Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
PoC: CurveBall
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)
PoC: chainoffools
A PoC for CVE-2020-0601
PoC: curveball
CVE-2020-0601 #curveball - Alternative Key Calculator
PoC: badecparams
Proof of Concept for CVE-2020-0601
PoC: cve-2020-0601
Zeek package to detect CVE-2020-0601
PoC: CVE-2020-0601-EXP
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!
PoC: Curveball
PoC for CVE-2020-0601 - CryptoAPI exploit
PoC: CurveballCertTool
PoC for CVE-2020-0601 vulnerability (Code Signing)
PoC: cve-2020-0601-plugin
Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts
PoC: Awesome-CVE-2020-0601
😂An awesome curated list of repos for CVE-2020-0601.
PoC: CVE-2020-0601
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall
PoC: -CVE-2020-0601-ECC---EXPLOIT
CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers can supply hand-rolled generators, bypassing validation, antivirus & all non-protections.
PoC: CVE-2020-0601
CurveBall CVE exploitation
PoC: CVE-2020-0601
Remote Code Execution Exploit
PoC: cve-2020-0601_poc
CVE-2020-0601 proof of concept
PoC: CurveBallDetection
Resources related to CurveBall (CVE-2020-0601) detection
PoC: CurveBall
CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)
PoC: CVE-2020-0601
Curated list of CVE-2020-0601 resources
PoC: twoplustwo
Implementing CVE-2020-0601
PoC: meetup-2-curveball
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
PoC: gringotts
proof of concept for CVE-2020-0601
PoC: PoC_CurveBall
PoC for "CurveBall" CVE-2020-0601
PoC: curveball_lua
Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic
PoC: cve-2020-0601-Perl
Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601
PoC: Windows10_Cumulative_Updates_PowerShell
Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909
PoC: cve-2020-0601-utils
C++ based utility to check if certificates are trying to exploit CVE-2020-0601
PoC: CVE-2020-0601
A Windows Crypto Exploit
PoC: CVE-2020-0601_PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall
PoC: curveball-plus
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
PoC: -Awesome-CVE-2020-0601-
2017-0021
PoC: CurveballCertTool
PoC for CVE-2020-0601 vulnerability (Code Signing)
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free