Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Rufus 3.17.1846 DLL Hijacking
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
Rufus version 3.17.1846 suffers from a dll hijacking vulnerability for both the executable and portable executable versions.
MD5 |
Download
Source:packetstormsecurity.com
Rufus 3.17.1846 DLL Hijacking
https://4.bp.blogspot.com/-jEyO8wrBbtw/WWlvSr9oRmI/AAAAAAAAINg/irp20P4NPo4dOJoHHzIQ0XpAovWCMUh6wCLcBGAs/s1600/h38.png
Rufus version 3.17.1846 suffers from a dll hijacking vulnerability for both the executable and portable executable versions.
MD5 |
7400017ae2e5420d56dc998e4cc514ebDownload
Hi all,
I would like to disclose a vulnerability that I just found today.
Details below:
Vulnerable Software and Version:
1. Rufus 3.17.1846 executable
2. Rufus 3.17.1846 portable executable
Vulnerable software download link:
https://rufus.ie/en/
https://github.com/pbatard/rufus/releases/tag/v3.17
Date discovered and reported:
25 Feb 2022
Description:
Both Rufus 3.17.1846 executable AND portable executable are suffering from DLL
Hijacking by placing x86 MSASN1.dll or VERSION.dll in the same directory as
the executables, which could cause arbitrary code execution and privilege
escalation.
Taking MSASN1.dll as an example, craft a malicious x86 DLL with an entry
point with DllMain and place in the same directory, once double click the
executable, an x86 admin shell could be obtained as the executable requires
admin right to run by design.
Attack vector:
Taking MSASN1.dll as an example PoC code of dll can be found in my
repository
Attack steps:
1.
Craft and drop a malicious DLL named as "MSASN1.dll" with entry point
DllMain [image: image]
<https:
2.
Double click the executable "Rufus", administrator privilege is required
to run
3.
Malicious DLL has been called and an admin shell can be obtained as
PoC [image:
image]
<https:
This issue has been submitted to github as well and is acknowledged by the
owner,
https://github.com/pbatard/rufus/issues/1877
Thanks and regards,
James Tsz Ko Yeung
Source:packetstormsecurity.com
hacking: security in practice
Tor bridges from 2022-02-19 to 2022-02-26 - all up & running and reachable in Russia for now…
Basically all of the bridges are up and running: https://metrics.torproject.org/rs.html#details/A0872A7FABF80812D29CA8AD18FA0415E73F05CE https://metrics.torproject.org/rs.html#details/2B7109812DC92CD5F448D755F4DAB2E8656B916F https://metrics.torproject.org/rs.html#details/8E3B4F4A4203866EFC984BC22CC2B1C4D97FECAA https://metrics.torproject.org/rs.html#details/EE16ABDD9EC8BF430F471917B2F9AA521133031B https://metrics.torproject.org/rs.html#details/4B8EF7EBF7392BE08D94C6290DBF3C647E95382B https://metrics.torproject.org/rs.html#details/E314AF558EC26A505C84CCF4C70F2030BE59C793 https://metrics.torproject.org/rs.html#details/E0DA515E727924C8E23E25B9262B46B3C19811A5 https://metrics.torproject.org/rs.html#details/7F0576510A411BC58CC9FDC5C0722ABCE472CD68 https://metrics.torproject.org/rs.html#details/F473F114E7CCF82599102F9EC51E4047448D1799 https://metrics.torproject.org/rs.html#details/F54A81923E07316E35197C10F7731FFB77DE8286 https://metrics.torproject.org/rs.html#details/A11445333CB8CA31E2AFBB68C60058DB025728DD https://metrics.torproject.org/rs.html#details/3AEED207EC3D29B71541CEAED18B3D8639CA0D07 https://metrics.torproject.org/rs.html#details/66469139C4772B3B224CBC8E6370E3DF8760F147 https://metrics.torproject.org/rs.html#details/77E2191A541DB1F40F63EF53189915DEC1D5F4D0 https://metrics.torproject.org/rs.html#details/6CF18408BAB497E90FBE8B9118500AB12D74DAAF https://metrics.torproject.org/rs.html#details/FC79259148975A1331D1565691AF7FED0849147B https://metrics.torproject.org/rs.html#details/8F3C610A19F7EB3726B04E993D475663367DB0F6 https://metrics.torproject.org/rs.html#details/AF746CF5EC1A5DB668CB87205F41262E6F980E17 