Advanced Web Application Security: Exploiting SSTI Vulnerabilities
Server-Side Template Injection (SSTI) vulnerabilities are often overlooked, but they can have severe consequences if exploited by an…Continue reading on InfoSec Write-ups »
Read more...
Server-Side Template Injection (SSTI) vulnerabilities are often overlooked, but they can have severe consequences if exploited by an…Continue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
O QUE É ESCALONAMENTO DE PRIVILÉGIOS? PARTE 1
https://cdn-images-1.medium.com/max/1080/1*s7sPLAporxpH1ODYorpC_A.jpeg
A escalação de privilégios é o processo de exploração de vulnerabilidades ou configurações incorretas em sistemas para elevar privilégios…
Continue reading on Medium »
O QUE É ESCALONAMENTO DE PRIVILÉGIOS? PARTE 1
https://cdn-images-1.medium.com/max/1080/1*s7sPLAporxpH1ODYorpC_A.jpeg
A escalação de privilégios é o processo de exploração de vulnerabilidades ou configurações incorretas em sistemas para elevar privilégios…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Mastering Network Scanning: A Step-by-Step Guide using Nessus and Nmap
https://cdn-images-1.medium.com/max/626/0*v6dnZ4WqL0b2kJ5-
Discover vulnerabilities and secure your network with Nessus and Nmap network scanning tools.
Continue reading on Medium »
Mastering Network Scanning: A Step-by-Step Guide using Nessus and Nmap
https://cdn-images-1.medium.com/max/626/0*v6dnZ4WqL0b2kJ5-
Discover vulnerabilities and secure your network with Nessus and Nmap network scanning tools.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Reentrancy Attack ($70 million Attack): Hacking Solidity and How to Guard Against It
https://cdn-images-1.medium.com/max/1280/1*aq78rLzHlClLv6toN-l-kA.png
Section 1: What is a Reentrancy Attack?
Continue reading on Medium »
Reentrancy Attack ($70 million Attack): Hacking Solidity and How to Guard Against It
https://cdn-images-1.medium.com/max/1280/1*aq78rLzHlClLv6toN-l-kA.png
Section 1: What is a Reentrancy Attack?
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Reportly - An AzureAD User Activity Report Tool
https://blogger.googleusercontent.com/img/a/AVvXsEhKtu3LUMHFWuaDMxWY7NPlInCtM1ao0_8VDYFU2vRzkH-PeTudPkRHHPb8KSc8CBngHCdUqfFXMc1gIxYGvK17LjUM287CzIBAkVann3RRm7TAKF5_7HoK-KCuVTPi4lw4N7vusUcB0SggAEDOzQofMYkcrBaONHybIU21lL-n3ofLbyCpI6WA7M7HbQ=s320 Reportly is an AzureAD user activity report tool. About the toolThis is a tool that will help blue teams during a cloud incident. When running the tool, the researcher will enter as input a suspicious user and a time frame and will receive a report detailing the following:
1. Information about the user
2. Actions taken by the user
3. Actions taken on the user
4. User login and failure logs UsageWhen running the tool, a link to authentication and a device code will show, follow the link and enter the code to authenticate. https://blogger.googleusercontent.com/img/a/AVvXsEhlEf_DcSqxBrNw1DHVGFL5cIetIiJlTGrz14CQOaY4XB21pNjkc_VApy-zBNc99iznXkDDCdmJqePHzUb1cR1IMNODAoNZ9lluygAHxihygL4tHQ4Wr40whsMgmu8MWRKcvrmkWg5kven6q29mbxOKP9YOfpezgSr42krw0hMF55C-Bsj0euN0EIgbbA=w640-h156 Insert User principal name of a suspicious user.
Insert start and end times in the following format: 2022-11-16
I recommend a range of no longer then a week.
After authentication, in order to create a full report choose the option "5" https://blogger.googleusercontent.com/img/a/AVvXsEiET-TSt49mTgn1dCWYkfn5fc3oI5nlWwo202PooXpsZ_LwNuJJjTAeRDNhShjQB67GgHvJaH5niwGHUGTfe6kzJ5PI8g_p6AiIsjMAGsRiiMdtv8yfSDIy8XkJpszMZhklcyjzB1bVOvSLcsR-f37EvygdASuDMOIOktlzXOMDZ69UmSIEvQ4E7ktUNQ=w640-h230 When the report will be ready the tool will print "Your report is ready!". The reports are created in the executable's directory. InstallationIn order to use the tool you will need an AzureAD application with the following delegated microsoft graph api permissions:
* AuditLog.Read.All
* GroupMember.Read.All
* RoleManagement.Read.Directory
* User.Read
* User.Read.All
dont forget to grant admin consent https://blogger.googleusercontent.com/img/a/AVvXsEhuuN5ziaE8rZe8CoTc_9mJ5ALOY1nGYvHTl3aeDI8btJnbVYlGKJB0-LzkuHE2Z1-oyfLJpa8k8niIXqeh7FDgAoRjJaNZdZv0Eicxrt3C_ZAlaMMbnfG4hd-cI3tr6oOI1OEnmRllU2KFrlTqhdEyvPM7mZl68j9CJavRthWaNrEqDMs7YZz6sP1YdQ=w640-h166 To create an application go to "App registration" tab and select "New registration" option. https://blogger.googleusercontent.com/img/a/AVvXsEg7B3l02Cmog3p0QANhXoisjXDIP1rCAdk6r6YNle7rM_VQQpLxCkSKHJuqaxRcFNExPuyij0rY7BYskMQWd1puN1lxv0CKLqiekIMROTR6rByCEPjreRfDEAdQYSqH6x1ISOhfbjVFMQspVGLftKR_jEq8-c1kSg2rZdSJ5UXcq7xYdTx1MAtGTT9ZGw=w640-h72 Also, when creating the application, make sure you mark the following option as "yes": https://blogger.googleusercontent.com/img/a/AVvXsEjklHW86ryDHw7Sne0FSwlUCrTyGTO50fgvtCY9RDdTw6VRaXe9uHiOi5eih5mdcPZmCunBMhKRNg_OUmAsQfW4xBwjOiVqjLFimKVNoUn3uPVBWp3noGSilSS_H13mRgedQX0i_EOHcSgEYIakoQMtHXYcqOYQN-2Z_IbIqNNi0cD2f7yZGph5D6lZ5g=w640-h158 * you can find this property under the application's "Authentication" tab.
Add a secret to the application. https://blogger.googleusercontent.com/img/a/AVvXsEhc1Yu4qNEcgkE4T1IuIIzkAkPL4hjbuvrBRU7Sf-HCGozQahX7AjDDtPYnIE9O3E022yuCF2m6orSDFtYXFu4pmCdrDTeCB5EXeaXbkODPLwWvr00UuDTw24m8rHJELFTahfGuaR5ysEl-_y_Qr5RPMGlLTQlGy3_lJGpFGGeqcYAqkiRhaBLczMsHLg=w640-h166 * Go to "Certificates & secrets"
* Add a secret
* Immediately copy the secret to the config file (after you watch it once, it disappears)
After you created the application you need to fill the config.cfg file:
clientId = application id
clientSecret = application secret
tenantId = tenant id Download Reportly
Reportly - An AzureAD User Activity Report Tool
https://blogger.googleusercontent.com/img/a/AVvXsEhKtu3LUMHFWuaDMxWY7NPlInCtM1ao0_8VDYFU2vRzkH-PeTudPkRHHPb8KSc8CBngHCdUqfFXMc1gIxYGvK17LjUM287CzIBAkVann3RRm7TAKF5_7HoK-KCuVTPi4lw4N7vusUcB0SggAEDOzQofMYkcrBaONHybIU21lL-n3ofLbyCpI6WA7M7HbQ=s320 Reportly is an AzureAD user activity report tool. About the toolThis is a tool that will help blue teams during a cloud incident. When running the tool, the researcher will enter as input a suspicious user and a time frame and will receive a report detailing the following:
1. Information about the user
2. Actions taken by the user
3. Actions taken on the user
4. User login and failure logs UsageWhen running the tool, a link to authentication and a device code will show, follow the link and enter the code to authenticate. https://blogger.googleusercontent.com/img/a/AVvXsEhlEf_DcSqxBrNw1DHVGFL5cIetIiJlTGrz14CQOaY4XB21pNjkc_VApy-zBNc99iznXkDDCdmJqePHzUb1cR1IMNODAoNZ9lluygAHxihygL4tHQ4Wr40whsMgmu8MWRKcvrmkWg5kven6q29mbxOKP9YOfpezgSr42krw0hMF55C-Bsj0euN0EIgbbA=w640-h156 Insert User principal name of a suspicious user.
Insert start and end times in the following format: 2022-11-16
I recommend a range of no longer then a week.
