Sunday, January 28, 2024

Critical Bug Found In WordPress Plugin For Elementor With Over A Million Installations

 


A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites.

The plugin in question is Essential Addons for Elementor, which provides WordPress site owners with a library of over 80 elements and extensions to help design and customize pages and posts.

"This vulnerability allows any user, regardless of their authentication or authorization status, to perform a local file inclusion attack," Patchstack said in a report. "This attack can be used to include local files on the filesystem of the website, such as /etc/passwd. This can also be used to perform RCE by including a file with malicious PHP code that normally cannot be executed."

That said, the vulnerability only exists if widgets like dynamic gallery and product gallery are used, which utilize the vulnerable function, resulting in local file inclusion – an attack technique in which a web application is tricked into exposing or running arbitrary files on the webserver.

The flaw impacts all versions of the addon from 5.0.4 and below, and credited with discovering the vulnerability is researcher Wai Yan Myo Thet. Following responsible disclosure, the security hole was finally plugged in version 5.0.5 released on January 28 "after several insufficient patches."

The development comes weeks after it emerged that unidentified actors tampered with dozens of WordPress themes and plugins hosted on a developer's website to inject a backdoor with the goal of infecting further sites.

Related news
  1. Hack Tools For Mac
  2. Black Hat Hacker Tools
  3. Tools Used For Hacking
  4. Hacker Security Tools
  5. Hack Tools Pc
  6. Pentest Tools Bluekeep
  7. Hack App
  8. Pentest Tools Apk
  9. Pentest Tools Subdomain
  10. Nsa Hack Tools Download
  11. Hacker Tools For Mac
  12. Wifi Hacker Tools For Windows
  13. Best Hacking Tools 2019
  14. Hacking Tools Windows
  15. Hacking Tools Name
  16. Pentest Tools Apk
  17. Pentest Tools Tcp Port Scanner
  18. Hacking Tools Windows 10
  19. How To Install Pentest Tools In Ubuntu
  20. Top Pentest Tools
  21. How To Hack
  22. Hack Tools Download
  23. Pentest Tools Online
  24. Hack Tools Mac
  25. Wifi Hacker Tools For Windows
  26. Hacking Tools And Software
  27. Hacker Tool Kit
  28. Kik Hack Tools
  29. Hacking Tools Pc
  30. Hacking App
  31. Nsa Hack Tools
  32. Pentest Tools Url Fuzzer
  33. Hacker Tools Online
  34. Pentest Tools Url Fuzzer
  35. Pentest Automation Tools
  36. Pentest Tools Github
  37. Hacker Tools Apk Download
  38. Hacking Tools Windows
  39. Hacking Tools For Windows 7
  40. Hacking Tools And Software
  41. How To Hack
  42. Hacking Tools Github
  43. Hacking Tools Free Download
  44. Hacker Tools 2019
  45. Physical Pentest Tools
  46. Best Hacking Tools 2020
  47. Bluetooth Hacking Tools Kali
  48. Pentest Tools Linux
  49. Hacker Tools Linux
  50. Android Hack Tools Github
  51. Hacking Tools For Pc
  52. Hacker Tools
  53. World No 1 Hacker Software
  54. Hacker Tools Free
  55. Hack Tools For Ubuntu
  56. What Is Hacking Tools
  57. Pentest Tools For Windows
  58. Ethical Hacker Tools
  59. Hackers Toolbox
  60. Hack Tools For Windows
  61. Hacker Tools For Pc
  62. Hacker Tools Free Download
  63. Hack Tools For Mac
  64. New Hacker Tools
  65. Hacker Techniques Tools And Incident Handling
  66. Pentest Tools
  67. Pentest Tools Nmap
  68. Hack Tools Github
  69. Computer Hacker
  70. Hack And Tools
  71. Hacking Tools Pc
  72. What Is Hacking Tools
  73. Wifi Hacker Tools For Windows
  74. Hacks And Tools
  75. Hackrf Tools
  76. Hack App
  77. Pentest Tools Subdomain
  78. Hacker Tools Software
  79. What Are Hacking Tools
  80. Hacking Tools
  81. Pentest Tools For Mac
  82. Hacking Tools For Mac
  83. Hacker Tools Linux
  84. Hacking Tools For Windows Free Download
  85. Pentest Tools Bluekeep
  86. Pentest Tools Nmap
  87. Hacker Tools 2019
  88. What Is Hacking Tools
  89. Hacker Tools Free
  90. Hacker Tools 2019
  91. Pentest Tools Find Subdomains
  92. Pentest Tools Windows
  93. Pentest Tools Nmap
  94. Growth Hacker Tools
  95. Nsa Hacker Tools
  96. Pentest Tools Kali Linux
  97. Hacker Tools Software
  98. What Are Hacking Tools
  99. Best Hacking Tools 2020
  100. Hack Tools Github
  101. Github Hacking Tools
  102. Pentest Tools Nmap
  103. Pentest Recon Tools
  104. Hack Tools
  105. Hack Website Online Tool
  106. Pentest Tools Github
  107. Hacking Tools Kit
  108. Wifi Hacker Tools For Windows
  109. New Hack Tools
  110. New Hacker Tools
  111. How To Install Pentest Tools In Ubuntu
  112. Pentest Tools Url Fuzzer
  113. Hacker
  114. Pentest Tools Nmap
  115. Hack Tool Apk
  116. Physical Pentest Tools
  117. Hack Tools
  118. Hacker Security Tools
  119. Pentest Tools
  120. Hacking Tools For Kali Linux
  121. Computer Hacker
  122. Pentest Tools Website
  123. Hacker Tools Github
  124. Pentest Tools Windows
  125. Pentest Recon Tools
  126. Pentest Tools Website
  127. Nsa Hacker Tools
  128. Hacker Hardware Tools
  129. Github Hacking Tools
  130. Best Hacking Tools 2020
  131. Hack Tools For Pc
  132. Hack Apps
  133. Pentest Tools Website
  134. Hacking Tools 2020
  135. Hacker Tools 2019

Evolving Logic Until Pass Tests Automatically

Automating the automation is still a challenge, but in some cases it's possible under certain situations.

In 2017 I created logic-evolver, one of my experiments for creating logic automatically or better said evolving logic automatically.

In some way, the computer create its own program that satisfies a set of tests defined by a human.

https://github.com/sha0coder/logic-evolver

This implementation in rust, contains a fast cpu emulator than can execute one million instructions in less than two seconds. And a simple genetic algorithm to do the evolution.


Here we create the genetic algorithm, and configure a population of 1000 individuals, and the top 5 to crossover. We run the genetic algorithm with 500 cycles maximum.
Note that in this case the population are programs initially random until take the correct shape.


An evaluation function is provided in the run method as well, and looks like this:




The evaluation function receives a CPU object, to compute a test you need to set the initial parameters, run the program and set a scoring regarding the return value.


More information
  1. Blackhat Hacker Tools
  2. Computer Hacker
  3. Pentest Tools Subdomain
  4. Hacking Tools For Beginners
  5. Pentest Tools Online
  6. Hack Tool Apk
  7. Growth Hacker Tools
  8. Hacking Tools Github
  9. World No 1 Hacker Software
  10. Hacker Tools Hardware
  11. Hacking Tools For Pc
  12. Pentest Tools Open Source
  13. Pentest Tools Free
  14. Hacker Tools Apk
  15. Hacker Hardware Tools
  16. Hack Tools Pc
  17. Pentest Tools Nmap
  18. Hacking Tools For Beginners
  19. Blackhat Hacker Tools
  20. What Is Hacking Tools
  21. What Is Hacking Tools
  22. Hacker Tools Apk Download
  23. Hacker Tools
  24. Kik Hack Tools
  25. Hacking Tools For Pc
  26. Hacking Tools Windows 10
  27. Hacking Tools For Games
  28. Hack Tools 2019
  29. Hacking Tools 2019
  30. Bluetooth Hacking Tools Kali
  31. Hacking Tools 2019
  32. Pentest Tools Kali Linux
  33. Hacking Tools For Beginners
  34. Pentest Automation Tools
  35. Growth Hacker Tools
  36. Hacker Tools For Pc
  37. Hack Tools
  38. Hacker Hardware Tools
  39. Hack Tools For Mac
  40. Hack Tools For Pc
  41. Best Hacking Tools 2020
  42. Hacking Tools Download
  43. Hacking Tools For Mac
  44. Pentest Tools Open Source
  45. Pentest Tools Github
  46. Hacking Tools Windows
  47. Nsa Hack Tools
  48. Android Hack Tools Github
  49. Hacker Tools For Windows
  50. Hack And Tools
  51. Best Hacking Tools 2020
  52. Physical Pentest Tools
  53. Hacking Tools Kit
  54. Pentest Tools Framework
  55. Hacker Tools 2019
  56. Hacker Tools Online
  57. Pentest Tools For Ubuntu
  58. Android Hack Tools Github
  59. Pentest Tools Download
  60. Game Hacking
  61. Hack Tools
  62. Hacker Tools Linux
  63. What Is Hacking Tools
  64. Blackhat Hacker Tools
  65. Pentest Tools
  66. Pentest Tools Online
  67. Hack Tools Mac
  68. Pentest Tools Download
  69. Hacking Tools And Software
  70. New Hack Tools
  71. Hacker Techniques Tools And Incident Handling
  72. Hacking Tools
  73. Hackers Toolbox
