
Sfruttamento di CVE-2023-44604. Utilizzando una VM Kali Linux (attaccante) e una VM server Debian 11 (vittima).
[ATTENZIONE]
Questo progetto è destinato esclusivamente a scopi educativi e di laboratorio. Usa queste tecniche solo in ambienti di tua proprietà o per i quali sei autorizzato a fare test.
Questo laboratorio simulerà lo sfruttamento di CVE-2023-46604, utilizzando una VM Kali Linux (attaccante) e una VM server Debian 11 (vittima).
Questo laboratorio funziona solo se il sistema operativo host è Windows!
--> Se usi Linux, questo laboratorio non funzionerà!
ATTENZIONE
Il software Apache e Java verrà installato automaticamente (tramite script) sulle VM. Non installarli manualmente sul tuo PC host!
In questo esercizio usiamo il seguente software:
Installa VBoxManage e rendi il comando una variabile d'ambiente:
Clona o scarica il repository in una posizione a tua scelta. (i comandi vboxmanage devono poter funzionare in questa cartella)
C:\Users\<user_name>\CVE-2023-46604\Dopo aver clonato il repository sul tuo sistema locale, aggiungi in quella cartella (\CVE-2023-46604\) una nuova cartella VDI\.
La struttura delle cartelle dovrebbe ora essere simile a questa:
CVE-2023-46604\
│
├── .gitignore
│
├── LICENSE
│
├── README.md
│
├── scripts\
│ ├── DebCreate.ps1
│ ├── DebDelete.ps1
│ ├── KalCreate.ps1
│ ├── KalDelete.ps1
│ ├── sshDebian.ps1
│ ├── sshKali.ps1
│ ├── softwareInstallDebian.sh
│ └── softwareInstallKali.sh
│
└── VDI\
Gli script di questo laboratorio utilizzano le VDI per creare ed eliminare le VM. Ora scaricheremo le seguenti VDI:
CVE-2023-46604\VDI\.Debian-original.vdi.CVE-2023-46604\VDI\.Kali-original.vdi.La struttura delle cartelle dovrebbe ora essere simile a questa:
CVE-2023-46604\
│
├── .gitignore
│
├── LICENSE
│
├── README.md
│
├── scripts\
│ ├── DebCreate.ps1
│ ├── DebDelete.ps1
│ ├── KalCreate.ps1
│ ├── KalDelete.ps1
│ ├── sshDebian.ps1
│ ├── sshKali.ps1
│ ├── softwareInstallDebian.sh
│ └── softwareInstallKali.sh
│
└── VDI\
├── Debian-original.vdi
└── Kali-original.vdi
Username: osboxes
Password: osboxes.org
cd scripts
.\DebCreate.ps1
.\sshDebian.ps1
[NOTA]
Al primo collegamento SSH, potresti vedere un messaggio come questo:The authenticity of host '[127.0.0.1]:2220' can't be established. ED25519 key fingerprint is SHA256:... Are you sure you want to continue connecting (yes/no/[fingerprint])?È normale. SSH ti avvisa che la chiave host della VM non è ancora memorizzata nel tuo file
.ssh/known_hosts.
Se vuoi controllare la tua VM Debian, puoi collegarti via SSH alla VM:
ssh -p2220 [email protected]
Username: osboxes
Password: osboxes.org
cd scripts
.\KalCreate.ps1
vboxmanage startvm "Kali Linux"
# When enabling ssh, the server will from then on start on boot.
sudo systemctl enable ssh
# Power off the VM.
sudo poweroff
Da questo momento in poi, SSH si avvierà automaticamente all'avvio della VM.
Se vuoi controllare la tua VM Kali, puoi collegarti via SSH alla VM:
ssh -p2225 [email protected]
.\sshKali.ps1
[NOTA]
Al primo collegamento SSH, potresti vedere un messaggio come questo:The authenticity of host '[127.0.0.1]:2225' cant be established. ED25519 key fingerprint is SHA256:... Are you sure you want to continue connecting (yes/no/[fingerprint])?È normale. SSH ti avvisa che la chiave host della VM non è ancora memorizzata nel tuo file
.ssh/known_hosts.
Ora hai accesso di Remote Command Execution (RCE) alla VM vittima Debian.
Puoi eseguire alcuni comandi Linux per verificare di avere ora accesso remoto alla VM Debian11:
# Show the current directory
pwd
# Check the operating system
cat /etc/os-release
# Check the current user
whoami
# Check the kernel information
uname -a
Dopo uno sfruttamento riuscito: