Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2025-32433-LAB — A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials in the Erlang/OTP SSH server | Kitploit
उपकरण/GitHubGitHub/damnkrishna/cve-2025-32433-lab
Packet Sniffing & AnalysisVulnerability ScannersContainer SecurityVulnerability AnalysisExploitationNetwork SecurityIntrusion DetectionLearning & EducationLabs & Practice
GitHubdamnkrishna/cve-2025-32433-lab

CVE-2025-32433-LAB

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials in the Erlang/OTP SSH server

रिपॉजिटरी देखें
2519 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2025-32433 Vulnerability Research & Security Lab

✅ PRE-AUTH RCE CONFIRMED — Exploit successfully demonstrated.
📄 Technical Blog (PDF): CVE-2025-32433-Technical-Blog.pdf
📸 Visual Evidence: screenshots/
🔍 Proof of Concept Details: docs/PROOF_OF_CONCEPT.md

CVE-2025-32433 is a CVSS 10.0 Critical vulnerability in the Erlang/OTP SSH daemon. An unauthenticated attacker can open SSH channels and execute arbitrary commands before completing authentication — zero credentials required.

This lab gives you a fully working, isolated environment to reproduce the vulnerability, run the exploit, verify it, and test detection mechanisms — all on your local machine.


Prerequisites

Before you start, ensure you have the following installed:

ToolMinimum VersionCheck Command
Docker Desktop4.x+docker --version
Docker Composev2.20+docker compose version
Python3.10+python --version

You also need the Python paramiko library for the detection suite:

pip install paramiko

Important Note — Why We Build From Source

Docker Hub's erlang:26.2.5 image tag was silently overwritten with the patched 26.2.5.11 release after CVE-2025-32433 was disclosed. Pulling it from Docker Hub gives you the patched version, not the vulnerable one.

This lab's lab/Dockerfile compiles OTP 26.2.5 directly from the official Erlang GitHub release tarball to guarantee the genuine vulnerable runtime. The first build takes ~10 minutes.


Lab Architecture

                  ┌──────────────────────────────────────────┐
                  │         Isolated Docker Bridge           │
                  │            (cve-lab-bridge)              │
                  └────┬────────────────────────────┬────────┘
                       │                            │
       ┌───────────────┴─────────────┐┌─────────────┴──────────────┐
       │  target_vulnerable          ││  target_patched             │
       │  OTP 26.2.5 (source-built)  ││  erlang:26.2.5.11           │
       │  Host Port: 127.0.0.1:2222  ││  Host Port: 127.0.0.1:2223  │
       └─────────────────────────────┘└─────────────────────────────┘
                                       │
                        ┌──────────────┴──────────────┐
                        │  attacker                   │
                        │  Python 3 + Scapy/Paramiko  │
                        │  Workdir: /work             │
                        └─────────────────────────────┘
ContainerPortOTP VersionStatus
cve-2025-32433-vulnerable127.0.0.1:222226.2.5 (ERTS 14.2.5)❌ Vulnerable
cve-2025-32433-patched127.0.0.1:222326.2.5.11 (ERTS 14.2.5.15)✅ Patched
cve-2025-32433-attackerInternal onlyPython 3 toolingAttacker toolset

Step 1 — Clone the Repository

git clone https://github.com/damnkrishna/CVE-2025-32433-LAB.git
cd CVE-2025-32433-LAB

Step 2 — Build the Vulnerable Container

⏱️ This takes ~10 minutes — it compiles Erlang/OTP 26.2.5 from C source. This is expected. Do not interrupt it.

docker compose build --no-cache target_vulnerable

You will see compiler output like make[1]: Leaving directory '/tmp/otp_src_26.2.5/lib/...' — this is normal. It ends with:

✔ Image ine_cyber_assignment_job-target_vulnerable Built

Step 3 — Build the Patched Container

docker compose build --no-cache target_patched

Step 4 — Start the Lab

docker compose up -d target_vulnerable target_patched

Step 5 — Verify Everything is Running

docker compose ps

Expected output:

NAME                        STATUS              PORTS
cve-2025-32433-vulnerable   Up (healthy)        127.0.0.1:2222->2222/tcp
cve-2025-32433-patched      Up (healthy)        127.0.0.1:2223->2222/tcp

Both containers must show (healthy) before continuing.


Step 6 — Verify the Vulnerable Version

Confirm the container is genuinely running OTP 26.2.5 (not the patched version):

docker exec cve-2025-32433-vulnerable cat /usr/local/otp/lib/erlang/releases/RELEASES

Expected output — must show 14.2.5 with NO .15 suffix:

[{release,"Erlang/OTP","26","14.2.5",
          [{kernel,"9.2.4",...},

If you see 14.2.5.15 — the container image is wrong. Rebuild with --no-cache.


Step 7 — Normal Authenticated SSH Login (Baseline)

Connect as a legitimate user to confirm the server accepts standard authentication:

ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -p 2222 [email protected]

When prompted enter the password: LabPass2026!Secured

You will land in an Erlang shell:

Eshell V14.2.5 (press Ctrl+G to abort, type help(). for help)
1>

Try some commands inside the Erlang shell:

ls().
file:write_file("test.txt", "hello").
file:read_file("test.txt").

To exit the Erlang shell:

q().

Step 8 — Monitor Logs Live (Run This in a Separate Terminal)

Before running the exploit, open a second PowerShell terminal and tail the server log:

Get-Content -Path .\logs\target_vulnerable\ssh.log -Wait -Tail 20

Keep this terminal open. You will see connection events appear in real time.


Step 9 — Run the CVE-2025-32433 Exploit

This is the pre-authentication remote code execution proof of concept. No credentials are used.

cd attacker_work\exploit
python payload.py

Expected output:

[*] Connecting to SSH server...
[+] Received banner: SSH-2.0-Erlang/5.1.4
[*] Sending SSH_MSG_KEXINIT...
[*] Sending SSH_MSG_CHANNEL_OPEN...
[*] Sending SSH_MSG_CHANNEL_REQUEST (pre-auth)...
[✓] Exploit sent! If the server is vulnerable, it should have written to /lab.txt.
[+] Received response: 000003d4...

The banner must show SSH-2.0-Erlang/5.1.4 (no .15 suffix) to confirm you hit the vulnerable server.


Step 10 — Verify the Exploit Worked

docker exec cve-2025-32433-vulnerable cat /lab.txt

Expected output:

pwned

If you see pwned — CVE-2025-32433 pre-authentication RCE is confirmed. The exploit wrote to the container filesystem with zero credentials.


Step 11 — Confirm Patched Container is NOT Vulnerable

Run the same exploit against the patched container on port 2223:

Edit attacker_work\exploit\payload.py line 6:

PORT = 2223   # change from 2222 to 2223

Run the exploit:

python payload.py

Then check for the file:

docker exec cve-2025-32433-patched cat /lab.txt

Expected output:

cat: /lab.txt: No such file or directory

The patched container rejects the unauthenticated channel request. No file written = patched.

Restore payload.py port back to 2222 when done.


Step 12 — Run the Detection Suite

Go back to the repo root:

cd ..\..

Option A: Version Banner Scanner (checks if target is vulnerable by SSH banner)

Scan the vulnerable target:

python detection\detect_cve_2025_32433.py 127.0.0.1 2222

Scan the patched target:

python detection\detect_cve_2025_32433.py 127.0.0.1 2223

Option B: Host Process & File Integrity Monitor

Monitors the container process table for unexpected child processes spawned by Erlang (e.g. shell processes that indicate RCE):

python detection\host_process_monitor.py
टूल डाउनलोड करें