home.social

#webshell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #webshell, aggregated by home.social.

fetched live
  1. Hackers Exploit KnowledgeDeliver Flaw to Install Web Shells

    Hackers have exploited a critical flaw in KnowledgeDeliver, using it as a zero-day to sneakily install a powerful .NET web shell called Godzilla on vulnerable servers. This sneaky attack was made possible by a deserialization vulnerability, CVE-2026-5426, that allowed threat actors to execute code at the operating-system level.

    osintsights.com/hackers-exploi

    #Cve20265426 #ZeroDay #WebShell #ViewstateDeserialization #Net

  2. Cookie-gesteuerte PHP-Webshells: Wie Angreifer Linux-Hosting-Server heimlich kompromittieren

    Sicherheitsforscher von Microsoft beobachten eine zunehmend verbreitete Angriffsmethode auf Linux-Hosting-Umgebungen: PHP-basierte Webshells, die HTTP-Cookies als Steuerkanal nutzen.

    all-about-security.de/cookie-g

    #microsoft #linux #php #cookies #webshell

  3. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  4. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  5. found this malware on my friend's site. checking on it and the original file looks so messy. vim can do `gg=G` to forcing re-indentation of the messed php file with html inside it >.<
    #webshell

  6. #webshell #opendir #netsupport #rat at:

    https://appointedtimeagriculture\.com/wp-includes/blocks/post-content/

    GatewayAddress=95.179.158.213:443
    RADIUSSecret=dgAAAPpMkI7ke494fKEQRUoablcA

  7. 2024-12-04 (Wednesday): Casual review of my most recent Apache web server access logs shows what looks like an attempt to get a PHP #webshell on my web server.

    URL for the PHP webshell is hxxp://1.14.123[.]164/ote.txt

  8. 2024-12-04 (Wednesday): Casual review of my most recent Apache web server access logs shows what looks like an attempt to get a PHP #webshell on my web server.

    URL for the PHP webshell is hxxp://1.14.123[.]164/ote.txt

  9. Just build a simple tool to interact with web shells and command injection vulnerabilities. Hope it's as useful for you as it was for me :)

    github.com/gildasio/weshlient

  10. Jak przejąć sieć operatora telekomunikacyjnego oraz dane jego klientów poprzez upload favicona?

    Niedawno wykryto kampanię hackerską celującą w amerykańskich dostawców sieci (zainfekowano w ten sposób minimum czterech ISP). W tym celu wykorzystano podatność w rozwiązaniu SD-WAN firmy Versa Networks. Podatność występuje w mechanizmie uploadu favicona w aplikacji webowej. Ale zamiast favicona można zuploadować webshella w Javie… Upload favicona wymaga jednak posiadania dostępu...

    #WBiegu #Apt #Atak #Chiny #Websec #Webshell

    sekurak.pl/jak-przejac-siec-op

  11. Podatności o niskim ryzyku, a jednak dały RCE – zobacz wektor ataku jaki odnaleźliśmy z naszego ostatniego pentestu

    W pracy pentestera bardzo często spotykamy się z podatnościami, które same w sobie niosą niskie lub średnie ryzyko. Ich wykorzystanie do niecnych celów przez atakującego wymaga spełnienia szeregu warunków, nierzadko bardzo trudnych do osiągnięcia – na przykład kliknięcie przez użytkownika w spreparowany i podesłany mu link. Im bardziej wyśrubowane warunki,...

    #Aktualności #Cve #Lfd #Pentesty #Rce #SQLInjection #Webshell

    sekurak.pl/podatnosci-o-niskim

  12. Podatności o niskim ryzyku, a jednak dały RCE – zobacz wektor ataku jaki odnaleźliśmy z naszego ostatniego pentestu

    W pracy pentestera bardzo często spotykamy się z podatnościami, które same w sobie niosą niskie lub średnie ryzyko. Ich wykorzystanie do niecnych celów przez atakującego wymaga spełnienia szeregu warunków, nierzadko bardzo trudnych do osiągnięcia – na przykład kliknięcie przez użytkownika w spreparowany i podesłany mu link. Im bardziej wyśrubowane warunki,...

