Hackers Abuse Zero-Day Exploit for CrushFTP

Поділитися
Вставка
  • Опубліковано 7 лис 2024

КОМЕНТАРІ • 78

  • @mu11668B
    @mu11668B 6 місяців тому +47

    I still find it funny that quite often people goes for paid products with fancy presentations and unnecessary black-box automations. We use OpenSSH sftp with Linux access control and rarely do we have to worry about random 10/10 RCEs.

    • @CZghost
      @CZghost 6 місяців тому +9

      That's just Apple's ecosystem. All it is is just a shiny polished shit.

    • @mu11668B
      @mu11668B 6 місяців тому +5

      @@CZghost Microsoft has been doing it for years too.

    • @morgannelson5756
      @morgannelson5756 6 місяців тому

      Familiar with CVE-2024-33663?

    • @biigsmokee
      @biigsmokee 6 місяців тому

      @@CZghost macos has ssh and built-in nfsd

  • @Napert
    @Napert 6 місяців тому +49

    can we like calm the fuck down with all the vulnerabilities this year?

    • @fokyewtoob8835
      @fokyewtoob8835 6 місяців тому +2

      N O

    • @carsonjamesiv2512
      @carsonjamesiv2512 6 місяців тому +1

      🤣😂

    • @BillAnt
      @BillAnt 6 місяців тому +4

      Exploits and vuln are found almost every day. What's different lately, which has nothing to do with April in particular, is that more of them are being published on UA-cam, so it seems like a whole lot of them all of a sudden. More and higher bug-bounties are also a factor. ;)

  • @Palmit_
    @Palmit_ 6 місяців тому +4

    Flare looks very interesting. however, the pricing is elite and well crafted 0-day. I ain't buyin to something even for a trial to find out it's extortionate pricing. the FREE trial is not free. They should be open with their pricing.

  • @TheMAZZTer
    @TheMAZZTer 6 місяців тому +3

    This is nuts. It seems like they don't have a proper security model in place if it's just that easy.
    Also the CrushFTP desktop UI doesn't instill me with confidence lol. At least the web UI looks decent.

  • @HectorDiabolucus
    @HectorDiabolucus 6 місяців тому +54

    Having inside information on this one I can only laugh, and laugh, and laugh. There are more vulnerabilities. You just haven't found them yet. 😂

    • @mangodude-nq6su
      @mangodude-nq6su 6 місяців тому +14

      Classic closed-source tomfoolery

    • @skellybin
      @skellybin 6 місяців тому +2

      Chill, I was expecting you wise ahh comment

    • @HectorDiabolucus
      @HectorDiabolucus 6 місяців тому +2

      @@mangodude-nq6su well having seen that source, trust me, you’re better off.

    • @Daveychief23
      @Daveychief23 6 місяців тому +1

      Sec researcher here - any info you can drop without breaching NDAs?

    • @HectorDiabolucus
      @HectorDiabolucus 6 місяців тому +4

      @@Daveychief23 No NDA but common decency prevents me from trashing a former colleague. Plus I have a competing product that makes his look like a child’s toy.

  • @kettlestew
    @kettlestew 6 місяців тому +7

    Nice "enterprise grade" software you got there.

    • @xenostim
      @xenostim 6 місяців тому

      shodilly reinventing the wheel?

  • @juandig
    @juandig 6 місяців тому +4

    Flare doesn't show their pricing on their website... I hate that

    • @crashtfa
      @crashtfa 6 місяців тому +1

      They charge based on identifiers, we pay for flare and we get 1000 identifiers and pay 36k a year

  • @hgvhjfcjdudrsxhxj
    @hgvhjfcjdudrsxhxj 6 місяців тому

    hey i have a question Jhon, what virtual machine manager u use Vb or vmware?

  • @userou-ig1ze
    @userou-ig1ze 6 місяців тому

    So why would anyone use crushFTP?

  • @trisnguyen4625
    @trisnguyen4625 6 місяців тому

    Thanks for the demonstration. Very helpful !!!

  • @akashaki11
    @akashaki11 6 місяців тому

    Hello @john hammond, recently my Discord was hacked by someone who used it to send phishing links in the NahamSec general discussion group. I’ve resolved the issue, but now I’m unable to rejoin your Discord. Could you please allow me back in?

  • @BurkenProductions
    @BurkenProductions 6 місяців тому

    But no one is using crushftp whats wrong with people

  • @dukeofwelington
    @dukeofwelington 6 місяців тому

    John are you going to be in the people's call center this year?

  • @guilhermeAK9
    @guilhermeAK9 5 місяців тому

    Nice video, thanks for that.
    Allow me to do a question: how can the ssh_host_rsa_key can be useful in some way for hacking once its not related to any user?

  • @pixl_xip
    @pixl_xip 6 місяців тому +27

    *another* vulnerability this april‽‽

    • @realestden
      @realestden 6 місяців тому +5

      i swear theres a vulnerability every day now XD

    • @xCheddarB0b42x
      @xCheddarB0b42x 6 місяців тому +1

      A lot more than one!

  • @RichardinSA
    @RichardinSA 6 місяців тому +6

    Can we all agree that JH is the goat?

  • @CesSanchez
    @CesSanchez 6 місяців тому

    Hi, I don't know how to send this to you, but are you aware of the Sabrent situation? They're apparently hosting malware as legitimate firmware updates in their web. Maybe a video could help people not to fall on this and make the company finally solve the issue. Thanks a lot, and please excuse me if this is not the right way to reach you.

  • @kintag4459
    @kintag4459 6 місяців тому

    Thank you

  • @hamzarashid7579
    @hamzarashid7579 6 місяців тому

    I'm surprised that you didn't talked about Linux XZ malware.

  • @㘭
    @㘭 6 місяців тому

    another zero day.... im not even surprised at this point

  • @nickcarnevalino7462
    @nickcarnevalino7462 6 місяців тому

    cant stand places that have a "start free trial" button with no price given for full ver

  • @harald4game
    @harald4game 6 місяців тому +1

    Die sitzen in ihrer Ideologieblase und sind anderem gegenüber Beratungsresistent.
    Selbst wenn der jemand gefragt hätte aus seiner Umgebung hätte er keine Kritik bekommenm

  • @Rachaelshaw7
    @Rachaelshaw7 6 місяців тому

    Hi! If you can please create a video on the brokewell malware thx 😊

  • @BakersBuilds23
    @BakersBuilds23 6 місяців тому

    Great Vid!

  • @wafinashwan8242
    @wafinashwan8242 6 місяців тому +1

    15 min gang

  • @goodthingforall8973
    @goodthingforall8973 6 місяців тому +1

    April and its vulnerabilities 😂

  • @carsonjamesiv2512
    @carsonjamesiv2512 6 місяців тому

    COOL!

  • @technicalkalilinux
    @technicalkalilinux 6 місяців тому

    make video on CVE-2023-24059 sir if its exploit is free

  • @HwSystems
    @HwSystems 6 місяців тому +3

    I do not understand enterprise using app developed in Java. It is like using an NES emulator to do your presentation.

  • @TituDas-pl2ch
    @TituDas-pl2ch 6 місяців тому

    help me sir

  • @dyna.
    @dyna. 6 місяців тому

    Never heard of this software before... Enterprise ready? The vulnerability info on the download page looks like it's written by a kid and the linux installation instructions are just a joke. Custom start scripts? Then scrolling down i see a systemd service file and at first i thought like oh maybe it's not that bad, but then i look at the actual content and they are not just wrapping their script in a systemd service, no it's wrapped in rc.local and the systemd service is to call rc.local...with a "start" argument that is not used, and without a shebang while it's called directly??? Suprised that even works tbh.
    I was gonna say, what is this 1995? But heck even in 1995 things weren't this amateuristic.

  • @xTwistCinema
    @xTwistCinema 6 місяців тому

    hell yea

  • @dirkthomas1042
    @dirkthomas1042 6 місяців тому

    There is no cloud. It's just someone else's computer.

  • @SuperWabo
    @SuperWabo 6 місяців тому

    08:53

  • @WakiwakiJayson-rw4lc
    @WakiwakiJayson-rw4lc 6 місяців тому

    should i be worried haha i dont even know that software lolz

  • @ExplosiveAnyThing
    @ExplosiveAnyThing 6 місяців тому

    Can somebody explain? I dont really understand how it can read a file outside of the virtual machine?

  • @ArsalanRamazan-zx1ux
    @ArsalanRamazan-zx1ux 6 місяців тому

    ‏‪4:56‬‏

  • @LazyPlays_
    @LazyPlays_ 6 місяців тому +1

    am i dumb or did you just not realize that u were able to pretty much do %hostname% which is effectively a command execution? lol

    • @_JohnHammond
      @_JohnHammond  6 місяців тому +3

      %hostname% isn't getting passed to cmd.exe as if it were an environment variable, it is being specifically handled within the application with their custom processing-- so per your question, no, it isn't command execution, and you are dumb. (You said it, not me)

  • @psyonix_2829
    @psyonix_2829 6 місяців тому

    27th

  • @itsnee
    @itsnee 6 місяців тому +1

    abit too early i guess lmao

  • @fimdy6530
    @fimdy6530 6 місяців тому +1

    i just pissed on my wall

    • @Olflix
      @Olflix 6 місяців тому

      good for you

  • @estersone
    @estersone 6 місяців тому

    Most liked comment 👍

  • @davidlu1003
    @davidlu1003 6 місяців тому

    😁😁😁

  • @sunilgaikwad6335
    @sunilgaikwad6335 6 місяців тому

    Sir please next video social media authentication bypass make this video please 🥲😭

  • @ishanpatel597
    @ishanpatel597 6 місяців тому

    😁😁🙌🙌

  • @gojo99998
    @gojo99998 6 місяців тому

    First !❤

  • @xCheddarB0b42x
    @xCheddarB0b42x 6 місяців тому

    PRO-see-yohn
    Thanks for the info dude!