Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CallStranger — Callstranger(CVE-2020-12695)漏洞检查器 | Kitploit
工具/GitHubGitHub/yunuscadirci/callstranger
漏洞扫描器物联网安全端口扫描数据泄露网络安全DNS 分析
GitHubyunuscadirci/callstranger

CallStranger

Callstranger(CVE-2020-12695)漏洞检查器

查看仓库
40362205年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CallStranger

此脚本由 Yunus Çadırcı(https://twitter.com/yunuscadirci)创建,用于检测 CallStranger(CVE-2020-12695)漏洞。攻击者可利用此漏洞进行:

  • 绕过 DLP 以窃取数据
  • 利用数百万面向互联网的 UPnP 设备作为放大反射式 TCP DDoS / SYN Flood 的源
  • 从面向互联网的 UPnP 设备扫描内部端口 该脚本仅模拟数据窃取。 详细信息请访问 https://www.callstranger.com https://kb.cert.org/vuls/id/339275 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12695 基础 UPnP 通信使用了 https://github.com/5kyc0d3r/upnpy 的略微修改版本

CallStranger 漏洞

CallStranger 漏洞存在于数十亿 UPnP 设备中,可用于窃取数据(即使具备适当的 DLP/边界安全措施),或扫描网络,甚至使你的网络参与 DDoS 攻击。 该漏洞——CallStranger——由 UPnP SUBSCRIBE 函数中的 Callback 标头值引起,攻击者可控制该值,从而导致类似 SSRF 的漏洞,影响数百万面向互联网的设备及数十亿局域网设备。此漏洞可用于:

  • 绕过 DLP 和网络安全设备以窃取数据
  • 利用数百万面向互联网的 UPnP 设备作为放大反射式 TCP DDoS 的源(与 https://www.cloudflare.com/learning/ddos/ssdp-ddos-attack/ 不同)
  • 从面向互联网的 UPnP 设备扫描内部端口 可能的缓解措施:
  • 禁用不必要的 UPnP 服务,尤其是面向互联网的设备/接口。
  • 检查内网和服务器网络,确保 UPnP 设备(路由器、IP 摄像机、打印机、媒体网关等)不允许数据窃取。
  • 评估网络安全日志,检查该漏洞是否已被威胁行为者利用。
  • 联系 ISP/DDoS 防护供应商,确认其解决方案能否阻断由 UPnP SUBSCRIBE(HTTP NOTIFY)生成的流量。 由于这是一个协议漏洞,供应商可能需要较长时间才能提供补丁。访问 https://callstranger.com 和 https://kb.cert.org/vuls/id/339275 获取详细信息、受影响设备、软件以及后续更新。CVE-2020-12695 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12695 已分配给 CallStranger。 OCF 已于 2020 年 4 月 17 日更新 UPnP 规范以修复此漏洞。查看新规范:https://openconnectivity.org/upnp-specs/UPnP-arch-DeviceArchitecture-v2.0-20200417.pdf

安装

sudo python3 setup.py install

如果需要

sudo pip3 install -r requirements.txt

cryptography requests termcolor

使用

导航至 CallStranger 目录并使用 Python3 运行(已在 Windows 10 上的 Python 3.7.5 和 Kali 2020.2 上的 Python 3.8.2 测试通过) 扫描并测试当前子网:

python3 CallStranger.py

单设备测试:

python3 CallDirect.py http://DeviceDocumentPath

示例:python3 CallDirect.py http://192.168.1.1:37215/upnpdev.xml

脚本工作原理

  1. 发现局域网内所有 UPnP 设备
  2. 查找所有 UPnP 服务
  3. 查找所有订阅端点
  4. 将这些端点加密后通过 UPnP Callback 发送至验证服务器
  5. 由于所有加密均在客户端完成,服务器无法查看这些端点
  6. 从验证服务器获取加密的服务列表,并在客户端解密
  7. 比较找到的 UPnP 服务与已验证的服务

输出示例

_________        .__  .__    _________ __
\_   ___ \_____  |  | |  |  /   _____//  |_____________    ____    ____   ___________
/    \  \/\__  \ |  | |  |  \_____  \   __\_  __ \__  \  /    \  / ___\_/ __ \_  __ \
\     \____/ __ \|  |_|  |__/        \|  |  |  | \// __ \|   |  \/ /_/  >  ___/|  | \/
 \______  (____  /____/____/_______  /|__|  |__|  (____  /___|  /\___  / \___  >__|
        \/     \/                  \/                  \/     \//_____/      \/
This script created by Yunus Çadırcı (https://twitter.com/yunuscadirci) to check against CallStranger (CVE-2020-12695) vulnerability. An attacker can use this vulnerability for:
* Bypassing DLP for exfiltrating data
* Using millions of Internet-facing UPnP device as source of amplified reflected TCP DDoS / SYN Flood
* Scanning internal ports from Internet facing UPnP devices
You can find detailed information on https://www.callstranger.com  https://kb.cert.org/vuls/id/339275 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12695
Slightly modified version of https://github.com/5kyc0d3r/upnpy used for base UPnP communication
Stranger Host: http://20.42.105.45
Stranger Port: 80
!Error in service definition http://192.168.1.24:2869 urn:dial-multiscreen-org:service:dial:1
10  devices found:

 Huawei Home Gateway http://192.168.1.1:37215 ( http://192.168.1.1:37215/upnpdev.xml )

  5 service(s) found for Huawei Home Gateway
     urn:schemas-upnp-org:service:Layer3Forwarding:1    --> http://192.168.1.1:37215/evt/Layer3Forwarding_1
     urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1    --> http://192.168.1.1:37215/evt/WANCommonInterfaceConfig_1
     urn:schemas-upnp-org:service:WANPPPConnection:1    --> http://192.168.1.1:37215/evt/WANPPPConnection_1
     urn:schemas-upnp-org:service:WANEthernetLinkConfig:1       --> http://192.168.1.1:37215/evt/WANEthernetLinkConfig_1
     urn:schemas-upnp-org:service:LANHostConfigManagement:1     --> http://192.168.1.1:37215/evt/LANHostConfigManagement_1

 OturmaTV http://192.168.1.22:2870 ( http://192.168.1.22:2870/dmr.xml )

  3 service(s) found for OturmaTV
     urn:schemas-upnp-org:service:RenderingControl:3    --> http://192.168.1.22:2870/event/RenderingControl
     urn:schemas-upnp-org:service:ConnectionManager:3   --> http://192.168.1.22:2870/event/ConnectionManager
     urn:schemas-upnp-org:service:AVTransport:3         --> http://192.168.1.22:2870/event/AVTransport

 ChromecastOturma4k http://192.168.1.21:8008 ( http://192.168.1.21:8008/ssdp/device-desc.xml )

  1 service(s) found for ChromecastOturma4k
     urn:dial-multiscreen-org:service:dial:1    --> http://192.168.1.21:8008/ssdp/notfound
     --skipping  http://192.168.1.21:8008/ssdp/notfound because it contains dummy service keywords

 VESTEL TV http://192.168.1.40:2870 ( http://192.168.1.40:2870/dmr.xml )

  3 service(s) found for VESTEL TV
     urn:schemas-upnp-org:service:RenderingControl:1    --> http://192.168.1.40:2870/RenderingControl/event
     urn:schemas-upnp-org:service:ConnectionManager:1   --> http://192.168.1.40:2870/ConnectionManager/event
     urn:schemas-upnp-org:service:AVTransport:1         --> http://192.168.1.40:2870/AVTransport/event

 MutfakChromecast http://192.168.1.36:8008 ( http://192.168.1.36:8008/ssdp/device-desc.xml )

  1 service(s) found for MutfakChromecast
     urn:dial-multiscreen-org:service:dial:1    --> http://192.168.1.36:8008/ssdp/notfound
     --skipping  http://192.168.1.36:8008/ssdp/notfound because it contains dummy service keywords

 VESTEL TV http://192.168.1.40:2870 ( http://192.168.1.40:2870/dmr.xml )

  3 service(s) found for VESTEL TV
     urn:schemas-upnp-org:service:RenderingControl:1    --> http://192.168.1.40:2870/RenderingControl/event
     urn:schemas-upnp-org:service:ConnectionManager:1   --> http://192.168.1.40:2870/ConnectionManager/event
     urn:schemas-upnp-org:service:AVTransport:1         --> http://192.168.1.40:2870/AVTransport/event

 DESKTOP-AEE3E5V http://192.168.1.31:2869 ( http://192.168.1.31:2869/upnphost/udhisapi.dll?content=uuid:7ea9d240-fbe4-4ad8-8001-5074901c3695 )

  1 service(s) found for DESKTOP-AEE3E5V
     urn:schemas-upnp-org:service:RenderingControl:1    --> http://192.168.1.31:2869/upnphost/udhisapi.dll?event=uuid:7ea9d240-fbe4-4ad8-8001-5074901c3695+urn:upnp-org:serviceId:RenderingControl

 OturmaTV http://192.168.1.22:49154 ( http://192.168.1.22:49154/nmsDescription.xml )

  2 service(s) found for OturmaTV
     urn:schemas-upnp-org:service:ContentDirectory:3    --> http://192.168.1.22:49154/upnp/event/ContentDirectoryNmsO
     urn:schemas-upnp-org:service:ConnectionManager:2   --> http://192.168.1.22:49154/upnp/event/ConnectionManagerNmsO

 XboxOne http://192.168.1.24:2869 ( http://192.168.1.24:2869/upnphost/udhisapi.dll?content=uuid:e69c8b0b-8a9d-4811-839e-c94650077ee0 )

  0 service(s) found for XboxOne

 XboxOne http://192.168.1.24:2869 ( http://192.168.1.24:2869/upnphost/udhisapi.dll?content=uuid:e4d56268-9801-43d2-b1cf-0dbf71d3c06c )

  3 service(s) found for XboxOne
     urn:schemas-upnp-org:service:RenderingControl:1    --> http://192.168.1.24:2869/upnphost/udhisapi.dll?event=uuid:e4d56268-9801-43d2-b1cf-0dbf71d3c06c+urn:upnp-org:serviceId:RenderingControl
     urn:schemas-upnp-org:service:AVTransport:1         --> http://192.168.1.24:2869/upnphost/udhisapi.dll?event=uuid:e4d56268-9801-43d2-b1cf-0dbf71d3c06c+urn:upnp-org:serviceId:AVTransport
     urn:schemas-upnp-org:service:ConnectionManager:1   --> http://192.168.1.24:2869/upnphost/udhisapi.dll?event=uuid:e4d56268-9801-43d2-b1cf-0dbf71d3c06c+urn:upnp-org:serviceId:ConnectionManager

 Total 20 service(s) found. do you want to continue to VERIFY if service(s) are vulnerable?
下载工具