目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2020-8816 PoC — Pi-hole 操作系统命令注入漏洞

来源
关联漏洞
标题: Pi-hole 操作系统命令注入漏洞 (CVE-2020-8816)
Description:Pi-hole是Pi-hole公司的一款网络级广告拦截应用程序。 Pi-hole Web interface 4.3.2及之前版本中存在安全漏洞。攻击者可利用该漏洞执行任意命令。
Description
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
介绍
# Notes to defend against this exploit
* Patching
  * Just do it... now.
  * Subscribe to/watch the [Pi-hole repository](https://github.com/pi-hole/pi-hole) for new releases (and Issues and Pull requests if you're serious).
* Network
  * Do not expose Pi-hole to the internet.
  * Only expose Pi-hole DNS port 53 to DNS clients, not other ports like management interface.
* Management
  * Use unique and complex (meaning many characters) passphrases for admin account.

# CVE-2020-8816
**The full PoC is available in the PDF document**

This is a variation of a PoC for RCE on Pi-hole 4.3.2: https://natedotred.wordpress.com/2020/03/28/cve-2020-8816-pi-hole-remote-code-execution/ 

The original PoC requires the **$PATH** variable to be 'opt/pihole:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin'. This is not the case for a Pi-hole installation on Ubuntu Server with default settings.

Therefore, my PoC requires the **$PWD** variable for www-data to be '/var/www/html/admin'. This should be the case for more types of Pi-hole installations. My PoC also solves a problem: this new string from **$PWD** does not contain the letter ‘p’ required for a ‘php -r' execution as used in the original PoC.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →