用于 Pulse Secure SSL VPN 任意文件读取的漏洞利用工具(CVE-2019-11510)
你可以使用单个域名,也可以使用域名列表。域名前必须包含 https://。
用法:cat targetlist.txt | bash CVE-2019-11510.sh / bash CVE-2019-11510.sh -d https://vpn.target.com/
如果你只想验证漏洞并下载 /etc/passwd,请使用:
cat targetlist.txt | bash CVE-2019-11510.sh --only-etc-passwd
bash CVE-2019-11510.sh -d https://vpn.target.com/ --only-etc-passwd
输出结果将保存在 output/vpn.target.com/ 目录中
演示:
https://blog.orange.tw/2019/09/attacking-ssl-vpn-part-3-golden-pulse-secure-rce-chain.html
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf