Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-0601 PoC — Microsoft Windows CryptoAPI 信任管理问题漏洞

Source
Associated Vulnerability
Title:Microsoft Windows CryptoAPI 信任管理问题漏洞 (CVE-2020-0601)
Description:A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Description
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
File Snapshot

[4.0K] /data/pocs/b8bd7d6d740adef472fb28b833f4dc8dcf07f4a9 ├── [4.0K] docs │   ├── [3.7K] CVE-2020-0601 aka Curveball - meetup content.md │   └── [4.0K] images │   ├── [1.8K] equation1.png │   ├── [ 18K] image-20191031134352945.png │   ├── [ 18K] image-20191031134459649.png │   ├── [ 25K] image-20191031134634258.png │   ├── [ 10K] image-20200303092849710.png │   ├── [ 94K] image-20200303121643424.png │   ├── [147K] image-20200303183406026.png │   ├── [345K] image-20200303183429876.png │   ├── [276K] image-20200303183501587.png │   ├── [ 90K] image-20200303184236548.png │   ├── [102K] image-20200303185302079.png │   ├── [123K] image-20200303185404239.png │   ├── [227K] image-20200303185641879.png │   ├── [ 94K] image-20200303191421925.png │   └── [398K] image-20200303213048034.png └── [4.0K] poc-impl ├── [4.0K] certs │   ├── [ 599] generate_tls_certs.sh │   ├── [1.3K] GlobalSignRootCA.cer │   ├── [1.1K] MicrosoftECCProductRootCertificateAuthority.cer │   └── [ 314] openssl_tls.conf ├── [4.0K] curveball │   └── [1.5K] curveball.c ├── [4.0K] examples │   └── [4.0K] mitm │   ├── [1.9K] mitmServer.js │   ├── [ 257] package.json │   └── [ 183] spoof.cap └── [1.3K] readme.md 7 directories, 25 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →