Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cpanel-sessionscribe — Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2. | Kitploit
Tools/GitHubGitHub/rfxn/cpanel-sessionscribe
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability AnalysisExploitationReverse EngineeringForensicsWAF BypassWeb SecurityPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Incident Response
GitHubrfxn/cpanel-sessionscribe

cpanel-sessionscribe

View RepositoryWebsite
141174 months agoNot yet reviewed

About

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.

Share

SessionScribe - CVE-2026-41940

Critical unauthenticated RCE in cPanel & WHM. Four HTTP requests forge a root session via CRLF injection into the password field of a preauth session. No auth, no preconditions, every supported tier affected. Disclosed 2026-04-28 by Sina Kheirkhah / watchTowr Labs.

rfxn.com research article

CVE Severity Disclosed License

Quickstart · ioc-scan · mitigate · remote-probe · Affected builds · Priority order

[!IMPORTANT] Tiers 112, 114, 116, 120, 122, 128 have no vendor patch. Every build on those tiers is vulnerable; upgrade or migrate is the only durable fix. Until then: firewall TCP/2082, 2083, 2086, 2087, 2095, 2096 to management CIDRs (mitigate.sh --apply does this) and front the remaining surface with the ModSec rule pack.


Quickstart

Three oneliners, in operator priority order:

# 1. Are we already compromised?  (on-host IOC scan, fast triage)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash

# 2. Close the window  (idempotent; firewalls cpsrvd ports, deploys ModSec, etc.)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-mitigate.sh | bash -s -- --apply

# 3. Sweep the fleet from anywhere  (non-destructive remote verdict)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-remote-probe.sh | bash -s -- --target HOST

Exit codes are designed for fleet automation: ioc-scan exits 4 on COMPROMISED, 1 on VULNERABLE; mitigate exits 0 clean / 1 applied / 2 manual / 3 tool error; remote-probe exits 2 if any target is VULN.


Tools

In order of operational priority. Every artifact emits structured output (--json / --jsonl / --csv) keyed on host, os, cpanel_version, ts for fleet roll-up.

ToolRoleWhere it runs
sessionscribe-ioc-scan.shFirst-class triage. IOC ladder, code-state + host-state verdicts, kill-chain reconstruction, IR bundle.on the cPanel host
sessionscribe-mitigate.shClose the window. Phased mitigation: patch check, firewall, proxysub, ModSec.on the cPanel host
sessionscribe-remote-probe.shSupporting collateral. Non-destructive 4-stage probe → VULN/SAFE per host.anywhere with curl
modsec-sessionscribe.confModSec rule pack deployed by mitigate.Apache front-end
sessionscribe-revsnap.shPer-tier RE snapshot collector for binary diffing.on the cPanel host, around upcp

GPL v2. All artifacts curl-ready via the raw URLs above.


sessionscribe-ioc-scan.sh - IOC ladder + kill-chain

Run this first. Detection-only by default (fast, fleet-friendly); add --full to run the forensic phases inline (defense timeline, offense ingest, reconcile, kill-chain renderer, IR bundle).

# fast triage  (detection only)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash

# full kill-chain reconstruction inline
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --full

# full + ship IR bundle to intake
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --full --upload

# JSONL for SIEM ingest
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --jsonl --quiet > host.jsonl

# host IOCs only - periodic post-patch sweep, last 7 days
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --ioc-only --since 7

# replay forensic phases against a saved envelope (no re-scan)
curl -fsSL https://raw.githubusercontent.com/rfxn/cpanel-sessionscribe/main/sessionscribe-ioc-scan.sh | bash -s -- --replay /var/cpanel/sessionscribe-ioc/<run_id>.json

Verdicts

Two axes report independently. code_verdict (PATCHED / VULNERABLE / INCONCLUSIVE) comes from version, Perl source patterns, and cpsrvd binary fingerprint. host_verdict (CLEAN / SUSPICIOUS / COMPROMISED) comes from the session-file IOC ladder, access-log scan, and Patterns A–G destruction probes. A patched host can still exit 4 if prior exploitation left IOCs on disk.

ExitCode-stateHost-stateTriage action
0CLEAN/PATCHEDCLEANnone
1VULNERABLE(any)patch cpsrvd
2INCONCLUSIVE(any)manual code-state review (also: tool error)
3(any)SUSPICIOUSreview session/access logs
4(any)COMPROMISEDfull IR; bundle + upload

Sessions tagged with nxesec_canary_<nonce> (left by the remote probe) bucket as PROBE_ARTIFACT and do not escalate to COMPROMISED.

Kill-chain output sample

--full collates every IOC against defense activations and classifies each as PRE-DEFENSE, POST-DEFENSE, POST-PARTIAL, or UNDEFENDED, then summarises with verdict + defense-lag headline. PRE-DEFENSE = host was open to the exploit when the indicator landed; POST-DEFENSE = collateral or pre-mitigation noise.

+-- CVE-2026-41940 / IC-5790 --------------------------------------------
| host         cpanel.example.com ()
| cpanel       unknown   os unknown
| verdict      COMPROMISED   score 315   ioc-scan v2.5.0
| defenses     patch x absent   modsec + up   csf + clean   mitigate + ran
+------------------------------------------------------------------------

  |  -- PRE-DEFENSE (32 events) --
  |  2026-03-25T09:43:19Z  ! pattern X     ioc_attacker_ip_2xx_on_cpsess         57 hit(s) (last 90d) from IC-5790 IPs returned 2xx on /cpsess<N>/ paths - real exploitation
  |  2026-04-28T14:35:56Z  ! pattern X     ioc_cve_2026_41940_crlf_access_chain  15 CRLF-bypass chain(s) — POST /login 401 then GET /cpsess<N> 2xx as root within 2s
  |  2026-04-28T16:38:45Z  ! pattern E     ioc_pattern_e_websocket_shell_hits    45 external IP(s) reached /cpsess*/websocket/Shell with 2xx
  |  2026-04-29T08:41:22Z  ! pattern F     ioc_pattern_f_smark_envelope          __S_MARK__/__E_MARK__ harvester envelope in /root/.bash_history
  |  2026-04-29T16:41:24Z  ! pattern A     ioc_pattern_a_ransom_readme           /home/user1/README.md
  |  …  (22 more Pattern A ransom_readme events across customer homedirs)
  |  2026-04-29T16:42:09Z  ! pattern A     ioc_pattern_a_sorry_files_present     608 .sorry-encrypted files present
  |  2026-04-29T17:52:58Z  ! pattern D     ioc_pattern_d_acctlog_encrypted       /var/cpanel/accounting.log.sorry
Download Tool