Sploitus

Exploit for Path Traversal in Ivanti Connect Secure

githubexploit · 2020-07-27

Exploit Code

README44 lines
## https://sploitus.com/exploit?id=059DC199-E425-50EE-B5F5-E351E0323E69
# pulsexploit
Automated script for Pulse Secure SSL VPN exploit ([CVE-2019-11510](https://vulners.com/cve/CVE-2019-11510 "CVE 2019-11510")) using hosts retrieved from Shodan API. You must have a Shodan account to use this script. Click [here](https://account.shodan.io/register) if you don't have Shodan account.

![image](https://user-images.githubusercontent.com/22043590/70325539-29340b80-186d-11ea-8d28-7c1573e92c5e.png)

## Installation

1. Install dependencies.
```bash
    # CentOS & Fedora
    yum install git python3 -y

    # Ubuntu & Debian
    apt install git python3 python3-pip -y

    # FreeBSD
    pkg install -y python3 git
    python3 -m ensurepip
```

2. Clone repository & install python3 module
```bash
    git clone https://github.com/andripwn/pulse-exploit.git
    cd pulse-exploit
    pip3 install -r requirements.txt
```

3. Add your Shodan API key and edit the search query
```python
    # Shodan API Key (change according to your Shodan API key)
    api_key = ''
    # Shodan search query (edit this, but don't remove the html and port)
    search_query = 'html:"/dana/" port:"443"'
```

## Usage

```bash
    python3 pulsexploit.py -t 
```

## Disclaimer
This script is only for penetration testing and security research, I will not be responsible if you use it for illegal activities.