Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
elegant-bouncer — ELEGANTBOUNCER 是一款用于检测基于文件的移动端漏洞利用的工具。 | Kitploit
工具/GitHubGitHub/msuiche/elegant-bouncer
iOS安全漏洞分析移动取证恶意软件分析数字取证移动安全二进制分析
GitHubmsuiche/elegant-bouncer

elegant-bouncer

ELEGANTBOUNCER 是一款用于检测基于文件的移动端漏洞利用的工具。

查看仓库
1771111个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

替代文本

ELEGANTBOUNCER

ELEGANTBOUNCER 是一款用于检测基于文件的移动端漏洞的工具。

它采用创新的方法进行高级的基于文件的威胁识别,无需在野样本,且优于基于正则表达式或 IOC 的传统方法。目前,它主要针对识别诸如 FORCEDENTRY (CVE-2021-30860)、BLASTPASS (CVE-2023-4863、CVE-2023-41064) 和 TRIANGULATION (CVE-2023-41990) 等移动端漏洞。

支持表

威胁名称CVE 编号是否支持
FORCEDENTRYCVE-2021-30860✅
BLASTPASSCVE-2023-4863, CVE-2023-41064✅
TRIANGULATIONCVE-2023-41990✅
CVE-2025-43300CVE-2025-43300✅

检测工具的输出

了解更多

  • FORCEDENTRY
  • BLASTPASS

终端用户界面

ELEGANTBOUNCER TUI - 实时并行扫描可视化

TUI 模式提供并行扫描操作的实时可视化,可同时显示所有活动的工作线程。在扫描目录时使用 --tui 标志启用它。

快速开始

root@kitploit:~
elegant-bouncer v0.2
ELEGANTBOUNCER Detection Tool
Detection tool for file-based mobile exploits.

A utility designed to detect the presence of known mobile APTs in commonly distributed files.

Usage: elegant-bouncer [OPTIONS] <Input path>

Arguments:
  <Input path>
          Path to the input file or folder

Options:
  -v, --verbose
          Print extra output while parsing

  -s, --scan
          Assess a given file or folder, checking for known vulnerabilities

  -c, --create-forcedentry
          Create a FORCEDENTRY-like PDF

  -r, --recursive
          Recursively scan subfolders

  -m, --messaging
          Scan messaging app databases for attachments (iOS backup format)

  --ios-extract
          Extract/reconstruct iOS backup to readable folder structure

  -o, --output <OUTPUT>
          Output directory for iOS backup extraction

  -f, --force
          Force overwrite of output directory if not empty

  -e, --extensions <EXTENSIONS>
          File extensions to scan (comma-separated, e.g., "pdf,webp,ttf")
          Default: pdf,gif,webp,jpg,jpeg,png,tif,tiff,dng,ttf,otf

  -h, --help
          Print help information (use `-h` for a summary)

  -V, --version
          Print version information

扫描文件和文件夹

单文件扫描

使用 --scan 检查单个文件是否存在已知漏洞:

root@kitploit:~
elegantbouncer --scan suspicious_file.pdf

文件夹扫描

扫描目录中的所有受支持文件:

root@kitploit:~
elegantbouncer --scan /path/to/folder

递归文件夹扫描

使用 -r 标志递归扫描所有子目录:

root@kitploit:~
elegantbouncer --scan /path/to/folder -r

自定义文件扩展名

使用 -e 标志指定要扫描的文件类型:

root@kitploit:~
# Scan only PDF and DNG files
elegantbouncer --scan /path/to/folder -e pdf,dng

# Scan only image files recursively
elegantbouncer --scan /path/to/folder -r -e jpg,jpeg,png,webp,gif

默认扩展名

默认情况下,该工具会扫描具有以下扩展名的文件:

  • 文档:pdf
  • 图像:gif、webp、jpg、jpeg、png、tif、tiff、dng
  • 字体:ttf、otf

示例输出

扫描目录时,该工具提供:

  • 实时进度更新
  • 即时威胁检测通知
  • 包含所有漏洞类型的摘要表
  • 详细的感染文件表,包含:
    • 文件路径
    • 威胁名称
    • 关联的 CVE 编号
root@kitploit:~
[+] Scanning directory: /path/to/documents
[+] Recursive mode enabled
[+] Extensions: pdf, gif, webp, jpg, jpeg, png, tif, tiff, dng, ttf, otf

[1] Scanning: /path/to/documents/invoice.pdf
[2] Scanning: /path/to/documents/photo.jpg
[3] Scanning: /path/to/documents/malicious.webp
  └─ THREAT found: BLASTPASS
[4] Scanning: /path/to/documents/report.pdf
  └─ THREAT found: FORCEDENTRY

