Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CVE-2012-3951 Scrutinizer NetFlow and sFlow Analyzer exploit #671

Merged
merged 3 commits into from Aug 7, 2012

Conversation

wchen-r7
Copy link
Contributor

@wchen-r7 wchen-r7 commented Aug 7, 2012

This uses a default MySQL admin credential to write a php file to the web directory, extracts our malicious executable, and then finally execute it. We get SYSTEM. I decided to put this under the 'mysql' directory, because we're actually exploiting a MySQL config problem.

This uses a default MySQL admin credential to write a php file to
the web directory, extracts our malicious executable, and then
finally execute it. We get SYSTEM.
@wchen-r7 wchen-r7 merged commit 5f4297a into rapid7:master Aug 7, 2012
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants