
استغلال RCE لـ CVE-2018-14772
هذا استغلال PoC لتنفيذ الأوامر عن بُعد (Remote Code Execution) للثغرة CVE-2018-14772، وهي ثغرة اكتشفتها في منصة مشاركة الملفات pydio. يتطلب الاستغلال صلاحيات مسؤول تطبيق pydio لكي يعمل. يمكنك تشغيل الاستغلال على النحو التالي:
$ python exploit.py -h
usage: exploit.py [-h] -t TARGET -u USERNAME -p PASSWORD -L LISTENER_IP -P
LISTENER_PORT [--payload PAYLOAD]
[*] exploit some pydio boxes (academically)
optional arguments:
-h, --help show this help message and exit
--payload PAYLOAD one of the pre-built reverse-shell payloads (1, 2, 3, 4,
or 5), or a custom command. keep in mind you can't use
the (") character as it breaks the injection
required arguments:
-t TARGET this is the target URI for the pydio instance..i.e.
http://127.0.0.1:31337/pydio/
-u USERNAME this is the username of the admin user
-p PASSWORD this is the password of the admin user
-L LISTENER_IP IP address to catch reverse shell on
-P LISTENER_PORT port to catch reverse shell on
لقد أضفتُ بعض حمولات الصدفة العكسية (reverse shell) التي يمكنك تجربتها. بالإضافة إلى ذلك، يمكنك استخدام أوامر مخصصة (ad-hoc). ضع في اعتبارك أن استخدام الحرف " سيكسر حقن الأوامر، لذا عليك التحايل على هذا القيد.

موجود على مدونتي هنا