
CVE-2020-3452를 악용하여 CISCO ASA 장비의 웹 디렉터리에서 접근 가능한 표준 파일들을 열거하는 기본적인 스캐너입니다.
CVE-2020-3452를 악용하여 CISCO ASA/FTD 장비의 웹 디렉터리에서 접근 가능한 표준 파일들을 열거하는 기본적인 익스플로잇입니다.
기본적으로 Metasploit Framework의 CVE-2018-0296 샘플 출력에서 구성된 파일 목록을 사용합니다 (https://github.com/rapid7/metasploit-framework/blob/master/documentation/modules/auxiliary/scanner/http/cisco_directory_traversal.md).
Usage: cve-2020-3452.sh <target ip/hostname>
Example: cve-2020-3452.sh mytarget.com
Files that are downloaded will be in the newly created 'cisco_asa_files' directory