Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ERP Sankhya 4.13.x Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
ERP Sankhya versions 4.13.x and below suffer from a cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
ERP Sankhya 4.13.x Cross Site Scripting
https://2.bp.blogspot.com/-OQpvXY0U-U0/WWlvZUlJM8I/AAAAAAAAIOw/4zP2-mVc-vo2HWf5V3aXS_jzwpZLTa24QCLcBGAs/s1600/h59.png
ERP Sankhya versions 4.13.x and below suffer from a cross site scripting vulnerability.
SHA-256 |
1744ed67564a520b1a5d65928e4721a6bdd822c0125cd9c31ecb715595b6e46aDownload
# Exploit Title: ERP Sankhya - XSS to Account Takeover
# Google Dork: N/A
# Date: 19/10/2022
# Exploit Author: Lucas Alves Da Cunha - (0xLucas)
# Vendor Homepage: https://www.sankhya.com.br
# Version: Sankhya Om <=
# Tested on: Sankhya Om 4.11
# CVE: CVE-2022-42989
# Descrição:
Um usuário comum no ERP Sankhya pode enviar uma mensagem para qualquer outro usuário do sistema inclusive administradores, através da função "Caixa de Entrada". No corpo da mensagem, podemos injetar códigos html/javascript levando para um cross site scripting.
Payload para verificar existência da vulnerabilidade:
1
Payload utilizado para capturar os dados da sessão do usuário:
1
# Passos para reprodução:
1 - Encontrando a funcionalidade: https://i.imgur.com/B9SWknH.png
2 - Enviando payload para verificar existência da vulnerabilidade: https://i.imgur.com/ZKSkLmx.png
2.1 - Vulnerabilidade comprovada: https://i.imgur.com/1KiAa1m.png
3 - Explorando a vulnerabilidade: https://i.imgur.com/n8Jevum.png
3.1 - Sessão capturada: https://i.imgur.com/aDatjyN.png
Podemos utilizar os dados da sessão capturada e manipular a sessão utilizando a ferramenta: Cookie-Editor do Google Chrome, e assim entraremos na sessão do usuário desejado. Conforme a imagem a seguir: https://i.imgur.com/L10Yf9f.png
# Impacto:
Explorando essa vulnerabilidade, podemos comprometer qualquer conta de usuário do sistema, desde uma simples conta até mesmo uma conta de administrador do sistema, causando assim um grande impacto de negócio.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ERP Sankhya 4.13.x Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Dinstar FXO Analog VoIP Gateway DAG2000-16O Cross Site Scripting
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png
Dinstar FXO Analog VoIP Gateway version DAG2000-16O suffers from a persistent cross site scripting vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Dinstar FXO Analog VoIP Gateway DAG2000-16O Cross Site Scripting
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png
Dinstar FXO Analog VoIP Gateway version DAG2000-16O suffers from a persistent cross site scripting vulnerability.
SHA-256 |
97eaa1028dd6a201c66d40bfa6162f161c2586c5696100d18bc50025c51b3882Download
# Exploit Title: Dinstar FXO Analog VoIP Gateway DAG2000-16O Stored Cross Site Scripting
# Google Dork: NA
# Date: 25/10/2022
# Exploit Author: Yehia Elghaly
# Vendor Homepage: https://www.dinstar.com/
# Software Link: https://www.dinstar.com/analog-voip-gateway/16-fxo/
# Version: DAG2000-16O
# CVE: N/A
Summary: DAG1000-16O FXO analog gateway is a type of access gateway offering seamless connectivity between IP-based telephony networks and legacy telephones (POTS) and PBX systems. The analog gateway has 16 FXO ports and is used to connect to analog PBX or the PSTN lines of telecom carriers. With the standard SIP protocol, it's compatible with leading IMS/NGN platforms and SIP-based IP Phone systems. It provides low-cost and easy-to-use VoIP solutions for small and medium businesses, call centers, SOHO, remote offices as well as enterprises with multiple branches.
Description: The attacker can able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.: Stored XSS found on when (Add new Port) affected field is (Primary Authenticate ID)
Payload:
[Affected Component]
(Add new Port)--> (Primary Authenticate ID)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Dinstar FXO Analog VoIP Gateway DAG2000-16O Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Do any of you guys know of any pen testing jobs that would hire you w/o a degree?
https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/
Hi my parents and I live in NY, and I would like to know about some jobs that would hire a pen tester w/o a degree. I’ve looked on Glassdoor and other sites and they said that it’s required to have a bachelors degree or at least a few years of working in the IT or any computer related field. The reason why I’m asking is because I asked my dad if he would like to get into cybersecurity particularly pen testing in about 2 to 3 years from now and he said that he would see about it, and think about it. He’s an electrician but I think that he’s interested in cybersecurity and because he told me that he used to work on programming computers when he was younger. And he also knows a little bit about cybersecurity like not to connect to a public WIFI, and to use a VPN whenever you connect to one. He also knows about the dark web as well. So do any of y’all know about any pen testing jobs that would hire someone w/o a degree only certificates? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/) [comments] (https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/
Hi my parents and I live in NY, and I would like to know about some jobs that would hire a pen tester w/o a degree. I’ve looked on Glassdoor and other sites and they said that it’s required to have a bachelors degree or at least a few years of working in the IT or any computer related field. The reason why I’m asking is because I asked my dad if he would like to get into cybersecurity particularly pen testing in about 2 to 3 years from now and he said that he would see about it, and think about it. He’s an electrician but I think that he’s interested in cybersecurity and because he told me that he used to work on programming computers when he was younger. And he also knows a little bit about cybersecurity like not to connect to a public WIFI, and to use a VPN whenever you connect to one. He also knows about the dark web as well. So do any of y’all know about any pen testing jobs that would hire someone w/o a degree only certificates? submitted by /u/ELIDAL99 (https://www.reddit.com/user/ELIDAL99)
[link] (https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/) [comments] (https://www.reddit.com/r/Pentesting/comments/ye0scr/do_any_of_you_guys_know_of_any_pen_testing_jobs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Do any of you guys know of any pen testing jobs that would hire...