  74. Pentest Tools Review
  75. Tools 4 Hack
  76. Pentest Reporting Tools
  77. Hacker Tools For Ios
  78. Hackrf Tools
  79. Hacking Tools Free Download
  80. Hack Tools For Ubuntu
  81. Hacker Tools Linux
  82. Hacks And Tools
  83. Hacking Tools Windows
  84. Hack Tools For Games
  85. Hacking Tools For Mac
  86. Hacking Tools Online
  87. Free Pentest Tools For Windows
  88. Hacker Tools Linux
  89. Hack Tool Apk No Root
  90. Underground Hacker Sites
  91. Pentest Tools Windows
  92. Hacking Tools For Pc
  93. Hack Tools Download
  94. Hack Apps
  95. What Are Hacking Tools
  96. Tools For Hacker
  97. Bluetooth Hacking Tools Kali
  98. Hack Tools
  99. Pentest Tools Bluekeep
  100. Wifi Hacker Tools For Windows
  101. Hacker Tools Software
  102. Best Hacking Tools 2020
  103. Pentest Tools Review
  104. Hacking Tools For Mac
  105. Pentest Tools Online
  106. Pentest Tools Linux
  107. Hack Tools Mac
  108. Pentest Tools Port Scanner
  109. Hack Tools For Mac
  110. World No 1 Hacker Software
  111. Termux Hacking Tools 2019
  112. Hack And Tools
  113. Hacking Tools For Windows
  114. How To Make Hacking Tools
  115. Hacking Tools For Beginners
  116. Hacking Tools For Beginners
  117. Hacking Tools For Pc
  118. Bluetooth Hacking Tools Kali
  119. Hacking Tools Hardware

ChopChop - ChopChop Is A CLI To Help Developers Scanning Endpoints And Identifying Exposition Of Sensitive Services/Files/Folders


ChopChop is a command-line tool for dynamic application security testing on web applications, initially written by the Michelin CERT.

Its goal is to scan several endpoints and identify exposition of services/files/folders through the webroot. Checks/Signatures are declared in a config file (by default: chopchop.yml), fully configurable, and especially by developers.



"Chop chop" is a phrase rooted in Cantonese. "Chop chop" means "hurry" and suggests that something should be done now and without delay.


Building

We tried to make the build process painless and hopefully, it should be as easy as:

$ go mod download
$ go build .

There should be a resulting gochopchop binary in the folder.


Using Docker

Thanks to Github Container Registry, we are able to provide you some freshly-build Docker images!

docker run ghcr.io/michelin/gochopchop scan https://foobar.com -v debug

But if you prefer, you can also build it locally, see below:


Build locally
docker build -t gochopchop .

Usage

We are continuously trying to make goChopChop as easy as possible. Scanning a host with this utility is as simple as :

$ ./gochopchop scan https://foobar.com

Using Docker
docker run gochopchop scan https://foobar.com

Custom configuration file
docker run -v ./:/app chopchop scan -c /app/chopchop.yml https://foobar.com

What's next

The Golang rewrite took place a couple of months ago but there's so much to do, still. Here are some features we are planning to integrate : [x] Threading for better performance [x] Ability to specify the number of concurrent threads [x] Colors and better formatting [x] Ability to filter checks/signatures to search for [x] Mock and unit tests [x] Github CI And much more!


