
가상 채널 주입을 통한 RDP 클립보드 하이재킹용 CVE-2026-7070 PoC; 데이터 탈취/자격 증명 가로채기를 위한 시뮬레이션 서버 및 익스플로잇 스크립트를 포함합니다.
# rdp_server_sim.py - Simulated RDP server with trusted virtual channel
from http.server import HTTPServer, BaseHTTPRequestHandler
import json, threading
clipboard = ""
# Simulate an RDP virtual channel that any client can open and write to.
# In real RDP, the CLIPRDR channel is used for clipboard sync.
class RDPHandler(BaseHTTPRequestHandler):
def do_POST(self):
global clipboard
if self.path == '/clipboard':
data = json.loads(self.rfile.read(int(self.headers['Content-Length'])))
# Vulnerability: accepts clipboard updates from any channel without auth
clipboard = data['content']
self.send_response(200)
self.end_headers()
self.wfile.write(b"Clipboard updated")
else:
self.send_response(404)
self.end_headers()
def do_GET(self):
if self.path == '/clipboard':
self.send_response(200)
self.end_headers()
self.wfile.write(clipboard.encode())
else:
self.send_response(404)
self.end_headers()
server = HTTPServer(('0.0.0.0', 3389), RDPHandler) # using HTTP for simulation
print("RDP clipboard simulator on :3389")
server.serve_forever()
RDP 서버는 적절한 접근 제어 없이 모든 가상 채널 연결을 신뢰합니다. RDP 세션에 연결할 수 있는 공격자는 (낮은 권한의 사용자라도) 악성 가상 채널을 주입하고 공유 클립보드를 변조하여 데이터 도난이나 자격 증명 가로채기로 이어질 수 있습니다.
python rdp_server_sim.py
python exploit_rdp_clipboard.py