CVE-2021-21985 VCenter Pre-Auth RCE (Direct Shell)

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ม.ค. 2025

ความคิดเห็น • 12

  • @odilbek6054
    @odilbek6054 3 ปีที่แล้ว +1

    What if the server is on a different subnet? Well, your exploit working only one subnet. But when I set up different subnet is not working. Is there anything problem, or need to set up comething again?

  • @darkoct5687
    @darkoct5687 3 ปีที่แล้ว

    can you tell me where is the document root path?

  • @Платон300
    @Платон300 3 ปีที่แล้ว

    I tested this bug on my server. I managed to get access but it is useless. not enough rights to do something about it. What can be done using this vulnerability?

  • @TheGh0stShip
    @TheGh0stShip 3 ปีที่แล้ว

    Fuck yea! Get it!

  • @robotforex2429
    @robotforex2429 3 ปีที่แล้ว

    Cho mình hỏi là cái này và cái PoC ông TQ đều phải kết nối ra ngoài phải k ta =)), như video thì rev shell thực tế sẽ connect ra ngoài đúng k nhỉ ?

    • @testanull
      @testanull  3 ปีที่แล้ว

      k cần nhé

    • @robotforex2429
      @robotforex2429 3 ปีที่แล้ว

      @@testanull Thế thì ông phải ở trong mạng nội bộ của n hả ? Hay có cách nào khác tunnel tới nó ?

    • @testanull
      @testanull  3 ปีที่แล้ว

      @@robotforex2429 cái video này chỉ là poc cho rce thôi, chứ đã execute code đc trên server rồi thì làm gì chả đc ?

  • @davoodamini9128
    @davoodamini9128 3 ปีที่แล้ว

    Can you please give the poc link?

    • @hamankoo
      @hamankoo 3 ปีที่แล้ว +2

      github.com/testanull/Project_CVE-2021-21985_PoC/blob/main/PoC_1.py

    • @Платон300
      @Платон300 3 ปีที่แล้ว +1

      @@hamankoo I tested this bug on my server. I managed to get access but it is useless. not enough rights to do something about it. What can be done using this vulnerability?

  • @marcosj809
    @marcosj809 3 ปีที่แล้ว

    Holly shit dude!