local
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Easy File Sharing Web Server 7.2 – ‘New User’ Local Overflow (SEH)
#!/usr/bin/python
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
Exploit Title: SockPuppet 3
Microsoft Windows 10 – ‘WSReset’ UAC Protection Bypass (propsys.dll)
// ref : https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e
macOS 18.7.0 Kernel – Local Privilege Escalation
# macOS-Kernel-Exploit
docPrint Pro 8.0 – SEH Buffer Overflow
import struct
AppXSvc – Privilege Escalation
#-----------------------------------------------------------------------------#
Microsoft Windows NTFS – Privileged File Access Enumeration
[+] Credits: John Page (aka hyp3rlinx)
Microsoft Windows – ‘WSReset’ UAC Protection Bypass (Registry)
#### Fileless UAC bypass (WSReset.exe)
Kaseya VSA agent 9.5 – Privilege Escalation
# Exploit Title: Kaseya VSA agent
ChaosPro 3.1 – SEH Buffer Overflow
#!C:\Python27\python.exe
ChaosPro 2.1 – SEH Buffer Overflow
#!C:\Python27\python.exe
ChaosPro 2.0 – SEH Buffer Overflow
#!C:\Python27\python.exe
Canon PRINT 2.5.5 – Information Disclosure
# Exploit Title: Content Provider URI Injection on Canon PRINT 2.5.5
Microsoft Windows 10 – SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
Windows: SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
Microsoft Windows Text Services Framework MSCTF – Multiple Vulnerabilities
The msctf subsystem is part of the Text Services Framework, The TSF manages things like input methods, keyboard layou...
Microsoft Windows 10 AppXSvc Deployment Service – Arbitrary File Deletion
# Author : Abdelhamid Naceri
Steam Windows Client – Local Privilege Escalation
$SteamRegKey = "HKLM:\SOFTWARE\WOW6432Node\Valve\Steam\NSIS"
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
// Linux 4.10 < 5.1.17 PTRACE_TRACEME local root (CVE-2019-13272)
Comtrend-AR-5310 – Restricted Shell Escape
# Exploit Title: Comtrend-AR-5310 - Restricted Shell Escape
Docker – Container Escape
# On the host
Microsoft Windows 10 1903/1809 – RPCSS Activation Kernel Security Callback Privilege Escalation
Windows: RPCSS Activation Kernel Security Callback EoP
DameWare Remote Support 12.0.0.509 – ‘Host’ Buffer Overflow (SEH)
#!/usr/bin/env python
R 3.4.4 (Windows 10 x64) – Buffer Overflow SEH (DEP/ASLR Bypass)
#!/usr/bin/python
Streamripper 2.6 – ‘Song Pattern’ Buffer Overflow
#!/usr/bin/python
SNMPc Enterprise Edition 9/10 – Mapping Filename Buffer Overflow
#!/usr/bin/python
Tuneclone 2.20 – Local SEH Buffer Overflow
# Exploit Title: TuneClone Local Seh Exploit
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1)
CVE-2019-12181 Serv-U 15.1.6 Privilege Escalation
Exim 4.87 – 4.91 – Local Privilege Escalation
#!/bin/bash
Aida64 6.00.5100 – ‘Log to CSV File’ Local SEH Buffer Overflow
#!/usr/bin/python
CentOS 7.6 – ‘ptrace_scope’ Privilege Escalation
#!/usr/bin/env bash
ProShow 9.0.3797 – Local Privilege Escalation
#!/usr/bin/python