[๐Ÿ“] Ligolo-ng, pivot/tunnel tool.

Ligolo-ng stands out as a straightforward, lightweight, and high-speed tool specifically designed for penetration testers to create tunnels through a reverse TCP/TLS connection using a tun interface, eliminating the need for SOCKS proxies. / / (_)___ _____ / /___ ____ ____ _ / / / / __ `/ __ \/ / __ \______/ __ \/ __ `/ / /___/ / /_/ / /_/ / / /_/ /_____/ / / / /_/ / /_____/_/\__, /\____/_/\____/ /_/ /_/\__, / /____/ /____/ Cheat Sheet Hereโ€™s a cheat sheet with the most commonly used commands:...

August 25, 2023 ยท 1 min ยท 147 words

[๐Ÿ“] NFS no_root_squash privesc

Introduction In some environments, the root user on a networked file system is treated as an unprivileged user. This is known as โ€œroot squashing.โ€ If root squashing is disabled, an attacker who gains access to an unprivileged account on the file system may be able to escalate their privileges to root. Demonstration Attacker machine Create a directory named /tmp/mount: mkdir /tmp/mount Mount the network file system to /tmp/mount: mount -t nfs <IP>:<SHARED_FOLDER> /tmp/mount Copy the /bin/bash binary from the attackerโ€™s system to the mounted file system:...

April 11, 2023 ยท 1 min ยท 126 words

[๐Ÿ“] LFI to RCE with Log Poisoning

Introduction LFI (Local File Inclusion) is a common vulnerability found in web applications, allowing an attacker to include local files in the server. LFI Log Poisoning is a technique that leverages LFI vulnerabilities to write arbitrary content to log files on the server. By doing so, an attacker can leverage a LFI to a RCE. This is the path of a vulnerable LFI : http://127.0.0.1/index.php?page=/../../../../etc/passwd The local file can be read :...

April 6, 2023 ยท 2 min ยท 365 words