
मिसिंग KB की गणना करें और उपयोगी विशेषाधिकार वृद्धि कमजोरियों के लिए शोषण सुझाएँ
Watson एक .NET टूल है जो गुम KBs को गिनने और विशेषाधिकार वृद्धि कमजोरियों के लिए एक्सप्लॉइट सुझाने के लिए डिज़ाइन किया गया है।
C:\> Watson.exe
__ __ _
/ / /\ \ \__ _| |_ ___ ___ _ __
\ \/ \/ / _` | __/ __|/ _ \| '_ \
\ /\ / (_| | |_\__ \ (_) | | | |
\/ \/ \__,_|\__|___/\___/|_| |_|
v2.0
@_RastaMouse
[*] OS Build Number: 14393
[*] Enumerating installed KBs...
[!] CVE-2019-0836 : VULNERABLE
[>] https://exploit-db.com/exploits/46718
[>] https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/
[!] CVE-2019-0841 : VULNERABLE
[>] https://github.com/rogue-kdc/CVE-2019-0841
[>] https://rastamouse.me/tags/cve-2019-0841/
[!] CVE-2019-1064 : VULNERABLE
[>] https://www.rythmstick.net/posts/cve-2019-1064/
[!] CVE-2019-1130 : VULNERABLE
[>] https://github.com/S3cur3Th1sSh1t/SharpByeBear
[!] CVE-2019-1253 : VULNERABLE
[>] https://github.com/padovah4ck/CVE-2019-1253
[!] CVE-2019-1315 : VULNERABLE
[>] https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html
[*] Finished. Found 6 potential vulnerabilities.
मैं प्रत्येक पैच मंगलवार के बाद Watson को अपडेट करने की कोशिश करता हूं, लेकिन संभावित गलत सकारात्मकता के लिए Windows Update Catalog में नवीनतम प्रतिस्थापन जानकारी की जांच करें। यदि आपको अभी भी लगता है कि कोई त्रुटि है, तो Bug लेबल के साथ एक Issue खोलें।
यदि कोई विशेष कमजोरी है जिसे आप Watson में देखना चाहते हैं जो पहले से शामिल नहीं है, तो Vulnerability Request लेबल के साथ एक Issue खोलें और CVE नंबर शामिल करें।
यदि आप Watson में किसी भी कमजोरी के लिए एक अच्छा एक्सप्लॉइट जानते हैं, तो Exploit Suggestion लेबल के साथ एक Issue खोलें और एक्सप्लॉइट का URL प्रदान करें।