Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
[+] Run commands on the operating system.
posix-linux $ whoami
root
posix-linux $ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
To get a full list of options, use --help argument. Interactive mode In interactive mode, commands are used to interact with SSTImap. To enter interactive mode, you can use -i argument. All other arguments, except for the ones regarding exploitation payloads, will be used as initial values for settings. Some commands are used to alter settings between test runs. To run a test, target URL must be supplied via initial -u argument or url command. After that, you can use run command to check URL for SSTI. If SSTI was found, commands can be used to start the exploitation. You can get the same exploitation capabilities, as in the predetermined mode, but you can use Ctrl+C to abort them without stopping a program. By the way, test results are valid until target url is changed, so you can easily switch between exploitation methods without running detection test every time. To get a full list of interactive commands, use command help in interactive mode. Supported template engines SSTImap supports multiple template engines and eval()-like injections. New payloads are welcome in PRs. Engine RCE Blind Code evaluation File read File write Mako ✓ ✓ Python ✓ ✓ Jinja2 ✓ ✓ Python ✓ ✓ Python (code eval) ✓ ✓ Python ✓ ✓ Tornado ✓ ✓ Python ✓ ✓ Nunjucks ✓ ✓ JavaScript ✓ ✓ Pug ✓ ✓ JavaScript ✓ ✓ doT ✓ ✓ JavaScript ✓ ✓ Marko ✓ ✓ JavaScript ✓ ✓ JavaScript (code eval) ✓ ✓ JavaScript ✓ ✓ Dust (<= dustjs-helpers@1.5.0) ✓ ✓ JavaScript ✓ ✓ EJS ✓ ✓ JavaScript ✓ ✓ Ruby (code eval) ✓ ✓ Ruby ✓ ✓ Slim ✓ ✓ Ruby ✓ ✓ ERB ✓ ✓ Ruby ✓ ✓ Smarty (unsecured) ✓ ✓ PHP ✓ ✓ Smarty (secured) ✓ ✓ PHP ✓ ✓ PHP (code eval) ✓ ✓ PHP ✓ ✓ Twig (<=1.19) ✓ ✓ PHP ✓ ✓ Freemarker ✓ ✓ Java ✓ ✓ Velocity ✓ ✓ Java ✓ ✓ Twig (>1.19) × × × × × Dust (> dustjs-helpers@1.5.0) × × × × × Burp Suite Plugin Currently, Burp Suite only works with Jython as a way to execute python2. Python3 functionality is not provided. Future plans If you plan to contribute something big from this list, inform me to avoid working on the same thing as me or other contributors. Make template and base language evaluation functionality more uniform Add more payloads for different engines Short arguments as interactive commands? Automatic languages and engines import Engine plugins as objects of Plugin class? JSON/plaintext API modes for scripting integrations? Argument to remove escape codes? Spider/crawler automation Better integration for Python scripts More POST data types support Payload processing scripts

Download SSTImap (https://github.com/vladko312/SSTImap)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
how to access data on non-storage usb devices?

i have some devices i want to modify data on, however they are NOT storage devices.

examples: mouse, powerbank, usb headset

Basicaly any device that uses usb to charge. I remember an old windws app that could do it, however i cannot recall it's name. Any help would be appreciated.

submitted by /u/dragon1f
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
IDE — TryHackMe

https://cdn-images-1.medium.com/max/870/1*5MrlFpJ-nIFFHgJsuIcc_g.png
Hi pada write up lanjutan ini saya akan membagikan tulisan mengenai mechine yang telah saya selesaikan pada tryhackme.Challenge ini…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Domains IPv6 DNS TakeOVER via MITM6

https://cdn-images-1.medium.com/max/1511/0*LWPd3uhsl6-uZt8C
IPv4 e alternatif olarak üretilen ve günümüzde hala pek etkin olarak kullanılmayan IPv6 protokolü ağlarımızda varsayılan halde…

Continue reading on Medium »
Disclosing Facebook page admins by playing a game

Hello there, It’s been a long time since I wrote any article on my resolved reports due to some internal problems so today I’m going to…Continue reading on Medium »
Read more...
The easiest way to get subdomain takeover

بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمContinue reading on Medium »
Read more...
CRLF-Carriage Return and Line Feed in Short | 2023

Carriage Return and Line Feed In Short Bug Bounty | karthikeyan NagarajContinue reading on InfoSec Write-ups »
Read more...
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمContinue reading on Medium » (https://medium.com/@AhmedMhesham/easiest-way-to-get-subdomain-takeover-76f444c8ee6f?source=rss------bug_bounty-5)