Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-39197 PoC — HelpSystems Cobalt Strike 跨站脚本漏洞

Source
Associated Vulnerability
Title: HelpSystems Cobalt Strike 跨站脚本漏洞 (CVE-2022-39197)
Description:An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
Description
cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
Readme
# about_cobaltstrike4.5_cdf
cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等

如果您在寻找这个项目:cobaltstrike4.5_cdf
是的它又被封了:`Repository unavailable due to DMCA takedown.`

如果您对原文中的不涉及软件版权的去除checksum8特征、bypass BeaconEye、错误路径泄漏stage、totp双因子认证的思路和方法感兴趣,相信你可以在Internet中搜索到相关文章。

曾经发布过的hash如下,谨防有人篡改加料:
```
d0388ce3b646d5d3ab6d41261848a26af248c8345e0bab5475cedfd9e82328b5  cs.jar

eeba31fac820508a9fe5a733a617e5d6  cobaltstrike4.5_cdf.zip
2aba5e2942799f606c144699ff5ef120  cobaltstrike4.5_cdf_without_totp.zip

4509eea090a7403e2ea646adf3c3117e  cobaltstrike4.5_cdf.zip
977967c7a32f28222e1f9f2164e8002e  cobaltstrike4.5_cdf_without_totp.zip

9454823009d3e41d88cd5bff5e0bc9b9  cobaltstrike4.5_cdf.zip
4e9dc80430438387a8ec63487bc478a5  cobaltstrike4.5_cdf_without_totp.zip
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →