
CVE-2022-35513 | blink1-pass-decrypt
نص برمجي صغير (poc) مصمم لفك تشفير النص المشفر الموجود في /blink/input
لخادم api في تثبيتات blink1control2 (الإصدارات <=2.2.7).
يستخدم تطبيق blink1control2 تشفيرًا ضعيفًا لكلمات المرور وطريقة تخزين غير آمنة يمكن العثور عليها عبر الوصول إلى عنوان /blink1/input
لخادم api.
يتم عرض النص المشفر لكلمات مرور عمليات تسجيل الدخول إلى skype والبريد الإلكتروني ويمكن فك تشفيره.
sudo apt install npm
npm install argparse
npm install simplecrypt
استخدم ./blink1-pass-decrypt أو node blink1-pass-decrypt مع -h أو --help لعرض قائمة المساعدة:
usage: blink-pass-decrypt [-h] ciphertext
decrypts passwords found at the /blink/input url of the blink1control2 api
server (version <= 2.2.7 ).
positional arguments:
ciphertext encrypted password string to use
optional arguments:
-h, --help show this help message and exit
مثال:
node blink1-pass-decrypt '69827e0ecea378946e999df4313cb9a1e49c049a7b9bac8bf1105cdec9f221c8'