla - extensionsforjoomla.com │
│ Software : Joomla Vik Booking 1.15.0 │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Greets:

The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL

CryptoJob (Twitter) twitter.com/CryptozJob

┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Path: /index.php/en/booking

GET parameter 'categories' is vulnerable to XSS

https://extensionsforjoomla.com/livedemo/vikbooking/index.php/en/booking?option=com_vikbooking&task=showprc&roomsnum=1&roomopt%5B%5D=9&adults%5B%5D=2&children%5B%5D=1&days=1&checkin=1665057600&checkout=1665136800&category_id=&categories=rnrtm%2522%253e%253cscript%253ealert%25281%2529%253c%252fscript%253ew3vus&Itemid=103
[-] Done
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Hackathon this weekend!

Hi everyone! On behalf of Harlem Coding Kids i would like to let you all know about the HCK hackathon! It is going to be from October 8-9 and will be a 24 hour hackathon with a 2 hour networking event before hand. There will also be workshops and speaker events that will include a speaker from Cornell Engineering!

The hackathon is also beginner friendly! We will have an advance track and a beginner track.

All participants are welcome to join, come, and go whenever they want to fit your schedule. You will also be able to participate on your own or in a group of up to five! If you fo join in a group, please have all team members sign up.

Anyone can join from anywhere in the world! If you are interested, even if you’re not sure you’re going to join, please sign up at the link below! https://forms.gle/gdCbSeCt6YsCjJEU7

submitted by /u/GirlsEducationMatter
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Patch Now: Fortinet FortiGate & FortiProxy Contain Critical Vuln

Fortinet issued a customer advisory urging customers to apply its update immediately.
Dark Reading: Attacks/Breaches
LofyGang Uses 100s of Malicious NPM Packages to Poison Open Source Software

The group has been operating for over a year, promoting their tools in hacking forums, stealing credit card information, and using typosquatting techniques to target open source software flaws.
[Writeup] Vault game — Hats Finance CTF#2

This is my solution for Vault-game from Hats Finance making me one of winners with rewards of 1000 DAI and a NFT.Continue reading on CoinsBench »
Read more...