Premium Only Content

CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
28:42
CatfishedOnline
1 day ago $1.40 earnedWoman Insists Morgan Wallen Relationship Isn't a Romance Scam!
19.1K -
16:25
TSPLY
1 day agoNew CNN / MSNBC Meltdown Moments Of Getting Mad At Donald Trump In February
24.5K16 -
8:33
scoutthedoggie
5 hours agoAirsoft War Games Scotland
28.3K4 -
4:56
Kirill MultitoolOfficial
1 day ago $2.70 earnedSurvival TIPS and usefull bushcraft DIY in the wild
43.9K3 -
27:25
ArturRehi
1 day agoThis is How Dictatorships are Formed
23.7K5 -
59:35
AlaskanBallistics
18 hours ago $0.63 earnedI Love this Gun Episode # 11
16.7K1 -
1:21:01
BibleUnbound
20 hours agoThe Complete Story of Moses: The Man of God
21.5K4 -
15:56
Chris From The 740
9 hours ago $0.01 earnedFenix LR36R Review: The Most Powerful Light I've Ever Tested!
13K1 -
1:01:47
Wendy Bell Radio
10 hours agoPet Talk With The Pet Doc
20.7K6 -
2:23:45
Game On!
20 hours ago $10.49 earnedTom Brady approves of President Trump calling out Governors wanting men in women's sports!
54.6K14