
OpenPLC 3 WebServer Ejecución Remota de Código Autenticada.
Ejecución remota de código autenticada en el servidor web de OpenPLC 3.
La presencia de inyección de comandos en el servidor web de OpenPLC v3 permite a atacantes remotos ejecutar código arbitrario explotando el componente "Hardware Layer Code Box" que se encuentra en la página "/hardware" de la aplicación. Solo probado en la máquina Wifinetictwo.htb de hackthebox.
usage: openplc_exploit.py [-h] [--usage] --ip ADDR --port PORT --target URL -U USER -P PASSWORD
[--payload-program PAYLOAD_PROGRAM]
options:
-h, --help show this help message and exit
--usage show usage message
--ip ADDR ip address for the reverse connection
--port PORT port number to the reverse connection
--target URL target url. Example: http://localhost:8080
-U USER, --username USER
username to log int to openplc web server
-P PASSWORD, --password PASSWORD
password to log in to openplc web server
--payload-program PAYLOAD_PROGRAM
structured text openplc format to send to /upload-program