tpx Security ⠠⠵
2.41K subscribers
2.32K photos
103 videos
24 files
3.97K links
Hacking, ciberseguridad e Inteligencia.
Download Telegram
Cuando te piden que les enseñes a juackear!!! 😂
:V jajaja
Sistemas operativos obsoletos en el gobierno, la principal puerta para los ciberataques.
Nginx/ memory disclosure via null byte

Insecure implementation of nginx rewrite / OpenResty ngx.req.set_uri() + memory content leak in nginx.

https://hackerone.com/reports/513236
This script is a simple experiment to exploit the KR00K vulnerability (CVE-2019-15126), that allows to decrypt some WPA2 CCMP data in vulnerable devices (Access Point or Clients). More specifically this script attempts to retrieve decrypted data of WPA2 CCMP packets knowning:

the TK (128 bites all zero)
the Nonce (sent plaintext in packet header)
the Encrypted Data

Where:

WPA2 AES-CCMP decryption --> AES(Nonce,TK) XOR Encrypted Data = Decrypted Data
Decrypted stream starts with "\xaa\xaa\x03\x00\x00\x00"
Nonce (104 bits) = Priority (1byte) + SRC MAC (6bytes) + PN (6bytes)


https://github.com/akabe1/kr00ker
Para esos días de cuarentena juega en HackToday

https://hacktoday.tpx.mx/
👀😅