[+] Scanned 4 files

[+] Summary Results:
╭────────────────┬───────────────────────────────┬──────────────────────────────────────────────────────────────────────────┬──────────╮
│ name           │ cve_ids                       │ description                                                              │ detected │
├────────────────┼───────────────────────────────┼──────────────────────────────────────────────────────────────────────────┼──────────┤
│ FORCEDENTRY    │ CVE-2021-30860                │ Malicious JBIG2 PDF shared over iMessage                                 │ Yes      │
│ BLASTPASS      │ CVE-2023-4863, CVE-2023-41064 │ Malicious WebP presumably shared over iMessage and other mediums         │ Yes      │
│ TRIANGULATION  │ CVE-2023-41990                │ Maliciously crafted TrueType font embedded in PDFs shared over iMessage  │ No       │
│ CVE-2025-43300 │ CVE-2025-43300                │ Malicious DNG with JPEG Lossless compression exploiting RawCamera.bundle │ No       │
╰────────────────┴───────────────────────────────┴──────────────────────────────────────────────────────────────────────────┴──────────╯

[!] Infected Files Details:
╭────────────────────────────────┬─────────────┬───────────────────────────────╮
│ path                           │ threat_name │ cve_ids                       │
├────────────────────────────────┼─────────────┼───────────────────────────────┤
│ /path/to/documents/report.pdf  │ FORCEDENTRY │ CVE-2021-30860                │
│ /path/to/documents/malicious.webp │ BLASTPASS   │ CVE-2023-4863, CVE-2023-41064 │
╰────────────────────────────────┴─────────────┴───────────────────────────────╯

iOS 备份分析

提取 iOS 备份结构

将 iOS 备份重建为可读的文件夹结构:

root@kitploit:~
# Extract backup to default location (creates _reconstructed folder)
elegantbouncer --ios-extract /path/to/ios/backup

# Extract to specific output directory
elegantbouncer --ios-extract /path/to/ios/backup -o /path/to/output

# Force overwrite if output directory exists
elegantbouncer --ios-extract /path/to/ios/backup -o /path/to/output --force

扫描消息应用附件

扫描 iOS 备份中消息应用里的恶意附件:

root@kitploit:~
# Scan messaging databases (iMessage, WhatsApp, Viber, Signal, Telegram)
elegantbouncer --scan --messaging /path/to/ios/backup

# Combine with extraction for complete analysis
elegantbouncer --ios-extract /path/to/ios/backup -o /tmp/extracted
elegantbouncer --scan --messaging /tmp/extracted

此功能可检测来自以下位置的附件威胁:

  • iMessage - SMS/MMS 数据库附件
  • WhatsApp - 聊天中的媒体文件
  • Viber - 共享文件和媒体
  • Signal - 附件文件夹(数据库已加密)
  • Telegram - 缓存媒体文件

create-forcedentry

使用 --create-forcedentry 从零开始生成一个旨在利用 CVE-2021-30860 的 PDF。此功能仍在开发中。

注意:可在 samples/ 目录中找到预制样本。

建议

如果您认为自己有可能是重点目标,请使用 锁定模式 来减少攻击面。

致谢

  • Hamid K. (@Hamid-K) 感谢其对消息应用扫描和 iOS 备份重建的原始实现
  • 卡巴斯基的 Valentin Pashkov、Mikhail Vinogradov、Georgy Kucherin (@kucher1n)、Leonid Bezvershenko (@bzvr_) 和 Boris Larin (@oct0xor)
  • Apple Security Engineering and Architecture (SEAR)
  • Bill Marczack
  • Jeff 帮助我理解了 FORCEDENTRY
  • Valentina 建议选择这个目标
  • Ian Beer 和 Samuel Groß(Google Project Zero)对 Citizen Lab 与他们共享的样本撰写了精彩的分析
  • @mistymntncop 感谢我们的交流以及他在 CVE-2023-4863 上的工作
  • Ben Hawkes

参考资料

  • 检测 CVE-2025-43300:深入剖析苹果的 DNG 处理漏洞
  • 研究 Triangulation:使用单字节签名检测 CVE-2023-41990。
  • 研究 FORCEDENTRY:在无样本情况下检测漏洞利用
  • 研究 BLASTPASS:检测 WebP 文件中的漏洞利用 - 第 1 部分
  • 研究 BLASTPASS:分析 Apple 和 Google 的 WebP POC 文件 - 第 2 部分
下载工具