Premium Only Content

CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
LIVE
Major League Fishing
1 day agoLIVE MLF College Fishing Championship!
171 watching -
1:12:00
Jeff Ahern
2 hours ago $0.47 earnedFriday Freak out with Jeff Ahern! (1pm Pacific)
13.2K -
2:12:33
The Quartering
5 hours agoWild Joe Rogan Stream, China Retaliates, Woke Jerks Review BOMB My Coffee & More!
227K88 -
1:07:03
Sean Unpaved
5 hours agoNIL Controversy In Tennessee, Second Round of Masters Tee-Off, Flacco's Return To Cleveland!
56.4K3 -
16:09
Clownfish TV
6 hours agoSnow White Can't Even Break $100 Million?!
44.4K9 -
13:23
T-SPLY
5 hours agoStephen Miller BLOWS UP On CNN For Questioning Deportations
31.1K37 -
59:26
Revenge of the Cis
3 hours agoEpisode 1473: Cyber Tuck
16.8K3 -
15:09
Talk Nerdy Sports - The Ultimate Sports Betting Podcast
2 hours ago4/11/25 - Payday Parlays & Bookie Beatdowns: The AI Wants Blood
18.1K1 -
1:02:31
Crypto Power Hour
10 hours ago $2.31 earnedFrom Tariffs to WFH Multinationals, Catalysts Starting a Tokenization Tsunami
26.9K2 -
49:35
Rethinking the Dollar
2 hours agoFed Official Warns: They're Ready to Step In— If It Gets Worse | RTD News Update
10.2K4