目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-1718 PoC — Bitrix24 安全漏洞

来源
关联漏洞
标题: Bitrix24 安全漏洞 (CVE-2023-1718)
Description:Bitrix24是美国Bitrix公司的一套企业社交平台。该平台包括在线通讯、日历管理和CRM(客户关系管理)等功能。 Bitrix24 22.0.300版本存在安全漏洞,该漏洞源于文件/file.ajax.php的文件流访问不正确,导致攻击者可以通过特制的tmpurl造成拒绝服务(DOS)。
Description
This Python script is designed to exploit a security vulnerability in Bitrix24, leading to a Denial of Service (DoS) attack. The vulnerability, identified as CVE-2023-1718, allows an attacker to disrupt the normal operation of a Bitrix24 instance.
介绍
# Bitrix24 DoS Exploit

This repository contains a Python script designed to exploit a Denial of Service (DoS) vulnerability in Bitrix24. Please note that this script is for educational purposes only, and its use for unauthorized activities is illegal and unethical.

## CVE-2023-1718

- **CVE Identifier**: CVE-2023-1718
- **Vulnerability Type**: Denial of Service (DoS)
- **Target System**: Bitrix24

## Usage

To use this script, follow the instructions below:

1. Clone the repository to your local machine.

2. Install the required dependencies using the following command:

   ```bash
   pip install aiohttp

3. Run the script by providing the necessary command-line arguments:

   ```bash
   python3 bitrix24dos.py --host <Target Host URL> --site_id <SITE_ID Value> --num_requests <Number of Requests>


## Result
![Screenshot 2023-11-07 at 17 20 15](https://github.com/jhonnybonny/Bitrix24DoS/assets/87495218/e6c6af1e-e777-4e31-bbdd-6e4910129a00)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →