
CrushFTP 인증 우회(CVE-2025-2825)를 위한 익스플로잇 스크립트로, 조작된 Authorization 헤더와 CrushAuth 쿠키를 사용하여 무단 액세스를 획득합니다.
이 스크립트는 CrushFTP 인증 우회 취약점을 다음 버전에서 악용합니다:
CrushFTP의 AWS S3 스타일 인증은 다음을 사용하여 우회될 수 있습니다:
Authorization 헤더c2f 매개변수와 일치하는 특별히 조작된 CrushAuth 쿠키chmod +x exploit_crushftp.sh
./exploit_crushftp.sh http://<target>:<port>