I'm super happy🥳to announce my Advanced .NET Exploitation Training a 4 day training course on teaching you how to exploit advanced .NET enterprise targets 🔥, bypass mitigations, chain bugs🐞🪲 and pop shellz. more information can be found below
https://t.co/biDIcQiFsr
@bl4sty@shuffle2 yes and the response to that is the bash script in the screenshot. no guarantees that the response didn't change in content (lines commented based on IP?) though
@bl4sty@shuffle2 Here's the server response to the request to /hash.php, zipped, psw: "xnand_"
I haven't analysed that bit as I then moved to dynamic analysis, but in case you guys want it...
https://t.co/VjNur38MNl
For anyone that has ran this PoC, consider your data stolen. This is what eventually runs on your host after a few stages. If you wanna analyse it, don't use a web browser or your IP will get blacklisted. #CVE_2023_35829#backdoor
@r0rt1z2 That server is conceiving. Send only the Host header and nothing else, like the malware would do. Also don't spam it or you'll get blacklisted. I used tor to change my IP and never used the browser
@Dinosn This project is backdoored and fake. DO NOT RUN THIS POC!
For an example, here is their exploit for CVE-2023-20871: https://t.co/hK4YgMIXAw
That code looks very similar hmm....
@mugundhanbalaji@domchell yes, that's the first stage which will do some initial persistence, mem deobfuscation and eventually run a wget command to the same domain to download and run the script in the screenshot
Also check:
~/.bashrc
~/.ssh/authorized_keys
/tmp/.iCE-unix.pid
Remove ~/.local/kworker
Monitor traffic for https://t.co/9DbXRbjvzr, https://t.co/CKKVXzBfmf and IP 81.4.109.16
Monitor processes with name [kworker/8:3]
I published the writeup of
"Exploiting Hibernate Injection (HQL) in "Order by" Clause (Oracle database)" which we found during an assessment.
https://t.co/6yQQmkIEQq
Special Thanks to: @irsdl sir and @NomanRiffat bhai ji
#injection#websecurity#bugbountytips#Pentesting
☀️ Summer Solstice philanthropy: I am making this mini-class available for free!
4 hours of deeply systematical theory & practice introduction on hypervisor vulns and how to find them, taught by a specialist researcher, bug hunter and pwner 🔥
How to claim your seat, thread 👉🏻