Aggregator
Ladon CMS识别 FortiGate Vcenter Zimbra Exchange FireEye
〖EXP〗Ladon漏洞复现 CVE-2023-21839 Weblogic
攻击机:Windows
靶场:vulhub 12.2.1.3环境
0x01 影响版本允许远程用户在未经授权的情况下通过 IIOP
CISA Weighs In on Alleged Oracle Cloud Breach
〖key〗Vmware 17 注册码 许可证 官方免注册下载地址
17.x
JU090-6039P-08409-8J0QH-2YR7F
vmware12及vmware14注册码
vmware12 5A02H-AU243-TZJ4
〖Tech〗Ladon PostShell连接CmdShell
〖教程〗Ladon渗透5个Potato提权
++++++++++++++++++++++++++++++++++++++++++++
Ladon渗透Oracle数据库一键提权 密码爆破
<% Visit %>
========
Ladon渗透SQL Server数据库一键提权 密码爆破
<% Visit %>
========
〖教程〗Ladon Socks代理扫描(附Proxifier V4.11注册码)
=============================================================================================
+++++++++++++++++++++++++++++++++++++++
〖Tech〗Ladon RouterOS/Mikrotik路由器探测
Ladon渗透Mysql数据库一键提权 密码爆破
<% Visit %>
========
Ladon渗透 HTA服务器 访问DOC执行HTA
Ladon for Kali/Ubuntu/Mac/Centos/Router/MIPS/ARM
HTA服务器 一键启动 访问DOC也能执行HTALadon和LadonGO用法一致
LadonExp CVE-2024-45216 漏洞复现批量扫描教程
++++++++++++++++++
Ladon漏洞复现Win11 RCE CVE-2023-38146
<% Visit %>
LadonExp CVE-2024-29973漏洞复现批量扫描教程
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
〖提权〗cve-2023-36802 Win10/11/2019/2022
〖Tech〗CVE-2022-36537 未授权RCE漏洞复现
=============================================================================================
+++++++++++++++++++++++++++++++++++++++
Ladon渗透绕过WAF、EDR、防火墙扫描
=============================================================================================
+++++++++++++++++++++++++++++++++++++++
CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability
Proof-of-concept code has been released after researchers disclosed a maximum severity remote code execution vulnerability in Erlang/OTP SSH. Successful exploitation could allow for complete takeover of affected devices.
BackgroundOn April 16, Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, and Jörg Schwenk of the Ruhr University Bochum in Germany disclosed a critical vulnerability in Erlang/OTP SSH to the OpenWall vulnerability mailing list. Additionally an official advisory was posted to the GitHub project for Erlang/OTP crediting the researchers for their disclosure.
CVE Description CVSSv3 VPR CVE-2025-32433 Erlang/OTP SSH Remote Code Execution Vulnerability 10.0 10*Please note: Tenable’s Vulnerability Priority Rating (VPR) scores are calculated nightly. This blog post was published on April 18 and reflects VPR at that time.
AnalysisCVE-2025-32433 is a remote code execution (RCE) vulnerability affecting the Erlang/OTP SSH server. The vulnerability exists due to a flaw in the SSH protocol message handling which could allow an unauthenticated attacker to execute arbitrary code. According to the advisory, all users running Erlang/OTP SSH servers are impacted and to assume impact if your application utilizes the Erlang/OTP SSH library. This vulnerability received the maximum CVSSv3 score of 10.0 and when the SSH daemon is running as root, allows an attacker to completely compromise an affected device.
At the time this blog was published, no known exploitation has been observed, however with the ease of exploitation and critical severity, we anticipate attacks will occur soon.
Proof of conceptOn April 17, researchers at Platform Security released a public proof-of-concept (PoC) exploit for CVE-2025-32433. The writeup notes that the PoC was generated with the help of ChatGPT and Cursor, and that it was fairly simple to do so using those AI tools.
The PoC initiates an SSH protocol negotiation as a normal client would. But, before authenticating the user, the client sends an unexpected message with an arbitrary command. The vulnerable server will process these messages and execute the commands. A patched server will disconnect immediately upon seeing these messages prior to authentication.
An additional PoC has been released, and the Horizon3 Attack Team posted on X (formerly Twitter) that they had developed a PoC but have chosen not to release it as of writing.
Just finished reproducing CVE-2025-32433 and putting together a quick PoC exploit — surprisingly easy. Wouldn’t be shocked if public PoCs start dropping soon. If you’re tracking this, now’s the time to take action. #Erlang #SSH pic.twitter.com/hBqJMfFHMN
— Horizon3 Attack Team (@Horizon3Attack) April 17, 2025
SolutionErlang/OTP has released patches to address this vulnerability.
Affected Versions Fixed Versions OTP-27.3.2 and below OTP-27.3.3 OTP-26.2.5.10 and below OTP-26.2.5.11 OTP-25.3.2.19 and below OTP-25.3.2.20If immediate patching cannot be performed, restricting access via a firewall or disabling the SSH server are mitigation steps provided by Erlang/OTP. However, we strongly recommend upgrading as soon as possible to fully remediate this vulnerability.
Identifying affected systemsA list of Tenable plugins for this vulnerability can be found on the individual CVE page for CVE-2025-32433 as they’re released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline.
Additionally, customers can utilize Tenable Attack Surface Management to identify hosts running Erlang/OTP SSH Server.
Get more informationJoin Tenable's Security Response Team on the Tenable Community.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
The post CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability appeared first on Security Boulevard.