Git Product home page Git Product logo

gerbsec / cve-2020-24572-poc Goto Github PK

View Code? Open in Web Editor NEW
8.0 8.0 0.0 17 KB

An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS running this software, and execute commands on the system including ones for uploading of files and execution of code.

License: GNU General Public License v3.0

Python 100.00%

cve-2020-24572-poc's Introduction

hey, i'm gerbsec

offsec n stuff

gerbsec

  • anything and everything offsec with a lil bit of purple
  • founder and team captain of protosec

Socials:

๐Ÿ… Certifications and Achievements

OSEP OSCP OSWA OSWP KLCP CRTL CRTO CPTS CBBH CDSA CRTP PNPT PJPT SEC+

๐Ÿ–ฅ๏ธ Languages and Tools

Kali Linux Ghidra BinaryNinja Cobalt Strike BurpSuite Python Java Rust C C++ C# Golang PowerShell VScode Docker Bloodhound git

cve-2020-24572-poc's People

Contributors

gerbsec avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

cve-2020-24572-poc's Issues

Issue trying to reproduce the exploit

Hello, I am trying to reproduce the exploit for a school project but I can't manage to get it working.

  • I installed RaspAP/2.5 by modifying installers/raspbian.sh 's branch parameter so that it installs correctly (as only cloning RaspAP tagged 2.5 and running the script installs the latest version)
  • I ran my netcat waiting for a shell on the attacker's pc
  • I ran the exploit but nothing happened
  • I checked launching the reverse shell manually to see if it works, it does.
  • After wiresharking the post request I noticed I was getting an internal server error from RaspAP.

So I went to check what was going on in lightpd logs and this is what I got.

image

Did you ever encounter something like this while running the exploit and how should I go about fixing it ?

Hope you can help me.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.