
SCAN END POC THE CVE-2024-4367
⚠️ 중요 보안 도구 | CVE-2024-4367(CVSS 9.8) - PDF.js 원격 코드 실행(RCE) 취약점 탐지
모든 웹사이트에서 작동 - 별도 설정 불필요
CVE-2024-4367은 PDF.js(4.2.67 미만 버전)의 치명적인 취약점으로, 악성 PDF 파일을 통해 임의 JavaScript 실행을 허용합니다. 이 스캐너는 모든 웹사이트에서 취약한 PDF.js 인스턴스를 자동으로 탐지합니다.
PDF.js에는 PDF 파일에 포함된 JavaScript가 적절한 샌드박싱 없이 실행되는 결함이 있어, 공격자가 다음을 수행할 수 있습니다:
F12를 눌러 DevTools를 엽니다Enter를 누릅니다이 URL로 북마크를 생성합니다:
javascript:(function(){const s=document.createElement('script');s.src='https://cdn.jsdelivr.net/gh/yourusername/CVE-2024-4367-Scanner/scanner.js';document.body.appendChild(s);})();
git clone https://github.com/yourusername/CVE-2024-4367-Scanner
cd CVE-2024-4367-Scanner
# Open any website and run the script
<embed> 요소<object> 데이터 태그?pdf=, ?file=, ?src=).pdf를 허용하는 파일 입력 필드┌─────────────────────────────────────────────────────────────┐
│ SCAN PROCESS FLOW │
├─────────────────────────────────────────────────────────────┤
│ │
│ 1. 📚 LOAD SCRIPTS │
│ ├─ External scripts (all <script src="">) │
│ └─ Inline scripts (all <script> tags) │
│ │
│ 2. 🔍 EXTRACT PDF.JS VERSION │
│ ├─ Pattern matching in code │
│ ├─ Package.json detection │
│ └─ Node_modules path parsing │
│ │
│ 3. 🎯 IDENTIFY VULNERABILITY │
│ ├─ version < 4.2.67 ? → VULNERABLE │
│ └─ version = 2.16.105 ? → VULNERABLE │
│ │
│ 4. 🖼️ LOCATE VIEWERS │
│ ├─ DOM element scanning │
│ └─ Attribute detection │
│ │
│ 5. ⚡ GENERATE POC │
│ ├─ Create test PDF │
│ └─ Provide download link │
│ │
│ 6. 📊 DISPLAY RESULTS │
│ ├─ Visual overlay │
│ ├─ Console report │
│ └─ Global variable storage │
│ │
└─────────────────────────────────────────────────────────────┘
╔═══════════════════════════════════════════════════════════════════════════════════╗
║ CVE-2024-4367 - UNIVERSAL PDF.js SCANNER ║
║ Detects vulnerable PDF.js versions and potential exploitation ║
╚═══════════════════════════════════════════════════════════════════════════════════╝
📚 PHASE 1: Scanning JavaScript Bundles for PDF.js
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[+] Found 42 external scripts
[+] Found 12 inline scripts
[1/42] Analyzing: vendor.bundle.js
→ PDF.js indicator found: pdfjs-dist
✅ PDF.js version found: 2.16.105
🚨 VULNERABLE to CVE-2024-4367!
🎯 PHASE 4: Identifying Exploitation Vectors
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠️ URL parameter accepts PDF: file=/documents/report.pdf
⚠️ PDF upload form found
█████████████████████████████████████████████████████████████████████████████████
FINAL SCAN REPORT
█████████████████████████████████████████████████████████████████████████████████
🚨 CRITICAL VULNERABILITY CONFIRMED!
CVE: CVE-2024-4367
CVSS: 9.8 (CRITICAL)
Impact: Arbitrary JavaScript Execution
┌─────────────────────────────────────────────────────────────┐
│ CVE-2024-4367 SCAN RESULTS │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 📍 Target: example.com │
│ 📦 PDF.js: 2.16.105 │
│ 🎯 Vulnerable: YES │
│ 📄 Viewers: 3 │
│ ⚡ Vectors: 2 │
│ ━━━━━━━━━━━━━━━━━━━━━━━ │
│ 🔴 CRITICAL - Upgrade Required │
└─────────────────────────────────────────────────────────────┘
# For Node.js projects
npm install pdfjs-dist@latest
# For CDN usage
# Update to version 4.2.67 or higher
// Set this before loading PDF.js
pdfjsLib.GlobalWorkerOptions.disableJavaScript = true;
Content-Security-Policy: script-src 'self';
object-src 'none';
worker-src 'none'
// Validate PDF files before rendering
function validatePDF(file) {
// Check magic bytes
const header = file.slice(0, 5);
if (header !== '%PDF-') {
throw new Error('Invalid PDF file');
}
// Scan for JavaScript
const text = file.toString();
if (text.includes('/JavaScript') ||
text.includes('/JS') ||
text.includes('<< /S /JavaScript >>')) {
throw new Error('PDF contains JavaScript');
}
}
| 해결 방법 | 난이도 | 효과 |
|---|---|---|
| PDF.js 업그레이드 | 쉬움 | ✅ 완전한 해결 |
| PDF.js에서 JS 비활성화 | 쉬움 | ✅ 완전한 해결 |
| CSP 구현 | 보통 | ✅ 양호 |
| 서버측 검증 | 보통 | ✅ 양호 |
| 샌드박스 렌더링 | 어려움 | ✅ 탁월 |
URL 매개변수
/viewer?file=malicious.pdf
/download?pdf=malicious.pdf
파일 업로드
<input type="file" accept=".pdf">