
Una implementación de una prueba de concepto para CVE-2018-5767
Una implementación de una prueba de concepto para CVE-2018-5767 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5767)
The following is an actualization of CVE-2018-5767, a vulnerability which
exploits an unguarded call to sscanf that occurs when parsing the 'Cookie'
header for a password. The vulnerability was initially discovered in, and
reported for, the AC15 model router, but has been rediscovered in several
different routers in this product line. This implementation sees it exploit the
model AC9, which is not presently covered by any CVE. A memory address for the
base of libc known to work on this router is 0x2ad6d000.
Vea lo siguiente para más información: https://www.cve.org/CVERecord?id=CVE-2018-5767 https://www.fidusinfosec.com/remote-code-execution-cve-2018-5767/ https://www.klogixsecurity.com/scorpion-labs-blog/sometimes-exploits-need-patches-too-working-through-a-change-of-address
usage: CVE-2018-5767-AC9.py [-h] [-t TARGET] [-p PORT] [-l LIBC] [-c COMMAND] [-v] [-a]
opciones: -h, --help muestra este mensaje de ayuda y sale -t TARGET, --target TARGET URL o dirección IP del objetivo a atacar -p PORT, --port PORT puerto del objetivo a atacar (por defecto = 80) -l LIBC, --libc LIBC dirección base estimada de libc (por defecto = 0x2ad6d000) -c COMMAND, --command COMMAND comando(s) a ejecutar en el objetivo (por defecto = exit) -v, --verbose aumenta la verbosidad de la salida (actualmente no implementado) -a, --about imprime información sobre esta vulnerabilidad y sale