Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Wuca.nz Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Backdoor.Win32.Wuca.nz malware suffers from an insecure permissions vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Backdoor.Win32.Wuca.nz Insecure Permissions
https://3.bp.blogspot.com/-p2bRUn4ag8U/WWlvPJDaCwI/AAAAAAAAIMw/gkQGiTtaXucRRVbpvBkwiWIbJMO4BFlLwCLcBGAs/s1600/h28.png
Backdoor.Win32.Wuca.nz malware suffers from an insecure permissions vulnerability.
MD5 |
5d74f82ae3f1b602aa0b456af75385eaDownload
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/378b225b07979e12062f86ab1fbaf2ed.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Wuca.nz
Vulnerability: Insecure Permissions
Description: The malware creates a VBS script "112.vbe" with insecure permissions under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 378b225b07979e12062f86ab1fbaf2ed
Vuln ID: MVID-2021-0241
Dropped files: 112.vbe
Disclosure: 06/08/2021
Exploit/PoC:
C:\>cacls 112.vbe
C:\112.vbe BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress Visitors-App 0.3 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Visitors-App plugin version 0.3 suffers from a persistent cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
WordPress Visitors-App 0.3 Cross Site Scripting
https://1.bp.blogspot.com/-PwD2Dirg2NY/WWlu3CzGC6I/AAAAAAAAIIs/x87GenQxU4E4sY7pWpFvaHW3XEOYBksJQCLcBGAs/s1600/h10.png
WordPress Visitors-App plugin version 0.3 suffers from a persistent cross site scripting vulnerability.
MD5 |
6a44e77f41ca425ab34453bff4fae337Download
# Exploit Title: WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
# Date: 09/06/2021
# Exploit Author: Mesut Cetin
# Vendor Homepage: https://profiles.wordpress.org/domingoruiz/
# Software Link: https://wordpress.org/plugins/visitors-app/
# Version: 0.3
# Tested on: Debian GNU/Linux 10
# Reference: https://wpscan.com/vulnerability/06f1889d-8e2f-481a-b91b-3a8008e00ffc
## Description:
# A vulnerability in the Wordpress plugin "visitors" version 0.3 and prior allows remote attacker through
# Cross-Site Scripting (XSS) to redirect administrators and visitors and potentially obtain sensitive informations
# The 'user-agent' parameter allows attacker to escalate their privileges.
## PoC
# Replace google.com with malicious attacker page
curl -i http://localhost/wordpress --user-agent ""
# on http://localhost/wordpress/wp-admin, browse the tab "visitors"
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Internet Explorer jscript9.dll Memory Corruption
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
There is a vulnerability in jscript9 that could potentially be exploited to execute arbitrary code when viewing an attacker-controlled website in Internet Explorer. The vulnerability has been confirmed on Windows 10 64-bit with the latest security patches applied.
MD5 |
Download
Source:packetstormsecurity.com
Internet Explorer jscript9.dll Memory Corruption
https://2.bp.blogspot.com/-S-N0q2XL8x8/WWlu5FDj1eI/AAAAAAAAIJA/vGskVQb_QegQZ0-UZMHSDeFJ08ju6pdGQCLcBGAs/s1600/h104.png
There is a vulnerability in jscript9 that could potentially be exploited to execute arbitrary code when viewing an attacker-controlled website in Internet Explorer. The vulnerability has been confirmed on Windows 10 64-bit with the latest security patches applied.
MD5 |
7bf1477df1aec690e996f9ebbce9b10cDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Ransomware Is Not the Problem
Arbitrarily powerful software -- applications, operating systems -- is a problem, as is preventing it from running on enterprise systems.
___________________________
@hacking_Attack
@Hacking_Video
Ransomware Is Not the Problem
Arbitrarily powerful software -- applications, operating systems -- is a problem, as is preventing it from running on enterprise systems.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to discover Universal Plug and Play (UPnP) hosts using Miranda
https://cdn-images-1.medium.com/max/768/1*BiCFS9d-bs-mh843wpgfsA.jpeg
Miranda is a Python-based Universal Plug-n-Play client application intended to discover, query, and connect with UPnP gadgets, especially…
Continue reading on Medium »
How to discover Universal Plug and Play (UPnP) hosts using Miranda
https://cdn-images-1.medium.com/max/768/1*BiCFS9d-bs-mh843wpgfsA.jpeg
Miranda is a Python-based Universal Plug-n-Play client application intended to discover, query, and connect with UPnP gadgets, especially…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Web application reconnaissance using Rocon-ng
https://cdn-images-1.medium.com/max/800/1*9sB_mT7kBiNDy8PYEzGDyA.jpeg
Recon-ng is a full-included Web Reconnaissance system written in Python. Complete with autonomous modules, database association, worked in…
Continue reading on Medium »
Web application reconnaissance using Rocon-ng
https://cdn-images-1.medium.com/max/800/1*9sB_mT7kBiNDy8PYEzGDyA.jpeg
Recon-ng is a full-included Web Reconnaissance system written in Python. Complete with autonomous modules, database association, worked in…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
DNS enumeration using domain information groper (Dig)
https://cdn-images-1.medium.com/max/1200/1*Rc8jgBrSCkAkN-lI_07zVg.jpeg
Dig (domain information groper) is a versatile instrument for cross-examining DNS name servers. It performs DNS queries and shows the…
Continue reading on Medium »
DNS enumeration using domain information groper (Dig)
https://cdn-images-1.medium.com/max/1200/1*Rc8jgBrSCkAkN-lI_07zVg.jpeg
Dig (domain information groper) is a versatile instrument for cross-examining DNS name servers. It performs DNS queries and shows the…
Continue reading on Medium »
Basics Penetration Testing Tools
https://vengeance.medium.com/basics-penetration-testing-tools-603a2995834e?source=rss------bug_bounty-5
Subdomain enumeration toolsContinue reading on Medium » (https://vengeance.medium.com/basics-penetration-testing-tools-603a2995834e?source=rss------bug_bounty-5)
https://vengeance.medium.com/basics-penetration-testing-tools-603a2995834e?source=rss------bug_bounty-5
Subdomain enumeration toolsContinue reading on Medium » (https://vengeance.medium.com/basics-penetration-testing-tools-603a2995834e?source=rss------bug_bounty-5)
Big Stages Implementation And Library Files
https://www.reddit.com/r/redteamsec/comments/nvxj7j/big_stages_implementation_and_library_files/
submitted by /u/hlldz (https://www.reddit.com/user/hlldz)
[link] (https://artofpwn.com/2021/06/08/big-stages-implementation-and-library-files.html) [comments] (https://www.reddit.com/r/redteamsec/comments/nvxj7j/big_stages_implementation_and_library_files/)
https://www.reddit.com/r/redteamsec/comments/nvxj7j/big_stages_implementation_and_library_files/
submitted by /u/hlldz (https://www.reddit.com/user/hlldz)
[link] (https://artofpwn.com/2021/06/08/big-stages-implementation-and-library-files.html) [comments] (https://www.reddit.com/r/redteamsec/comments/nvxj7j/big_stages_implementation_and_library_files/)
hacking: security in practice
Hacking a sphero specdrum ring to be used for other things
I recently received a sphero specdrum, a light-enabled ring that behaves as a trigger pad. At launch, these suckers were actually capable bluetooth-midi devices, but sphero has since removed that capability in the firmware, so I decided to try to figure out what data it sends and make a helper program.
This is a filtered wireshark capture from my phone. (I'm only worried about the data for now, I'll figure out how to connect later.)
This is also the unfiltered capture, it seems to include some things the filtered one doesn't
I can see what is going on (whenever I trigger the ring with a color, I get an event with identifier 0x0018) but I don't know what the data it sends back means, just that the first seven bytes are usually the same (8d3011011a1eff) and then there is what I can only assume to be a color value (4c5b7ef80b005ed8) and potentially an intensity value, but it is also usually 8 bytes with a few frames that have d8 shifted into a 9th byte.
