
Identifica instancias vulnerables (RCE) de vBulletin 5.0.0 - 5.5.4 mediante Shodan (CVE-2019-16759)
Identifica instancias vulnerables (RCE) de vBulletin 5.0.0 - 5.5.4 usando Shodan (CVE-2019-16759)
Bulletin
Demo
Esta herramienta itera de forma asíncrona sobre los hosts de vBulletin en los puertos 443 y 80 y ejecuta un PoC para comprobar si son vulnerables a CVE-2019-16759. Puedes usar Shodan para recopilar objetivos potenciales:
shodan download vbullet-443 'html:"vbulletin" port:443'
shodan parse vbullet-443.json.gz --fields ip_str > vbullet-443
shodan download vbullet-80 'html:"vbulletin" port:80'
shodan parse vbullet-80.json.gz --fields ip_str > vbullet-80
Gracias al usuario anónimo que publicó este 0day en https://seclists.org/fulldisclosure/2019/Sep/31
No soy responsable de lo que hagas con esta herramienta, esto es simplemente con fines de investigación.