Drupal 7 Sql Injection SA-CORE-2014-005 CVE-2014-3704

claudio@backbox3:~$ ./drupal.py -t http://127.0.0.1/drupal -u 4dm1n -p p4ssw0rd ______ __ _______ _______ _____ | _ \ .----.--.--.-----.---.-| | | _ || _ | _ | |. | \| _| | | _ | _ | | |___| _|___| |.| | |. | |__| |_____| __|___._|__| / |___(__ `-|. | |: 1 / |__| | | |: 1 | |: | |::.. . / | | |::.. . | |::.| `------' `---' `-------' `---' _______ __ ___ __ __ __ | _ ....

October 16, 2014 · 1 min · claudio

How to install Faraday Community Edition on BackBox Linux 3

Tested on: Faraday Community Edition BackBox Linux 3.x x86_64 Download Faraday claudio@backbox3:~$ wget https://github.com/infobyte/faraday/archive/master.zip Install requirements claudio@backbox3:~$ sudo pip install psycopg2 Downloading/unpacking psycopg2 Running setup.py egg_info for package psycopg2 Installing collected packages: psycopg2 Running setup.py install for psycopg2 Successfully installed psycopg2 Cleaning up... claudio@backbox3:~$ Modify installation script claudio@backbox3:~$ unzip master.zip claudio@backbox3:~$ cd faraday-master/ claudio@backbox3:~/faraday-master$ ls apis AUTHORS config data deps exporters faraday.py gui install....

October 11, 2014 · 2 min · claudio

Come installare Windows OEM su VMware ESXi

Avete un server HP, Dell o IBM con VMware ESXi e volete installare una macchina virtuale windows utilizzando il relativo CD OEM? Avete già effettuato un tentativo ma vi siete imbattuti in questo tipo d’errore? Bene, anzi male, ma vi trovate nella pagina giusta per risolvere il problema. Questi supporti con sistemi windows OEM sono predisposti di controlli in modo da poter essere eseguiti solo su hardware specifico. Per aggirare queste protezioni basta inserire una particolare opzione all’interno della configurazione della macchina virtuale....

October 4, 2014 · 1 min · claudio

IPFire Cgi Web Interface Authenticated Bash Environment Variable Code Injection exploit

[claudio@localhost ~]$ python ipfire_cgi_shellshock.py ___ _______ _______ __ _______ __ | | _ | _ |__.----.-----. | _ .-----|__| |. |. 1 |. 1___| | _| -__| |. 1___| _ | | |. |. ____|. __) |__|__| |_____| |. |___|___ |__| |: |: | |: | |: 1 |_____| |::.|::.| |::.| |::.. . | `---`---' `---' `-------' _______ __ __ __ _______ __ __ | _ | |--.-----| | | _ | |--....

September 29, 2014 · 1 min · claudio

Gnu Bash 4.3 and below Cgi Scan + Remote Command Injection Exploit

[claudio@localhost ~]$ ./bash_env_rci_v2.py _______ _______ __ | _ .-----.--.--. | _ .---.-.-----| |--. |. |___| | | | |. 1 | _ |__ --| | |. | |__|__|_____| |. _ |___._|_____|__|__| |: 1 | |: 1 \ |::.. . | |::.. . / `-------' `-------' ___ ___ _______ _______ _______ ___ | Y | | _ | | _ | _ | | | | |_|___| | |. l |. 1___|....

September 26, 2014 · 1 min · claudio