I've never really worked with Bluetooth and while I'm familiar with how it generally works, I don't have much deep knowledge.
How do I figure out how to make this data human-readable so I can see what's happening and code for it?
(I also am running on a Linux environment, so if there are packages that could help, feel free to recommend something)
submitted by /u/pcs3rd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking a sphero specdrum ring to be used for other things
I recently received a sphero specdrum, a light-enabled ring that behaves as a trigger pad. At launch, these suckers were actually capable bluetooth-midi devices, but sphero has since removed that capability in the firmware, so I decided to try to figure out what data it sends and make a helper program.
This is a filtered wireshark capture from my phone. (I'm only worried about the data for now, I'll figure out how to connect later.)
This is also the unfiltered capture, it seems to include some things the filtered one doesn't
I can see what is going on (whenever I trigger the ring with a color, I get an event with identifier 0x0018) but I don't know what the data it sends back means, just that the first seven bytes are usually the same (8d3011011a1eff) and then there is what I can only assume to be a color value (4c5b7ef80b005ed8) and potentially an intensity value, but it is also usually 8 bytes with a few frames that have d8 shifted into a 9th byte.
I've never really worked with Bluetooth and while I'm familiar with how it generally works, I don't have much deep knowledge.
How do I figure out how to make this data human-readable so I can see what's happening and code for it?
(I also am running on a Linux environment, so if there are packages that could help, feel free to recommend something)
submitted by /u/pcs3rd
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Hacking a sphero specdrum ring to be used for other things
I recently received a sphero specdrum, a light-enabled ring that behaves as a trigger pad. At launch, these suckers were actually capable...
hacking: security in practice
Any good books or courses for complete beginner (com science student)?
I'm a freshman computer science, previously studied a Diploma in IT, so I've got some knowledge on Web/Software development, Data Structures/Algorithms, Networking but nothing advanced.
I've taken a module on Computer Organisation and Architecture, learnt about registers, basic arm assembly, virtual memory cache etc, just the basic stuff (there is going to be an advance mod).
I'm interested in hacking, in the software aspect, but not too interested in networking side.
The reddit threads I've read suggest books that cover mainly network related security, but I'm mainly interested in the operating system and software aspect.
Any good recommendations on that? Currently I'm planning to buy this book:
Hacking: The Art Of Exploitation, Practical Reverse Engineering
submitted by /u/cocag13996
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Any good books or courses for complete beginner (com science student)?
I'm a freshman computer science, previously studied a Diploma in IT, so I've got some knowledge on Web/Software development, Data Structures/Algorithms, Networking but nothing advanced.
I've taken a module on Computer Organisation and Architecture, learnt about registers, basic arm assembly, virtual memory cache etc, just the basic stuff (there is going to be an advance mod).
I'm interested in hacking, in the software aspect, but not too interested in networking side.
The reddit threads I've read suggest books that cover mainly network related security, but I'm mainly interested in the operating system and software aspect.
Any good recommendations on that? Currently I'm planning to buy this book:
Hacking: The Art Of Exploitation, Practical Reverse Engineering
submitted by /u/cocag13996
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Any good books or courses for complete beginner (com science student)?
I'm a freshman computer science, previously studied a Diploma in IT, so I've got some knowledge on Web/Software development, Data...
Pied Piper E15.mp4
➠Cʜᴀɴɴᴇʟ : @CinimaBhranthanmar
✯ ━━━━━━ ✧ ━━━━━━ ✯
🔰 Fɪʀꜱᴛ Oɴ Tᴇʟᴇɢʀᴀᴍ
✅ @CINE_CLUBB
@CC_ARCHIVES
@CC_NEWMOVIES
Close
➠Cʜᴀɴɴᴇʟ : @CinimaBhranthanmar
✯ ━━━━━━ ✧ ━━━━━━ ✯
🔰 Fɪʀꜱᴛ Oɴ Tᴇʟᴇɢʀᴀᴍ
✅ @CINE_CLUBB
@CC_ARCHIVES
@CC_NEWMOVIES
Close