Windows Escalate UAC Protection Bypass (Via COM Handler Hijack)

Windows Escalate UAC Protection Bypass (Via COM Handler Hijack)

This Metasploit module will bypass Windows UAC by creating COM handler registry entries in the HKCU hive. When certain high integrity processes are loaded, these registry entries are referenced resulting in the process loading user-controlled DLLs. These DLLs contain the payloads that result in elevated sessions. Registry key modifications are cleaned up after payload invocation. […]

The post Windows Escalate UAC Protection Bypass (Via COM Handler Hijack) appeared first on MondoUnix.

VMware VDP Known SSH Key

VMware VDP Known SSH Key

VMware vSphere Data Protection appliances 5.5.x through 6.1.x contain a known ssh private key for the local user admin who is a sudoer without password.
Source: VMware VDP Known SSH Key
The post VMware VDP Known SSH Key appeared first on MondoUnix.

IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution

IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution

This Metasploit module exploits an unauthenticated remote PHP code execution vulnerability in IBM OpenAdmin Tool included with IBM Informix versions 11.5, 11.7, and 12.1. The ‘welcomeServer’ SOAP service does not properly validate user input in the ‘new_home_page’ parameter of the ‘saveHomePage’ method allowing arbitrary PHP code to be written to the config.php file. The config.php […]

The post IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution appeared first on MondoUnix.

Bettercap 1.6.2

Bettercap 1.6.2

BetterCAP is a powerful, flexible, and portable tool created to perform various types of MITM attacks against a network, manipulate HTTP, HTTPS and TCP traffic in realtime, sniff for credentials and much more.
Source: Bettercap 1.6.2
The post Bettercap…

AIEngine 1.8.1

AIEngine 1.8.1

AIEngine is a packet inspection engine with capabilities of learning without any human intervention. It helps network/security professionals to identify traffic and develop signatures for use them on NIDS, Firewalls, Traffic classifiers and so on.
Sour…