elsec(@adrielsec) 's Twitter Profileg
elsec

@adrielsec

🙋‍♂️Ethical Hacker🪓👨‍💻

ID:65976419

linkhttps://linktr.ee/elsec calendar_today15-08-2009 20:57:15

6,0K Tweets

3,0K Followers

229 Following

elsec(@adrielsec) 's Twitter Profile Photo

IDOR + ATO Account Takeover via Reset Password

- a logged in area;
- intercept password change request;
- change username to another;
- if u have successfully changed user pass, u have an IDOR + ATO;

Impact: Critical

tips tip

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

Found Jolokia endpoint?
/actuator/jolokia/

Try LFI (local file inclusion) (misconfig)

PoC: xxxx[.]com/actuator/jolokia/exec/com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/passwd

tips tip

Found Jolokia endpoint? /actuator/jolokia/ Try LFI (local file inclusion) (misconfig) PoC: xxxx[.]com/actuator/jolokia/exec/com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/passwd #bugbounty #bugbountytips #bugbountytip #lfi
account_circle
elsec(@adrielsec) 's Twitter Profile Photo

App running moodle?🔥
Ex URL: https://xxx/mod/lti/auth.php

We can test an openredirect payload in the redirect_uri parameter

?redirect_uri=//example.com

Ref OWASP: cheatsheetseries.owasp.org/cheatsheets/Un…

tip tips

App running moodle?🔥 Ex URL: https://xxx/mod/lti/auth.php We can test an openredirect payload in the redirect_uri parameter ?redirect_uri=//example.com Ref OWASP: cheatsheetseries.owasp.org/cheatsheets/Un… #bugbounty #bugbountytip #bugbountytips
account_circle
elsec(@adrielsec) 's Twitter Profile Photo

PoC + Nuclei + Query CVE-2024-25600 Unauth RCE - WordPress Bricks <= 1.9.6 CVSS 9.8

Query Fofa: body='/wp-content/themes/bricks/'
PoC: github.com/Chocapikk/CVE-…
Nuclei: github.com/Christbowel/CV…

tip tips

PoC + Nuclei + Query CVE-2024-25600 Unauth RCE - WordPress Bricks <= 1.9.6 CVSS 9.8 Query Fofa: body='/wp-content/themes/bricks/' PoC: github.com/Chocapikk/CVE-… Nuclei: github.com/Christbowel/CV… #bugbounty #bugbountytip #bugbountytips
account_circle
elsec(@adrielsec) 's Twitter Profile Photo

Password reset link hijacked via host header poisoning:

Requested password reset, intercepted with Burp, added under Host (X-Forwarded-Host: xxx.com)

tips tip

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

PoC CVE-2023-6553 RCE Unauth Backup Migration plugin < 1.3.7, via /includes/backup-heart.php. According to official Wordpress statistics, 50k sites running WordPress still use the vulnerable version.

github.com/Chocapikk/CVE-…

tip tips

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

PoC CVE-2023-27524 Insecure Default Configuration in Apache Superset Leads to RCE (Remote Code Execution) + Shodan Dork:

github.com/horizon3ai/CVE…

Shodan Dork: http.favicon.hash:1582430156

tips tip

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

PoC CVE-2023-46214 Splunk Enterprise RCE (Remote Code Execution)

github.com/nathan31337/Sp…
blog.hrncirik.net/cve-2023-46214…

tip tips

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

PoC Privilege Escalation in Ubuntu/Kali Linux (CVE-2023-2640 and CVE-2023-32629)

Code is available at: gist.github.com/win3zz/aa1ac16…

For more details, refer to the original research article: wiz.io/blog/ubuntu-ov…

tip tips

PoC Privilege Escalation in Ubuntu/Kali Linux (CVE-2023-2640 and CVE-2023-32629) Code is available at: gist.github.com/win3zz/aa1ac16… For more details, refer to the original research article: wiz.io/blog/ubuntu-ov… #hacking #bugbounty #bugbountytip #bugbountytips #ubuntu
account_circle
elsec(@adrielsec) 's Twitter Profile Photo

XSS (dalfox)
Open redirect (Oralyzer)
SSRF (headers interactsh, param values with ffuf)
CRLF (crlfuzz)
LFI (ffuf)
SQLi (SQLMap, ghauri)
SSTI (ffuf)
SSL (testssl)
Broken Links (katana)
Prototype Pollution (ppfuzz)
4XX Bypasser (byp4xx)

tips tip

account_circle
elsec(@adrielsec) 's Twitter Profile Photo

Confluence Broken Access Control CVE-2023-22515

PoC: yuvvi21.medium.com/confluence-cve…

Nuclei template: github.com/projectdiscove…

Exploit: github.com/Chocapikk/CVE-…

tip tips

account_circle