Subscribe via feed.

Mercurial Custom hg-ssh Wrapper Remote Code Execution

Posted by deepcore on April 27, 2017 – 7:49 am

This Metasploit module takes advantage of custom hg-ssh wrapper implementations that don’t adequately validate parameters passed to the hg binary, allowing users to trigger a Python Debugger session, which allows arbitrary Python code execution.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.