Hey Everyone,Continue reading on Medium » (https://medium.com/@sandh0t/the-bad-twin-a-peculiar-case-of-jwt-exploitation-scenario-1efa03e891c0?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Bad Twin: a peculiar case of JWT exploitation scenario
Hey Everyone,
Some critical vulnerabilities found with passive analysis on bug bounty programs explained
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…Continue reading on InfoSec Write-ups »
Read more...
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…Continue reading on InfoSec Write-ups »
Read more...
Hacking on Medium
Cyber Security Internship
Hi Everyone, I’m Darshan Kumar B K from Bangalore. I’m Interested in Ethical Hacking and Programming. I’ve have take up an internship at…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Cyber Security Internship
Hi Everyone, I’m Darshan Kumar B K from Bangalore. I’m Interested in Ethical Hacking and Programming. I’ve have take up an internship at…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Cyber Security Internship
Hi Everyone, I’m Darshan Kumar B K from Bangalore. I’m Interested in Ethical Hacking and Programming. I’ve have take up an internship at…
Hacking on Medium
Bypassing 2FA With Cookies
https://cdn-images-1.medium.com/max/600/1*olr_E6r-fiVedUIyh3pNYg.png
Two-factor authentication (2FA) is a specific type of multi-factor authentication (MFA) that strengthens access security by requiring two…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Bypassing 2FA With Cookies
https://cdn-images-1.medium.com/max/600/1*olr_E6r-fiVedUIyh3pNYg.png
Two-factor authentication (2FA) is a specific type of multi-factor authentication (MFA) that strengthens access security by requiring two…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bypassing 2FA With Cookies
Two-factor authentication (2FA) is a specific type of multi-factor authentication (MFA) that strengthens access security by requiring two…
Hacking on Medium
DC-4 VM WalkThrough
https://cdn-images-1.medium.com/max/716/0*ODdMgQHywig85BrG
Makineyi indirebilirsiniz.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
DC-4 VM WalkThrough
https://cdn-images-1.medium.com/max/716/0*ODdMgQHywig85BrG
Makineyi indirebilirsiniz.
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
DC-4 VM WalkThrough
Makineyi indirebilirsiniz.
Hacking on Medium
¿Qué es el malware?
https://cdn-images-1.medium.com/max/800/1*OWCel0y6ppxgG6URK_FbRg.jpeg
La palabra malware es una contracción de “software malicioso”, que en inglés significa código de programa malicioso. El malware cubre una…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
¿Qué es el malware?
https://cdn-images-1.medium.com/max/800/1*OWCel0y6ppxgG6URK_FbRg.jpeg
La palabra malware es una contracción de “software malicioso”, que en inglés significa código de programa malicioso. El malware cubre una…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
¿Qué es el malware?
La palabra malware es una contracción de “software malicioso”, que en inglés significa código de programa malicioso. El malware cubre una…
Hacking on Medium
How do i hack one of the famous Virtual Youtuber Agencies in Indonesia
https://cdn-images-1.medium.com/max/640/1*4vLdJ3cseEydRuN6EEi57Q.gif
Hello guys, hope u are fine. It’s been almost 5 months i haven’t done any hacking activity *lol . The last few years the internet world is…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
How do i hack one of the famous Virtual Youtuber Agencies in Indonesia
https://cdn-images-1.medium.com/max/640/1*4vLdJ3cseEydRuN6EEi57Q.gif
Hello guys, hope u are fine. It’s been almost 5 months i haven’t done any hacking activity *lol . The last few years the internet world is…
Continue reading on Medium »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
How do i hack one of the famous Virtual Youtuber Agencies in Indonesia
Hello guys, hope u are fine. It’s been almost 5 months i haven’t done any hacking activity *lol . The last few years the internet world is…
Hacking on Medium
Some critical vulnerabilities found with passive analysis on bug bounty programs explained
https://cdn-images-1.medium.com/max/1327/1*wgNKbh2qJC5DfTsTE_Q4ow.png
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…
Continue reading on InfoSec Write-ups »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Some critical vulnerabilities found with passive analysis on bug bounty programs explained
https://cdn-images-1.medium.com/max/1327/1*wgNKbh2qJC5DfTsTE_Q4ow.png
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…
Continue reading on InfoSec Write-ups »
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Medium
Some critical vulnerabilities found with passive analysis on bug bounty programs explained
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…
Some critical vulnerabilities found with passive analysis on bug bounty programs explained
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…Continue reading on InfoSec Write-ups »
Read more...
This post describes three vulnerabilities found on paid bounty programs along with an overview about how it was found and the performed…Continue reading on InfoSec Write-ups »
Read more...
The Bad Twin: a peculiar case of JWT exploitation scenario
Hey Everyone,Continue reading on Medium »
Read more...
