rastating.github.io

Creating a Bind Shell TCP Shellcode

September 4, 2018

“Bind shells” are used to spawn a shell on a remote system and provide access to it over a network. At minimum, a bind shell would need to carry out the following tasks:

Continue reading

Multiple Vulnerabilities in XBTIT Torrent Tracker

September 3, 2018

In August, 2018, I identified multiple vulnerabilities in the XBTIT torrent tracker software; a system in use by various active torrent trackers.

Continue reading

From LFI to SQL Database Backup

August 6, 2018

When exploiting local file inclusion vulnerabilities on a host that does not adhere to The Principle of Least Privilege, a common file to target is the SAM file in order to crack the NTLM hashes or to attempt Pass The Hash attacks. What about when the web server is the only service and there is no practical use of those hashes?

Continue reading

Unrestricted File Upload via Plugin Uploader in WordPress

August 4, 2018

On 11th July, 2018, a pull request was opened on the WordPress Exploit Framework GitHub Page to add a new feature that a user (Vinicius Marangoni) had created whilst completing a boot2root machine from VulnHub.

Continue reading

Creating a "Reboot into Windows" Button in Ubuntu

May 10, 2018

If you're dual booting a Windows and Ubuntu desktop, it can feel a bit cumbersome having to wait for GRUB and then manually choosing to boot into Windows. There is a utility packaged with GRUB which can help resolve this, but it requires a bit of setup.

Continue reading
Prev Next