Premium Only Content
CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
1:01:10
Crypto Power Hour
11 hours ago $2.34 earnedAnimus Bitcoin Technology
20.7K8 -
LIVE
Game On!
18 hours ago $2.87 earnedAnother FOOTBALL FRIDAY! Weekend Preview And BEST BETS!
20 watching -
31:55
ZeeeMedia
19 hours agoHow Gold & Silver Fight Against Digital ID ft. Bill Armour | Daily Pulse Ep 148
15.9K9 -
13:29
Clintonjaws
15 hours ago $17.94 earnedCNN Host Stops Show & Plays Surprise Clip Forcing Democrat To Correct Lie
44.7K25 -
14:55
World2Briggs
19 hours ago $2.61 earnedThe 10 U.S. Cities Americans Can No Longer Afford — 2025 Edition
20.4K -
8:19
Millionaire Mentor
18 hours agoATC Whistleblower EXPOSES Obama’s Dirty FAA Secret
23.4K10 -
2:05:30
BEK TV
1 day agoTrent Loos in the Morning - 11/21/2025
18K2 -
LIVE
The Bubba Army
23 hours agoCHICAGO SUBWAY FIRE ATTACK - Bubba the Love Sponge® Show | 11/21/25
1,174 watching -
57:31
Side Scrollers Podcast
18 hours agoBlabs VS DuckTales
16.5K10 -
8:52
MetatronGaming
15 hours agoOverwatch 2 New Hero Vendetta La Lupa
119K11