Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Search - "nubs"
-
5 minutes downtime: "I lost millions because of you"
$100 extra on invoice: "it's too much I don't make money"6 -
Fuck this. I can't spend half my day stepping around your ego, even if you are the so called lead frontend. It's time for a chat with hr.1
-
Pentesting for undisclosed company. Let's call them X as to not get us into trouble.
We are students and are doing our first pentest at an actual company instead of assignments at school. So we're very anxious. But today was a good day.
We found some servers with open ports so we checked a few of them out. I had a set of them with a bunch of open ports like ftp and... 8080. Time to check this out.
"please install flash player"... Security risk 1 found!
System seemed to be some monitoring system. Trying to log in using admin admin... Fucking works. Group loses it cause the company was being all high and mighty about being secure af. Other shit is pretty tight though.
Able to see logs, change password, add new superuser, do some searches for USERS_LOGGEDIN_TODAY! I shit you not, the system even had SUGGESTIONS for usernames to search for. One of which had something to do with sftp and auth keys. Unfortunatly every search gave a SQL syntax error. Used sniffing tools to maybe intercept message so we could do some queries of our own but nothing. Query is probably not issued from the local machine.
Tried to decompile the flash file but no luck. Only for some weird lines and a few function names I presume. But decompressing it and opening it in a text editor allowed me to see and search text. No GET or POST found. No SQL queries or name checks or anything we could think of.
That's all I could do for today. So we'll have to think of stuff for next week. We've already planned xss so maybe we can do that on this server as well.
We also found some older network printers with open telnet. Servers with a specific SQL variant with a potential exploit to execute terminal commands and some ftp and smb servers we need to check out next week.
Hella excited about this!
If you guys have any suggestions let us know. We are utter noobs when it comes to this.6 -
I was trying to book a visit to my doctor at the largest private clinic of the country... I wonder what would a normal user understand from this message? 🤣4
-
What to do when you think your boss sucks at a language they're developing in, but everyone assumes they are awesome because they don't know that language, and you're stuck as the junior fixing their code?
-
Creative javascript encrypters:
((86.4E1, 0x169) > (1.116E3, 1.22E2) ? (0xE5, "k") : 0x96 >= (1.182E3, 7.74E2) ? (53, 1.56E2) : (112, 0x115))
just to write "k"