Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-1040 PoC — Sophos Firewall 授权问题漏洞

Source
Associated Vulnerability
Title: Sophos Firewall 授权问题漏洞 (CVE-2022-1040)
Description:An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
Description
Save the trouble to open the burpsuite...
Readme
# Environment
## In Python Environment(3.10)
``` python3.10
# It's strongly recommended to use the virtual environment)

pip3 install baseproxy
# python3.10 will raise an AttributeError if the version of pyOpenSSL(downloaded with baseproxy) is too low. Reinstalling the latest version will fix it.
pip3 uninstall pyOpenSSL 
pip3 install pyOpenSSL

# run
python3 Sophos-poc.py 
```

## In Docker
``` bash
docker pull keithdockerhub/cve-2022-1040:latest # or build yourself
docker run -it -p 8788:8788  keithdockerhub/cve-2022-1040:latest
```
# How to use
1. Make sure your browser use the http proxy: http://127.0.0.1:8788. 
2. Fill in username and password with literally any contents.(It doesn't matter)
3. Click login.

---
The principle is the same as the burpsuite. 
It sets up a https mitm(man in the middle) and change the http body in a specific post request then we can get access to the web admin of Sophos Firewall without authentication.   
<font size=3 color=red>***Please do not use it for illegal purposes.***</font>

# Reference
[https://github.com/qiyeboy/BaseProxy](https://github.com/qiyeboy/BaseProxy)  
[https://github.com/APTIRAN/CVE-2022-1040](https://github.com/APTIRAN/CVE-2022-1040)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →