Waraxe IT Security Portal
Login or Register
September 11, 2026
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 773
Members: 0
Total: 773
Full disclosure
[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)
[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)
[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)
[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)
[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)
[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)
[0day-rubbish] DBxtra .NET 13.1.1.0 Unauthenticated SOAP API to xp_cmdshell code execution (9.8)
**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)
CVE-2026-52307: Stored XSS in 1CMS v5.6
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 /CVE-2026-12556
Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists
O-CMS 1.0.0 Authenticated OS Command Injection viaai_cli_script
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index
Search found 89 matches
Hash Kind
PostForum:All other hashes Posted: Sun Sep 20, 2009 2:39 pm Subject: Hash Kind
Heintz
Replies: 3
Views: 8269




hash is nothing but random bytes hex encoded.
so you have two choices

1) count how many hex chars that is and take a guess by looking lengths
http://en.wikipedia.org/wiki/List_of_hash_functions ...
[Help Please] Upload shell to another site on same box?
PostForum:Newbies corner Posted: Sun Sep 20, 2009 2:07 pm Subject: [Help Please] Upload shell to another site on same box?
Heintz
Replies: 2
Views: 9647




You want to backdoor all other sites index files or all files?
Discression is always good and infecting every file on servers might not be very discrete.
/edit
allthough in some cases it could hel ...
a nice site explaining A.I,
PostForum:Future of the IT Posted: Sun Sep 20, 2009 1:43 pm Subject: a nice site explaining A.I,
Heintz
Replies: 1
Views: 12357




http://www.ai-junkie.com/

hands on and plain english , not too academical.

Cause i'm being taught java i rewrote the genetic algorithm and neural network classes over to java. for learning purpo ...
Made a encrypted cgi proxy / raw http test tool / php-shell
PostForum:Php Posted: Fri Oct 05, 2007 12:09 pm Subject: Made a encrypted cgi proxy / raw http test tool / php-shell
Heintz
Replies: 1
Views: 12870




Hi,

I happened to read once here about Waraxe describing how a good php shell should be like. I had similar ideas at the time, but my script was half done / and originally meant private use. Then i ...
Wordlist precomputer (hash key sorting) / hash searcher
PostForum:Tools Posted: Thu Feb 15, 2007 8:42 pm Subject: Wordlist precomputer (hash key sorting) / hash searcher
Heintz
Replies: 1
Views: 10366




Hello been a long time,

thought someone might be interested to know about this tool.
download address: http://www.plain-text.info/dl/file/gwl

What it does: It takes wordlists as input and sorts ...
php <= 5.1.4 and <= 4.4.3 local buffer underflow
PostForum:Php Posted: Mon Aug 07, 2006 10:16 pm Subject: php <= 5.1.4 and <= 4.4.3 local buffer underflow
Heintz
Replies: 0
Views: 9255




http://www.securityfocus.com/archive/1/442438/30/0/threaded

Affected versions: php 5.1.4 and older, 4.4.3 and possibly older

Cause: when php-s sscanf functions format argument contains argument ...
a question for the pro's
PostForum:All other security holes Posted: Wed Aug 02, 2006 11:52 am Subject: a question for the pro's
Heintz
Replies: 6
Views: 18412




if apache runs as a high privileged user like root and php is badly configured then yes. 'whoami' shell cmd to find out what user you are.

anyway i took a look at the c99sh source and its half-lie ...
shellcodes
PostForum:Assembler Posted: Mon Jun 26, 2006 7:03 pm Subject: shellcodes
Heintz
Replies: 3
Views: 14062




i think any somewhat experienced c programmer knows the technique, but
the real thing is the exploitation. in other words making a schellcode from bytes which get through all kinds of different filte ...
Crack md5 hashes / help!
PostForum:MD5 hashes Posted: Sun Jun 18, 2006 2:31 pm Subject: Crack md5 hashes / help!
Heintz
Replies: 1128
Views: 1483039





7af36368f003c7e68e752b963072900d alhadara 54959db46671c1aa6eaf9d9a95d66a26 xp7ytp


big thanks to Waraxe for linking Smile
Md5 Reverse Lookup!The easiest way to crack your md5 hashes
PostForum:MD5 hashes Posted: Tue Jun 06, 2006 4:52 pm Subject: Md5 Reverse Lookup!The easiest way to crack your md5 hashes
Heintz
Replies: 80
Views: 148424




What's the deal with Plain-Text.info anyway? I've got a hash that's at 97% and has been waiting for 208 hours. Sorting their list shows the last hash have been waiting 391 hours at 97%.

Yet they cl ...
[waraxe-2006-SA#047] - Evading sql-injection filters in 7.8
PostForum:PhpNuke Posted: Sun Feb 26, 2006 1:05 am Subject: [waraxe-2006-SA#047] - Evading sql-injection filters in 7.8
Heintz
Replies: 3
Views: 15930




i now start to see the nessesarity of rewrite of nuke source. i took a look at nuke source too and some patches seem to be directly for exploit urls.
what i mean is like fictional (not found in nuke ...
New phpnuke security advisories will be out very soon!
PostForum:PhpNuke Posted: Tue Feb 14, 2006 5:34 pm Subject: New phpnuke security advisories will be out very soon!
Heintz
Replies: 10
Views: 22118




firstable, great work on last advisory.
will be interesting to read the coming ones. hopefully software author respond more sensibly too Smile
Weird Md5 hash?
PostForum:PhpBB Posted: Mon Jan 23, 2006 7:01 pm Subject: Weird Md5 hash?
Heintz
Replies: 4
Views: 12370




shure

http://www.php.net/uniqid
Weird Md5 hash?
PostForum:PhpBB Posted: Sat Jan 21, 2006 11:25 am Subject: Weird Md5 hash?
Heintz
Replies: 4
Views: 12370




working on "the" forum? doesnt say anything to me. firstable tell what software you are working on (NOT the url where the forum is though).
and not every long hex string is a md5 hash.
so get the so ...
what happens to waraxe.us
PostForum:General discussion Posted: Fri Nov 18, 2005 2:47 pm Subject: what happens to waraxe.us
Heintz
Replies: 11
Views: 18440




this might be a bit offtopic but here goes anyway,

Those GET tricks reminded me another issue that is also often overlooked:
auto-submitting forms:
nice.html:

<html>
<head>
<t ...
Page 1 of 6 Goto page 1, 2, 3, 4, 5, 6Next
All times are GMT


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.050 Seconds