
CVE-2023-33246のリモートコード実行に対して脆弱なApache RocketMQブローカーをエクスプロイトし、IP、CIDR、またはファイル入力でターゲットをチェックします。
CVE-2023-33246 - Apache RocketMQ 設定によるリモートコード実行エクスプロイト
RocketMQ は分散型メッセージングおよびストリーミングプラットフォームです。
RocketMQ バージョン 5.1.0 以下は、任意のコードインジェクションに対して脆弱です。RocketMQ の Broker コンポーネントが外部ネットワークに漏洩し、アクセス許可の検証が不足しています。攻撃者は設定更新機能を利用して、RocketMQ を実行しているシステムユーザーとしてコマンドを実行できます。さらに、RocketMQ プロトコルコンテンツを偽装することで同じ効果を得ることも可能です。
usage: check.py [-h] [--ip IP] [--file FILE] [--port PORT] [--cidr CIDR]
Check CVE-2023-33246 RocketMQ RCE vulnerability
optional arguments:
-h, --help show this help message and exit
--ip IP A single IP address to check
--file FILE A file containing a list of IP addresses, one per line
--port PORT The port number to use when connecting to the server (default
is 9876)
--cidr CIDR A CIDR range to scan (e.g. 1.2.3.0/24)
python3 check.py --ip 127.0.0.1 --port 9876
python3 check.py --cidr 192.168.1.0/24
# or
python3 check.py --file rocketmq_targets.txt --port 9876
# target in file format:
# ip
# ip:port
# http://ip:port