CitrixBleed2 poc
# CVE-2025-5777
(AKA CitrixBleed 2) Is an OOB read in the login process of Citrix Gateway. <br>
This is a Proof of Concept exploiting the OOB (CVE-2025-5777) to obtain memory data from a vulnerable Citrix Gateway instance, possibly leading to cookies/credentials theft.
## Usage
I highly recommend using a `venv` when using the script. <br>
```
usage: main.py [-h] [-t THREADS] [-o OUTPUT] url
positional arguments:
url target URL
options:
-h, --help show this help message and exit
-t THREADS, --threads THREADS
number of threads [10]
-o OUTPUT, --output OUTPUT
output file [leak.dump]
```
## Technical details
An amazing writeup by [@watchTowr](https://twitter.com/watchtowrcyber) || [watchtowr writeup](https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/)
登录后查看神龙缓存的 POC 文件快照
登录查看