hacking: security in practice
USB autorun
I’m trying to make a virus that steals files however the several methods I’ve used to make it start when I insert the USB have failed so if anyone knows how to do so please let me know (batch virus)
submitted by /u/xXhyperinstinctXx_YT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
USB autorun
I’m trying to make a virus that steals files however the several methods I’ve used to make it start when I insert the USB have failed so if anyone knows how to do so please let me know (batch virus)
submitted by /u/xXhyperinstinctXx_YT
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
USB autorun
I’m trying to make a virus that steals files however the several methods I’ve used to make it start when I insert the USB have failed so if anyone...
hacking: security in practice
Does anyone know a program that is easy to use and is capabile of doing this?
Hi, I am currently researching an exploit in an Android App (via emulator on windows), I want to try and brutefroce my OTP using a wordlist so something along the lines of this:
1.Program reads 123456 from text file
2.Program types 123456 and press enter
3.Program clicks the typing box..
4.Program backspaces the whole thing, reads 123457 and types it
1. Program repeats this until number 999999 is reached.
submitted by /u/eclipsek20
[link] [comments]
Does anyone know a program that is easy to use and is capabile of doing this?
Hi, I am currently researching an exploit in an Android App (via emulator on windows), I want to try and brutefroce my OTP using a wordlist so something along the lines of this:
1.Program reads 123456 from text file
2.Program types 123456 and press enter
3.Program clicks the typing box..
4.Program backspaces the whole thing, reads 123457 and types it
1. Program repeats this until number 999999 is reached.
submitted by /u/eclipsek20
[link] [comments]
reddit
Does anyone know a program that is easy to use and is capabile of...
Hi, I am currently researching an exploit in an Android App (via emulator on windows), I want to try and brutefroce my OTP using a wordlist so...
hacking: security in practice
DoS attack?
Can someone teach me how to perform it on an account of an application making the app crash for that certain user?
submitted by /u/Mr-Invincible3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
DoS attack?
Can someone teach me how to perform it on an account of an application making the app crash for that certain user?
submitted by /u/Mr-Invincible3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
reddit.com: over 18?
Reddit gives you the best of the internet in one place. Get a constantly updating feed of breaking news, fun stories, pics, memes, and videos just for you. Passionate about something niche? Reddit has thousands of vibrant communities with people that share…
APSoft-Web-Scanner-v2 - Powerful Dork Searcher And Vulnerability Scanner For Windows Platform
APSoft Webscanner Version 2 new version of APSoft Webscanner Version 1Software pictures What can i do with this ? with this software, you will be able to search your dorks in supported search engines and scan grabbed urls to find their vulnerabilities. in addition , you will be able to generate dorks, scan urls and saerch dorks separately when ever you want Supported search engines Google Yahoo Bing Supported vulnerabilities SQL Injection XSS LFI Whats new in version 2 (most important updates) ? adding custom payloads you can edit payloads.json file which will be created when you open and close software once, and add payloads as much as you want , easier than drinking water adding custom error checks once a payload injected in url, software will looks for errors in new website source, you can also customize those errors too. what you have to do is easily edit payloadserror.json file which will be created when you open and close software once. you can also use regexes as error , with REIT|your regex here format multy vulnerability check in old version, you were not able to choose more than 1 vulnerabilites to check, but in v2, you can do this easily. multy search engine grabber in old version, you were not able to choose more than 1 saerchengines to saerch in, but in v2, you can do this easily. memory management we`ve added memory management to avoid lack of memory in your system dork generator you can generate dorks and save them very fast with your custom configurations and keywords. valid configuration format should contain {DORK} that will be replaced with each keyword in dork generation process updates list (all) new threading system based on microsoft task using linq technology dork generator part ability to add regexes as payloads error low usage moving from WPF to Windows form (just because my designes are bad, contact me if you can do better) ability to use scanner-graber separately and simultaneously and .... support / suggestion = ph09nixom@gmail.com - t.me/ph09nix Leave a STAR if you found this usefull :) Download APSoft-Web-Scanner-v2
Read more...
___________________________
@hacking_Attack
@Hacking_Video
APSoft Webscanner Version 2 new version of APSoft Webscanner Version 1Software pictures What can i do with this ? with this software, you will be able to search your dorks in supported search engines and scan grabbed urls to find their vulnerabilities. in addition , you will be able to generate dorks, scan urls and saerch dorks separately when ever you want Supported search engines Google Yahoo Bing Supported vulnerabilities SQL Injection XSS LFI Whats new in version 2 (most important updates) ? adding custom payloads you can edit payloads.json file which will be created when you open and close software once, and add payloads as much as you want , easier than drinking water adding custom error checks once a payload injected in url, software will looks for errors in new website source, you can also customize those errors too. what you have to do is easily edit payloadserror.json file which will be created when you open and close software once. you can also use regexes as error , with REIT|your regex here format multy vulnerability check in old version, you were not able to choose more than 1 vulnerabilites to check, but in v2, you can do this easily. multy search engine grabber in old version, you were not able to choose more than 1 saerchengines to saerch in, but in v2, you can do this easily. memory management we`ve added memory management to avoid lack of memory in your system dork generator you can generate dorks and save them very fast with your custom configurations and keywords. valid configuration format should contain {DORK} that will be replaced with each keyword in dork generation process updates list (all) new threading system based on microsoft task using linq technology dork generator part ability to add regexes as payloads error low usage moving from WPF to Windows form (just because my designes are bad, contact me if you can do better) ability to use scanner-graber separately and simultaneously and .... support / suggestion = ph09nixom@gmail.com - t.me/ph09nix Leave a STAR if you found this usefull :) Download APSoft-Web-Scanner-v2
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows Container Manager Service CmsRpcSrv_MapVirtualDiskToContainer Privilege Escalation
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
The Container Manager Service does not impersonate the caller when granting access to virtual disk images leading to privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
Windows Container Manager Service CmsRpcSrv_MapVirtualDiskToContainer Privilege Escalation
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
The Container Manager Service does not impersonate the caller when granting access to virtual disk images leading to privilege escalation.
