Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BMC Remedy ITSM-Suite 9.1.10 / 20.02 HTML Injection
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
BMC Remedy ITSM-Suite version 9.1.10 (20.02 in new versioning scheme) suffers from an html injection vulnerability.
SHA-256 |
Download
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
BMC Remedy ITSM-Suite 9.1.10 / 20.02 HTML Injection
https://4.bp.blogspot.com/-zX4owX_f6gA/WWlvEjBsFTI/AAAAAAAAILA/L-jpFLkKi_AyIykovxrESAdO3HPxIIp7QCLcBGAs/s1600/h132.png
BMC Remedy ITSM-Suite version 9.1.10 (20.02 in new versioning scheme) suffers from an html injection vulnerability.
SHA-256 |
ed89f3f49d37ea4299f6f6221ace6ef8292ada73199f9aac17bae7cf6165fad3Download
SEC Consult Vulnerability Lab Security Advisory < 20221110-0 >
=======================================================================
title: HTML Injection
product: BMC Remedy ITSM-Suite
vulnerable version: 9.1.10 (= 20.02 in new versioning scheme)
fixed version: 22.1
CVE number: CVE-2022-26088
impact: Low
homepage: https://www.bmc.com/it-solutions/remedy-itsm.html
found: 2021-08-11
by: Daniel Hirschberger (Office Bochum)
SEC Consult Vulnerability Lab
An integrated part of SEC Consult, an Atos company
Europe | Asia | North America
https://www.sec-consult.com
=======================================================================
Vendor description:
-------------------
"Remedy IT Service Management Suite (Remedy ITSM Suite) and BMC Helix
ITSM service provide out of-the-box IT Information Library (ITIL)
service support functionality. Remedy ITSM Suite and BMC Helix ITSM
service streamline and automate the processes around IT service desk,
asset management, and change management operations. It also enables
you to link your business services to your IT infrastructure to help
you manage the impact of technology changes on business and business
changes on technology — in real time and into the future. In addition,
you can understand and optimize the user experience, balance current
and future infrastructure investments, and view potential impact on
the business by using a real-time service model."
Source: https://docs.bmc.com/docs/itsm91/home-608490971.html
Business recommendation:
------------------------
The vendor provides an updated version which should be installed immediately.
The vendor states that:
> We have done hardening in version 22.1.
> However, we do not agree with assigning the CVE to this vulnerability.
> As mentioned previously this is an informative vulnerability, and no real
impact is demonstrated.
Nevertheless, this can be used to trigger actions on internal services via CSRF or
exfiltrate information.
Vulnerability overview/description:
-----------------------------------
1) HTML Injection (CVE-2022-26088)
An authenticated attacker who can forward incidents per email is able to inject
a limited set of HTML tags. This is accomplished by inserting arbitrary content
into the "To:" field of the email. There is a filtering mechanism that prevents
the injection of many HTML tags, for example ➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
BMC Remedy ITSM-Suite 9.1.10 / 20.02 HTML Injection
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
VMware NSX Manager XStream Unauthenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
VMware NSX Manager XStream Unauthenticated Remote Code Execution
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
VMware NSX Manager XStream Unauthenticated Remote Code Execution
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
WordPress BeTheme BeCustom 1.0.5.2 Cross Site Request Forgery
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
WordPress BeTheme BeCustom plugin versions 1.0.5.2 and below suffer from a cross site request forgery vulnerability.
SHA-256 |
Download
Source:packetstormsecurity.com
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
WordPress BeTheme BeCustom 1.0.5.2 Cross Site Request Forgery
https://2.bp.blogspot.com/-QZ2Sf2sxziM/WWlvZhEG73I/AAAAAAAAIO0/d0s8s4TXkHwnfXzbpubNEBqDxa568NQgwCLcBGAs/s1600/h60.png
WordPress BeTheme BeCustom plugin versions 1.0.5.2 and below suffer from a cross site request forgery vulnerability.
SHA-256 |
651b396c90687b1931dfce7d1f9402a1dff09a912ce895903c27111b0634e43eDownload
RCE Security Advisory
https://www.rcesecurity.com
1. ADVISORY INFORMATION
=======================
Product: BeCustom Wordpress Plugin
Vendor URL: https://muffingroup.com/betheme/features/be-custom/
Type: Cross-Site Request Forgery [CWE-253]
Date found: 2021-10-28
Date published: 2022-11-10
CVSSv3 Score: 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N)
CVE: CVE-2022-3747
2. CREDITS
==========
This vulnerability was discovered and researched by Julien Ahrens from
RCE Security.
3. VERSIONS AFFECTED
====================
BeTheme BeCustom 1.0.5.2 and below
4. INTRODUCTION
===============
Built in-house add-on, perfect for agencies and web developers will let you rebrand
Be & WordPresss Admin to your own product by replacing all the Be & Muffin logos with
own.
This tool is supplied exclusively to the customers of Betheme and allows for changes
like: complete dashboard customization, replacement of logos, colors managment and much
more. With just a few clicks, you will turn the Be & Muffin brand into yours, thanks to
which you will increase the trust of your customers.
Moreover, from now on you can also customize the WPLogin page.
(from the vendor's homepage)
5. VULNERABILITY DETAILS
========================
The WordPress plugin lacks an anti-CSRF protection on all of its functionalities, which
ultimately allows an attacker to (amongst others):
- Set custom brandings
- Enable/Disable BeCustom features
- Modify the WP Login view
- Modify the BeDashboard texts
Since there is no anti-CSRF token protecting these functionalities, they are
vulnerable to Cross-Site Request Forgery attacks allowing an attacker to perform
a variety of attacks as mentioned above.
To successfully exploit this vulnerability, a user with the right to access the
plugin must be tricked into visiting an arbitrary website while having an authenticated
session in the application.
6. PROOF OF CONCEPT
===================
An exemplary exploit to reset the plugin's configuration:
7. SOLUTION
===========
Update to BeCustom 1.0.5.3
8. REPORT TIMELINE
==================
2022-10-28: Discovery of the vulnerability
2022-10-28: CVE requested from Wordfence (CNA)
2022-10-28: Wordfence assigns CVE-2022-3747
2022-11-01: Vendor notification
2022-11-07: No response. Sent another notification.
2022-11-08: Opened up a security support case on envato.com
2022-11-xx: Vendor publishes version 1.0.5.3 without notification which fixes this issue
2022-11-10: Public disclosure
9. REFERENCES
=============
https://github.com/MrTuxracer/advisories
Source:packetstormsecurity.com
➖ Sent by @TheFeedReaderBot ➖
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
WordPress BeTheme BeCustom 1.0.5.2 Cross Site Request Forgery
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Simmeth System GmbH Supplier Manager LFI / SQL Injection / Bypass
___________________________
@hacking_Attack
@Hacking_Video
Simmeth System GmbH Supplier Manager LFI / SQL Injection / Bypass
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Simmeth System GmbH Supplier Manager LFI / SQL Injection / Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Exploit Collector
Cisco Secure Email Gateway Malware Detection Evasion
___________________________
@hacking_Attack
@Hacking_Video
Cisco Secure Email Gateway Malware Detection Evasion
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Cisco Secure Email Gateway Malware Detection Evasion
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
hacking: security in practice
How to convert SHA-1 or NTLM to cracker compatible wordlist ?
cracker like hashcat
submitted by /u/RedditNoobie777
[link] [comments]
How to convert SHA-1 or NTLM to cracker compatible wordlist ?
cracker like hashcat
submitted by /u/RedditNoobie777
[link] [comments]
reddit
How to convert SHA-1 or NTLM to cracker compatible wordlist ?
cracker like hashcat
hacking: security in practice
want to Trade Original Bash Bunny for Original Shark jack Keychain
I had recently bought the new bash bunny so I have no use for my old one and I wanted the shark jack Keychain but they had none in stock will also trade for a plunder bug since they also don't have one of those in stock. I got the cable shark jack I just wanted the Keychain one.
I have a bunch of other none hak5 equipment I may trade in exchange just depends on what your looking for and if I have it and if I don't need it.
submitted by /u/Wildcardsec
[link] [comments]
want to Trade Original Bash Bunny for Original Shark jack Keychain
I had recently bought the new bash bunny so I have no use for my old one and I wanted the shark jack Keychain but they had none in stock will also trade for a plunder bug since they also don't have one of those in stock. I got the cable shark jack I just wanted the Keychain one.
I have a bunch of other none hak5 equipment I may trade in exchange just depends on what your looking for and if I have it and if I don't need it.
submitted by /u/Wildcardsec
[link] [comments]
reddit
want to Trade Original Bash Bunny for Original Shark jack Keychain
I had recently bought the new bash bunny so I have no use for my old one and I wanted the shark jack Keychain but they had none in stock will also...
Device for Magstrip Read/Write + other functionality?
https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/
<!-- SC_OFF -->I live in a housing unit that uses cards w/ magstrips for front doors. I will be having a friend stay with me for ~1 month, and need to clone my access card (I don't want to go to my landlord, as I think they might not want me to have a medium-term guest like this). Anyway, I need a magstrip reader/writer. I remember seeing some device (can't remember where) that had this functionality + more (for example scanning for access points, and im sure many other things --- i forget details now). If I already am going to shell out for a reader/writer, may as well look into things that do more than just this. Is there some well-known/common pentesting tool that includes the ability to clone magstrips? <!-- SC_ON --> submitted by /u/orangejake (https://www.reddit.com/user/orangejake)
[link] (https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/) [comments] (https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/)
https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/
<!-- SC_OFF -->I live in a housing unit that uses cards w/ magstrips for front doors. I will be having a friend stay with me for ~1 month, and need to clone my access card (I don't want to go to my landlord, as I think they might not want me to have a medium-term guest like this). Anyway, I need a magstrip reader/writer. I remember seeing some device (can't remember where) that had this functionality + more (for example scanning for access points, and im sure many other things --- i forget details now). If I already am going to shell out for a reader/writer, may as well look into things that do more than just this. Is there some well-known/common pentesting tool that includes the ability to clone magstrips? <!-- SC_ON --> submitted by /u/orangejake (https://www.reddit.com/user/orangejake)
[link] (https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/) [comments] (https://www.reddit.com/r/Pentesting/comments/yw913h/device_for_magstrip_readwrite_other_functionality/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Home Grown Red Team: Lateral Movement With Havoc C2 And Microsoft EDR
https://cdn-images-1.medium.com/max/600/1*lyAiUEVfU6diywz3cP3YnA.png
Lateral movement is extremely important for any red team engagement.
Continue reading on Medium »
Home Grown Red Team: Lateral Movement With Havoc C2 And Microsoft EDR
https://cdn-images-1.medium.com/max/600/1*lyAiUEVfU6diywz3cP3YnA.png
Lateral movement is extremely important for any red team engagement.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Google pagará una multa de privacidad de $391 millones por rastrear en secreto la ubicación de los…
https://cdn-images-1.medium.com/max/1763/0*XM74zBUruPE_DE97
El gigante de Internet Google acordó pagar un récord de 391,5 millones de dólares para llegar a un acuerdo con 40 estados de EE. UU. por…
Continue reading on Medium »
Google pagará una multa de privacidad de $391 millones por rastrear en secreto la ubicación de los…
https://cdn-images-1.medium.com/max/1763/0*XM74zBUruPE_DE97
El gigante de Internet Google acordó pagar un récord de 391,5 millones de dólares para llegar a un acuerdo con 40 estados de EE. UU. por…
Continue reading on Medium »