Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2023-3128 — نص Python لاكتشاف تجاوز المصادقة CVE-2023-3128 في Grafana عبر التحقق من مطالبة البريد الإلكتروني Azure AD. يتحقق من تكوين Azure AD SSO ويبلغ عن الثغرة المحتملة. | Kitploit
أدوات/GitHubGitHub/spyata123/cve-2023-3128
المصادقة والترخيصماسحات الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويباختبار الاختراقأمن السحابة
GitHubspyata123/cve-2023-3128

CVE-2023-3128

نص Python لاكتشاف تجاوز المصادقة CVE-2023-3128 في Grafana عبر التحقق من مطالبة البريد الإلكتروني Azure AD. يتحقق من تكوين Azure AD SSO ويبلغ عن الثغرة المحتملة.

عرض المستودع
5منذ سنة واحدةلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2023-3128

للتحقق مما إذا كان نطاق معيّن عرضة لثغرة CVE-2023-3128، والتي تتضمن تجاوز المصادقة في Grafana بسبب التحقق من مطالبة البريد الإلكتروني في Azure AD، يمكنك استخدام سكربت Python التالي:


#!/usr/bin/env python3 import requests import argparse

def check_cve_2023_3128(target_url, verbose=False): """Check for CVE-2023-3128 vulnerability""" session = requests.Session()

root@kitploit:~
# Step 1: Verify Azure AD SSO configuration
try:
    response = session.get(
        f"{target_url}/login",
        allow_redirects=False,
        timeout=10
    )
    azure_ad_configured = any(
        "azuread" in location.lower() 
        for location in response.headers.get('Location', '')
    )
    
    if verbose:
        print(f"[*] Azure AD SSO configured: {azure_ad_configured}")
        
except requests.RequestException as e:
    if verbose:
        print(f"[!] Connection error: {str(e)}")
    return False

# Step 2: Attempt authentication bypass (spoofing)
# Note: This requires creating an Azure AD account with the same email as a target Grafana user.
#       This step is not automated due to ethical and legal considerations.
if azure_ad_configured:
    if verbose:
        print("[*] Azure AD SSO is enabled. Vulnerability may be exploitable via email spoofing.")
    return True
else:
    if verbose:
        print("[-] Azure AD SSO not detected or not vulnerable.")
    return False

def main(): parser = argparse.ArgumentParser(description='CVE-2023-3128 Scanner') parser.add_argument('url', help='Target URL (e.g., https://example.com)') parser.add_argument('-v', '--verbose', action='store_true', help='Enable verbose output') args = parser.parse_args()

root@kitploit:~
if check_cve_2023_3128(args.url, verbose=args.verbose):
    print(f"\nTarget {args.url} may be vulnerable to CVE-2023-3128.")
    print("Recommendation: Update Grafana to version ≥9.5.5 and ensure Azure AD OAuth is properly configured.")
else:
    print(f"\nTarget {args.url} does not appear to be vulnerable to CVE-2023-3128.")

if name == "main": main()

تنزيل الأداة