Testing

To quickly end-to-end test chopchop, we provided a web-server in tests/server.go. To try it, please run go run tests/server.go then run chopchop with the following command ./gochopchop scan http://localhost:8000 --verbosity Debug. ChopChop should print "no vulnerabilities found".

There are also unit test that you can launch with go test -v ./.... These tests are integrated in the github CI workflow.


Available flags

You can find the available flags available for the scan command :

Flag Full flag Description
-h --help Help wizard
-v --verbosity Verbose level of logging
-c --signature Path of custom signature file
-k --insecure Disable SSL Verification
-u --url-file Path to a specified file containing urls to test
-b --max-severity Block the CI pipeline if severity is over or equal specified flag
-e --export Export type of the output (csv and/or json)
--export-filename Specify the filename for the export file(s)
-t --timeout Timeout for the HTTP requests
--severity-filter Filter Plugins by severity
--plugin-filter Filter Plugins by name of plugin
--threads Number of concurrent threads

Advanced usage

Here is a list of advanced usage that you might be interested in. Note: Redirectors like > for post processing can be used.

  • Ability to scan and disable SSL verification
$ ./gochopchop scan https://foobar.com --insecure
  • Ability to scan with a custom configuration file (including custom plugins)
$ ./gochopchop scan https://foobar.com --insecure --signature test_config.yml
  • Ability to list all the plugins or by severity : plugins or plugins --severity High
$ ./gochopchop plugins --severity High
  • Ability to specify number of concurrent threads : --threads 4 for 4 workers
$ ./gochopchop plugins --threads 4
  • Ability to block the CI pipeline by severity level (equal or over specified severity) : --max-severity Medium
$ ./gochopchop scan https://foobar.com --max-severity Medium
  • Ability to specify specific signatures to be checked
./gochopchop scan https://foobar.com --timeout 1 --verbosity --export=csv,json --export-filename boo --plugin-filters=Git,Zimbra,Jenkins
  • Ability to list all the plugins
$ ./gochopchop plugins
  • List High severity plugins
$ ./gochopchop plugins --severity High
  • Set a list or URLs located in a file
$ ./gochopchop scan --url-file url_file.txt
  • Export GoChopChop results in CSV and JSON format
$ ./gochopchop scan https://foobar.com  --export=csv,json --export-filename results

Creating a new check

Writing a new check is as simple as :

  - endpoint: "/.git/config"
checks:
- name: Git exposed
match:
- "[branch"
remediation: Do not deploy .git folder on production servers
description: Verifies that the GIT repository is accessible from the site
severity: "High"

An endpoint (eg. /.git/config) is mapped to multiple checks which avoids sending X requests for X checks. Multiple checks can be done through a single HTTP request. Each check needs those fields:

Attribute Type Description Optional ? Example
name string Name of the check No Git exposed
description string A small description for the check No Ensure .git repository is not accessible from the webroot
remediation string Give a remediation for this specific "issue" No Do not deploy .git folder on production servers
severity Enum("High", "Medium", "Low", "Informational") Rate the criticity if it triggers in your environment No High
status_code integer The HTTP status code that should be returned Yes 200
headers List of string List of headers there should be in the HTTP response Yes N/A
no_headers List of string List of headers there should NOT be in the HTTP response Yes N/A
match List of string List the strings there should be in the HTTP response Yes "[branch"
no_match List of string List the strings there should NOT be in the HTTP response Yes N/A
query_string GET parameters that have to be passed to the endpoint String Yes query_string: "id=FOO-chopchoptest"

External Libraries
Library Name Link License
Viper https://github.com/spf13/viper MIT License
Go-pretty https://github.com/jedib0t/go-pretty MIT License
Cobra https://github.com/spf13/cobra Apache License 2.0
strfmt https://github.com/go-openapi/strfmt Apache License 2.0
Go-homedir https://github.com/mitchellh/go-homedir MIT License
pkg-errors https://github.com/pkg/errors BSD 2 (Simplified License)
Go-runewidth https://github.com/mattn/go-runewidth MIT License

Please, refer to the third-party.txt file for further information.


Talks

License

ChopChop has been released under Apache License 2.0. Please, refer to the LICENSE file for further information.


Authors
  • Paul A.
  • David R. (For the Python version)
  • Stanislas M. (For the Golang version)


Related word