Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2020-0601 PoC — Microsoft Windows CryptoAPI 信任管理问题漏洞

Source
Associated Vulnerability
Title:Microsoft Windows CryptoAPI 信任管理问题漏洞 (CVE-2020-0601)
Description:A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Description
Zeek package to detect CVE-2020-0601
File Snapshot

[4.0K] /data/pocs/087115d0223d222cda5fd9343a7a79c716695999 ├── [1.4K] COPYING ├── [2.3K] Readme.md ├── [4.0K] scripts │   ├── [1.2K] cve-2020-0601.zeek │   └── [ 27] __load__.zeek ├── [4.0K] testing │   ├── [4.0K] Baseline │   │   ├── [4.0K] scripts.broken │   │   │   └── [ 307] notice.log │   │   ├── [4.0K] scripts.explicit │   │   │   └── [ 283] x509.log │   │   ├── [4.0K] scripts.exploit │   │   │   └── [ 309] notice.log │   │   └── [4.0K] scripts.extract-exploit │   │   ├── [1.5K] cve-2020-0601-certs.log │   │   └── [ 309] notice.log │   ├── [ 423] btest.cfg │   ├── [ 381] diff-remove-timestamps │   ├── [1.3K] get-zeek-env │   ├── [ 15] Makefile │   ├── [ 192] random.seed │   ├── [4.0K] scripts │   │   ├── [ 284] broken.zeek │   │   ├── [ 404] explicit.zeek │   │   ├── [ 285] exploit.zeek │   │   ├── [ 369] extract-exploit.zeek │   │   └── [ 141] non-vul.zeek │   └── [4.0K] Traces │   ├── [3.9K] broken.pcap │   ├── [4.1K] ecdsa-cert.pcap │   ├── [3.9K] explicit.pcap │   └── [3.2K] exploit.pcap └── [ 170] zkg.meta 9 directories, 24 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →