• XSS.stack #1 – первый литературный журнал от юзеров форума

Мануал/Книга Router Apk and get ssh access over host

oxostore

HDD-drive
Пользователь
Регистрация
07.08.2023
Сообщения
35
Реакции
17
Holla XSS!

I love to share my [ out of the box ] findings

when your at home and hack your router Apk and get ssh access over host ;)



lets make it long short

downloaded a router online config apk , run it on LD Player and activated burp suite .


1.jpg


RUN BURP AND CHECK REQUEST ...

2-1-1.jpg


checking the request and sending it to repeater .


3.jpg


response got a filter "0.0.0.0\n"

changed a bit in it and play again and i was able to remote command !



4.jpg



i was thinking to get reverse shell and all failed ( i guess due to iptables )

Got my attention ...


5.jpg



did my key (ssh-keygen) locally and decided to inject it ! :t

6.jpg


Injecting by echo..

7.jpg


Volla we got ssh session active!

8-1.jpg


------------------------------------------------------------
Note : after my last thread i got contacted to do some pen-testing
[ i got paid for my time not my findings ]
AND ANY DEAL have to be in XSS , i dont do stuff like dump a db for me !!!
------------------------------------------------------------
./0x0



Credits Please if Copied never shared in other forums!

show some love to keep this going by reaction or whatever support !

any translation to Russian is appreciated from experienced user !



 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх