
CVE-2020-1350 SIGRED, CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473을 탐지하는 NSE 스크립트
Microsoft SMBv3 압축(일명 coronablue, SMBGhost)에서 취약한 CVE-2020-0796 이슈를 탐지하는 NSE 스크립트
이 스크립트는 smb-protocols.nse 스크립트의 수정 버전으로, v3.11 탐지 및 CVE-2020-0796 검증을 위해 출력 데이터가 수정되었습니다.
참고: 이 스크립트는 SMBv3에서 CVE-2020-0796 취약점을 안전하게 확인만 하며, 그 이상의 시도는 하지 않습니다.
.nse 파일을 nmap/scripts/ 폴더에 복사하고 업데이트를 실행하세요
cp cve-2020-0796.nse /usr/share/nmap/scripts/
nmap --script-updatedb
다음과 같이 실행
nmap -p445 --script cve-2020-0796 <<target>>
-- @output
-- | smb-protocols:
-- | dialects:
-- | NT LM 0.12 (SMBv1) [dangerous, but default]
-- | 2.02
-- | 2.10
-- | 3.00
-- | 3.02
-- |_ 3.11 (SMBv3.11) LZNT1 compression algorithm - Vulnerable to CVE-2020-0796 SMBGhost
압축 확인은 https://github.com/ollypwn/SMBGhost/ 기반으로 수행됩니다. nselib의 smb.lua를 사용할 수도 있었지만 함수를 상당히 수정해야 했기에 소켓을 사용했습니다.
Microsoft DNS 서버(일명 SIGRed)에서 취약한 CVE-2020-1350 이슈를 탐지하는 NSE 스크립트
이 스크립트는 dns-nsid.nse 스크립트의 코드 구성 요소를 사용하며 CVE-2020-1350에 대한 확인을 수행합니다.
참고: 이 스크립트는 식별 목적으로만 Microsoft DNS 서버에서 CVE-2020-1350 취약점을 안전하게 확인하며, 그 이상의 시도는 하지 않습니다. 이 스크립트는 완벽하지 않으며 dig CH TXT bind.version @target의 출력에 의존하며, DNS 버전 번호가 숨겨져 있으면 실패합니다.
.nse 파일을 nmap/scripts/ 폴더에 복사하고 업데이트를 실행하세요
cp cve-2020-1350.nse /usr/share/nmap/scripts/
nmap --script-updatedb
다음과 같이 실행
sudo nmap -sSU -p53 --script cve-2020-1350 <<target>>
sudo nmap -sSU -p53 --script cve-2020-1350 <<target>> --script-args output=<outputfile.txt>
스크립트 인수로 제공된 사용자 정의 HTTP 제목을 검색하는 NSE 스크립트입니다. 이 스크립트는 필요한 HTTP 제목의 결과만 검색하고 제공하는 데 도움을 줍니다.
.nse 파일을 nmap/scripts/ 폴더에 복사하고 업데이트를 실행하세요
cp http-custom-title.nse /usr/share/nmap/scripts/
nmap --script-updatedb
다음과 같이 실행
nmap --script ./http-custom-title.nse -p80 scanme.nmap.org --script-args customtitle='ScanMe'
nmap --script ./http-custom-title.nse <<target>> --script-args customtitle='Apache'
vCenter의 CVE-2021-21972, CVE-2021-21973 취약점 확인용입니다. 이 스크립트는 추가로 vSphere 버전 및 빌드 번호를 출력합니다.
.nse 파일을 nmap/scripts/ 폴더에 복사하고 업데이트를 실행하세요
cp cve-2021-21972.nse /usr/share/nmap/scripts/
nmap --script-updatedb
다음과 같이 실행
nmap --script cve-2021-21972.nse -p443 <host> (선택 사항: --script-args output=report.txt)