Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
SQL Injection: A Common Web Application Security Vulnerability
https://cdn-images-1.medium.com/max/640/1*Mty7wDaPzVgiIbjnsagqAA.jpeg
SQL injection is a method of exploiting vulnerabilities in a website’s code to gain unauthorized access to its database.
Continue reading on Medium »
SQL Injection: A Common Web Application Security Vulnerability
https://cdn-images-1.medium.com/max/640/1*Mty7wDaPzVgiIbjnsagqAA.jpeg
SQL injection is a method of exploiting vulnerabilities in a website’s code to gain unauthorized access to its database.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Basic SSTI — Server-Side Template Injection | 2023
https://cdn-images-1.medium.com/max/600/0*gcu4cXwN3c1VhGbs.png
Portswigger — Basic server-side template injection Solution | Karthikeyan Nagaraj
Continue reading on InfoSec Write-ups »
Basic SSTI — Server-Side Template Injection | 2023
https://cdn-images-1.medium.com/max/600/0*gcu4cXwN3c1VhGbs.png
Portswigger — Basic server-side template injection Solution | Karthikeyan Nagaraj
Continue reading on InfoSec Write-ups »
Hacking on Medium
The Dark Side of AI Generation, beyond student cheating
https://cdn-images-1.medium.com/max/600/1*qnmn3GytnOxkh3fE5moL9g.png
ChatGPT is a powerful language model developed by OpenAI that can be used for a wide range of applications, from helping with writing…
Continue reading on Predict »
The Dark Side of AI Generation, beyond student cheating
https://cdn-images-1.medium.com/max/600/1*qnmn3GytnOxkh3fE5moL9g.png
ChatGPT is a powerful language model developed by OpenAI that can be used for a wide range of applications, from helping with writing…
Continue reading on Predict »
Medium
The Dark Side of AI Generation, beyond student cheating
ChatGPT is a powerful language model developed by OpenAI that can be used for a wide range of applications, from helping with writing tasks…
Hacking on Medium
Atención usuarios de Android: Surge un nuevo malware Hook con capacidades RAT
https://cdn-images-1.medium.com/max/882/0*sggKbvAKJeIx3q1W
El actor de amenazas detrás de los troyanos bancarios para Android BlackRock y ERMAC ha desatado otro malware en alquiler llamado Hook que…
Continue reading on Medium »
Atención usuarios de Android: Surge un nuevo malware Hook con capacidades RAT
https://cdn-images-1.medium.com/max/882/0*sggKbvAKJeIx3q1W
El actor de amenazas detrás de los troyanos bancarios para Android BlackRock y ERMAC ha desatado otro malware en alquiler llamado Hook que…
Continue reading on Medium »
Medium
Atención usuarios de Android: Surge un nuevo malware Hook con capacidades RAT
El actor de amenazas detrás de los troyanos bancarios para Android BlackRock y ERMAC ha desatado otro malware en alquiler llamado Hook que…
Hacking on Medium
Ya está listo el primer algoritmo cuántico que amenaza de muerte a las técnicas de cifrado más…
https://cdn-images-1.medium.com/max/1639/0*ANcy6f8cLWkTO8E_
A los expertos no los ha cogido por sorpresa. Al menos, no del todo. La posibilidad de que un ordenador cuántico pueda ser utilizado para…
Continue reading on Medium »
Ya está listo el primer algoritmo cuántico que amenaza de muerte a las técnicas de cifrado más…
https://cdn-images-1.medium.com/max/1639/0*ANcy6f8cLWkTO8E_
A los expertos no los ha cogido por sorpresa. Al menos, no del todo. La posibilidad de que un ordenador cuántico pueda ser utilizado para…
Continue reading on Medium »
Medium
Ya está listo el primer algoritmo cuántico que amenaza de muerte a las técnicas de cifrado más avanzadas
A los expertos no los ha cogido por sorpresa. Al menos, no del todo. La posibilidad de que un ordenador cuántico pueda ser utilizado para…
Good UAL (Universal Audit Log) Hunting
https://www.reddit.com/r/redteamsec/comments/10h36co/good_ual_universal_audit_log_hunting/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/GoodUALHunting) [comments] (https://www.reddit.com/r/redteamsec/comments/10h36co/good_ual_universal_audit_log_hunting/)
https://www.reddit.com/r/redteamsec/comments/10h36co/good_ual_universal_audit_log_hunting/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/GoodUALHunting) [comments] (https://www.reddit.com/r/redteamsec/comments/10h36co/good_ual_universal_audit_log_hunting/)
Dark Reading: Attacks/Breaches
The Evolution of Account Takeover Attacks: Initial Access Brokers for IoT
Head off account takeover attacks by being proactive about IoT security. Start with designing and building better security protocols into IoT devices, always change weak default configurations, and regularly apply patches to ensure that IoT devices are secure.
The Evolution of Account Takeover Attacks: Initial Access Brokers for IoT
Head off account takeover attacks by being proactive about IoT security. Start with designing and building better security protocols into IoT devices, always change weak default configurations, and regularly apply patches to ensure that IoT devices are secure.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
wolfSSL Session Resumption Denial Of Service
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png wolfSSL versions prior to 5.5.0 suffer from a denial of service condition related to session resumption. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. The bug occurs after a client performs a handshake against a wolfSSL server and then closes the connection. If the server reuses the previous session structure (struct WOLFSSL) by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello, which resumes the previous session, crashes the server. Note, that this bug only exists in resumed handshakes using TLS session resumption. This bug was discovered using the novel symbolic-model-guided fuzzer tlspuffin.
SHA-256 |
wolfSSL Session Resumption Denial Of Service
https://4.bp.blogspot.com/-1sVwQJsRVpo/WWlvgaUDftI/AAAAAAAAIQM/9m_QfduSdAQi14Fs6kLQe2-YLO5Bx1iKQCLcBGAs/s1600/h87.png wolfSSL versions prior to 5.5.0 suffer from a denial of service condition related to session resumption. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. The bug occurs after a client performs a handshake against a wolfSSL server and then closes the connection. If the server reuses the previous session structure (struct WOLFSSL) by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello, which resumes the previous session, crashes the server. Note, that this bug only exists in resumed handshakes using TLS session resumption. This bug was discovered using the novel symbolic-model-guided fuzzer tlspuffin.
SHA-256 |
1b9325efbf39604c8462f0298d0d79f674ddf2937457ea4559d7da387dd41a30Download # wolfSSL before 5.5.0: Denial-of-service with session resumption
=================================================================
## INFO
=======
The CVE project has assigned the id CVE-2022-38152 to this issue.
Severity: 7.5 HIGH
Affected version: before 5.5.0
End of embargo: Ended August 30, 2022
## SUMMARY
==========
When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on
its session, the server crashes with a segmentation fault. The bug occurs after
a client performs a handshake against a wolfSSL server and then closes the
connection. If the server reuses the previous session structure (struct WOLFSSL)
by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello,
which resumes the previous session, crashes the server. Note, that this bug only
exists in resumed handshakes using TLS session resumption. This bug was
discovered using the novel symbolic-model-guided fuzzer tlspuffin.
## DETAILS
==========
Line numbers below are valid for the wolfSSL Git tag v5.4.0-stable. The
vulnerability is exploitable with default compilation flags. If the
--enable-postauth flag is used, then this bug is no longer exploitable. When
creating a new TLS session (represented by a struct WOLFSSL), a struct called
arrays is allocated in internal.c:6652.
```
int InitSSL(WOLFSSL* ssl, WOLFSSL_CTX* ctx, int writeDup)
{
...
ssl->arrays = (Arrays*)XMALLOC(sizeof(Arrays), ssl->heap,
DYNAMIC_TYPE_ARRAYS);
...
}
```
Note that this function is only called when creating a new session structure
using wolfSSL_new. After a handshake is done, resources related to it are freed
by default using the FreeHandshakeResources function in line ssl.c:3735. This
frees the memory behind ssl->arrays and sets the pointer to NULL.
```
void FreeHandshakeResources(WOLFSSL* ssl)
{
...
if (!ssl->options.tls1_3)
FreeArrays(ssl)
...