After authentication, in order to create a full report choose the option "5" https://blogger.googleusercontent.com/img/a/AVvXsEiET-TSt49mTgn1dCWYkfn5fc3oI5nlWwo202PooXpsZ_LwNuJJjTAeRDNhShjQB67GgHvJaH5niwGHUGTfe6kzJ5PI8g_p6AiIsjMAGsRiiMdtv8yfSDIy8XkJpszMZhklcyjzB1bVOvSLcsR-f37EvygdASuDMOIOktlzXOMDZ69UmSIEvQ4E7ktUNQ=w640-h230 When the report will be ready the tool will print "Your report is ready!". The reports are created in the executable's directory. InstallationIn order to use the tool you will need an AzureAD application with the following delegated microsoft graph api permissions:
* AuditLog.Read.All
* GroupMember.Read.All
* RoleManagement.Read.Directory
* User.Read
* User.Read.All
dont forget to grant admin consent https://blogger.googleusercontent.com/img/a/AVvXsEhuuN5ziaE8rZe8CoTc_9mJ5ALOY1nGYvHTl3aeDI8btJnbVYlGKJB0-LzkuHE2Z1-oyfLJpa8k8niIXqeh7FDgAoRjJaNZdZv0Eicxrt3C_ZAlaMMbnfG4hd-cI3tr6oOI1OEnmRllU2KFrlTqhdEyvPM7mZl68j9CJavRthWaNrEqDMs7YZz6sP1YdQ=w640-h166 To create an application go to "App registration" tab and select "New registration" option. https://blogger.googleusercontent.com/img/a/AVvXsEg7B3l02Cmog3p0QANhXoisjXDIP1rCAdk6r6YNle7rM_VQQpLxCkSKHJuqaxRcFNExPuyij0rY7BYskMQWd1puN1lxv0CKLqiekIMROTR6rByCEPjreRfDEAdQYSqH6x1ISOhfbjVFMQspVGLftKR_jEq8-c1kSg2rZdSJ5UXcq7xYdTx1MAtGTT9ZGw=w640-h72 Also, when creating the application, make sure you mark the following option as "yes": https://blogger.googleusercontent.com/img/a/AVvXsEjklHW86ryDHw7Sne0FSwlUCrTyGTO50fgvtCY9RDdTw6VRaXe9uHiOi5eih5mdcPZmCunBMhKRNg_OUmAsQfW4xBwjOiVqjLFimKVNoUn3uPVBWp3noGSilSS_H13mRgedQX0i_EOHcSgEYIakoQMtHXYcqOYQN-2Z_IbIqNNi0cD2f7yZGph5D6lZ5g=w640-h158 * you can find this property under the application's "Authentication" tab.
Add a secret to the application. https://blogger.googleusercontent.com/img/a/AVvXsEhc1Yu4qNEcgkE4T1IuIIzkAkPL4hjbuvrBRU7Sf-HCGozQahX7AjDDtPYnIE9O3E022yuCF2m6orSDFtYXFu4pmCdrDTeCB5EXeaXbkODPLwWvr00UuDTw24m8rHJELFTahfGuaR5ysEl-_y_Qr5RPMGlLTQlGy3_lJGpFGGeqcYAqkiRhaBLczMsHLg=w640-h166 * Go to "Certificates & secrets"
* Add a secret
* Immediately copy the secret to the config file (after you watch it once, it disappears)
After you created the application you need to fill the config.cfg file:
clientId = application id
clientSecret = application secret
tenantId = tenant id Download Reportly
hacking: security in practice
Pool on the roof - April 10, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Pool on the roof - April 10, 2023
Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?
This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.
Make sure to read our wiki as it's full of resources for you.
Keep all beginner questions in this weekly stickied post.
submitted by /u/AutoModerator
[link] [comments]
Reddit
r/hacking on Reddit: Pool on the roof - April 10, 2023
Posted by u/AutoModerator - No votes and no comments
hacking: security in practice
RFID modification for snapper card (my research and an issue)
This morning i got curious as to how easy it would be to theoretically modify the amount of money stored in my snapper transit card, I've seen this done before so I got to work, here is what I have so far and the issue im facing.
Hardware used -
Galaxy S21 Ultra (2x)
My Research -
I first wanted to see if the balance is stored on the card itself or in metlink's servers, I got 2 phones, both with the mobile top-up app that uses NFC from the phones, one phone had its network connections all turned off, both WIFI and data
I first had $6.31 on the card, I used the internet connected phone, opened the snapper app and added $40 to my card, then switched over to the phone with network turned off and read the card with the snapper app and it showed my balance as $46.31, now this concludes that the data for the balance is stored on the card itself and not on metlink's servers. I still do worry that this info isnt only stored on the card but also metlink's servers to cross verify the balance info but I doubt each bus and train is fitted with an internet connection to allow for this.
