emp3r0r 是一款专为 Linux 环境设计、由 Linux 用户开发的 C2(Command and Control,命令与控制)工具。在 4.2.5 版本之前,其 C2 传输层在完成 CBOR 身份验证之前,即接受由攻击者控制的 HTTP 轮询会话。一个未经身份验证的远程攻击者可以创建任意的轮询会话,并发送会被转发至 C2 分派路径的请求体。这可能会消耗服务器资源,并触发认证前的 C2 处理逻辑。该问题已在 4.2.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet