Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
exim-rce-cve-2018-6789 — This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works. | Kitploit
Tools/GitHubGitHub/martinclauss/exim-rce-cve-2018-6789
Vulnerability AnalysisExploitationDebuggersLearning & EducationBinary ExploitationLabs & Practice
GitHubmartinclauss/exim-rce-cve-2018-6789

exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

View Repository
117172 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exim RCE (CVE-2018-6789) Learning Environment

Description

This is a set of files, scripts, notes, ... to set up an environment to investigate the Exim RCE (CVE-2018-6789). It can be used to debug Exim, write exploits, trace Exim function calls, learn about Exim's custom memory management (storeblocks), find out how a real-world exploit works, ...

It should only be used for academic purposes!

Requirements

  • Vagrant with libvirt/KVM (the vagrant-libvirt plugin)
  • Docker (only if you decide to run Docker on your host and not inside the Vagrant VM)

Setup

Download Exim's source code by executing

$ git submodule update --init

VM

There is a Vagrantfile in the root directory. It uses libvirt as the virtualization provider. The box is pulled directly from Fedora's mirror via box_url because Vagrant Cloud downloads are currently broken (HCP migration); Fedora only publishes libvirt and VirtualBox boxes there (no VMware), and a direct box_url is provider-specific, so this setup targets libvirt only.

# -*- mode: ruby -*-
# vi: set ft=ruby :

memory = 8192 # in MiB
cpus = 4

Vagrant.configure("2") do |config|
  # Vagrant Cloud downloads are broken; pull the box from Fedora's mirror
  config.vm.box = "fedora-44-cloud-base"
  config.vm.box_url = "https://download.fedoraproject.org/pub/fedora/linux/releases/44/Cloud/x86_64/images/Fedora-Cloud-Base-Vagrant-libvirt-44-1.7.x86_64.vagrant.libvirt.box"

  config.vm.provider "libvirt" do |lv|
    lv.memory = memory
    lv.cpus = cpus
  end

  config.vm.provision "shell", inline: <<-SHELL
  	/vagrant/scripts/setup_vm.sh
  SHELL
end

You can change the configuration as you like but keep in mind that, for example, the setup_vm.sh script uses dnf to install packages. If you want to use Ubuntu you must replace the dnf install lines with apt-get install and adjust the package names accordingly. However, there is no guarantee that the setup will work correctly.

When you are happy with your configuration just run:

$ vagrant up

to set up the machine and after that

$ vagrant ssh

to connect to it. If you don't know how to use Vagrant have a look here: https://www.vagrantup.com/intro/getting-started/

Docker container

Vagrant maps the current directory (i.e. the repository you just cloned) as a shared directory to /vagrant. To create and run the Docker image for Exim enter the following commands inside your VM (vagrant ssh)

[vagrant@localhost ~]$ cd /vagrant
[vagrant@localhost vagrant]$ ./scripts/reset_docker.sh

The first time will take much longer because Exim will be built from source. If you modify debugging scripts or other files that will be copied into the docker container you can always use ./scripts/reset_docker.sh to rebuild the Docker image. Surely, you can also just cut out necessary lines from the script and run them as single commands.

When everything is done you should see a root console:

Successfully tagged exim:latest
787f310ef922a1e519cf8bb47f1c4fed5f510da705e7ceefd48f160c980e969c
root@787f310ef922:/opt#

The weird strings may look different on your machine but you are now in a Debian Docker container running in a Fedora VM on your host machine.

Usage of the VM and the container

First, you can create two SSH sessions with vagrant ssh in two terminal windows. One can be used to run exploits and interact with Exim via SMTP. The other one is used to start, run, debug, ... Exim within the Docker container. ASLR is disabled in the VM so you can set reliable breakpoints that do not change during debugging sessions.

Example session:

First terminal:

$ vagrant ssh
[vagrant@localhost vagrant]$

Second terminal:

$ vagrant ssh
[vagrant@localhost vagrant]$ cd /vagrant
[vagrant@localhost vagrant]$ ./scripts/reset_docker.sh
...
# now you are inside the Debian Docker container
root@99296cf63016:/opt# ./run_exim.sh
root@99296cf63016:/opt# ./attach_exim.sh

The run_exim.sh script exits and Exim runs in the background. The ./attach_exim.sh script should attach gdb to the running Exim daemon process and give you an output like this:

...
pwndbg: loaded 170 commands. Type pwndbg [filter] for a list.
pwndbg: created $rebase, $ida gdb functions (can be used with print/break)

Attaching to process 14
Reading symbols from /usr/exim/bin/exim-4.89_1-1-fc6d6586-XX-1...done.
...
0x00007ffff6b7f5e3 in __select_nocancel () at ../sysdeps/unix/syscall-template.S:84
84	../sysdeps/unix/syscall-template.S: No such file or directory.
Breakpoint 1 at 0x5555555c03d2: file smtp_in.c, line 1762.
Breakpoint 2 at 0x5555555c051d: file smtp_in.c, line 1884.
Breakpoint 3 at 0x55555556a2c8: file base64.c, line 154.
Breakpoint 4 at 0x5555555c6aca: file smtp_in.c, line 3690.

Exim is running and waiting for requests. The breakpoints that were set come from the debugging/breakpoints file. You can use Ctrl+C to interrupt the process and give control to gdb. You could also run one of the provided exploit scripts to test if everything is working as expected:

First terminal:

[vagrant@localhost ~]$ cd /vagrant/sploits/
[vagrant@localhost sploits]$ ./sploit_0.py
[+] Opening connection to localhost on port 25: Done

Second terminal:

Download Tool