Premium Only Content
CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
6:35
China Uncensored
13 hours agoEconomic EXPERT Reveals the Surprising Truth About China's Economy
14.4K4 -
1:17:55
Game On!
13 hours ago $6.11 earnedThursday Night Football NFL Week 14 Rams at 49ers!
67.1K4 -
6:46
Dr. Nick Zyrowski
1 day agoWhat Happens If You Drink Lemon Water for 14 Days?
25.4K6 -
12:25
IsaacButterfield
1 day ago $6.98 earnedGEN Z SHOULD BE ASHAMED!
17.2K4 -
5:13
BIG NEM
14 hours agoIs AI Coming for Comedians Too?
12.8K3 -
28:29
Goose Pimples
1 day ago7 SCARY Videos That’ll Make Your Knees Wobble
83.8K8 -
52:00
Uncommon Sense In Current Times
22 hours ago $15.54 earned"Inclusive or Excluding? The Hidden Agenda Behind 'Happy Holidays"
80.9K14 -
2:36
Canadian Crooner
1 year agoPat Coolen | Frosty the Snowman
47K5 -
55:02
Bek Lover Podcast
22 hours agoAl Qaeda Take Over of Syria Backed by US & Israel? More Strange News...
32.9K8 -
4:04:32
Alex Zedra
13 hours agoLIVE! New Scary Game w/ Heather
138K3