Alphonse | Android application through an open FTP | xss | Proxy XSS | mygg.js | session writting|
Автор: Hack by Knowledge
Загружено: 2025-12-31
Просмотров: 12
Alphonse is a workstation used for local development and unfortunately he was sharing an Android application through an open FTP server. By reverse engineering this, we learned about an API that was vulnerable to blind XSS, triggered by a visitor on an admin panel. Since the session cookies were protected, we used a tool to ride the authenticated user’s session and proxying our attacking web browser through the victim’s web browser. From here we learned about another API that communicated with a binary on the OS, which was vulnerable to OS command injection. The final step was to abuse another binary to achieve root privileges.
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: