Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare
New Windows Search zero-day added to Microsoft protocol nightmarePost Views: 6
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
The security issue can be leveraged because Windows supports a URI protocol handler called ‘search-ms’ that allows applications and HTML links to launch customized searches on a device.
While most Windows searches will look on the local device’s index, it is also possible to force Windows Search to query file shares on remote hosts and use a custom title for the search window.
For example, the popular Sysinternals toolset allows you to remotely mount live.sysinternals.com as a network share to launch their utilities. To search this remote share and list only files matching a particular name, you could use the following ‘search-ms’ URI:
A customized search window will appear when this command is executed from a Run dialog or web browser address bar on Windows 7, Windows 10, and Windows 11, as shown below.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/search-ms-protocol-handler/search-ms-sysinternals.jpg
Microsoft Office takes it to the next levelThis week, researchers discovered that threat actors were utilizing a new Windows zero-day vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT). To exploit it, threat actors created malicious Word documents that launched the ‘ms-msdt’ URI protocol handler to execute PowerShell commands simply by opening the document.
Identified as CVE-2022-30190, the flaw makes it possible to modify Microsoft Office documents to bypass Protected View and launch URI protocol handlers without interaction by users, which will only lead to further abuse of protocol handlers.
This was seen yesterday when Hickey converted existing Microsoft Word MSDT exploits to use the search-ms protocol handler we described earlier[...]
___________________________
@hacking_Attack
@Hacking_Video
New Windows Search zero-day added to Microsoft protocol nightmare
New Windows Search zero-day added to Microsoft protocol nightmarePost Views: 6
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
The security issue can be leveraged because Windows supports a URI protocol handler called ‘search-ms’ that allows applications and HTML links to launch customized searches on a device.
While most Windows searches will look on the local device’s index, it is also possible to force Windows Search to query file shares on remote hosts and use a custom title for the search window.
For example, the popular Sysinternals toolset allows you to remotely mount live.sysinternals.com as a network share to launch their utilities. To search this remote share and list only files matching a particular name, you could use the following ‘search-ms’ URI:
search-ms:query=proc&crumb=location:%5C%5Clive.sysinternals.com&displayname=Searching%20SysinternalsAs you can see from the command above, the search-ms ‘crumb’ variable specifies the location to search, and the ‘displayname’ variable specifies the search title.A customized search window will appear when this command is executed from a Run dialog or web browser address bar on Windows 7, Windows 10, and Windows 11, as shown below.
https://www.bleepstatic.com/images/news/Microsoft/vulnerabilities/search-ms-protocol-handler/search-ms-sysinternals.jpg
Microsoft Office takes it to the next levelThis week, researchers discovered that threat actors were utilizing a new Windows zero-day vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT). To exploit it, threat actors created malicious Word documents that launched the ‘ms-msdt’ URI protocol handler to execute PowerShell commands simply by opening the document.
Identified as CVE-2022-30190, the flaw makes it possible to modify Microsoft Office documents to bypass Protected View and launch URI protocol handlers without interaction by users, which will only lead to further abuse of protocol handlers.
This was seen yesterday when Hickey converted existing Microsoft Word MSDT exploits to use the search-ms protocol handler we described earlier[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare | Black Hat Ethical Hacking
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare
___________________________
@hacking_Attack
@Hacking_Video
New Windows Search zero-day added to Microsoft protocol nightmare
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
New Windows Search zero-day added to Microsoft protocol nightmare | Black Hat Ethical Hacking
A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document.
Reverse Engineering Discord’s Party Mode
https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reverse Engineering Discord’s Party Mode
If you haven’t noticed yet, Discord added a ‘Party Mode’ because they are celebrating their 7th birthday. When a friend convinced me to enable it, I did the first few challenges, but quickly noticed…
Continue reading on Medium » (https://medium.com/@not-matthias/reverse-engineering-discords-party-mode-d9c9dcaf0be4?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Reverse Engineering Discord’s Party Mode
If you haven’t noticed yet, Discord added a ‘Party Mode’ because they are celebrating their 7th birthday. When a friend convinced me to enable it, I did the first few challenges, but quickly noticed…
How I Mass hunt for Admin Panel Access…
https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Mass hunt for Admin Panel Access…🤩
Hello All,🙂
Hello All,🙂Continue reading on Medium » (https://medium.com/@ratnadip1998/how-i-mass-hunt-for-admin-panel-access-8c2ad145054?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Mass hunt for Admin Panel Access…🤩
Hello All,🙂
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is Clickjacking?
https://cdn-images-1.medium.com/max/2600/1*ojUOoQkfcsxDs4rz9kaaRA.jpeg
The malicious technique of clickjacking (or user interface redress attack) involves tricking users into clicking on something other than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is Clickjacking?
https://cdn-images-1.medium.com/max/2600/1*ojUOoQkfcsxDs4rz9kaaRA.jpeg
The malicious technique of clickjacking (or user interface redress attack) involves tricking users into clicking on something other than…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is Clickjacking?
The malicious technique of clickjacking (or user interface redress attack) involves tricking users into clicking on something other than…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
What is a Data Spillage?
https://cdn-images-1.medium.com/max/2600/1*HeFz5z3SSpO-Pa7QVZVrSg.jpeg
There is a risk of data leakage when sensitive, confidential, or harmful information is moved into an environment where it is not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
What is a Data Spillage?
https://cdn-images-1.medium.com/max/2600/1*HeFz5z3SSpO-Pa7QVZVrSg.jpeg
There is a risk of data leakage when sensitive, confidential, or harmful information is moved into an environment where it is not…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
What is a Data Spillage?
There is a risk of data leakage when sensitive, confidential, or harmful information is moved into an environment where it is not permitted…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I Mass hunt for Admin Panel Access…
https://cdn-images-1.medium.com/max/1562/1*NA2e8jOkzbaFMUazaicHTA.png
Hello All,🙂
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How I Mass hunt for Admin Panel Access…
https://cdn-images-1.medium.com/max/1562/1*NA2e8jOkzbaFMUazaicHTA.png
Hello All,🙂
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I Mass hunt for Admin Panel Access…🤩
Hello All,🙂
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
#WHOAMI
My name is Ibrahim and I am a Cyber Security Analyst in The Netherlands. A large part of my blog will be about Cyber Security and I will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
#WHOAMI
My name is Ibrahim and I am a Cyber Security Analyst in The Netherlands. A large part of my blog will be about Cyber Security and I will…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
#WHOAMI
My name is Ibrahim and I am a Cyber Security Analyst in The Netherlands. A large part of my blog will be about Cyber Security and I will…
Exploiting CVE-2022-26923 by Abusing AD CS
https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/
We are doing 2 THM Labs. In the first one we are abusing vulnerable certificate templates manually with Certify and Rubeus, then changing the domain Administrator's password. In the second lab, we are utilizing Certipy POC to takeover DC machine and dump hashes for all users. Available on YouTube: https://youtu.be/HBRCI5O35R8 Hope you enjoy the video and learn something new. The channel is new and all feedback is appreciated. submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/) [comments] (https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/
We are doing 2 THM Labs. In the first one we are abusing vulnerable certificate templates manually with Certify and Rubeus, then changing the domain Administrator's password. In the second lab, we are utilizing Certipy POC to takeover DC machine and dump hashes for all users. Available on YouTube: https://youtu.be/HBRCI5O35R8 Hope you enjoy the video and learn something new. The channel is new and all feedback is appreciated. submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/) [comments] (https://www.reddit.com/r/redteamsec/comments/v35a1b/exploiting_cve202226923_by_abusing_ad_cs/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Exploiting CVE-2022-26923 by Abusing AD CS
We are doing 2 THM Labs. In the first one we are abusing vulnerable certificate templates manually with Certify and Rubeus, then changing the...
Complete Bug Bounty CheatSheet | Joas Antonio
XSS, SQLi, SSRF, CRLF, CSV-Injection, Command Injection, Directory Traversal, LFI, XXE, Open-Redirect, RCE, Crypto, Template Injection…Continue reading on Medium »
Read more...
XSS, SQLi, SSRF, CRLF, CSV-Injection, Command Injection, Directory Traversal, LFI, XXE, Open-Redirect, RCE, Crypto, Template Injection…Continue reading on Medium »
Read more...
Complete Bug Bounty CheatSheet | Joas Antonio
https://0xshakhawat.medium.com/complete-bug-bounty-cheatsheet-joas-antonio-ef7ea5411cca?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://0xshakhawat.medium.com/complete-bug-bounty-cheatsheet-joas-antonio-ef7ea5411cca?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Complete Bug Bounty CheatSheet | Joas Antonio
XSS, SQLi, SSRF, CRLF, CSV-Injection, Command Injection, Directory Traversal, LFI, XXE, Open-Redirect, RCE, Crypto, Template Injection…
XSS, SQLi, SSRF, CRLF, CSV-Injection, Command Injection, Directory Traversal, LFI, XXE, Open-Redirect, RCE, Crypto, Template Injection…Continue reading on Medium » (https://0xshakhawat.medium.com/complete-bug-bounty-cheatsheet-joas-antonio-ef7ea5411cca?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Complete Bug Bounty CheatSheet | Joas Antonio
XSS, SQLi, SSRF, CRLF, CSV-Injection, Command Injection, Directory Traversal, LFI, XXE, Open-Redirect, RCE, Crypto, Template Injection…