Secondly, I checked what type of card this is using the RFID card reader app which showed this as a MIFARE Classic 4k card.
I found the tool MIFARE Classic Tool on the playstore, with this it will show me the bytes/data stored on the card, after reading the card it only shows me sector 0 here - https://imgur.com/DizzOIe
The Issue -
As the recording shows only sector 0 is being read (out of 40 sectors, so 0 - 39) and it has no data for balance as it reads identically even after a top up, im assuming this only stores the card identifier and no balance info.
So how can I read the other sectors in this MIFARE Classic 4k card?
I did find some external readers but they are quite expensive so I also want to ask will this cheap combo work?
PN532 NFC RFID Module V3
CP2102 to USB adapter
submitted by /u/xyig
[link] [comments]
RFID modification for snapper card (my research and an issue)
This morning i got curious as to how easy it would be to theoretically modify the amount of money stored in my snapper transit card, I've seen this done before so I got to work, here is what I have so far and the issue im facing.
Hardware used -
Galaxy S21 Ultra (2x)
My Research -
I first wanted to see if the balance is stored on the card itself or in metlink's servers, I got 2 phones, both with the mobile top-up app that uses NFC from the phones, one phone had its network connections all turned off, both WIFI and data
I first had $6.31 on the card, I used the internet connected phone, opened the snapper app and added $40 to my card, then switched over to the phone with network turned off and read the card with the snapper app and it showed my balance as $46.31, now this concludes that the data for the balance is stored on the card itself and not on metlink's servers. I still do worry that this info isnt only stored on the card but also metlink's servers to cross verify the balance info but I doubt each bus and train is fitted with an internet connection to allow for this.
Secondly, I checked what type of card this is using the RFID card reader app which showed this as a MIFARE Classic 4k card.
I found the tool MIFARE Classic Tool on the playstore, with this it will show me the bytes/data stored on the card, after reading the card it only shows me sector 0 here - https://imgur.com/DizzOIe
The Issue -
As the recording shows only sector 0 is being read (out of 40 sectors, so 0 - 39) and it has no data for balance as it reads identically even after a top up, im assuming this only stores the card identifier and no balance info.
So how can I read the other sectors in this MIFARE Classic 4k card?
I did find some external readers but they are quite expensive so I also want to ask will this cheap combo work?
PN532 NFC RFID Module V3
CP2102 to USB adapter
submitted by /u/xyig
[link] [comments]
Reddit
r/hacking on Reddit: RFID modification for snapper card (my research and an issue)
Posted by u/xyig - No votes and no comments
Revealing a Logic Flaw in an E-commerce Website
Explore how I found a business logic error in an online store’s appointment feature during a bug bounty program and earned a $60 bounty.Continue reading on Medium »
Read more...
Explore how I found a business logic error in an online store’s appointment feature during a bug bounty program and earned a $60 bounty.Continue reading on Medium »
Read more...
Binance corrige problemas de futuros para traders.
Durante as primeiras horas do dia 10 de abril, usuários de futuros da Binance enfrentaram dificuldades para realizar negociações na…Continue reading on Medium »
Read more...
Durante as primeiras horas do dia 10 de abril, usuários de futuros da Binance enfrentaram dificuldades para realizar negociações na…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
This is how I takeover 10+ users account
https://cdn-images-1.medium.com/max/2600/1*CsBQwi6x2at4BHM2iC_ypg.png
P1 bug by recon only- 10+ users session hijacked
Continue reading on Medium »
This is how I takeover 10+ users account
https://cdn-images-1.medium.com/max/2600/1*CsBQwi6x2at4BHM2iC_ypg.png
P1 bug by recon only- 10+ users session hijacked
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Crush the Competition with These Easy Marketing Hacks for Writers
https://cdn-images-1.medium.com/max/600/1*tCc6F-TCXMrOQWPhYhE3Cg.jpeg
Crush the Competition with These Easy Marketing Hacks for Writers
Continue reading on Medium »
Crush the Competition with These Easy Marketing Hacks for Writers
https://cdn-images-1.medium.com/max/600/1*tCc6F-TCXMrOQWPhYhE3Cg.jpeg
Crush the Competition with These Easy Marketing Hacks for Writers
Continue reading on Medium »