CVE-2024-41570 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the demon callback handling component of Havoc 2 0.7. The flaw allows an attacker to send arbitrary network requests from the team server by exploiting the callback mechanism, without requiring authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a two-file Python proof-of-concept/operational exploit repository: README.md documents the chain and havoc_pwn.py implements it. It combines the Havoc SSRF issue identified as CVE-2024-41570 with an authenticated Havoc payload-creation command injection. The script uses AES-CTR helpers and manually formatted Havoc Demon protocol packets to register a fake agent, issue a socket-open request, and relay data to an attacker-selected IPv4 TCP service. It then uses manually created WebSocket traffic over that relayed socket to authenticate to the Havoc teamserver, create a random-named listener, and submit repeated user-supplied commands as a malicious Service-Name during Demon payload creation. No fixed external IP address, hostname, URL, credential, or filesystem/registry persistence target is embedded; primary network destinations and credentials are supplied at runtime. The code is not a framework module and is not merely a scanner: its interactive loop provides authenticated remote command execution if the stated deployment conditions are met.
This repository contains a Python proof-of-concept exploit for CVE-2024-41570, targeting the Havoc C2 Team Server's WebSocket interface. The exploit automates the process of agent registration, WebSocket handshake, authentication, and command injection to achieve remote code execution (RCE) via a crafted WebSocket payload. The main file, 'exploit.py', is a standalone script that takes command-line arguments for the target URL, credentials, and listener details. It uses the 'requests' and 'pycryptodome' libraries to interact with the target and perform AES encryption/decryption as required by the protocol. The exploit ultimately delivers a reverse shell payload, causing the target to connect back to the attacker's listener (typically set up with netcat). The repository is structured with a README providing usage instructions, a requirements.txt for dependencies, and a permissive MIT license. No hardcoded external endpoints are present; all targets are supplied at runtime. The exploit is a functional PoC and not weaponized, as it requires manual setup and does not provide advanced evasion or automation features.
This repository provides an operational exploit for CVE-2024-41570, a chained remote code execution (RCE) vulnerability in the Havoc C2 Teamserver (versions 0.3 to 0.6). The exploit leverages a combination of SSRF and authenticated command injection vulnerabilities. The attacker first spoofs a demon agent registration and check-in to open a TCP socket on the teamserver, then delivers a command injection payload via a crafted JSON request. The injected command downloads and executes a bash script (payload.sh) from the attacker's HTTP server, which opens a reverse shell back to the attacker using netcat. The repository contains four files: a README.md with usage instructions, exploit.py (the main exploit logic in Python), payload.sh (the reverse shell payload), and requirements.txt (Python dependencies). The exploit requires the attacker to modify configuration variables (target URL, credentials, IP addresses) and to host the payload and listener. The main attack vector is network-based, targeting the Havoc C2 Teamserver over HTTP(S).
This repository contains a Python exploit for CVE-2024-41570, targeting Havoc C2 Framework version 0.7. The exploit leverages two vulnerabilities: an unauthenticated SSRF (Server-Side Request Forgery) and an authenticated Remote Code Execution (RCE). The main script, 'CVE-2024-41570.py', allows an attacker to spoof agent registration and interact with the teamserver by crafting and sending custom AES-encrypted packets. The SSRF component can leak internal information such as the origin IP of the teamserver. If valid credentials are provided, the script can escalate to RCE by injecting arbitrary commands into the 'Service Name' field of a configuration payload, which is then executed on the server. The exploit requires the attacker to specify the target teamserver URL, credentials, and other agent parameters. The repository also includes a README with usage instructions and references to the original PoCs and research. The exploit is operational and demonstrates both SSRF and RCE capabilities against the specified version of Havoc C2.
This repository contains a Python exploit (exploit.py) and a Bash payload (payload.sh), along with a README.md that provides usage instructions. The exploit targets a remote service accessible via HTTPS (example: https://10.10.11.49/). The attacker is instructed to host the payload.sh file on an HTTP server (port 8000) and listen for a reverse shell on port 4444. The exploit.py script crafts and sends custom AES-encrypted requests to a 'teamserver' listener, registering an agent and manipulating sockets to achieve code execution on the target. The payload delivered is a Bash reverse shell, which connects back to the attacker's listener. The exploit demonstrates operational maturity, as it automates the attack chain and delivers a working shell, but does not appear to be part of a larger exploitation framework. The main attack vector is network-based, leveraging HTTP(S) requests and reverse shell callbacks. Notable endpoints include the target URL, the attacker's IP and ports, and the HTTP location for the payload.
This repository contains a proof-of-concept exploit (exploit.py) for CVE-2024-41570, a server-side request forgery (SSRF) vulnerability in Havoc C2 version 0.7. The exploit works by spoofing a demon agent registration and check-in to the teamserver, then opening a TCP socket on the teamserver and sending arbitrary data through it. This can be used to leak the origin IPs of teamservers and potentially interact with internal services accessible from the teamserver. The exploit is implemented in Python and requires the attacker to specify the target teamserver's listener URL, the IP and port to connect to, and optional parameters for the spoofed agent. The repository also includes a README.md with usage instructions, a mitigation hotpatch for the teamserver, and links to further analysis. The main attack vector is network-based, targeting the HTTP(S) listener of the Havoc C2 teamserver. The exploit is a functional proof-of-concept and does not include weaponized payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.