Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2025-32433-LAB — A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials in the Erlang/OTP SSH server | Kitploit
ツール/GitHubGitHub/damnkrishna/cve-2025-32433-lab
Packet Sniffing & AnalysisVulnerability ScannersContainer SecurityVulnerability AnalysisExploitationNetwork SecurityIntrusion DetectionLearning & EducationLabs & Practice
GitHubdamnkrishna/cve-2025-32433-lab

CVE-2025-32433-LAB

A Flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials in the Erlang/OTP SSH server

リポジトリを見る
2519日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2025-32433 Vulnerability Research & Security Lab

✅ PRE-AUTH RCE CONFIRMED — Exploit successfully demonstrated.
📄 Technical Blog (PDF): CVE-2025-32433-Technical-Blog.pdf
📸 Visual Evidence: screenshots/
🔍 Proof of Concept Details: docs/PROOF_OF_CONCEPT.md

CVE-2025-32433 is a CVSS 10.0 Critical vulnerability in the Erlang/OTP SSH daemon. An unauthenticated attacker can open SSH channels and execute arbitrary commands before completing authentication — zero credentials required.

This lab gives you a fully working, isolated environment to reproduce the vulnerability, run the exploit, verify it, and test detection mechanisms — all on your local machine.


Prerequisites

Before you start, ensure you have the following installed:

ToolMinimum VersionCheck Command
Docker Desktop4.x+docker --version
Docker Composev2.20+docker compose version
Python3.10+python --version

You also need the Python paramiko library for the detection suite:

pip install paramiko

Important Note — Why We Build From Source

Docker Hub's erlang:26.2.5 image tag was silently overwritten with the patched 26.2.5.11 release after CVE-2025-32433 was disclosed. Pulling it from Docker Hub gives you the patched version, not the vulnerable one.

This lab's lab/Dockerfile compiles OTP 26.2.5 directly from the official Erlang GitHub release tarball to guarantee the genuine vulnerable runtime. The first build takes ~10 minutes.


Lab Architecture

                  ┌──────────────────────────────────────────┐
                  │         Isolated Docker Bridge           │
                  │            (cve-lab-bridge)              │
                  └────┬────────────────────────────┬────────┘
                       │                            │
       ┌───────────────┴─────────────┐┌─────────────┴──────────────┐
       │  target_vulnerable          ││  target_patched             │
       │  OTP 26.2.5 (source-built)  ││  erlang:26.2.5.11           │
       │  Host Port: 127.0.0.1:2222  ││  Host Port: 127.0.0.1:2223  │
       └─────────────────────────────┘└─────────────────────────────┘
                                       │
                        ┌──────────────┴──────────────┐
                        │  attacker                   │
                        │  Python 3 + Scapy/Paramiko  │
                        │  Workdir: /work             │
                        └─────────────────────────────┘
ContainerPortOTP VersionStatus
cve-2025-32433-vulnerable127.0.0.1:222226.2.5 (ERTS 14.2.5)❌ Vulnerable
cve-2025-32433-patched127.0.0.1:222326.2.5.11 (ERTS 14.2.5.15)✅ Patched
cve-2025-32433-attackerInternal onlyPython 3 toolingAttacker toolset

Step 1 — Clone the Repository

git clone https://github.com/damnkrishna/CVE-2025-32433-LAB.git
cd CVE-2025-32433-LAB

Step 2 — Build the Vulnerable Container

⏱️ This takes ~10 minutes — it compiles Erlang/OTP 26.2.5 from C source. This is expected. Do not interrupt it.

docker compose build --no-cache target_vulnerable

You will see compiler output like make[1]: Leaving directory '/tmp/otp_src_26.2.5/lib/...' — this is normal. It ends with:

✔ Image ine_cyber_assignment_job-target_vulnerable Built

Step 3 — Build the Patched Container

docker compose build --no-cache target_patched

Step 4 — Start the Lab

docker compose up -d target_vulnerable target_patched

Step 5 — Verify Everything is Running

docker compose ps

Expected output:

NAME                        STATUS              PORTS
cve-2025-32433-vulnerable   Up (healthy)        127.0.0.1:2222->2222/tcp
cve-2025-32433-patched      Up (healthy)        127.0.0.1:2223->2222/tcp

Both containers must show (healthy) before continuing.


Step 6 — Verify the Vulnerable Version

Confirm the container is genuinely running OTP 26.2.5 (not the patched version):

docker exec cve-2025-32433-vulnerable cat /usr/local/otp/lib/erlang/releases/RELEASES

Expected output — must show 14.2.5 with NO .15 suffix:

[{release,"Erlang/OTP","26","14.2.5",
          [{kernel,"9.2.4",...},

If you see 14.2.5.15 — the container image is wrong. Rebuild with --no-cache.


Step 7 — Normal Authenticated SSH Login (Baseline)

Connect as a legitimate user to confirm the server accepts standard authentication:

ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -p 2222 [email protected]

When prompted enter the password: LabPass2026!Secured

You will land in an Erlang shell:

Eshell V14.2.5 (press Ctrl+G to abort, type help(). for help)
1>

Try some commands inside the Erlang shell:

ls().
file:write_file("test.txt", "hello").
file:read_file("test.txt").

To exit the Erlang shell:

q().

Step 8 — Monitor Logs Live (Run This in a Separate Terminal)

Before running the exploit, open a second PowerShell terminal and tail the server log:

Get-Content -Path .\logs\target_vulnerable\ssh.log -Wait -Tail 20

Keep this terminal open. You will see connection events appear in real time.


Step 9 — Run the CVE-2025-32433 Exploit

This is the pre-authentication remote code execution proof of concept. No credentials are used.

cd attacker_work\exploit
python payload.py

Expected output:

[*] Connecting to SSH server...
[+] Received banner: SSH-2.0-Erlang/5.1.4
[*] Sending SSH_MSG_KEXINIT...
[*] Sending SSH_MSG_CHANNEL_OPEN...
[*] Sending SSH_MSG_CHANNEL_REQUEST (pre-auth)...
[✓] Exploit sent! If the server is vulnerable, it should have written to /lab.txt.
[+] Received response: 000003d4...

The banner must show SSH-2.0-Erlang/5.1.4 (no .15 suffix) to confirm you hit the vulnerable server.


Step 10 — Verify the Exploit Worked

docker exec cve-2025-32433-vulnerable cat /lab.txt

Expected output:

pwned

If you see pwned — CVE-2025-32433 pre-authentication RCE is confirmed. The exploit wrote to the container filesystem with zero credentials.


Step 11 — Confirm Patched Container is NOT Vulnerable

Run the same exploit against the patched container on port 2223:

Edit attacker_work\exploit\payload.py line 6:

PORT = 2223   # change from 2222 to 2223

Run the exploit:

python payload.py

Then check for the file:

docker exec cve-2025-32433-patched cat /lab.txt

Expected output:

cat: /lab.txt: No such file or directory

The patched container rejects the unauthenticated channel request. No file written = patched.

Restore payload.py port back to 2222 when done.


Step 12 — Run the Detection Suite

Go back to the repo root:

cd ..\..

Option A: Version Banner Scanner (checks if target is vulnerable by SSH banner)

Scan the vulnerable target:

python detection\detect_cve_2025_32433.py 127.0.0.1 2222

Scan the patched target:

python detection\detect_cve_2025_32433.py 127.0.0.1 2223

Option B: Host Process & File Integrity Monitor

Monitors the container process table for unexpected child processes spawned by Erlang (e.g. shell processes that indicate RCE):

python detection\host_process_monitor.py
ツールをダウンロード