目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-3400 PoC — Palo Alto Networks PAN-OS 命令注入漏洞

来源
关联漏洞
标题: Palo Alto Networks PAN-OS 命令注入漏洞 (CVE-2024-3400)
Description:Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一款下一代防火墙软件。 Palo Alto Networks PAN-OS 10.2、11.0、11.1存在命令注入漏洞,该漏洞源于GlobalProtect 功能中存在命令注入漏洞,可能使未经身份验证的攻击者在防火墙上以 root权限执行任意代码。
介绍
# PAN-OS Firewall Command Injection Vulnerability

This repository contains a Go script that exploits a Command Injection vulnerability in firewalls running Palo Alto Networks' PAN-OS operating system. The vulnerability, identified as CVE-2024-3400, allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.

## About the Vulnerability

CVE-2024-3400 is a critical vulnerability affecting multiple versions of PAN-OS, including PAN-OS 10.2, PAN-OS 11.0, and PAN-OS 11.1, when configured with the GlobalProtect Gateway and/or GlobalProtect Portal features and device telemetry enabled. Successful exploitation of this vulnerability can result in the execution of arbitrary code on the firewall, potentially leading to complete compromise of the device.

## About the Script

The script in this repository is developed for educational and research purposes, aiming to demonstrate how the vulnerability can be exploited. It allows users to perform attacks against vulnerable PAN-OS firewalls by injecting custom payloads into them.

### Usage of the Script

The script can be run in two ways: by entering values directly or by using a CSV file containing a list of targets. Here's how to use it:

#### Running with Direct Values:

1. Ensure you have Go installed on your system.
2. Clone this repository to your machine.
3. Open a terminal and navigate to the directory where you cloned the repository.
4. Run the script with the command `go run exploit.go`.
5. Choose option 'D' to enter values directly.
6. Follow the prompts to enter the firewall's IP address, the payload to be executed, and the path to the root CA certificate, if required.

#### Running with a CSV File:

1. Ensure you have Go installed on your system.
2. Prepare a CSV file containing a list of targets you want to attack. The format should include three columns: firewall IP address, payload, and the path to the root CA certificate (optional).
3. Clone this repository to your machine.
4. Open a terminal and navigate to the directory where you cloned the repository.
5. Run the script with the command `go run exploit.go`.
6. Choose option 'C' to use a CSV file.
7. Enter the path to the CSV file when prompted.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →