Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Inout Jobs Portal 2.2.2 Cross Site Scripting

https://2.bp.blogspot.com/-MVgbYjy2n8E/WWlvDeDSliI/AAAAAAAAIK0/xNViOH31E8QoNbofn2xwVueZLLEvjlYYACLcBGAs/s1600/h130.png
Inout Jobs Portal version 2.2.2 suffers from a cross site scripting vulnerability.

SHA-256 | 6f3be2d31feb3d9c7a0c800ce5810ede460356e4aec96ec7e16f05115241db1a

Download
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘

┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Vulnerability ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : inoutscripts.com │
│ Vendor : Inout Scripts - Nesote Technologies Private Limited │
│ Software : Inout Jobs Portal 2.2.2 │
│ Vuln Type: Reflected XSS │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Greets:

The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL

CryptoJob (Twitter) twitter.com/CryptozJob

┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Path: /index.php
Method: GET

URL parameter 'page' is vulnerable to XSS

https://www.website.com/index.php?page=index%2findexyar11%3cimg%20src%3da%20onerror%3dalert(1)%3ex75a9
[-] Done

Source:packetstormsecurity.com
Dexalot HackenProof Bug Bounty

Dexalot ek non-custodial, decentralized cryptocurrency exchange hai jisme ek Central Limit Order Book capability hai. Avalanche dwara…Continue reading on Dexalot »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to clone a student ID?

I want to make a second clone of a student ID so I can go in and out of my gf’s dorm whenever. The dorms open using a card swipe (magnetic strip I believe). Can someone point me to some hardware that can clone a magnetic strip and any other security features I should know about?

submitted by /u/Iittle_shit
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Are black hat hackers psychopaths?

Black hat hackers will hurt people in any way possible to make some profit. For example through ransomware, blackmailing, stealing crypto and so on.

Normal criminals usually have some honor and avoid hurting innocent people, but cyber criminals seem to lack all empathy.

So, can we classify the typical black hat hackers as psychopaths?

submitted by /u/BitContent6259
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Can iPad be access from wifi?

I’m sorry but I suck at everything tech and my wording is probably wrong, but I’m posting on behalf of a desperate friend.

We're in Canada and my friend lives with her in-laws. They use Bell internet services, which comes with an elaborate protection software.

Last month she discovered that her brother in law had been able to access and see everything she does on her computer, and when confronted he said it's actually easy because they're on the same network. She was extremely shocked to say the least.

She wants to plan an exit from this marriage, and wants to start using her iPad to look up apartments, lawyers, etc, and write notes to organize herself.

The question is: since she still has to connect to the house wifi to do this, would her in-laws still be able to access the notes and search results on the iPad? My understanding is that Apple has tighter security but I don't know if this stands when you're sharing the same internet.

I appreciate the help, thank you.

submitted by /u/Neolithique
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
I got rejected by BPO/Call Center during an interview because I told my hobbies are cybersecurity and spoke about stingray!

I am 24 years old with Bachalors's degree in finance and law. Today, I gave interview in a BPO/Call Center.

Interviewer asked me about my hobbies so I went on unhinged rant of computers and cybersecurity.

They asked me about speaking fluently on a topic relating to best thing in computing world or cyber security world since I like computers very much.

I spent 5 mins talking about stingray device and a ran

I got rejected.

submitted by /u/piglet_2298
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to use packet sniffer? (WireShark)

So i've read you can do allot with a packet sniffer, i am not looking to do anything illegal, but i do want to know how i ' analyze ' the files, see if there is anything wrong but also know what types of files show what,



Let's say i want to know if my DNS is being poisioned, i want to know what i should check obviously, and what if i want to know if there's uncrypted data packets being sent, i'm curious about that.



I am not sure if i'm allowed to discuss this, since if it's used in a bad way it is illegal, but my intent is to learn.



Edit:

I'm seeing packets that say extra things like TCP Spurious Retransmission, TCP Dup ACK, and allot of weird names like the ACK and RST and Handshake / protected payload / Notify Application data, etc etc.



How do those things work?

submitted by /u/Beat_The_Box_
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Insecure Direct Object Mapping or IDOMs is an underrated bug class and way more severe then IDORs

So IDOMs is a category to describe web app bugs that have been around since at least 2008. In different programming languages it's known as different names in Ruby it's called Mass Assignment, in Java and .NET ASPX it's called Data Binding or Reflection Binding. All these bugs have been categorized under the new IDOM name to prevent confusion. How they work is if a framework let's you append new objects depending on the parameters you place in your request they get mapped into the application which is a dangerous practice and the only way to prevent an IDOM is to explicitly whitelist object names in the programming logic so if you don't do this you are automatically vulnerable out of the gate. I've found IDOMs in so many big companies web apps especially java MVC based apps. At a recent blackhat conference in 2022 there was a presentation called "Data Binding 2 Shell" where a bunch of researchers have found severe IDOMs in popular java frameworks that led to RCE so the problem is still very much relevant to this day. Think of IDOM as writing to object data and think of IDOR as reading from object data there opposites of each other.

submitted by /u/TheCrazyAcademic
[link] [comments]