Premium Only Content

CVE-2022-4510: Directory Traversal RCE in binwalk
A path traversal vulnerability (CVE-2022-4510) was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 (inclusive). This vulnerability allows remote attackers to execute arbitrary code on affected installations of binwalk. User interaction is required to exploit this vulnerability in that the target must open the malicious file with binwalk using extract mode (-e option). The issue lies within the PFS (obscure filesystem format found in some embedded devices) extractor plugin that was merged into binwalk in 2017. Write-ups/tutorials aimed at beginners - Hope you enjoy 🙂 #Vulnerability #CVE-2022-4510 #Pentesting #OffSec
↢Social Media↣
Twitter: https://twitter.com/_CryptoCat
GitHub: https://github.com/Crypto-Cat
HackTheBox: https://app.hackthebox.eu/profile/11897
LinkedIn: https://www.linkedin.com/in/cryptocat
Reddit: https://www.reddit.com/user/_CryptoCat23
YouTube: https://www.youtube.com/CryptoCat23
Twitch: https://www.twitch.tv/cryptocat23
↢Video-Specific Resources↣
https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk
https://lekensteyn.nl/files/pfs/pfs.txt
https://github.com/ReFirmLabs/binwalk/pull/617
↢Resources↣
Ghidra: https://ghidra-sre.org/CheatSheet.html
Volatility: https://github.com/volatilityfoundation/volatility/wiki/Linux
PwnTools: https://github.com/Gallopsled/pwntools-tutorial
CyberChef: https://gchq.github.io/CyberChef
DCode: https://www.dcode.fr/en
HackTricks: https://book.hacktricks.xyz/pentesting-methodology
CTF Tools: https://github.com/apsdehal/awesome-ctf
Forensics: https://cugu.github.io/awesome-forensics
Decompile Code: https://www.decompiler.com
Run Code: https://tio.run
↢Chapters↣
Start: 0:00
Overview: 0:41
PFS (pfstool): 1:50
Vulnerability Breakdown: 2:46
Exploitation Details: 4:20
Proof of Concept (PoC): 6:56
CTF Use Cases: 11:29
End: 12:10
-
2:28:37
putther
3 hours ago $1.84 earned⭐ Bounty Hunting on GTA⭐
20.8K1 -
LIVE
Total Horse Channel
1 day agoAMHA 2025 9/20
535 watching -
1:53:15
I_Came_With_Fire_Podcast
15 hours agoThe Satanic Cults Convincing Kids to Commit Violence
52.5K19 -
1:02:13
X22 Report
8 hours agoMr & Mrs X - [DS] Created Antifa To Push An Insurgency In This Country - Ep 8
160K56 -
1:13:24
Wendy Bell Radio
12 hours agoPet Talk With The Pet Doc
58.2K44 -
1:19:30
Game On!
1 day ago $12.50 earnedCollege Football Week 4 Betting Preview!
168K5 -
26:04
Artur Stone Garage
4 days ago $3.20 earned$500 Civic: Will It EVER Drive Without Breaking Down?
47.8K17 -
31:44
SouthernbelleReacts
2 days ago $4.58 earned“E.T. Phone Home! 🛸 Emotional Mom Style Reaction to E.T. the Extra-Terrestrial (1982)”
59.6K6 -
20:10
JohnXSantos
1 day ago $2.17 earnedI Built a FAKE Luxury Brand With $100 In 7 Days
44.8K4 -
25:24
marcushouse
9 hours ago $3.48 earnedStarship Test Trouble… and Block 3 Finally Unveiled! 🤯
44K10