Skip to content

ohader/typo3v9-hack

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

30 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

TYPO3 v9 Hacking

This project is using TYPO3 v9.5.8 with a couple of unfixed/reverted security fixes. It is supposed to be insecure and serves as foundation for showing potential attack vectors against TYPO3.

H4CK5

Video

The mentioned hacks were demonstrated during TYPO3camp Mitteldeutschland, Dresden, DE in January 2019 - spoken language is unfortunately German, Slides are in English.

https://www.youtube.com/watch?v=lefgKJSWqx0&feature=youtu.be&t=10800

Installation

TYPO3 Backend Accounts

  • admin/password
  • user/password

Browser Exploitation Framework (BeEF)

Hook to be used as XSS attack vector (to be injected in target application):

http://typo3v9-hack.ddev.site:3000/hook.js

Admin and Control interface:

http://typo3v9-hack.ddev.site:3000/ui/panel

  • username: admin
  • password: joh316

Links

Security Contact

In case of finding additional security issues in the TYPO3 project please get in touch with the TYPO3 Security Team at [email protected]. Please do not disclose issues in the public without according coordination.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published