Hi my parents and I live in NY, and I would like to know about some jobs that would hire a pen tester w/o a degree. I’ve looked on Glassdoor and...
Dark Reading: Attacks/Breaches
Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM)
Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.
___________________________
@hacking_Attack
@Hacking_Video
Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM)
Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Content Security Market Worth $2.2 Million by 2027 - Exclusive Study by MarketsandMarkets(TM)
Concerns about breaches of sensitive information due to execution of malware scripts and growing adoption of cloud-based services are fueling growth of the content security market.
Dark Reading: Attacks/Breaches
Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program
Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.
___________________________
@hacking_Attack
@Hacking_Video
Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program
Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Google Enters Into Stipulated Agreement to Improve Legal Process Compliance Program
Google admitted to loss of data responsive to 2016 search warrant and agreed to program enhancements, reporting obligations, and a first-of-its-kind Independent Compliance Professional.
Dark Reading: Attacks/Breaches
54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds
Independent research from Encore uncovers hidden costs of cyber attacks.
___________________________
@hacking_Attack
@Hacking_Video
54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds
Independent research from Encore uncovers hidden costs of cyber attacks.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
54% of Staff Would Reconsider Working for a Firm That Had Experienced a Cyber Breach, Research Finds
Independent research from Encore uncovers hidden costs of cyber attacks.
Dark Reading: Attacks/Breaches
Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers
Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data sharing.
___________________________
@hacking_Attack
@Hacking_Video
Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers
Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data sharing.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Valence Security Announces $25M Series A to Scale Delivery of Collaborative SaaS Security Remediation Solutions to Customers
Led by Microsoft's M12 venture fund, Valence's Series A round accelerates the company's ability to help customers secure their SaaS mesh from risk created by democratized end-user adoption, third-party integrations, unmanaged identities, and external data…
Dark Reading: Attacks/Breaches
Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate
Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.
___________________________
@hacking_Attack
@Hacking_Video
Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate
Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Rezilion Vulnerability Scanner Benchmark Report Finds Top Scanners Only 73% Accurate
Majority of vulnerability scanner tools overwhelming teams with false positives and missing exploitable vulnerabilities.
Dark Reading: Attacks/Breaches
BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses
New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.
___________________________
@hacking_Attack
@Hacking_Video
BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses
New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
BlackBerry Launches Cyber Threat Intelligence Service to Strengthen Cyber Defenses
New service from BlackBerry's Threat Research and Intelligence Team reduces unknowns to enhance detection and response.
Dark Reading: Attacks/Breaches
Baltimore/Washington International Thurgood Marshall Airport Selects Telos to Process Background Checks for Aviation Workers
Telos' aviation channeling service offers increased efficiency and flexibility in credentialing operations at the busiest airport in the Washington-Baltimore region.
___________________________
@hacking_Attack
@Hacking_Video
Baltimore/Washington International Thurgood Marshall Airport Selects Telos to Process Background Checks for Aviation Workers
Telos' aviation channeling service offers increased efficiency and flexibility in credentialing operations at the busiest airport in the Washington-Baltimore region.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Baltimore/Washington International Thurgood Marshall Airport Selects Telos to Process Background Checks for Aviation Workers
Telos' aviation channeling service offers increased efficiency and flexibility in credentialing operations at the busiest airport in the Washington-Baltimore region.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Most Dangerous Cyber Attacks of 2022
https://cdn-images-1.medium.com/max/634/1*nXU5WQ3SPXO2UJsUjj4hCg.jpeg
TL;DR- Billions of dollars are stolen every year because of cyber attacks, but what are they and how are hackers so successful in…
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
The Most Dangerous Cyber Attacks of 2022
https://cdn-images-1.medium.com/max/634/1*nXU5WQ3SPXO2UJsUjj4hCg.jpeg
TL;DR- Billions of dollars are stolen every year because of cyber attacks, but what are they and how are hackers so successful in…
Continue reading on The Gray Area »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Most Dangerous Cyber Attacks of 2022
TL;DR- Billions of dollars are stolen every year because of cyber attacks, but what are they and how are hackers so successful in utilizing…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Online Reverse Shell Creator
https://cdn-images-1.medium.com/max/1567/1*UoHg_cObHPbkblwWlxlF4w.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Online Reverse Shell Creator
https://cdn-images-1.medium.com/max/1567/1*UoHg_cObHPbkblwWlxlF4w.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Online Reverse Shell Creator
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Find Out Who Hacked Your Instagram
https://cdn-images-1.medium.com/max/800/0*Lo60T3h2DsGEJaYi.jpg
Instagram is a social media platform used by millions of people around the world for sharing photos and videos. It was created by two…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to Find Out Who Hacked Your Instagram
https://cdn-images-1.medium.com/max/800/0*Lo60T3h2DsGEJaYi.jpg
Instagram is a social media platform used by millions of people around the world for sharing photos and videos. It was created by two…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to Find Out Who Hacked Your Instagram
Instagram is a social media platform used by millions of people around the world for sharing photos and videos. It was created by two…
Stored XSS To Cookie Exfiltration
Today I will be explaining an XSS (“Cross Site Scripting”) vulnerability I found in a private bug bounty program that allowed me to…Continue reading on Medium »
Read more...
Today I will be explaining an XSS (“Cross Site Scripting”) vulnerability I found in a private bug bounty program that allowed me to…Continue reading on Medium »
Read more...