PFSense
Exec Code Exploit
google: pfsense cve
cvedetails.com
bright red ones for 'pfsense'
'exec code' as indicator
Use: CVE-2014-4688 (only 6.5 score)
exploitdb: 43560 ..interesting
google: pfsense 2.1.3 changelog
Found: Nov 11, 2014 New Features
google: pfsense exploits ..find good blogpost
proteansec - pt4: directory traversal
proteansec - pt2: command injection
status_rrd_graph_img.php ..still unpatched, we will use
REF: ReverseShell, LFI, CharEvasion
Mixed Results
Had trouble following these examples from ippsec
gobuster - 45 minutes
More Injections
Octal Code to Injection
If Dashes and Slashes are Blocked
Use Octal Encoding
Easy Exploit
Metasploit
Plus Socks pivot from another box (since we were banned)
Advanced
Last updated
Was this helpful?