https://metrics.torproject.org/rs.html#details/31A072D8A5BF805408B04903C0E850F134B20C91 https://metrics.torproject.org/rs.html#details/60C5238C4290438B643D70B1B026E8688B82C115 https://metrics.torproject.org/rs.html#details/EF37E0443B17F0D69536ED7FE2DFFA017F0A2488 https://metrics.torproject.org/rs.html#details/128C61C1D2B36C21B2B1443BF49BB0EA1C632870 https://metrics.torproject.org/rs.html#details/15D642315E798B0B7DF8DFBF00CECF8608A55D9B https://metrics.torproject.org/rs.html#details/B58AAD104B47DF815E9158634F62B9A7B5F6AC2F https://metrics.torproject.org/rs.html#details/1D2A14EC5C660B9D6F70836480CC1FA7AC344B16 https://metrics.torproject.org/rs.html#details/78E5386B72DF91F1ED7E71A2EF45ADEFFD8D0202 https://metrics.torproject.org/rs.html#details/E7EF3CD6CBE07D322E97F3DD8C7C795EDBC20F76 https://metrics.torproject.org/rs.html#details/DB794AC83A787F5C427CD35A63DAB48061AAE901 https://metrics.torproject.org/rs.html#details/CF011A88087C307F2D6F745EFF8CC85FC1C67073 https://metrics.torproject.org/rs.html#details/B0185A20A52A43E7505C40A07A0623FF2D476179 https://metrics.torproject.org/rs.html#details/700EEEA97E5D465310C407BECA3D0876B214428A https://metrics.torproject.org/rs.html#details/619CE905DF37E8B0C2439414E68D979F627F50A5 https://metrics.torproject.org/rs.html#details/5DA3023733BFEA667FF96678C810A7AB02434674 https://metrics.torproject.org/rs.html#details/C2A82F6E81EAEB2BD881ADAD8FDCDD5F77EBEEF7 https://metrics.torproject.org/rs.html#details/7C155C23B939BC0B4F4AF048C8CA87F7962E58F7 https://metrics.torproject.org/rs.html#details/4ADA63EA721C16DC0704C2ED2D6C39901A576337 https://metrics.torproject.org/rs.html#details/2FD5FACC242350DB30316D591E7AA590EED725B9 https://metrics.torproject.org/rs.html#details/36A8A0D2768AB06CC6DAA056B60F002D94E0D182 https://metrics.torproject.org/rs.html#details/596BC461AB5E0DBB0F07BFF5F1DBC24CD6C817B2 https://metrics.torproject.org/rs.html#details/97876C18AF7CE8C3E06B63B9883CF4A612FE9FD7 https://metrics.torproject.org/rs.html#details/DA0009C3F02250DBF135BCAFFFAEE6796699BB23 https://metrics.torproject.org/rs.html#details/477BF9DE55231154A3CD28BD65252228F6B65EBC
[...]
Tor bridges from 2022-02-19 to 2022-02-26 - all up & running and reachable in Russia for now…
Basically all of the bridges are up and running: https://metrics.torproject.org/rs.html#details/A0872A7FABF80812D29CA8AD18FA0415E73F05CE https://metrics.torproject.org/rs.html#details/2B7109812DC92CD5F448D755F4DAB2E8656B916F https://metrics.torproject.org/rs.html#details/8E3B4F4A4203866EFC984BC22CC2B1C4D97FECAA https://metrics.torproject.org/rs.html#details/EE16ABDD9EC8BF430F471917B2F9AA521133031B https://metrics.torproject.org/rs.html#details/4B8EF7EBF7392BE08D94C6290DBF3C647E95382B https://metrics.torproject.org/rs.html#details/E314AF558EC26A505C84CCF4C70F2030BE59C793 https://metrics.torproject.org/rs.html#details/E0DA515E727924C8E23E25B9262B46B3C19811A5 https://metrics.torproject.org/rs.html#details/7F0576510A411BC58CC9FDC5C0722ABCE472CD68 https://metrics.torproject.org/rs.html#details/F473F114E7CCF82599102F9EC51E4047448D1799 https://metrics.torproject.org/rs.html#details/F54A81923E07316E35197C10F7731FFB77DE8286 https://metrics.torproject.org/rs.html#details/A11445333CB8CA31E2AFBB68C60058DB025728DD https://metrics.torproject.org/rs.html#details/3AEED207EC3D29B71541CEAED18B3D8639CA0D07 https://metrics.torproject.org/rs.html#details/66469139C4772B3B224CBC8E6370E3DF8760F147 https://metrics.torproject.org/rs.html#details/77E2191A541DB1F40F63EF53189915DEC1D5F4D0 https://metrics.torproject.org/rs.html#details/6CF18408BAB497E90FBE8B9118500AB12D74DAAF https://metrics.torproject.org/rs.html#details/FC79259148975A1331D1565691AF7FED0849147B https://metrics.torproject.org/rs.html#details/8F3C610A19F7EB3726B04E993D475663367DB0F6 https://metrics.torproject.org/rs.html#details/AF746CF5EC1A5DB668CB87205F41262E6F980E17 https://metrics.torproject.org/rs.html#details/31A072D8A5BF805408B04903C0E850F134B20C91 https://metrics.torproject.org/rs.html#details/60C5238C4290438B643D70B1B026E8688B82C115 https://metrics.torproject.org/rs.html#details/EF37E0443B17F0D69536ED7FE2DFFA017F0A2488 https://metrics.torproject.org/rs.html#details/128C61C1D2B36C21B2B1443BF49BB0EA1C632870 https://metrics.torproject.org/rs.html#details/15D642315E798B0B7DF8DFBF00CECF8608A55D9B https://metrics.torproject.org/rs.html#details/B58AAD104B47DF815E9158634F62B9A7B5F6AC2F https://metrics.torproject.org/rs.html#details/1D2A14EC5C660B9D6F70836480CC1FA7AC344B16 https://metrics.torproject.org/rs.html#details/78E5386B72DF91F1ED7E71A2EF45ADEFFD8D0202 https://metrics.torproject.org/rs.html#details/E7EF3CD6CBE07D322E97F3DD8C7C795EDBC20F76 https://metrics.torproject.org/rs.html#details/DB794AC83A787F5C427CD35A63DAB48061AAE901 https://metrics.torproject.org/rs.html#details/CF011A88087C307F2D6F745EFF8CC85FC1C67073 https://metrics.torproject.org/rs.html#details/B0185A20A52A43E7505C40A07A0623FF2D476179 https://metrics.torproject.org/rs.html#details/700EEEA97E5D465310C407BECA3D0876B214428A https://metrics.torproject.org/rs.html#details/619CE905DF37E8B0C2439414E68D979F627F50A5 https://metrics.torproject.org/rs.html#details/5DA3023733BFEA667FF96678C810A7AB02434674 https://metrics.torproject.org/rs.html#details/C2A82F6E81EAEB2BD881ADAD8FDCDD5F77EBEEF7 https://metrics.torproject.org/rs.html#details/7C155C23B939BC0B4F4AF048C8CA87F7962E58F7 https://metrics.torproject.org/rs.html#details/4ADA63EA721C16DC0704C2ED2D6C39901A576337 https://metrics.torproject.org/rs.html#details/2FD5FACC242350DB30316D591E7AA590EED725B9 https://metrics.torproject.org/rs.html#details/36A8A0D2768AB06CC6DAA056B60F002D94E0D182 https://metrics.torproject.org/rs.html#details/596BC461AB5E0DBB0F07BFF5F1DBC24CD6C817B2 https://metrics.torproject.org/rs.html#details/97876C18AF7CE8C3E06B63B9883CF4A612FE9FD7 https://metrics.torproject.org/rs.html#details/DA0009C3F02250DBF135BCAFFFAEE6796699BB23 https://metrics.torproject.org/rs.html#details/477BF9DE55231154A3CD28BD65252228F6B65EBC
[...]
reddit
Tor bridges from 2022-02-19 to 2022-02-26 - all up & running and...
Basically all of the bridges are up and...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hackers rename Putin’s £73million superyacht 'FCKPTN' and change destination to 'Hell'
https://external-preview.redd.it/QyBxNv3aVbFFujtBtP1DyE06VM3oslV-CIq0Eg8gMCU.jpg?width=640&crop=smart&auto=webp&s=7b9e2f158cf053a546b25c31222c228f0c038cf8 submitted by /u/lboog423
[link] [comments]
Hackers rename Putin’s £73million superyacht 'FCKPTN' and change destination to 'Hell'
https://external-preview.redd.it/QyBxNv3aVbFFujtBtP1DyE06VM3oslV-CIq0Eg8gMCU.jpg?width=640&crop=smart&auto=webp&s=7b9e2f158cf053a546b25c31222c228f0c038cf8 submitted by /u/lboog423
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
hacking: security in practice Tor bridges from 2022-02-19 to 2022-02-26 - all up & running and reachable in Russia for now… Basically all of the bridges are up and running: https://metrics.torproject.org/rs.html#details/A0872A7FABF80812D29CA8AD18FA0415E73F05CE…
opensea.io
bridges of ukraine - Collection | OpenSea
this is a collection of 42 bridges mostly named after Ukrainian cities
hacking: security in practice
Is it illegal to possess data leaked from a breach?
Let's say Company X was breached, and the attackers leaked the data publicly (or to the dark web). Could you get in legal trouble for downloading that data? I guess it's like possession of stolen goods, which is a crime, but what if you're a security researcher? Of if you're a customer of Company X, and want to see if any of your data is included in the breach?
submitted by /u/bigmetsfan
[link] [comments]
Is it illegal to possess data leaked from a breach?
Let's say Company X was breached, and the attackers leaked the data publicly (or to the dark web). Could you get in legal trouble for downloading that data? I guess it's like possession of stolen goods, which is a crime, but what if you're a security researcher? Of if you're a customer of Company X, and want to see if any of your data is included in the breach?
submitted by /u/bigmetsfan
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
hacking: security in practice
Am I the only one that feels like NetworkChuck is overrated?
When I started my hacking journey, I came across NetworkChuck a couple times in Youtube. When you look at their titles, they look very promising, but when you actually check the content of the video and try it out practically, around 80% of things often don't work or doesn't work you expect to do so.
I don't know if it's a good place to talk about it here, but I'm just wondering what you guys think about that
submitted by /u/407PrxAuthReq
[link] [comments]
Am I the only one that feels like NetworkChuck is overrated?
When I started my hacking journey, I came across NetworkChuck a couple times in Youtube. When you look at their titles, they look very promising, but when you actually check the content of the video and try it out practically, around 80% of things often don't work or doesn't work you expect to do so.
I don't know if it's a good place to talk about it here, but I'm just wondering what you guys think about that
submitted by /u/407PrxAuthReq
[link] [comments]
Reddit
From the hacking community on Reddit
Explore this post and more from the hacking community
Password Reset to Admin Access
https://hogarth45.medium.com/password-reset-to-admin-access-3b2a649bdc3?source=rss------bug_bounty-5
https://hogarth45.medium.com/password-reset-to-admin-access-3b2a649bdc3?source=rss------bug_bounty-5
While testing a web application that used a web GUI over the top of an API, I noted the calls to the API where authorized with a JWT token…Continue reading on Medium » (https://hogarth45.medium.com/password-reset-to-admin-access-3b2a649bdc3?source=rss------bug_bounty-5)
Hacking on Medium
Who Has Been Hacked and What Did You Do About It?
https://cdn-images-1.medium.com/max/2600/0*uUeGJhAtDpeSNpBd
I noticed 2 hacks and scam messages this morning.
Continue reading on Medium »
Who Has Been Hacked and What Did You Do About It?
https://cdn-images-1.medium.com/max/2600/0*uUeGJhAtDpeSNpBd
I noticed 2 hacks and scam messages this morning.
Continue reading on Medium »
Medium
Who Has Been Hacked and What Did You Do About It?
I noticed 2 hacks and scam messages this morning.
Hacking on Medium
Password Reset to Admin Access
https://cdn-images-1.medium.com/max/703/1*mOQbWkx9DjPO3g1vEt2rHQ.png
While testing a web application that used a web GUI over the top of an API, I noted the calls to the API where authorized with a JWT token…
Continue reading on Techiepedia »
Password Reset to Admin Access
https://cdn-images-1.medium.com/max/703/1*mOQbWkx9DjPO3g1vEt2rHQ.png
While testing a web application that used a web GUI over the top of an API, I noted the calls to the API where authorized with a JWT token…
Continue reading on Techiepedia »
Medium
Password Reset to Admin Access
While testing a web application that used a web GUI over the top of an API, I noted the calls to the API where authorized with a JWT token…
Hacking on Medium
How to install Kali Linux on Android using termux without root
https://cdn-images-1.medium.com/max/640/1*50DpMpzwHq5j7bUil-_JJg.png
Linux / Unix is an open-source operating system. It is one of the most used OS for hacking and provides adequate tools for hackers. Kali…
Continue reading on Medium »
How to install Kali Linux on Android using termux without root
https://cdn-images-1.medium.com/max/640/1*50DpMpzwHq5j7bUil-_JJg.png
Linux / Unix is an open-source operating system. It is one of the most used OS for hacking and provides adequate tools for hackers. Kali…
Continue reading on Medium »
Medium
How to install Kali Linux on Android using termux without root
Linux / Unix is an open-source operating system. It is one of the most used OS for hacking and provides adequate tools for hackers. Kali…
Hacking on Medium
$1.7m stolen from simple email phishing: 3 essential security takeaways from the OpenSea attack
https://cdn-images-1.medium.com/max/1312/0*ooY0Q0hwrk0iOyDz.jpg
On Saturday, February 19, attackers tricked OpenSea users using a basic email phishing attack.
Continue reading on The Harpie Blog »
$1.7m stolen from simple email phishing: 3 essential security takeaways from the OpenSea attack
https://cdn-images-1.medium.com/max/1312/0*ooY0Q0hwrk0iOyDz.jpg
On Saturday, February 19, attackers tricked OpenSea users using a basic email phishing attack.
Continue reading on The Harpie Blog »
Medium
$1.7m stolen from simple email phishing: 3 essential security takeaways from the OpenSea attack
On Saturday, February 19, attackers tricked OpenSea users using a basic email phishing attack. Users were emailed and asked to sign a smart…