
Pi-hole의 원격 코드 실행 취약점인 CVE-2020-8816을 악용하는 Python 스크립트
Pi-hole의 원격 코드 실행 취약점인 CVE-2020-8816을 익스플로잇하는 Python 스크립트입니다.
이 스크립트는 François Renaud-Philippon이 발견한 기술을 사용하여 웹 인터페이스 버전이 4.3.3 미만인 Pi-hole에서 원격 코드 실행을 달성합니다. 익스플로잇을 위해 www-data 사용자의 PATH가 /opt/pihole:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin이어야 합니다.
> python3 .\CVE-2020-8816.py -h
usage: CVE-2020-8816.py [-h] url password ip port
Receive a reverse shell on a Pi-hole with access to the admin web console
positional arguments:
url The URL of the Pi-hole console
password The admin password for the Pi-hole console
ip The IP address for the reverse shell to connect to
port The port for the reverse shell to connect to
optional arguments:
-h, --help show this help message and exit
