Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2019-2107 — Proof-of-Concept-Exploit für CVE-2019-2107, der Remote-Code-Ausführung mittels manipuliertem HEVC-Video im Android-Media-Framework demonstriert. Enthält Absturzanalyse und Anleitung zur Entwicklung von Payloads. | Kitploit
Tools/GitHubGitHub/infiniteloopers/cve-2019-2107
Android-SicherheitSchwachstellenanalyseExploitationFuzzingPayload-EntwicklungRemote-Access-TrojanerBinary-Exploitation
GitHubinfiniteloopers/cve-2019-2107

CVE-2019-2107

Proof-of-Concept-Exploit für CVE-2019-2107, der Remote-Code-Ausführung mittels manipuliertem HEVC-Video im Android-Media-Framework demonstriert. Enthält Absturzanalyse und Anleitung zur Entwicklung von Payloads.

Repository anzeigen
43vor 7 JahrenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

CVE-2019-2107

CVE-2019-2107

CVE-2019-2107 – sieht gruselig aus. Erinnern Sie sich noch an Stagefright und PNG-Bugs? Mit CVE-2019-2107 läuft der Decoder/Codec unter dem mediacodec-Benutzer und mit einem entsprechend präparierten Video (mit aktivierten Kacheln – ps_pps->i1_tiles_enabled_flag) kann man möglicherweise RCE (Remote Code Execution) erreichen. Der betroffene Codec ist HVEC (auch bekannt als H.265 und MPEG-H Part 2) #exploit #rce #android #stagefright #cve

alt text

Weitere Informationen

LineageOS (Android):

root@kitploit:~
02-11 20:18:48.238   260   260 D FFmpegExtractor: ffmpeg detected media content as 'video/hevc' with confidence 0.08
02-11 20:18:48.239   260   260 I FFMPEG  : [hevc @ 0xb348f000] Invalid tile widths.
02-11 20:18:48.239   260   260 I FFMPEG  : [hevc @ 0xb348f000] PPS id out of range: 0
02-11 20:18:48.240   260   260 I FFMPEG  : [hevc @ 0xb348f000] Invalid tile widths.
02-11 20:18:48.240   260   260 I FFMPEG  : [hevc @ 0xb348f000] PPS id out of range: 0
02-11 20:18:48.240   260   260 I FFMPEG  : [hevc @ 0xb348f000] Error parsing NAL unit #5.
02-11 20:18:48.240   260   260 I FFMPEG  : [hevc @ 0xb348f000] Invalid tile widths.

mplayer (laptop)

root@kitploit:~
id: 0
[hevc @ 0x7f0bf58a7560]Decoding VPS
[hevc @ 0x7f0bf58a7560]Main profile bitstream
[hevc @ 0x7f0bf58a7560]Decoding SPS
[hevc @ 0x7f0bf58a7560]Main profile bitstream
[hevc @ 0x7f0bf58a7560]Decoding VUI
[hevc @ 0x7f0bf58a7560]Decoding PPS
[hevc @ 0x7f0bf58a7560]Invalid tile widths.
[hevc @ 0x7f0bf58a7560]Decoding SEI
[hevc @ 0x7f0bf58a7560]Skipped PREFIX SEI 5
[hevc @ 0x7f0bf58a7560]PPS id out of range: 0
[hevc @ 0x7f0bf58a7560]Error parsing NAL unit #5.
Error while decoding frame!

Das stoppt es, wenn die Kachelbreite größer als erlaubt ist: https://gitlab.freedesktop.org/gstreamer/meson-ports/ffmpeg/blob/ebf648d490448d511b5fe970d76040169e65ef74/libavcodec/hevc_ps.c#L1526

Die Prüfungen sind also vorhanden.

Auf Stock/Google Android denke ich, dass es libhevc verwendet, nicht ffmpeg, wenn man VideoPlayer benutzt.

https://www.droidviews.com/enjoy-hevc-h-265-video-playback-on-android/

Ich habe den Google-Codec:

OMX.google.hevc.decoder

Ich frage mich jedoch, warum es nicht abstürzt ....

Das Video (videopoc.mp4) wird angehängt, das diese Bedingung auslösen sollte:

root@kitploit:~
if (value >= ps_sps->i2_pic_wd_in_ctb - start)
+                        {
+                            return IHEVCD_INVALID_HEADER;
+                        }

Vielleicht hat jemand mehr Glück.

Weitere Informationen 2

Whoooo hooo ... geschafft :)

Der Proof of Concept ist in hevc-crash-poc.mp4, andere Videos sind für Nicht-Android-Player.

Hvec-„Fright“ ist möglich. Sie können das Mobiltelefon übernehmen, indem Sie ein Video mit Payload ansehen. In meinem Beispiel habe ich keinen echten Payload eingefügt.

root@kitploit:~
07-13 21:50:59.000  3351  3351 I /system/bin/tombstoned: received crash request for pid 24089
07-13 21:50:59.006 24089 24089 F DEBUG   : *** *** *** *** *** *** *** *** *** *** *** *** *** *** *** ***
07-13 21:50:59.006 24089 24089 F DEBUG   : Build fingerprint: 'samsung/hero2ltexx/hero2lte:8.0.0/R16NW/G935FXXS4ESC3:user/release-keys'
07-13 21:50:59.006 24089 24089 F DEBUG   : Revision: '9'
07-13 21:50:59.006 24089 24089 F DEBUG   : ABI: 'arm64'
07-13 21:50:59.006 24089 24089 F DEBUG   : pid: 24089, tid: 24089, name: media.extractor  >>> mediaextractor <<<
07-13 21:50:59.006 24089 24089 F DEBUG   : signal 11 (SIGSEGV), code 1 (SEGV_MAPERR), fault addr 0x7ccb800050
07-13 21:50:59.009 24089 24089 F DEBUG   :     x0   00000000ffffff36  x1   0000000000000000  x2   00000000000000f0  x3   0000000000000001
07-13 21:50:59.009 24089 24089 F DEBUG   :     x4   0000000000000001  x5   0000007ccb5df1b8  x6   0000007cc927363e  x7   0000007cc8e7bd04
07-13 21:50:59.009 24089 24089 F DEBUG   :     x8   0000000000004170  x9   0000000000004160  x10  00000000ffffffff  x11  0000007ccb7fbef0
07-13 21:50:59.010 24089 24089 F DEBUG   :     x12  0000007ccb5d3ce0  x13  000000000000001e  x14  0000000000000003  x15  0000000000000001
07-13 21:50:59.010 24089 24089 F DEBUG   :     x16  0000007cc99f5f50  x17  0000007ccb88885c  x18  0000007ccb566225  x19  0000007ccb562020
07-13 21:50:59.010 24089 24089 F DEBUG   :     x20  0000007ccb4f18a0  x21  0000007ccb468c6c  x22  0000000000000000  x23  0000000000000006
07-13 21:50:59.010 24089 24089 F DEBUG   :     x24  000000000000001e  x25  0000000000000094  x26  0000000000004160  x27  0000000000000001
07-13 21:50:59.010 24089 24089 F DEBUG   :     x28  0000007ccb55e750  x29  0000007fd6d39d90  x30  0000007cc99c4438
07-13 21:50:59.010 24089 24089 F DEBUG   :     sp   0000007fd6d39d20  pc   0000007cc99c44c4  pstate 0000000080000000
07-13 21:50:59.013 24089 24089 F DEBUG   : 
--

alt text

Weitere Informationen 3

Wenn Sie es weiterbringen möchten, um RCE (Remote Command Execution) zu erreichen,

Ich würde damit beginnen, ein LineageOS-ROM mit Debug-Build zu besorgen (wenn Sie kein gerootetes Zieltelefon haben, bereitet Ihnen die Disassembly Kopfschmerzen, es sollte viel einfacher zu handhaben sein), möglicherweise den Speicher-Allokator auf jemalloc umstellen (um neuere Mobilgeräte anzugreifen) Sie könnten es in Ihrer BoardConfig festlegen:

device/samsung/msm8226-common/BoardConfigCommon.mk

root@kitploit:~
# Memory
#MALLOC_IMPL := dlmalloc
MALLOC_IMPL := jemalloc

Ich habe festgestellt, dass mein Samsung-Handy jemalloc verwendet hat, ich bin mir bei älteren/neueren Geräten nicht sicher. Hoffentlich dasselbe.

Weitere Informationen zu jemalloc/dlmalloc: https://blog.nsogroup.com/a-tale-of-two-mallocs-on-android-libc-allocators-part-1-dlmalloc/

Hier habe ich die Prüfungen aus libavcodec.so entfernt

Test auf LineageOS 7.1.2 auf Samsung S3 Neo+

Wie wir sehen, ist der Mediaplayer abgestürzt/verschwunden ... mit unbehandelten Ereignissen (MediaPlayer: mediaplayer went away with unhandled events). Nicht sicher, warum es nicht nativ abstürzt. Das Ziel wäre hier, den Ausführungsfluss zu übernehmen. Viel Glück!

root@kitploit:~
02-25 16:44:15.008  2954  2954 I art     : Explicit concurrent mark sweep GC freed 4988(521KB) AllocSpace objects, 1(40KB) LOS objects, 25% free, 6MB/8MB, paused 484us total 43.471ms
02-25 16:44:15.011  2954  2954 I art     : Starting a blocking GC Explicit
02-25 16:44:15.046  2954  2954 I art     : Explicit concurrent mark sweep GC freed 435(17KB) AllocSpace objects, 0(0B) LOS objects, 24% free, 6MB/8MB, paused 523us total 34.700ms
02-25 16:44:15.083  2954  2954 W MediaPlayer: mediaplayer went away with unhandled events
Tool herunterladen