}
void FreeArrays(WOLFSSL* ssl)
{
...
ssl->arrays = NULL;
}
```
If the compile flag --enable-postauth is not set, the variable options.tls1_3 is
false, and therefore the arrays are freed. If --enable-postauth is set, then the
arrays are not freed. The above code is executed during the handshake of a fresh
session. Users of wolfSSL might not allocate a new session by using
wolfSSL_new(), but reuse a previous struct WOLFSSL. This can be done by calling
wolfSSL_clear(WOLFSSL* ssl) on the previous session and reusing the struct. The
next abbreviated handshake, which resumes the previous connection, will now
cause a segmentation fault in tls13.c:5296. The segmentation fault occurs
because the arrays pointer still points to NULL as InitSSL is not called before
the Client Hello is handled.
## AFFECTED VERSIONS
====================
wolfSSL 5.3.0 and 5.4.0 are affected The server needs to handle sessions in a
non-default way by using wolfSSL_clear
## SUGGESTED REMEDIATION
========================
After a session has been cleared and is reused for the next client, it should be
reinitialized. Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Inout Multi-Vendor Shopping Cart 3.2.3 Cross Site Scripting
https://4.bp.blogspot.com/-qWHV3SrNBkU/WWlu99WsXjI/AAAAAAAAIJ4/a1ff3k5st1g65kjfNuwTJpgcbLEB4bHEACLcBGAs/s1600/h116.png Inout Multi-Vendor Shopping Cart version 3.2.3 suffers from a cross site scripting vulnerability.
SHA-256 |
Inout Multi-Vendor Shopping Cart 3.2.3 Cross Site Scripting
https://4.bp.blogspot.com/-qWHV3SrNBkU/WWlu99WsXjI/AAAAAAAAIJ4/a1ff3k5st1g65kjfNuwTJpgcbLEB4bHEACLcBGAs/s1600/h116.png Inout Multi-Vendor Shopping Cart version 3.2.3 suffers from a cross site scripting vulnerability.
SHA-256 |
555ec189fe910ed0f4a4c234e2fb6059b99c4a1cca99548dc06c4e9e63c80997Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : inoutscripts.com │
│ Vendor : Inout Scripts - Nesote Technologies Private Limited │
│ Software : Inout Multi-Vendor Shopping Cart 3.2.3 │
│ Vuln Type: Reflected XSS │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Path: /index.php
Method: GET
URL parameter 'page' is vulnerable to XSS
https://www.website.com/index.php?page=product%2fcouponsh446k%3cimg%20src%3da%20onerror%3dalert(1)%3eciqs8
URL parameter 'keyword' is vulnerable to XSS
https://www.website.com/index.php?page=product/productviews&keyword=tv24708%22%3balert(1)%2f%2f279
[-] Done Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ASKEY RTF3505VW-N1 Privilege Escalation
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
ASKEY routers version RTF3505VW-N1 suffer from a local privilege escalation vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
ASKEY RTF3505VW-N1 Privilege Escalation
https://2.bp.blogspot.com/-eFdyzozIeoQ/WWlvJBrapBI/AAAAAAAAIL0/M7DCjoWzT04QjJ3gTxRIZh_KH17rlqHhwCLcBGAs/s1600/h146.png
ASKEY routers version RTF3505VW-N1 suffer from a local privilege escalation vulnerability.
SHA-256 |
f9965ccc5dcd57f3e65a484ff64229ecc3616041f5f58399c8f18a9f6071866bDownload
# Exploit Title: ASKEY RTF3505VW-N1 - Privilege escalation
# Date: 07-12-2022
# Exploit Author: Leonardo Nicolas Servalli
# Vendor Homepage: www.askey.com
# Platform: ASKEY router devices RTF3505VW-N1
# Tested on: Firmware BR_SV_g000_R3505VMN1001_s32_7
# Vulnerability analysis: https://github.com/leoservalli/Privilege-escalation-ASKEY/blob/main/README.md
#Description:
#----------
# ASKEY RTF3505VW-N1 devices are provided with access through ssh into a restricted default shell (credentials are on the back of the router and in some cases these routers use default credentials).
# The command “tcpdump” is present in the restricted shell and do not handle correctly the -z flag, so it can be used to escalate privileges through the creation of a local file in the /tmp directory of the router, and injecting packets through port 80 (used for the router's Web GUI) with the string ";/bin/bash" in order to be executed by "-z sh". By using “;/bin/bash” as injected string we can spawn a busybox/ash console.
Source:packetstormsecurity.com