Premium Only Content

CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
LIVE
CassaiyanGaming
1 hour agoClean Water Charity Stream Day 1 - Black Ops 6 Level Grinding
64 watching -
LIVE
PudgeTV
3 hours ago🟣 Greak: Memories of Azur | Gaming on Rumble | September Charity Water Campaign
86 watching -
LIVE
LarryDickmanGaming
11 hours agoI am what I am and that's all that I am.
54 watching -
2:39:02
The Pascal Show
19 hours ago $2.81 earned'HE'S THE DEVIL!' Former Mother In Law Breaks Silence On Jake Haro & Emmanuel Haro Case
21.4K4 -
5:30:10
SpartakusLIVE
14 hours ago#1 Verdansk Sniper gets HACCUSATIONS because of INSANE Headshots
65.1K4 -
46:18
SB Mowing
3 days agoShe was LOSING HOPE but this SURPRISE CHANGED EVERYTHING
54.3K49 -
10:00:10
ItsLancOfficial
14 hours agoWE LIVE 🔴WE LIVE 🔴 SUNDAY SUNDAYS!!!!!!! TARKOV
44.1K3 -
4:09:32
EricJohnPizzaArtist
6 days agoAwesome Sauce PIZZA ART LIVE Ep. #59: Are You Ready for some FOOTBALL with GameOn!
55.1K8 -
1:21:43
Jake Shields' Fight Back Podcast
19 hours agoJake Shields and Paul Miller!
86.5K148 -
1:20:41
TRAGIKxGHOST
11 hours agoTrying to get SCARED tonight! | Are You SCARED!? | Screams Beyond Midnight | Grab a Snack
32.7K6