NodeJS Debugger Command Injection

NodeJS Debugger Command Injection

This Metasploit module uses the “evaluate” request type of the NodeJS V8 debugger protocol (version 1) to evaluate arbitrary JS and call out to other system commands. The port (default 5858) is not exposed non-locally in default configurations, but may be exposed either intentionally or via misconfiguration. Source: NodeJS Debugger Command Injection

The post NodeJS Debugger Command Injection appeared first on MondoUnix.

Zorin OS 12.2

Zorin OS 12.2

Zorin OS Zorin OS è una distribuzione Linux nata per rendere semplice il passaggio da Windows a Linux per tutti gli utenti. Per far questo viene usato un tema che eguaglia Windows 7 così gli utenti trovato tutto famigliare fin da subito. Versione 12.2 Questa versione contiene (in Inglese): We’re pleased to announce the release […]

Related posts:

  1. Zorin OS 12 Zorin OS Zorin OS è una distribuzione Linux nata per…
  2. Zorin OS 12.1 Zorin OS Zorin OS è una distribuzione Linux nata per…
  3. Linux Lite 3.6 Linux Lite Linux Lite è una distribuzione Linux per i…

Packet Fence 7.3.0

Packet Fence 7.3.0

PacketFence is a network access control (NAC) system. It is actively maintained and has been deployed in numerous large-scale institutions. It can be used to effectively secure networks, from small to very large heterogeneous networks. PacketFence provides NAC-oriented features such as registration of new network devices, detection of abnormal network activities including from remote snort […]

The post Packet Fence 7.3.0 appeared first on MondoUnix.

Supervisor XML-RPC Authenticated Remote Code Execution

Supervisor XML-RPC Authenticated Remote Code Execution

This Metasploit module exploits a vulnerability in the Supervisor process control software, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. Depending on how supervisord has been configured, this may be root. […]

The post Supervisor XML-RPC Authenticated Remote Code Execution appeared first on MondoUnix.