Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-47729 — CVE-2026-47729 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-47729
Password CrackingVulnerability AnalysisExploitationInformation GatheringWeb SecurityLearning & Education
GitHub0xblackash/cve-2026-47729

CVE-2026-47729

CVE-2026-47729

View Repository
5133 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🦑 CVE-2026-47729 - Squidbleed

ChatGPT Image Jun 22, 2026, 12_26_27 AM

⚠️ Heartbleed's ancient cousin, hiding in Squid since 1997.


✨ Features

  • Single-file PoC — Zero dependencies
  • Malicious FTP server mimicking NetWare banner + truncated LIST response
  • Real-time detection and decoding of Basic Auth + Bearer tokens
  • Multi-threaded heap spraying for faster leaks
  • Clean, colored console output with live statistics

🚀 Quick Start

git clone https://github.com/0xBlackash/CVE-2026-47729.git
cd CVE-2026-47729

python3 CVE-2026-47729.py --proxy 127.0.0.1:3128

Command Line Options

ArgumentDefaultDescription
--proxy127.0.0.1:3128Target Squid proxy (host:port)
--ftp-port2222Local evil FTP server port
-t, --threads4Number of concurrent polling threads

📸 Expected Output

[PoC] Squidbleed CVE-2026-47729 by Ashraf Zaryouh (0xBlackash)

[ 14.78s] [BASIC] cGFzc3dvcmQxMjM6c2VjcmV0
              decoded = admin:password123

[ 18.33s] [BEARER] eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

🛠️ How It Works

  1. Starts an evil FTP server that sends a truncated directory listing.
  2. Repeatedly forces Squid to connect via FTP URLs.
  3. Triggers the heap buffer over-read → leaks adjacent memory.
  4. Extracts credentials and tokens from leaked data.

⚠️ Disclaimer

This PoC is for educational and authorized testing purposes only.
Use responsibly on systems you own or have permission to test.


Made with ❤️ by Ashraf Zaryouh "0xBlackash"

Download Tool