Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
sccm_sql_backdoor — CVE-2024-43468 और CVE-2025-59213 का शोषण करके SCCM प्रबंधन बिंदु की SQL संग्रहीत प्रक्रिया में एक नियंत्रित बैकडोर स्थापित करें, जिससे HTTP के माध्यम से रिमोट SQL निष्पादन संभव हो सके। | Kitploit
उपकरण/GitHubGitHub/synacktiv/sccm_sql_backdoor
स्थायित्व तंत्रशोषणपोस्ट-शोषणपेनिट्रेशन टेस्टिंगकमांड एंड कंट्रोलरेड टीमिंग
GitHubsynacktiv/sccm_sql_backdoor

sccm_sql_backdoor

CVE-2024-43468 और CVE-2025-59213 का शोषण करके SCCM प्रबंधन बिंदु की SQL संग्रहीत प्रक्रिया में एक नियंत्रित बैकडोर स्थापित करें, जिससे HTTP के माध्यम से रिमोट SQL निष्पादन संभव हो सके।

रिपॉजिटरी देखें
362 महीने पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

sccm_sql_backdoor

एक प्रूफ-ऑफ-कॉन्सेप्ट टूल जो Management Point संग्रहीत प्रक्रिया (stored procedure) में एक नियंत्रित बैकडोर डालता है, जिससे एक वैध MP HTTP सेवा के माध्यम से अप्रत्यक्ष SQL निष्पादन संभव होता है।

इंस्टॉलेशन

आप रिपॉजिटरी को क्लोन करके और निर्भरताओं को इंस्टॉल करके इंस्टॉल कर सकते हैं।

root@kitploit:~
$ git clone --recurse-submodules https://github.com/synacktiv/sccm_sql_backdoor
$ cd sccm_sql_backdoor
$ python3 -m venv .venv && source .venv/bin/activate
$ pip install -e .

उपयोग

root@kitploit:~
$ python3 sccm_sql_backdoor.py -h 
usage: sccm_sql_backdoor.py [-h] -t TARGET [-debug] {CVE-2024-43468,CVE-2025-59213,revert} ...

SCCM SQL Backdoor

positional arguments:
  {CVE-2024-43468,CVE-2025-59213,revert}
    CVE-2024-43468      Use CVE-2024-43468 to inject the SPO backdoor
    CVE-2025-59213      Use CVE-2025-59213 to inject the SPO backdoor
    revert              Revert the changes to the original SPO

options:
  -h, --help            show this help message and exit
  -t, --target TARGET   Target (http://sccm-mp.local/)
  -debug                Turn DEBUG output ON

CVE-2025-59213

root@kitploit:~
$ python3 sccm_sql_backdoor.py CVE-2025-59213 -h                
usage: sccm_sql_backdoor.py CVE-2025-59213 [-h] [-a] [-m MARKER] [-k KEY] [-c CERT] [-sk SIGKEY] [-v] -cn CLIENT_NAME [-rs REGISTRATION_SLEEP]

options:
  -h, --help            show this help message and exit
  -a, --altauth         Use the MP's alternate authentication endpoint (Default: False)
  -m, --marker MARKER   Override marker to trigger the backdoor (Default: ABC)
  -k, --key KEY         Private key file for mTLS
  -c, --cert CERT       Certificate file
  -sk, --sigkey SIGKEY  SMS signature key
  -v, --verbose         Verbose output, print requests
  -cn, --client-name CLIENT_NAME
                        Name of the client that will be created in SCCM
  -rs, --registration-sleep REGISTRATION_SLEEP
                        The amount of time, in seconds, that should be waited after registrating a new device (2 seconds by default)

CVE-2024-43468

root@kitploit:~
$ python3 sccm_sql_backdoor.py CVE-2024-43468 -h                  
usage: sccm_sql_backdoor.py CVE-2024-43468 [-h] [-a] [-m MARKER] [-k KEY] [-c CERT]

options:
  -h, --help           show this help message and exit
  -a, --altauth        Use the MP's alternate authentication endpoint (Default: False)
  -m, --marker MARKER  Override marker to trigger the backdoor (Default: ABC)
  -k, --key KEY        Private key file for mTLS
  -c, --cert CERT      Certificate file

revert

root@kitploit:~
$ python3 sccm_sql_backdoor.py revert -h         
usage: sccm_sql_backdoor.py revert [-h] [-m MARKER]

options:
  -h, --help           show this help message and exit
  -a, --altauth        Use the MP's alternate authentication endpoint (Default: False)
  -m, --marker MARKER  Override marker to trigger the backdoor (Default: ABC)
  -k, --key KEY        Private key file for mTLS
  -c, --cert CERT      Certificate file
टूल डाउनलोड करें