Bash implementation of CVE-2014-5284# CVE-2014-5284
Bash implementation of CVE-2014-5284
Exploit Title: ossec 2.8 Insecure Temporary File Creation Vulnerability Privilege Escalation</br>
Python is nice but doesn't work all the time</br>
Exploit Author: mbadanoiu</br>
</br>
Python Exploit Author: skynet-13</br>
Vendor Homepage: www.ossec.net/</br>
Software Link: https://github.com/ossec/ossec-hids/archive/2.8.1.tar.gz</br>
Version: OSSEC - 2.8</br>
</br>
Created from Research by</br>
Jeff Petersen</br>
Roka Security LLC</br>
jpetersen@rokasecurity.com</br>
Original info at https://github.com/ossec/ossec-hids/releases/tag/2.8.1</br>
</br>
Kudos To: Radu Voicilas (rvoicilas) for the inotify-tools</br>
https://github.com/rvoicilas/inotify-tools
[4.0K] /data/pocs/e671b6c4149bcf7effe1fc3db28a2e0ac266cb6f
├── [2.4K] CVE-2014-5284.sh
├── [4.0K] inotify-tools
├── [3.0K] ossec_host_deny.py
└── [ 717] README.md
1 directory, 3 files