Hey Everyone,Continue reading on Medium »
Read more...
Black Hat Ethical Hacking
Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs
___________________________
@hacking_Attack
@Hacking_Video
Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs | Black Hat Ethical Hacking
mozilla 97.0.2 zero-day vulnerabilities exploited
PwnKit-Exploit - Proof Of Concept (PoC) CVE-2021-4034
http://www.kitploit.com/2022/03/pwnkit-exploit-proof-of-concept-poc-cve.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/03/pwnkit-exploit-proof-of-concept-poc-cve.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
PwnKit-Exploit - Proof Of Concept (PoC) CVE-2021-4034
Proof Of Concept (PoC) CVE-2021-4034 @c0br40x help to make this section in README!!
Proof of Concept
___________________________
@hacking_Attack
@Hacking_Video
Proof of Concept
___________________________
@hacking_Attack
@Hacking_Video
debian@debian:~/PwnKit-Exploit$ make
cc -Wall exploit.c -o exploit
debian@debian:~/PwnKit-Exploit$ whoami
debian
debian@debian:~/PwnKit-Exploit$ ./exploit
Current User before execute exploit
hacker@victim$whoami: debian
Exploit written by @luijait (0x6c75696a616974)
[+] Enjoy your root if exploit was completed succesfully
root@debian:/home/debian/PwnKit-Exploit# whoami
root
root@debian:/home/debian/PwnKit-Exploit#
Fix Command Use sudo chmod 0755 pkexec Fix CVE (https://www.kitploit.com/search/label/CVE) 2021-4034 Installation & Use git clone https://github.com/luijait/PwnKit-Exploit cd PwnKit-Exploit make ./exploit whoami Command Utility make clean Clean build to test code modified Explanation Based blog.qualys.com The beginning of pkexec’s main() function processes the command-line arguments (lines 534-568), and searches for the program to be executed, if its path is not absolute, in the directories of the PATH environment variable (lines 610-640): 435 main (int argc, char *argv[])
436 {
...
534 for (n = 1; n < (guint) argc; n++)
535 {
...
568 }
...
610 path = g_strdup (argv[n]);
...
629 if (path[0] != '/')
630 {
...
632 s = g_find_program_in_path (path);
...
639 argv[n] = path = s;
640 } unfortunately, if the number of command-line arguments argc is 0 – which means if the argument list argv that we pass to execve() is empty, i.e. {NULL} – then argv[0] is NULL. This is the argument list’s terminator. Therefore: at line 534, the integer n is permanently set to 1; at line 610, the pointer path is read out-of-bounds from argv[1]; at line 639, the pointer s is written out-of-bounds to argv[1]. But what exactly is read from and written to this out-of-bounds argv[1]? To answer this question, we must digress briefly. When we execve() a new program, the kernel (https://www.kitploit.com/search/label/Kernel) copies our argument, environment strings, and pointers (argv and envp) to the end of the new program’s stack; for example: |---------+---------+-----+------------|---------+---------+-----+------------|
| argv[0] | argv[1] | ... | argv[argc] | envp[0] | envp[1] | ... | envp[envc] |
|----|----+----|----+-----+-----|------|----|----+----|----+-----+-----|------|
V V V V V V
"program" "-option" NULL "value" "PATH=name" NULL
Clearly, because the argv and envp pointers are contiguous in memory, if argc is 0, then the out-of-bounds argv[1] is actually envp[0], the pointer to our first environment variable, “value”. Consequently: At line 610, the path of the program to be executed is read out-of-bounds from argv[1] (i.e. envp[0]), and points to “value”; At line 632, this path “value” is passed to g_find_program_in_path() (because “value” does not start with a slash, at line 629); Then, g_find_program_in_path() searches for an executable file named “value” in the directories of our PATH environment variable; If such an executable file is found, its full path is returned to pkexec’s main() function (at line 632); Finally, at line 639, this full path is written out-of-bounds to argv[1] (i.e. envp[0]), thus overwriting our first environment variable. So, stated more precisely: If our PATH environment variable is “PATH=name”, and if the directory (https://www.kitploit.com/search/label/Directory) “name” exists (in the current working directory) and contains an executable file named “value”, then a pointer to the string “name/value” is written out-of-bounds to envp[0]; OR If our PATH is “PATH=name=.”, and if the directory “name=.” exists and contains an executable file named “value”, then a pointer to the string “name=./value” is written out-of-bounds to envp[0]. In other words, this out-of-bounds write allows us to re-introduce an “unsecure” environment variable (for example, LD_PRELOAD) into pkexec’s environment. These “unsecure” variables are normally
___________________________
@hacking_Attack
@Hacking_Video
cc -Wall exploit.c -o exploit
debian@debian:~/PwnKit-Exploit$ whoami
debian
debian@debian:~/PwnKit-Exploit$ ./exploit
Current User before execute exploit
hacker@victim$whoami: debian
Exploit written by @luijait (0x6c75696a616974)
[+] Enjoy your root if exploit was completed succesfully
root@debian:/home/debian/PwnKit-Exploit# whoami
root
root@debian:/home/debian/PwnKit-Exploit#
Fix Command Use sudo chmod 0755 pkexec Fix CVE (https://www.kitploit.com/search/label/CVE) 2021-4034 Installation & Use git clone https://github.com/luijait/PwnKit-Exploit cd PwnKit-Exploit make ./exploit whoami Command Utility make clean Clean build to test code modified Explanation Based blog.qualys.com The beginning of pkexec’s main() function processes the command-line arguments (lines 534-568), and searches for the program to be executed, if its path is not absolute, in the directories of the PATH environment variable (lines 610-640): 435 main (int argc, char *argv[])
436 {
...
534 for (n = 1; n < (guint) argc; n++)
535 {
...
568 }
...
610 path = g_strdup (argv[n]);
...
629 if (path[0] != '/')
630 {
...
632 s = g_find_program_in_path (path);
...
639 argv[n] = path = s;
640 } unfortunately, if the number of command-line arguments argc is 0 – which means if the argument list argv that we pass to execve() is empty, i.e. {NULL} – then argv[0] is NULL. This is the argument list’s terminator. Therefore: at line 534, the integer n is permanently set to 1; at line 610, the pointer path is read out-of-bounds from argv[1]; at line 639, the pointer s is written out-of-bounds to argv[1]. But what exactly is read from and written to this out-of-bounds argv[1]? To answer this question, we must digress briefly. When we execve() a new program, the kernel (https://www.kitploit.com/search/label/Kernel) copies our argument, environment strings, and pointers (argv and envp) to the end of the new program’s stack; for example: |---------+---------+-----+------------|---------+---------+-----+------------|
| argv[0] | argv[1] | ... | argv[argc] | envp[0] | envp[1] | ... | envp[envc] |
|----|----+----|----+-----+-----|------|----|----+----|----+-----+-----|------|
V V V V V V
"program" "-option" NULL "value" "PATH=name" NULL
Clearly, because the argv and envp pointers are contiguous in memory, if argc is 0, then the out-of-bounds argv[1] is actually envp[0], the pointer to our first environment variable, “value”. Consequently: At line 610, the path of the program to be executed is read out-of-bounds from argv[1] (i.e. envp[0]), and points to “value”; At line 632, this path “value” is passed to g_find_program_in_path() (because “value” does not start with a slash, at line 629); Then, g_find_program_in_path() searches for an executable file named “value” in the directories of our PATH environment variable; If such an executable file is found, its full path is returned to pkexec’s main() function (at line 632); Finally, at line 639, this full path is written out-of-bounds to argv[1] (i.e. envp[0]), thus overwriting our first environment variable. So, stated more precisely: If our PATH environment variable is “PATH=name”, and if the directory (https://www.kitploit.com/search/label/Directory) “name” exists (in the current working directory) and contains an executable file named “value”, then a pointer to the string “name/value” is written out-of-bounds to envp[0]; OR If our PATH is “PATH=name=.”, and if the directory “name=.” exists and contains an executable file named “value”, then a pointer to the string “name=./value” is written out-of-bounds to envp[0]. In other words, this out-of-bounds write allows us to re-introduce an “unsecure” environment variable (for example, LD_PRELOAD) into pkexec’s environment. These “unsecure” variables are normally
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
removed (by ld.so) from the environment of SUID programs before the main() function is called. We will exploit this powerful primitive in the following section. Last-minute note: polkit also supports non-Linux operating systems such as Solaris (https://www.kitploit.com/search/label/Solaris) and *BSD, but we have not investigated their exploitability. However, we note that OpenBSD (https://www.kitploit.com/search/label/OpenBSD) is not exploitable, because its kernel refuses to execve() a program if argc is 0.
Download PwnKit-Exploit (https://github.com/luijait/PwnKit-Exploit)
___________________________
@hacking_Attack
@Hacking_Video
Download PwnKit-Exploit (https://github.com/luijait/PwnKit-Exploit)
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
My First Bug Bounty Reward
A blog about how I found my first blog and Some learning about bug bounty, which is very important for every bug bounty hunter.
Read more...
A blog about how I found my first blog and Some learning about bug bounty, which is very important for every bug bounty hunter.
Read more...
Methods to Bypass two-factor Authentication
There are multiple ways to bypass two-factor authentication. One of its kind here.
Read more...
There are multiple ways to bypass two-factor authentication. One of its kind here.
Read more...