exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

Files from Brandon McCann

Email addressbmccann at accuvant.com
First Active2013-02-18
Last Active2024-09-01
Wordpress Pingback Locator
Posted Sep 1, 2024
Authored by Brandon McCann, Thomas McCarthy, Christian Mehlmauer | Site metasploit.com

This Metasploit module will scan for wordpress sites with the Pingback API enabled. By interfacing with the API an attacker can cause the wordpress site to port scan an external target and return results. Refer to the wordpress_pingback_portscanner module. This issue was fixed in wordpress 3.5.1.

tags | exploit
advisories | CVE-2013-0235
SHA-256 | 65cbac95feefbe173371074c6a38d799642d743e4d6bf6a043123171794c676b
Drupal Views Module Users Enumeration
Posted Sep 1, 2024
Authored by Brandon McCann, Justin Klein Keane, Robin Francois | Site metasploit.com

This Metasploit module exploits an information disclosure vulnerability in the Views module of Drupal, brute-forcing the first 10 usernames from a to z. Drupal 6 with Views module less than or equal to 6.x-2.11 are vulnerable. Drupal does not consider disclosure of usernames as a weakness.

tags | exploit, info disclosure
SHA-256 | 03ba69cb09e97d79a5017073561678cbbb9c205b5d53faacede76e154667dd3a
Titan FTP XCRC Directory Traversal Information Disclosure
Posted Sep 1, 2024
Authored by jduck, Brandon McCann | Site metasploit.com

This Metasploit module exploits a directory traversal vulnerability in the XCRC command implemented in versions of Titan FTP up to and including 8.10.1125. By making sending multiple XCRC command, it is possible to disclose the contents of any file on the drive with a simple CRC "brute force" attack. Although the daemon runs with SYSTEM privileges, access is limited to files that reside on the same drive as the FTP servers root directory.

tags | exploit, root
advisories | CVE-2010-2426
SHA-256 | ed7575b07995a5b8577846eccae5dd4535f4645203b1365a49593336a9c3e5ff
MS12-020 Microsoft Remote Desktop Checker
Posted Aug 31, 2024
Authored by Brandon McCann, Royce Davis R3dy | Site metasploit.com

This Metasploit module checks a range of hosts for the MS12-020 vulnerability. This does not cause a DoS on the target.

tags | exploit
advisories | CVE-2012-0002
SHA-256 | 8af29fc18715a26cabbd8050a6eb7d7d09d6e5b2f6a5c4dbb175fc6d6bd10023
Windows Manage User Level Persistent Payload Installer
Posted Feb 18, 2013
Authored by Brandon McCann, Thomas McCarthy | Site metasploit.com

This Metasploit module creates a scheduled task that will run using service-for-user (S4U). This allows the scheduled task to run even as an unprivileged user that is not logged into the device. This will result in lower security context, allowing access to local resources only. The module requires 'Logon as a batch job' permissions (SeBatchLogonRight).

tags | exploit, local
SHA-256 | cbb54215cefd21bbad843bf7ad1489f0dbdc50063f7fe9bb3f39430b2a7f556d
Page 1 of 1
Back1Next

File Archive:

October 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Oct 1st
    39 Files
  • 2
    Oct 2nd
    23 Files
  • 3
    Oct 3rd
    18 Files
  • 4
    Oct 4th
    0 Files
  • 5
    Oct 5th
    0 Files
  • 6
    Oct 6th
    0 Files
  • 7
    Oct 7th
    0 Files
  • 8
    Oct 8th
    0 Files
  • 9
    Oct 9th
    0 Files
  • 10
    Oct 10th
    0 Files
  • 11
    Oct 11th
    0 Files
  • 12
    Oct 12th
    0 Files
  • 13
    Oct 13th
    0 Files
  • 14
    Oct 14th
    0 Files
  • 15
    Oct 15th
    0 Files
  • 16
    Oct 16th
    0 Files
  • 17
    Oct 17th
    0 Files
  • 18
    Oct 18th
    0 Files
  • 19
    Oct 19th
    0 Files
  • 20
    Oct 20th
    0 Files
  • 21
    Oct 21st
    0 Files
  • 22
    Oct 22nd
    0 Files
  • 23
    Oct 23rd
    0 Files
  • 24
    Oct 24th
    0 Files
  • 25
    Oct 25th
    0 Files
  • 26
    Oct 26th
    0 Files
  • 27
    Oct 27th
    0 Files
  • 28
    Oct 28th
    0 Files
  • 29
    Oct 29th
    0 Files
  • 30
    Oct 30th
    0 Files
  • 31
    Oct 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close