exploit

exploit etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
exploit etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

4 Kasım 2018 Pazar

Development Of Metasploit Module After 0day [Nuuo NVRmini2 RCE]



Hello Everyone


In this article I will tell you how to develop a 0day's metasploit module. Before writing Thank you to Numan Türle (@numanturle) for help on about ruby ​on rails



Vulnerability 

Vulnerability in a web application running on hardware, an input from a user caused a vulnerability in execution of a remote command execution.

This vulnerability affected 106 server




Examples Request



Usually this application is running on the server "8081" port. But when I do some research with shodan "50000" can work on ports such as "8080".

"uploaddir" value causes remote command execution vulnerability.in 

Example Response



The application works on root privileges. 

Metasploit-Framework Modules Development

Before you start writing, you can benefit greatly from here.If we need to summarize the first picture, we mentioned that the msf module is remote and we will use http client. 

Then enter the author, platforms, date and arch values.if this vulnerability was remote code execution, we should have chosen ARCH_PHP. But I used ARCH_CMD for remote command execution

There is a point we need to pay attention to here.people often compare "remote code execution" and "remote command execution" vulnerabilities

https://www.offensive-security.com/metasploit-unleashed/exploit-development/




If we need to summarize the first picture, we mentioned that the msf module is remote and we will use http client.


Then enter the author, platforms, date and arch values. There is a point we need to pay attention to here.
People often compare "remote code execution" and "remote command execution" vulnerabilities.If this vulnerability was remote code execution, we should have chosen ARCH_PHP. 




"if else" loop generated in response to  code in first lines. If response 200 and body / upload_tmp_dir / return vulnerable.


In the last lines we have specified the type of web request to be made "GET". 
Then the payload is entered with the "cmd" to the value that is the vulnerability. This payload gets backconnect with telnet.






Thank you for reading. twitter.com/berkdusunur
mailto::berkdusunurx@protonmail.com

25 Mart 2018 Pazar

TR-EN | Acrolinx Dashboard Directory Traversal (CVE 2018-7719)





Hello everyone :)

In this article I will publish the vulnerability I found on acrolinx dashboard.

What Is Acrolinx




Acrolinx is a server-client system developed to support quality assurance during the creation of expertise texts.

This support includes the application and supervision of the writing and style rules and has the component of terminology management and terminology extraction through the Acrolinx Terminology module.

This module integrates with the quality assurance system for the extraction, management and use of erminology.

In addition, term candidates can be suggested and terms can be searched. Acrolinx supports transport formats such as OLIF, XML, MTF, TBX and CSV.

What is a Directory Traversal Attack? 

Properly controlling access to web content is crucial for running a secure web server.
Directory traversal or Path Traversal is an HTTP attack which allows attackers to access restricted directories and execute commands outside of the web server’s root directory.

Web servers provide two main levels of security mechanisms  Access Control Lists (ACLs) Root directory An Access Control List is used in the authorization process.

It is a list which the web server’s administrator uses to indicate which users or groups are able to access, modify or execute particular files on the server, as well as other access rights.


Proof of Concept

The acrolinx dashboard running on Windows servers is affected by directory traversal. This vulnerability applies to all versions.

I know I was running this dashboard in windows server because I did a scan with nmap in the beginning.

Firstly I did various tests with wfuzz to an input value I caught. I did not get any results. I created a wordlist for Windows servers





Link for wfuzz usage: http://www.berkdusunur.net/2017/11/web-application-penetration-testing.html

Wordlist 

a short section

..\..\..\..\..\..\..\..\..\..\boot.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\boot.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini request 200 made with


I am with zehra when the http request is 200 :)





I obtained a directory traversal which is accomplished when I repeat this request using the burp suite



Then report process lived...

The company has released updates for all versions.

Twitter      @berkdusunur
Telegram   @berkdusunur

eng;

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7719

https://support.acrolinx.com/hc/en-us/articles/115002980125-Acrolinx-Server-Version-5-2-including-subsequent-service-releases-

https://support.acrolinx.com/hc/en-us/articles/115005757125-Acrolinx-Server-Version-5-3-including-subsequent-service-releases-

https://hackertor.com/2018/03/25/na-cve-2018-7719-acrolinx-server-before-5-2-5-on-windows-allows/

https://www.security-database.com/detail.php?alert=CVE-2018-7719

https://infosec.cert-pa.it/cve-2018-7719.html

https://nvd.nist.gov/vuln/detail/CVE-2018-7719




SAFE DAYS :)
 :)

28 Aralık 2017 Perşembe

Penetration Tests With Nessus (Chapter 1) Nessus İle Sızma Testleri




Hello  everyone. Today I will write to you about "Nessus Vulnerability Scanner"

This is the first part of my wiriting about nessus  in this section I will talk about simple scans and setup 

You can follow us on twitter @berkdusunur
Okay let's start :)

Nessus Linux Installation

You should first download the appropriate for your system.
You can view the packages in this;

https://www.tenable.com/products/nessus/select-your-operating-system 

I downloaded the debian package.  Let's go to setup :)


dpkg  -i Nessus-7.0.0-debian6_amd64.deb 





We got the activation code after opening Tenable membership. I then connected with the 8834 port scanner and entered the necessary information




Meanwhile I downloaded the "metasploitable 2" virtual machine.  Then started broadcasting with VirtualBox

FOr a short time IP Address for vulnerability researcher
Now right click on the new scan option


I will choose a simple network scan to be an example

after...


We enter the target name and ip address 212.83.175.136


This part asks if you want to do the scanning at the widespread ports or not


This section asks how to perform a scan on the web application.

We started scanning


Continues to scan I will have a coffee :) Nessus gives  more healthier result than its competitors.

I am using nessus with remote server because  I do not have to wait for slow scans


Many security vulnerabilities have been achieved.


In the second part we will explain how to exploit these vulnerabilities.

Thank you for reading.

E-Mail for your questions berkdusunurx@gmail.com