预认证远程命令执行通过串联两个漏洞实现:第一个是在特定条件下重置生产控制台管理员密码的能力,第二个是连接功能中一个简单的认证后远程命令执行,用户输入被直接拼接至 ssh 系统命令。
该漏洞利用脚本所需的第三方 Python 依赖可通过以下任一命令安装:
# pip - universal
pip3 install Pillow pytesseract requests beautifulsoup4
# pacman - Arch Linux
pacman -S python-pillow python-pytesseract python-requests python-beautifulsoup4
编写了一个漏洞利用脚本,用于处理以下几种场景:
Usage:
Examples:
Pre-Auth RCE (password reset + RCE)
python exploit.py -u http://example.org/scriptcase -c "command"
Password reset only (no auth)
python exploit.py -u http://example.org/scriptcase
RCE only (need account)
python exploit.py -u http://example.org/scriptcase -c "command" -p 'Password123*'
Detect deployment path
python exploit.py -u http://example.org/ -d
Options:
-h, --help show this help message and exit
-u BASE_URL, --base-url=BASE_URL
-c COMMAND, --command=COMMAND
-p PASSWORD, --password=PASSWORD
-d, --detect
Production Environment 模块的 1.0.003-build-2 版本受影响。该版本模块包含在 ScriptCase 9.12.006 (23) 中。更早的版本也很可能存在漏洞。
https://www.synacktiv.com/advisories/scriptcase-pre-authenticated-remote-command-execution