Skip to content

Latest commit

 

History

History
88 lines (54 loc) · 2.6 KB

SERVICES.md

File metadata and controls

88 lines (54 loc) · 2.6 KB

OS

Attacker

Linux

Windows

Services and Exploits

mysql

  • OS: any
  • Port: 3306
  • CVE: -
  • Service name in NASimEmu: 3306_any_mysql

This service is not exploitable. In the default scenarios, it is used as a sensitive_service, which is installed on all sensitive nodes (and on 10% of non-sensitive nodes).

proftpd

  • OS: Linux
  • Port: 21
  • CVE: CVE-2015-3306
  • Service name in NASimEmu: 21_linux_proftpd

More information about the exploit.

drupal

  • Os: Linux
  • Port: 80
  • Path: /drupal/
  • Service name in NASimEmu: 80_linux_drupal

More information about the vulnerability.

More information about the exploit.

Elasticsearch

The exploit use a security issue in the ElasticSearch prior to version 1.2.0.

  • OS: Windows
  • Port: 9200
  • CVE: CVE-2014-3120
  • Service name in NASimEmu: 9200_windows_elasticsearch

The vulnerability is available in the Windows metasploitable VM : for more information here.

More information about the exploit.

Wordpress

The exploit use a security issue in the Ninja Forms plugin (before version 2.9.42.1).

  • OS: Windows
  • Port: 80
  • Path: /wordpress/
  • CVE: CVE-2016-1209
  • Service name in NASimEmu: 80_windows_wp_ninja

The vulnerability is available in the Windows metasploitable VM : for more information here.

More information about the exploit.

phpwiki

  • OS: Linux
  • Port: 80
  • Path: /phpwiki/
  • CVE: CVE-2014-5519
  • Service name in NASimEmu: 80_linux_phpwiki

More information about the exploit.