
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apenas para uso ético, qualquer atividade maliciosa ou prejudicial não é permitida. E é sua responsabilidade.
CVE-2024-38856: Scanner & Exploit de execução remota de código no Apache OFBiz
A Análise CVE: https://blog.securelayer7.net/cve-2024-38856-apache-ofbiz-rce
18.12.14
██████╗██╗ ██╗███████╗ ██████╗ ██████╗ ██████╗ ██╗ ██╗ ██████╗ █████╗ █████╗ ███████╗ ██████╗
██╔════╝██║ ██║██╔════╝ ╚════██╗██╔═████╗╚════██╗██║ ██║ ╚════██╗██╔══██╗██╔══██╗██╔════╝██╔════╝
██║ ██║ ██║█████╗█████╗ █████╔╝██║██╔██║ █████╔╝███████║█████╗█████╔╝╚█████╔╝╚█████╔╝███████╗███████╗
██║ ╚██╗ ██╔╝██╔══╝╚════╝██╔═══╝ ████╔╝██║██╔═══╝ ╚════██║╚════╝╚═══██╗██╔══██╗██╔══██╗╚════██║██╔═══██╗
╚██████╗ ╚████╔╝ ███████╗ ███████╗╚██████╔╝███████╗ ██║ ██████╔╝╚█████╔╝╚█████╔╝███████║╚██████╔╝
╚═════╝ ╚═══╝ ╚══════╝ ╚══════╝ ╚═════╝ ╚══════╝ ╚═╝ ╚═════╝ ╚════╝ ╚════╝ ╚══════╝ ╚═════╝
Github: https://github.com/securelayer7/CVE-2024-38856_Scanner
By: Securelayer7(yosef0x01 & Zeyad Azima)
usage: cve-2024-38856_Scanner.py [-h] [-t TARGET] [-p PORT] [-c COMMAND] [-s] [-d DOMAIN] [-f FILE]
CVE-2024-38856 Apach Ofbiz RCE Scanners.
options:
-h, --help Show this help message and exit.
-t TARGET, --target TARGET
Specify the target host for the scan or exploit. This should be the IP address or domain name of the server you want to target.
-p PORT, --port PORT Specify the target port. This is the port on the target host where the vulnerable service is running (e.g., 8080).
-c COMMAND, --command COMMAND
The command to execute on the target server if you are exploiting the vulnerability. This option is only used with the `--exploit` flag.
-s, --scan Perform a scan to check for the vulnerability on the specified target. The scan will use basic network commands like `ping`, `curl`, and `wget` to probe the target.
-d DOMAIN, --domain DOMAIN
The domain or IP address to use when performing the scan. This is typically the attacker's domain that the target will interact with using commands like `ping`, `curl`, and `wget`. Defaults to `http://example.com` if not specified.
-f FILE, --file FILE Specify a file containing a list of targets. Each line in the file should be in the format `http(s)://target,port`. This option allows you to scan or exploit multiple targets in a batch mode.
-O OUTPUT, --output OUTPUT
The file to save the results to. If specified, the results of the scan or exploit will be written to this file instead of being printed to the console.
--proxy PROXY Specify a proxy to route your requests through. The format should be `http://proxyhost:port` or `https://proxyhost:port`. This is useful if you need to route your traffic through an intercepting proxy like Burp Suite or if you need to hide your IP address.
--exploit Exploit the vulnerability on the specified target. When this option is used, the script will attempt to execute the command provided with the `-c` or `--command` option on the target server. This option must be used if you want to exploit the vulnerability rather than just scan for it.
--timeout TIMEOUT Specify the timeout in seconds for the HTTP requests made by the script. This controls how long the script will wait for a response from the target server before considering the attempt failed. Default is 10 seconds.
-t, --target <host>: Especifica o host alvo. Não pode ser usado com a opção --file.
-p, --port <port>: Especifica a porta alvo. Além disso, esta opção é necessária se a porta não estiver especificada no arquivo de alvos.
-c, --command <comando>: Especifica o comando a ser executado no alvo.
-s, --scan: Ativa o modo de varredura. Quando esta opção é usada, o script executará uma série de comandos predefinidos (ping, curl, wget) no domínio especificado.
-d, --domain <domínio>: Especifica seu domínio (domínio do atacante) para usar na varredura com os comandos ping, curl e wget. Esta opção deve ser usada com .
Porta Global: Ao escanear o arquivo de alvos, você pode excluir ,porta e usar -p para definir uma porta global para todos os alvos.
python cve-2024-38856_Scanner.py -t <alvo> -p <porta> -c "comando" --exploit

python cve-2024-38856_Scanner.py -t <alvo> -p <porta> -s -d <domínio> --scan

python exploit.py -f <arquivo> -c "comando"

python exploit.py -f <arquivo> -p <porta> -s -d <domínio>



--scan-f, --file <arquivo>: Especifica um arquivo contendo uma lista de alvos no formato http(s)://alvo,porta. Esta opção não pode ser usada com --target.
-O, --output <arquivo_saída>: O arquivo de saída para os resultados.