MD5 |
ae8247dda745d9d8d6c85bfb03878028Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Android NFC nfa_rw_sys_disable Type Confusion
https://4.bp.blogspot.com/-SxgEc7szt9w/WWlva1nZfUI/AAAAAAAAIPE/UrvwYC_4YmMlGypxS9ASHy318XWSifzEQCLcBGAs/s1600/h71.png
Android NFC suffers from a type confusion vulnerability in nfa_rw_sys_disable.
MD5 |
Download
Source:packetstormsecurity.com
Android NFC nfa_rw_sys_disable Type Confusion
https://4.bp.blogspot.com/-SxgEc7szt9w/WWlva1nZfUI/AAAAAAAAIPE/UrvwYC_4YmMlGypxS9ASHy318XWSifzEQCLcBGAs/s1600/h71.png
Android NFC suffers from a type confusion vulnerability in nfa_rw_sys_disable.
MD5 |
c8afe4ec5b084a950377d0e1557801f8Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Odoo 12.0.20190101 Unquoted Service Path
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
Odoo version 12.0.20190101 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Odoo 12.0.20190101 Unquoted Service Path
https://1.bp.blogspot.com/-93ZP4TpCwBw/WWlu7wGG0SI/AAAAAAAAIJg/yDCONAkAMz8MX1TtbGL6KFo1njFu_UyvACLcBGAs/s1600/h111.png
Odoo version 12.0.20190101 suffers from an unquoted service path vulnerability.
MD5 |
2818299cf76dd1bf13481c862d845df4Download
# Exploit Title: Odoo 12.0.20190101 - 'nssm.exe' Unquoted Service Path
# Exploit Author: 1F98D
# Vendor Homepage: https://www.odoo.com/
# Software Link: https://nightly.odoo.com/12.0/nightly/windows/odoo_12.0.20190101.exe
# Tested Version: 12.0.20190101
# Tested on OS: Windows
# Step to discover Unquoted Service Path:
C:\> icacls "C:\Program Files (x86)\Odoo 12.0\nssm"
C:\Program Files (x86)\Odoo 12.0\nssm pc-1\user-1:(OI)(CI)(M)
NT SERVICE\TrustedInstaller:(I)(F)
NT SERVICE\TrustedInstaller:(I)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(I)(F)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(IO)(F)
BUILTIN\Administrators:(I)(F)
BUILTIN\Administrators:(I)(OI)(CI)(IO)(F)
BUILTIN\Users:(I)(RX)
BUILTIN\Users:(I)(OI)(CI)(IO)(GR,GE)
CREATOR OWNER:(I)(OI)(CI)(IO)(F)
APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(RX)
APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE)
APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(RX)
APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(I)(OI)(CI)(IO)(GR,GE)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Odoo 12.0.20190101 Unquoted Service Path
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows Container Manager Service Arbitrary Object Directory Creation Privilege Escalation
https://1.bp.blogspot.com/-q1b99IBpI9c/WWlu5sPD0hI/AAAAAAAAIJI/No13BTu40mUIIhRH8r1ULckiDMJCd7zkQCLcBGAs/s1600/h106.png
The Container Manager Service creates an AppContainer process without impersonating the access token leading to privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
Windows Container Manager Service Arbitrary Object Directory Creation Privilege Escalation
https://1.bp.blogspot.com/-q1b99IBpI9c/WWlu5sPD0hI/AAAAAAAAIJI/No13BTu40mUIIhRH8r1ULckiDMJCd7zkQCLcBGAs/s1600/h106.png
The Container Manager Service creates an AppContainer process without impersonating the access token leading to privilege escalation.
MD5 |
ad4654c8ed7054c3225224811ba94b15Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Splinterware System Scheduler Professional 5.30 Unquoted Service Path
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
Splinterware System Scheduler Professional version 5.30 suffers an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Splinterware System Scheduler Professional 5.30 Unquoted Service Path
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
Splinterware System Scheduler Professional version 5.30 suffers an unquoted service path vulnerability.
MD5 |
8f6dbe88705c0cb72b7fc1c5e9131bafDownload
# Exploit Title: Splinterware System Scheduler Professional 5.30 - Unquoted Service Path
# Date: 2021-05-11
# Exploit Author: Andrea Intilangelo
# Vendor Homepage: https://www.splinterware.com
# Software Link: https://www.splinterware.com/download/ssproeval.exe
# Version: 5.30 Professional
# Tested on: Windows 10 Pro 20H2 x64
System Scheduler Professional 5.30 is subject to privilege escalation due to insecure file permissions, impacting
where the service 'WindowsScheduler' calls its executable. A non-privileged user could execute arbitrary code with
elevated privileges (system level privileges as "nt authority\system") since the service runs as Local System;
renaming the WService.exe file located in the software's path and replacing it with a malicious file, the new one
will be executed after a short while.
C:\Users\test>sc qc WindowsScheduler
[SC] QueryServiceConfig OPERAZIONI RIUSCITE
NOME_SERVIZIO: WindowsScheduler
TIPO : 10 WIN32_OWN_PROCESS
TIPO_AVVIO : 2 AUTO_START
CONTROLLO_ERRORE : 0 IGNORE
NOME_PERCORSO_BINARIO : C:\PROGRA~2\SYSTEM~1\WService.exe
GRUPPO_ORDINE_CARICAMENTO :
TAG : 0
NOME_VISUALIZZATO : System Scheduler Service
DIPENDENZE :
SERVICE_START_NAME : LocalSystem
C:\Users\test>icacls C:\PROGRA~2\SYSTEM~1\
C:\PROGRA~2\SYSTEM~1\ BUILTIN\Users:(RX,W)
BUILTIN\Users:(OI)(CI)(IO)(GR,GW,GE)
NT SERVICE\TrustedInstaller:(I)(F)
NT SERVICE\TrustedInstaller:(I)(CI)(IO)(F)
NT AUTHORITY\SYSTEM:(I)(F)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(IO)(F)
BUILTIN\Administrators:(I)(F)
BUILTIN\Administrators:(I)(OI)(CI)(IO)(F)
BUILTIN\Users:(I)(RX)
BUILTIN\Users:(I)(OI)(CI)(IO)(GR,GE)
CREATOR OWNER:(I)(OI)(CI)(IO)(F)
AUTORITÀ PACCHETTI APPLICAZIONI\TUTTI I PACCHETTI APPLICAZIONI:(I)(RX)
AUTORITÀ PACCHETTI APPLICAZIONI\TUTTI I PACCHETTI APPLICAZIONI:(I)(OI)(CI)(IO)(GR,GE)
AUTORITÀ PACCHETTI APPLICAZIONI\TUTTI I PACCHETTI APPLICAZIONI CON RESTRIZIONI:(I)(RX)
AUTORITÀ PACCHETTI APPLICAZIONI\TUTTI I PACCHETTI APPLICAZIONI CON RESTRIZIONI:(I)(OI)(CI)(IO)(GR,GE)
Elaborazione completata per 1 file. Elaborazione non riuscita per 0 file
C:\Users\test>
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chevereto 3.17.1 Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Chevereto version 3.17.1 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Chevereto 3.17.1 Cross Site Scripting
https://2.bp.blogspot.com/-ulQQD3v8DYI/WWlvnLww_dI/AAAAAAAAIRM/ialO7Idq8vAmWKoyuXUdK7x44tFKJsnBwCLcBGAs/s1600/hack_img4.png
Chevereto version 3.17.1 suffers from a persistent cross site scripting vulnerability.
MD5 |
d2fa311cc91e61a5447460593e31993dDownload
# Exploit Title: Chevereto 3.17.1 - Cross Site Scripting (Stored)
# Google Dork: "powered by chevereto"
# Date: 19.04.2021
# Exploit Author: Akıner Kısa
# Vendor Homepage: https://chevereto.com/
# Software Link: https://chevereto.com/releases
# Version: 3.17.1
# Tested on: Windows 10 / Xampp
Proof of Concept:
1. Press the Upload image button and upload any image.
2. After uploading the image, press the pencil icon on the top right of the image and write "><svg instead of the title.
3. Upload the picture and go to the picture address.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Windows Container Manager Service CmsRpcSrv_CreateContainer Privilege Escalation
https://1.bp.blogspot.com/-jW_VWiRlkJ4/WWlvh6QcNII/AAAAAAAAIQg/x12g-flM0hAb9z-fRCiW9Z3UAYaaFuf7ACLcBGAs/s1600/h9.png
The Container Manager Service accepts an access token provided by the user without verification allowing an arbitrary process to be created with another user identity leading to privilege escalation.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Windows Container Manager Service CmsRpcSrv_CreateContainer Privilege Escalation
https://1.bp.blogspot.com/-jW_VWiRlkJ4/WWlvh6QcNII/AAAAAAAAIQg/x12g-flM0hAb9z-fRCiW9Z3UAYaaFuf7ACLcBGAs/s1600/h9.png
The Container Manager Service accepts an access token provided by the user without verification allowing an arbitrary process to be created with another user identity leading to privilege escalation.
MD5 |
12c1abb8e71fc62e306c9bc1dea254d3Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Windows Container Manager Service CmsRpcSrv_CreateContainer Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.