Premium Only Content
CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
1:01:12
Donald Trump Jr.
6 hours agoThe China Matrix with Journalist Lee Smith | TRIGGERED Ep.288
117K74 -
LIVE
Dr Disrespect
11 hours ago🔴LIVE - DR DISRESPECT - ARC RAIDERS - FULL SEND INTO THE RED
1,131 watching -
LIVE
JdaDelete
2 hours agoFinally playing Eldin Ring | First Playthrough Episode 2
20 watching -
1:02:08
BonginoReport
4 hours agoNicki Minaj Speaks Out Against Christian Persecution - Nightly Scroll w/ Hayley Caronia (Ep.169)
51.8K27 -
LIVE
HomieQuest
4 hours agoLive Streaming! Pokemon Legends Z-A
9 watching -
5:33:02
FusedAegisTV
7 hours agoFUSEDAEGIS PLAYS THE GREATEST JRPG EVER MADE ⌛► CHRONO TRIGGER (1995) Part 3
360 -
DVR
Nerdrotic
3 hours ago $2.05 earnedNerdrotic At Night 531
25.9K3 -
1:43:27
Glenn Greenwald
5 hours agoThe Right's Crusade to Cancel Tucker | SYSTEM UPDATE #542
67.6K64 -
2:10:04
Conductor_Jackson
23 hours agoLet's Play Unrailed 2 Solo! 🚂🚂🚂🚂🚂🚂
7.42K1 -
1:25:38
Kim Iversen
5 hours agoTrump’s Nigeria Threat Isn’t About Christians — It’s About China
84.9K90