
CVE-2019-15511에 대한 GOG Galaxy 익스플로잇
usage: exploit.py [-h]
[--action {LaunchElevatedRequest,FixDirectoryPrivilegesRequest,CreateDirectoryRequest,QueryProcessInfoRequest,InstallServiceRequest,DeleteServiceRequest,MoveAndVerifyGlobalDependencyRequest}]
target
positional arguments:
target
optional arguments:
-h, --help show this help message and exit
--action {LaunchElevatedRequest,FixDirectoryPrivilegesRequest,CreateDirectoryRequest,QueryProcessInfoRequest,InstallServiceRequest,DeleteServiceRequest,MoveAndVerifyGlobalDependencyRequest}
민감한 GalaxyClientService 메서드가 호출될 때 인증 부재를 악용합니다. FixDirectoryPrivilegesRequest (대상 파일에 EVERYONE 액세스 권한 부여) 또는 CreateDirectoryRequest (대상 위치에 디렉터리 생성)를 시도하여 실제 동작을 확인하세요.