module

Plixer Scrutinizer NetFlow and sFlow Analyzer HTTP Authentication Bypass

Disclosed
2012-07-27
Created
2018-05-30

Description

This will add an administrative account to Scrutinizer NetFlow and sFlow Analyzer
without any authentication. Versions such as 9.0.1 or older are affected.

Authors

MC [email protected]
Jonathan Claudius
Tanya Secker
sinn3r [email protected]

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/http/scrutinizer_add_user
msf auxiliary(scrutinizer_add_user) > show actions
...actions...
msf auxiliary(scrutinizer_add_user) > set ACTION < action-name >
msf auxiliary(scrutinizer_add_user) > show options
...show and set options...
msf auxiliary(scrutinizer_add_user) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.