    #Aktualności #Cve #Lfd #Pentesty #Rce #SQLInjection #Webshell

    sekurak.pl/podatnosci-o-niskim

  13. [Перевод] Перевод статьи «Injecting Java in-memory payloads for post-exploitation»

    В марте Synacktiv описали способы эксплуатации небезопасной десериализации в приложениях, написанных на Java. Позже, команда красных автора столкнулась с Java-приложениями, в которых были обнаружены другие уязвимости, приводящие к исполнению кода. А уже в этой статье автор представил несколько приемов, которые использовались для внедрения полезной нагрузки в память на примере широко известных приложений. Ну а мы, авторы telegram-канала AUTHORITY , перевели эту статью на русский.

    habr.com/ru/articles/833262/

    #Java #tomcat #jenkins #bitbucket #confluence #pentest #inmemory #exploit #webshell

  14. Как защититься от «бестелесных» веб-шеллов

    В сегодняшней статье эксперты Сайбер ОК проведут вас за руку по лабиринту хакерских уловок и на пальцах объяснят, что такое "бестелесные" веб-шеллы и как защитить от них свои ресурсы.

    habr.com/ru/companies/cyberok/

    #webshell #вебшелл #fileless_webshell #php #rce #cve #edr #soldr

  15. This novel web shell “hijacks the underlying Apache Tomcat webserver and silently inserts itself between Confluence and Tomcat–making itself available on every webpage ...”

    Interesting CVE-2023-22515 post-exploit behavior discovered by Aon's Stroz Friedberg Incident Response practice.

    “… patching Confluence to address CVE-2023-22515 and CVE-2023-22518 will not remediate the web shell if it has been deployed.”

    See the blog post for insights on identification of this web shell on your #Confluence server.

    aon.com/cyber-solutions/aon_cy

    #dfir #cve #webshell #exploit #atlassian #security

  16. Backlink slot gacor di web2 pemerintah/kampus tidak semudah itu bakal hilang soale banyak yang jual dan banyak juga yang mau beli akses webshell/cpanel domain .go.id dan .ac.id 😑

    @indonesia #webshell #cpanel #backdoor

  17. "⚠️ #Updated: Citrix CVE-2023-3519 Exploitation - Webshells Implanted! ⚠️"

    Initial Release Date: July 20, 2023

    The CISA has updated the alarm on CVE-2023-3519, a severe RCE vulnerability in NetScaler (Citrix) ADC & Gateway. In June 2023, threat actors exploited this as a zero-day, compromising a critical infrastructure organization. They planted a webshell, enabling AD reconnaissance & data exfiltration. Thankfully, network-segmentation controls halted their lateral movement. Citrix has since released a patch. Stay vigilant!

    Summary:
    The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding the exploitation of CVE-2023-3519, an unauthenticated remote code execution (RCE) vulnerability affecting NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. Threat actors exploited this vulnerability as a zero-day in June 2023, compromising a critical infrastructure organization's non-production environment NetScaler ADC appliance. The attackers planted a webshell, enabling them to perform Active Directory (AD) reconnaissance and data exfiltration. Although they attempted lateral movement to a domain controller, network-segmentation controls prevented their progress. Citrix released a patch on July 18, 2023.

    Technical Details:

    • CVE-2023-3519: This unauthenticated RCE vulnerability impacts various versions of NetScaler ADC and NetScaler Gateway. The affected appliance must be configured as a Gateway or for authentication, authorization, and auditing (AAA) to be exploited.

    Threat Actor Activity (Victim 1):

    • Initial exploit chain involved uploading a TGZ file containing a webshell, discovery script, and setuid binary.
    • The webshell was used for AD enumeration and data exfiltration.
    • NetScaler configuration files and decryption keys were accessed.
    • Actors queried AD data and encrypted discovery data for exfiltration.
    • Attempts to move laterally and delete artifacts were blocked by network-segmentation controls.

    Update September 6, 2023: Victim 2:

    • Actors uploaded a PHP webshell, gained root access, and conducted AD queries.
    • Exfiltrated data and deleted files and logs.
    • Used compromised pfSense devices for command and control (C2).

    Additional Observed Activity:

    • Actors leveraged open source webshells and tools for various purposes, including exfiltration, persistence, and tampering with monitoring tools.
    • Modified open-source tools to capture and exfiltrate credentials.
    • Deployed tunnellers for encrypted reverse TCP/TLS connections.
    • Employed Sysinternals ADExplorer for AD reconnaissance.

    Update September 6, 2023:
    The advisory was updated with additional techniques, including infrastructure compromise, tool acquisition, scripting interpreter usage, autostart execution, multi-hop proxying, file deobfuscation, permissions modification, defense impairment, indicator removal, masquerading, data staging, and protocol tunneling.

    Organizations are urged to apply the provided patches by Citrix and implement the detection guidance to identify potential system compromises. Incident response recommendations are included in the advisory for confirmed compromises, while vigilant monitoring and security measures are advised to prevent further exploitation.

    Source: CISA Advisory - AA23-201A

    Tags: #Cybersecurity #Citrix #CVE20233519 #NetScaler #ZeroDay #Webshell #DataExfiltration #PatchNow #StaySafe