目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-24576 PoC — Rust 安全漏洞

来源
关联漏洞
标题: Rust 安全漏洞 (CVE-2024-24576)
Description:Rust是美国Mozilla基金会的一款通用、编译型编程语言。 Rust 1.77.2之前版本存在安全漏洞,该漏洞源于没有正确转义Windows上批处理文件的参数,攻击者可以通过绕过转义来执行任意shell命令。
Description
PoC for CVE-2024-24576 vulnerability "BatBadBut"
介绍
# CVE-2024-24576-PoC-BatBadBut

PoC for CVE-2024-24576 vulnerability "BatBadBut"

## Information

After running the script will ask you for an argument, the argument will be passed the the bat file, if you close the argument with " and after that & you can run any Windows command.
For example:
```cmd
helloworld" & whoami
```

As a result, you will get the whoami command.

Of course in real time it would not look like that, this is just PoC for the CVE.

## Usage

Clone the repository:
``` cmd
git clone https://github.com/SheL3G/CVE-2024-24576-PoC-BatBadBut.git
```

Running the script:
```py
Python CVE-2024-24576.py
```
To make it work type something close with " and then "&" and any command like calc.exe, hostname, whoami...
```cmd
HelloWorld" & hostname
```
The Flow of the CVE and the possible way to make it work
![Flow](https://flatt.tech/research/batbadbut-you-cant-securely-execute-commands-on-windows/flowchart.svg)

## Credits

* [NIST](https://nvd.nist.gov/vuln/detail/CVE-2024-24576)

* [flatt.tech](https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/)

* [Mental Outlow](https://www.youtube.com/watch?v=jqsoSmOBFrQ)

## License

[MIT](https://choosealicense.com/licenses/mit/)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →