PFSense

Exec Code Exploit

  • google: pfsense cve

    • cvedetails.com

      • bright red ones for 'pfsense'

      • 'exec code' as indicator

    • Use: CVE-2014-4688 (only 6.5 score)

    • exploitdb: 43560 ..interesting

  • google: pfsense 2.1.3 changelog

    • Found: Nov 11, 2014 New Features

  • google: pfsense exploits ..find good blogpost

    • proteansec - pt4: directory traversal

    • proteansec - pt2: command injection

    • status_rrd_graph_img.php ..still unpatched, we will use

Mixed Results

  • Had trouble following these examples from ippsec

gobuster - 45 minutes

More Injections

Octal Code to Injection

  • If Dashes and Slashes are Blocked

  • Use Octal Encoding

Easy Exploit

Metasploit

  • Plus Socks pivot from another box (since we were banned)

Advanced

Last updated

Was this helpful?