Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Detections-CVE-2026-23918 — Regole di rilevamento per CVE-2026-23918 Apache http2 RCE - Crediti: stringa.ai, isec.pl | Kitploit
Strumenti/GitHubGitHub/insomnisec/detections-cve-2026-23918
Gestione degli Indicatori di Compromissione (IOC)Analisi delle VulnerabilitàExploitEvasione IDS/IPSSicurezza WebSicurezza di ReteThreat IntelligenceRilevamento IntrusioniRisposta agli Incidenti

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Archived
GitHubinsomnisec/detections-cve-2026-23918

Detections-CVE-2026-23918

Regole di rilevamento per CVE-2026-23918 Apache http2 RCE - Crediti: stringa.ai, isec.pl

Vedi Repository
93 mesi faNon ancora revisionato
Condividi

MIGRAZIONE VERSO: https://github.com/insomnisec/public_cve_detections

PER UNA MIGLIORE GESTIONE A LUNGO TERMINE DELLE PUBBLICAZIONI DI DETECTION

QUESTO REPO VERRÀ RIMOSSO A GIUGNO 2026

PER FAVORE UTILIZZA L'ALTRO REPO D'ORA IN POI

CVE-2026-23918 "Apache HTTP/2 Double-Free" — Pacchetto di Rilevamento e Risposta

Pubblicato: 2026-05-04
CVSSv3: 8.8 (Alto)
Tipo: Esecuzione di codice remoto / Denial of Service (corruzione della memoria double-free) Apache HTTP Server (percorso di pulizia dello stream in ) Apache HTTP Server 2.4.66 con HTTP/2 abilitato e MPM multi-threaded


Componente:
mod_http2
h2_mplx.c

Interessato:

Riferimenti:
  • Avviso di sicurezza di Apache HTTP Server
  • Segnalazione oss-security
  • Analisi tecnica di Hadrian
  • Copertura di insomnisec

Indice

  1. Sommario della vulnerabilità
  2. Come funziona l'exploit
  3. Architettura di rilevamento — Perché questo pacchetto differisce dai pacchetti LPE
  4. Limitazioni del rilevamento
  5. Mitigazione immediata
  6. Regole Suricata
  7. Configurazione ModSecurity / Coraza
  8. Regole Auditd
  9. Regole Wazuh
  10. Regole YARA
  11. Modello di evento MISP
  12. Patch e rimedio
  13. Riferimento chiave IoC

Sommario della vulnerabilità

CVE-2026-23918 è una vulnerabilità di corruzione della memoria double-free nell'implementazione del protocollo HTTP/2 di Apache HTTP Server 2.4.66, che interessa solo il percorso di pulizia dello stream del modulo mod_http2 in h2_mplx.c. Consente a un attaccante remoto non autenticato di mandare in crash i processi worker di Apache (Denial of Service) con una singola connessione TCP e due frame HTTP/2. In condizioni presenti sui sistemi derivati da Debian e sulle immagini Docker ufficiali di Apache, il double-free può essere trasformato in una piena esecuzione di codice remoto.

Lo sfruttamento del DoS è stato confermato in ambienti reali. Sono state osservate scansioni Internet su larga scala rivolte a endpoint HTTP/2. L'exploit RCE si è dimostrato utilizzabile in ambienti controllati, anche se al momento non vi è alcuna evidenza di sfruttamento pubblico diffuso per la RCE.

MPM prefork non è interessato: la vulnerabilità richiede una configurazione MPM multi-threaded (worker, event o simile). CVE-2026-23918 interessa solo Apache HTTP Server versione 2.4.66.


Come funziona l'exploit```

Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream

Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup

Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE

c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption

DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption

RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE

root@kitploit:~
> **Asimmetria chiave:** Il percorso DoS non richiede competenze di manipolazione dell'heap ed è già oggetto di sfruttamento attivo. Il percorso RCE è tecnicamente impegnativo, ma è stato dimostrato in condizioni di laboratorio e sarà quasi certamente armato nel prossimo futuro, dato l'indirizzo fisso dello scoreboard resistente ad ASLR.

---

## Architettura di rilevamento

> Questa sezione spiega perché gli strumenti di rilevamento qui differiscono sostanzialmente da un tipico pacchetto di escalation dei privilegi locali.

Copy Fail (CVE-2026-31431) era una vulnerabilità **lato host, post-accesso**. L'attaccante necessitava di una presenza già attiva sul sistema. Il rilevamento risiedeva principalmente a livello di syscall (auditd, Wazuh) con scansione YARA dello script PoC su disco.

CVE-2026-23918 è una vulnerabilità **lato rete, pre-accesso**. L'exploit arriva come frame del protocollo HTTP/2 sulla rete prima che venga eseguito qualsiasi codice applicativo. Questo sposta in modo significativo lo stack di rilevamento:

| Livello | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **Rilevamento primario** | Regole syscall di Auditd | Regole di rete Suricata |
| **WAF (ModSecurity)** | Limitato — non vede l'exploit | Rilevante — anomalia + post-exploit |
| **Auditd** | Rilevamento principale | Rilevamento degli esiti (crash, post-exploit) |
| **YARA** | Cerca lo script PoC | Cerca web shell (artefatti post-exploit) |
| **IDS di rete** | Non applicabile | Livello di rilevamento di prima classe |
| **Ispezione TLS** | N/D | Necessaria per una copertura Suricata completa |

La regola pratica: per una RCE a livello di rete, lavorare dall'esterno verso l'interno (rete → WAF → host). Per l'escalation dei privilegi locale, lavorare dall'host verso l'esterno.

---

## Limiti del rilevamento

> **Leggere questo prima di distribuire qualsiasi regola.**

**1. TLS termina la visibilità HTTP/2.**
La maggior parte delle distribuzioni Apache in produzione servono HTTPS. Suricata non può ispezionare il contenuto dei frame HTTP/2 cifrati senza che sia configurata la decifratura TLS. Se la tua distribuzione Suricata non ha accesso alle chiavi di sessione TLS o a un mirror di decifratura, le regole a livello di rete di seguito rileveranno solo:
- HTTP/2 in chiaro (h2c) — poco comune in produzione ma presente in ambienti interni
- La firma di rete del comportamento delle connessioni TCP (numero di connessioni, pattern RST a livello TCP)

Per le distribuzioni HTTPS, abilita la decifratura TLS di Suricata tramite l'impostazione `tls-decrypt` e la registrazione delle chiavi di sessione, oppure affidati ai livelli WAF (ModSecurity/Coraza) e host-based (auditd/Wazuh).

**2. ModSecurity non può bloccare l'innesco dell'exploit.**
Il double-free avviene all'interno del parser dei frame HTTP/2, prima che una richiesta HTTP completa venga assemblata e passata a ModSecurity. Il WAF vede la richiesta solo dopo il completamento del parsing dei frame — a quel punto il danno potrebbe essere già fatto. ModSecurity in questo pacchetto è usato per il rilevamento delle anomalie, il rate limiting e il rilevamento post-exploitation, non come blocco per l'innesco.

**3. MPM prefork non è interessato.**
Se la tua distribuzione Apache utilizza `mpm_prefork_module` (mono-thread), questa vulnerabilità non si applica. Il bug si manifesta solo negli MPM multi-thread (`mpm_event_module` o `mpm_worker_module`). Verifica con `apachectl -V | grep MPM` prima di distribuire regole che produrrebbero falsi positivi su server prefork.

**4. La RCE richiede l'allocatore mmap.**
Il percorso RCE (non quello DoS) richiede l'allocatore mmap di APR, che è quello predefinito nelle distribuzioni derivate da Debian e nelle immagini Docker ufficiali di Apache. Le distribuzioni basate su RHEL/CentOS che utilizzano jemalloc o la malloc di sistema hanno un rischio RCE ridotto, ma sono comunque pienamente vulnerabili al DoS.

**5. Nessun IoC post-exploitation stabile finora.**
Al momento della stesura di questo documento non esistono IoC pubblicati dai vendor per l'attività post-exploitation. Le regole YARA e le regole auditd mirate al comportamento post-exploitation si basano su pattern generali di web shell ed escalation dei privilegi — cattureranno gli esiti più comuni, ma non un payload sofisticato e personalizzato.

---

## Mitigazione immediata

Applicare in ordine di preferenza. Ciascuna è più dirompente della precedente, ma anche più completa.```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below

# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
#   Remove or comment out:  Protocols h2 h2c http/1.1
#   Replace with:           Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2

# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2

# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
#   nginx: proxy_http_version 1.1; (already the default for upstream connections)
#   HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly

Verifica la mitigazione: Dopo aver disattivato HTTP/2, conferma con:

root@kitploit:~
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/
# Should return "1.1", not "2"
apachectl -M | grep http2
# Should produce no output

Regole Suricata

Salva come cve-2026-23918.rules e referenzia da suricata.yaml.

Prerequisiti:

  • Suricata 6.0+ per il supporto delle keyword http2.frametype / http2.errorcode (consigliata Suricata 7.x)
  • app-layer.protocols.http2.enabled: yes in suricata.yaml
  • Decrittazione TLS configurata per la copertura HTTPS (vedi Limitazioni di Rilevamento sopra)
  • Variabile $HTTP_SERVERS impostata per includere i tuoi host Apache
  • Le SID di seguito sono esempi — adattale alla tua policy SID locale```

=============================================================

CVE-2026-23918 Apache HTTP/2 Double-Free — Suricata Rules

=============================================================

Rule overview:

9926231801 — HTTP/2 RST_STREAM with non-zero error code (app layer, high fidelity)

9926231802 — RST_STREAM flood threshold (DoS scanning pattern)

9926231803 — Raw HTTP/2 RST_STREAM frame detection (h2c / non-TLS fallback)

9926231804 — HEADERS+RST rapid sequence targeting HTTP/2 port (behavioral)

9926231805 — Apache worker crash signal (host-network correlation)

9926231806 — Outbound connection from Apache user post-RCE (lateral movement)

=============================================================

--- Rule 1: HTTP/2 RST_STREAM with non-zero error code (app layer) ---

Requires: Suricata HTTP/2 app layer parsing, TLS decryption for HTTPS

This is the highest-fidelity rule — targets the exact protocol condition that

triggers the double-free. RST_STREAM with error code 0 (NO_ERROR) is normal

and common; any non-zero error code in the early-reset context is suspicious.

Expected false positives: legitimate HTTP/2 connection errors (network issues,

client bugs). Tune threshold if noisy in your environment.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)

--- Rule 2: RST_STREAM flood threshold (active DoS/scan pattern) ---

Triggers after 10 RST_STREAM frames with non-zero error code from one source

within 30 seconds. This matches the confirmed in-the-wild DoS scanning behavior.

Lower threshold (e.g., count 5) for higher sensitivity in low-traffic environments.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)

--- Rule 3: Raw RST_STREAM frame detection (h2c cleartext / TLS fallback) ---

Matches the raw HTTP/2 RST_STREAM frame header bytes in cleartext traffic.

HTTP/2 RST_STREAM frame: 3-byte length (0x000004) | type (0x03) | flags (0x00)

This does NOT require app-layer HTTP/2 parsing and catches h2c (non-TLS) traffic.

Higher false positive rate than Rule 1 — use threshold in production.

For h2c on non-standard ports, adjust destination ports accordingly.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)

--- Rule 4: HTTP/2 connection preface followed by rapid RST (behavioral) ---

HTTP/2 client preface begins with "PRI * HTTP/2.0\r\n\r\nSM\r\n\r\n".

Matching this followed by a rapid close is consistent with DoS scanning tooling

that establishes a connection, sends the trigger, and moves to the next target.

Most useful on cleartext h2c; for HTTPS this requires TLS decryption.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)

--- Rule 5: Apache version string exposure (scanner pre-targeting) ---

Attackers actively scanning for vulnerable Apache 2.4.66 servers will often

trigger a version-identifying response. Alert on Apache/2.4.66 in server headers.

Useful for identifying which of your servers are exposed AND being actively scanned.

Note: ServerTokens Prod in Apache config suppresses the version string (recommended).

alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)

--- Rule 6: Suspicious outbound connection from web server process port ---

Post-RCE, an attacker will likely establish a reverse shell or exfiltrate data.

This rule detects NEW outbound TCP connections originating FROM HTTP server ports

to external destinations, which is anomalous for legitimate Apache behavior.

Tune $HOME_NET and $HTTP_SERVERS to avoid false positives on proxy configurations.

This rule pairs with the auditd rule monitoring www-data/apache outbound connects.

alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)

root@kitploit:~
### Note di ottimizzazione

Dopo aver implementato la modalità `alert` per 24–48 ore, esamina i riscontri sulle Regole 3 e 4: i client HTTP/2 legittimi possono innescarli in ambienti ad alto traffico. Se la Regola 1 (livello applicativo) rileva un segnale sufficiente, le Regole 3 e 4 possono essere spostate a una severità inferiore o rimosse.

Per le implementazioni Suricata con limiti di `stream-depth`, assicurati che il pattern del preambolo HTTP/2 nella Regola 4 rientri nella finestra di ispezione.

---

## Configurazione ModSecurity / Coraza

> **Prerequisiti:**
> - ModSecurity 2.x (`libapache2-mod-security2`) o [Coraza](https://coraza.io/) (successore drop-in, mantenuto attivamente)
> - OWASP Core Rule Set (CRS) 4.x consigliato: [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On` (o `DetectionOnly` per la modalità di solo logging durante la messa a punto iniziale)

### Perché ModSecurity è rilevante qui (ma non sufficiente)

Come indicato nella sezione Limiti di rilevamento, ModSecurity non può intercettare il trigger del double-free perché l'exploit opera a livello di frame HTTP/2. Tuttavia, ModSecurity fornisce tre livelli significativi di valore per questa CVE:

1. **Rate limiting** — rallenta la scansione DoS automatizzata e aumenta il costo del brute-forcing dell'heap spray dell'RCE
2. **Rilevamento post-exploitation** — se l'RCE viene raggiunto, l'attaccante tenterà di distribuire una web shell o eseguire comandi; ModSecurity può individuare entrambi
3. **Punteggio anomalie OWASP CRS** — header malformati e pattern di connessione associati allo sfruttamento possono ottenere punteggi anomali con CRS Paranoia Level 2+

### Indurimento della configurazione Apache (da applicare insieme a ModSecurity)

Aggiungi a `httpd.conf` o a un file di include. Queste sono direttive Apache, non regole ModSecurity, ma riducono la superficie di attacco HTTP/2:```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================

# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100

# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off

# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off

# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535

# If HTTP/2 is not required at all:
# Protocols http/1.1

Regole ModSecurity

Salva queste nel tuo file di regole personalizzate di ModSecurity (ad es. /etc/modsecurity/cve-2026-23918.conf):```apache

============================================================

CVE-2026-23918 ModSecurity Detection Rules

============================================================

Rule IDs 9923918xx — adjust range to fit your local policy.

============================================================

Initialize per-IP request counter in the IP collection

SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"

Rule 01: Rate limit — block IPs sending more than 30 requests per minute

Tune the threshold to match your expected legitimate traffic volume.

This catches automated DoS scanning tools that rapidly recycle connections.

SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"

Rule 02: Detect abnormal connection error rates from same IP

Legitimate clients rarely produce rapid sequences of HTTP errors.

Repeated 400-level errors suggest exploit scanning or fuzzing.

SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"

SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"

SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"

============================================================

POST-EXPLOITATION DETECTION

The following rules detect outcomes of successful RCE:

web shell deployment and in-request command execution.

These are NOT specific to CVE-2026-23918 but are the most

likely post-exploitation patterns given the Apache context.

============================================================

Rule 03: Web shell detection in POST body — command execution patterns

Catches PHP web shells that use $_GET/$_POST to pass OS commands.

Note: if you use legitimate PHP applications, tune false positives carefully.

SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 04: Web shell access pattern — direct GET parameter command execution

Catches requests like: GET /shell.php?cmd=id

These are the most common web shell interaction patterns.

SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 05: PHP web shell upload detection

Catches multipart file uploads containing PHP code.

If your application accepts PHP file uploads legitimately, tune carefully.

SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 06: Reverse shell patterns in request data

Catches common reverse shell one-liners often placed in web shells.

SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"

root@kitploit:~
### Raccomandazione di tuning OWASP CRS

Per ottenere il segnale di anomalia più elevato senza eccessivi falsi positivi, distribuisci CRS al Paranoia Level 2 con lo scoring delle anomalie abilitato. Il comportamento di connessione che innesca l'exploit (HTTP/2 malformato che porta a errori di fallback HTTP/1.x, reset ripetuti) accumulerà punteggio di anomalia secondo le regole CRS 920xxx e 921xxx e potrebbe superare la soglia predefinita `inbound_anomaly_score_threshold` di 5, generando avvisi senza regole personalizzate.

---

## Regole Auditd

Salva come `/etc/audit/rules.d/cve-2026-23918.rules`

Ricarica con: `sudo augenrules --load`

> **Principio di progettazione:** Poiché il trigger dell'exploit risiede nel livello di parsing HTTP/2 di rete/kernel, auditd non può intercettare il trigger stesso. Queste regole rilevano:
> 1. L'**esito** dello sfruttamento DoS (segnali di crash dei worker Apache)
> 2. **Attività post-exploitation** se si ottiene RCE (esecuzione di shell, scritture di file, connessioni in uscita da parte dell'utente Apache)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
##   1. Apache worker process crashes (DoS outcome)
##   2. Shell execution by the web server user (RCE outcome)
##   3. Web root file creation (web shell deployment)
##   4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
##   - Debian/Ubuntu: www-data = uid 33
##   - RHEL/Rocky/CentOS: apache = uid 48
##   Adjust -F uid= values for your distribution. Use `id www-data`
##   or `id apache` to confirm the UID on your systems.
## ============================================================

## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt

## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv

## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb

## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_rhel

## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html     -p wa -k cve_2026_23918_webroot_write
-w /var/www          -p wa -k cve_2026_23918_webroot_write
-w /srv/www          -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write

## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel

## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2      -p wa -k cve_2026_23918_apache_config
-w /etc/httpd        -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods

Correlare gli eventi di crash con l'attività di rete

Dopo la distribuzione, usare questo one-liner ausearch per verificare le sequenze crash-then-shell:```bash

Find all CVE-2026-23918 related auditd events from the past 24 hours

sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i

Look for www-data process trees that include shell execution

sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="

root@kitploit:~
---

## Regole Wazuh

Salva come file di regole personalizzato (es., `/var/ossec/etc/rules/local_rules.xml`).

> **Prerequisiti:**
> - Regole Auditd sopra distribuite e decoder auditd di Wazuh attivo
> - Log degli errori di Apache (`/var/log/apache2/error.log` o `/var/log/httpd/error_log`) aggiunto ai file monitorati da Wazuh
> - Log di accesso di Apache monitorato per i pattern di errore delle connessioni HTTP/2```xml
<!-- ==============================================================
     CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
     Requires:
       - auditd rules from cve-2026-23918.rules deployed
       - Apache error log monitored by Wazuh agent
     ============================================================== -->

<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_sigabrt</field>
    <description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_sigsegv</field>
    <description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
    <if_matched_sid>113001</if_matched_sid>
    <description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
    <group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>

<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
    <description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
    <group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>

<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_webroot_write</field>
    <description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
    <group>cve,rce,webshell,apache,</group>
</rule>

<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
    <description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
    <group>cve,rce,reverse_shell,apache,</group>
</rule>

<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
    <if_matched_sid>113004</if_matched_sid>
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
    <description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
    <group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>

<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
    <description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
    <group>cve,rce,persistence,apache,</group>
</rule>

<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
    <decoded_as>apache-errorlog</decoded_as>
    <match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
    <description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
    <if_matched_sid>113009</if_matched_sid>
    <if_matched_sid>113001</if_matched_sid>
    <description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
    <group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>

Regole YARA

Salva come cve_2026_23918.yar

Nota importante sull'ambito: A differenza di Copy Fail (CVE-2026-31431), YARA non può rilevare il trigger dello sfruttamento per questa vulnerabilità. Il trigger è costituito da due frame HTTP/2 grezzi inviati su una connessione di rete — non c'è alcuno script o file da scansionare. Le regole YARA di seguito hanno come obiettivo:

  1. Web shell post-sfruttamento che potrebbero essere distribuite dopo un RCE riuscito
  2. One-liner di reverse shell e payload codificati in file accessibili via web
  3. Lo strumento di exploit stesso se presente su un host pivot o su un server di staging dell'attaccante

Ambito di scansione consigliato: directory web root (/var/www/, /srv/www/), directory temporanee di Apache (/tmp/, /var/tmp/) e file creati di recente di proprietà di www-data o apache.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"

root@kitploit:~
strings:
    $php_open       = "<?php" ascii nocase
    $php_short      = "<?" ascii nocase

    // OS command execution functions
    $sys            = "system("       ascii nocase
    $exec           = "exec("         ascii nocase
    $passthru       = "passthru("     ascii nocase
    $shell_exec     = "shell_exec("   ascii nocase
    $popen          = "popen("        ascii nocase
    $proc_open      = "proc_open("    ascii nocase

    // Parameter sourcing — required for command injection
    $get_param      = "$_GET["        ascii
    $post_param     = "$_POST["       ascii
    $req_param      = "$_REQUEST["    ascii
    $cookie_param   = "$_COOKIE["     ascii
    $server_param   = "$_SERVER["     ascii

    // Obfuscation patterns common in web shells
    $b64decode      = "base64_decode(" ascii nocase
    $str_rot13      = "str_rot13("    ascii nocase
    $gzinflate      = "gzinflate("    ascii nocase
    $eval_call      = "eval("         ascii nocase

    // Common web shell capability strings
    $phpinfo        = "phpinfo()"     ascii nocase
    $file_put       = "file_put_contents(" ascii nocase

condition:
    filesize < 512KB and
    (
        // Classic command web shell: PHP + execution function + parameter input
        ($php_open or $php_short) and
        any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
        any of ($get_param, $post_param, $req_param, $cookie_param)
    )
    or
    (
        // Obfuscated web shell: eval + decode chain
        ($php_open or $php_short) and
        $eval_call and
        any of ($b64decode, $str_rot13, $gzinflate)
    )

}

rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"

root@kitploit:~
strings:
    // Bash TCP reverse shell
    $bash_tcp       = "/dev/tcp/"                   ascii
    $bash_rev       = "bash -i >&"                  ascii nocase

    // Netcat reverse shell
    $nc_e           = "nc -e /bin/"                 ascii nocase
    $nc_c           = "nc -c /bin/"                 ascii nocase
    $ncat_e         = "ncat -e /bin/"               ascii nocase

    // Python reverse shell
    $py_socket      = "import socket,subprocess"    ascii
    $py_pty         = "import pty;pty.spawn"        ascii

    // Perl reverse shell
    $perl_rev       = "perl -e 'use Socket"        ascii

    // Common reverse shell via curl/wget pipe to bash
    $curl_bash      = "curl http"                   ascii
    $wget_bash      = "wget -O- http"               ascii
    $bash_pipe      = "|bash"                       ascii

condition:
    filesize < 1MB and
    (
        ($bash_tcp and $bash_rev)
        or ($nc_e or $nc_c or $ncat_e)
        or ($py_socket and $py_pty)
        or $perl_rev
        or ($curl_bash and $bash_pipe)
        or ($wget_bash and $bash_pipe)
    )

}

rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"

root@kitploit:~
strings:
    // h2_mplx.c specific identifier from public PoC analysis
    $mplx_ref       = "h2_mplx_c1_client_rst"      ascii
    $spurge_ref     = "c1_purge_streams"            ascii
    $stream_ref     = "h2_stream_destroy"           ascii

    // CVE reference strings that appear in PoC tools
    $cve_str        = "CVE-2026-23918"              ascii
    $version_target = "Apache/2.4.66"               ascii

    // HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
    // HTTP/2 HEADERS frame header: type=0x01
    $h2_headers_frame  = { 00 00 ?? 01 }
    // HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
    $h2_rst_frame      = { 00 00 04 03 00 }

    // Python h2 library usage (hyper-h2) typical in PoC tools
    $hyper_h2       = "import h2"                   ascii
    $h2_connection  = "H2Connection"                ascii

condition:
    (
        ($mplx_ref or $spurge_ref or $stream_ref)
        or
        ($cve_str and $version_target)
        or
        ($hyper_h2 and $h2_connection and $h2_rst_frame)
    )

}

root@kitploit:~
---

## Modello di evento MISP

Salva come `misp_cve_2026_23918.json` e importa tramite MISP → Events → Import.

> Sostituisci gli UUID segnaposto con UUID4 appena generati prima dell'importazione.```json
{
    "Event": {
        "uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
        "info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
        "threat_level_id": "2",
        "analysis": "2",
        "date": "2026-05-04",
        "Attribute": [
            {
                "type": "vulnerability",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
                "comment": "CVE identifier",
                "value": "CVE-2026-23918"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
                "comment": "Vulnerability description",
                "value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
                "comment": "Affected component",
                "value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
                "comment": "RCE precondition",
                "value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
                "comment": "Fix commit — r1930444",
                "value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
                "comment": "Fix commit — r1930796",
                "value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
                "comment": "IoC: HTTP/2 frame trigger sequence",
                "value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
                "comment": "IoC: RST_STREAM frame bytes (raw)",
                "value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
                "comment": "IoC: Server response header (vulnerable version)",
                "value": "Server: Apache/2.4.66"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
                "comment": "Exploitation status",
                "value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
                "comment": "Immediate mitigation",
                "value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
            },
            {
                "type": "url",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
                "comment": "Apache official advisory",
                "value": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
                "type": "url",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
                "comment": "oss-security disclosure",
                "value": "https://seclists.org/oss-sec/2026/q2/387"
            }
        ],
        "Object": [
            {
                "name": "vulnerability",
                "meta-category": "vulnerability",
                "Attribute": [
                    {
                        "type": "vulnerability",
                        "object_relation": "id",
                        "value": "CVE-2026-23918"
                    },
                    {
                        "type": "cvss-score",
                        "object_relation": "cvss-score",
                        "value": "8.8"
                    },
                    {
                        "type": "text",
                        "object_relation": "summary",
                        "value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
                    }
                ]
            }
        ]
    }
}

Applicazione di patch e correzione

Percorso di aggiornamento

VersioneStatoAzione
2.4.67CorrettaVersione di destinazione
2.4.66VulnerabileAggiornare immediatamente
2.4.65 e versioni precedentiNon interessato da questo bug specificoPotrebbe avere altre CVE note — consultare l'avviso

Comandi di aggiornamento per distribuzione:

DistribuzioneComando
Ubuntu / Debiansudo apt-get update && sudo apt-get upgrade apache2
RHEL / Rocky / AlmaLinuxsudo dnf update httpd
Amazon Linuxsudo dnf update httpd
SUSE / openSUSEsudo zypper update apache2
Arch Linuxsudo pacman -Syu

Dopo l'aggiornamento, verificare:```bash apache2 -v # or httpd -v

Should show: Apache/2.4.67

root@kitploit:~
### Altre CVE risolte nella 2.4.67

La release 2.4.67 risolve cinque CVE. Le due più significative oltre a CVE-2026-23918 sono:

- **CVE-2026-24072** — Escalation dei privilegi tramite la gestione degli script CGI su Windows (interessa solo le distribuzioni Windows)
- **CVE-2026-24081** — La valutazione delle espressioni di `mod_rewrite` consente agli autori di `.htaccess` di leggere file arbitrari come utente httpd (interessa 2.4.66 e precedenti, segnalata il 2026-01-20)
- **CVE-2026-24088** — Overflow del buffer heap in `mod_proxy_ajp` tramite messaggi AJP appositamente predisposti da un backend AJP malintenzionato (interessa 2.4.66 e precedenti)

L'aggiornamento alla 2.4.67 risolve tutte e cinque con un'unica azione.

---

## Riferimento degli IoC principali

| Indicatore | Valore | Confidenza | Note |
|---|---|---|---|
| Versione interessata | `Apache/2.4.66` nell'header Server | **Alta** | La sola presenza indica l'esposizione |
| Tipo di frame HTTP/2 | RST_STREAM (0x03) con codice di errore non zero | Media | Gli errori di connessione legittimi producono lo stesso |
| Pattern di byte del frame | `00 00 04 03 00` (header RST_STREAM) | Media | Combinato con la soglia = alta |
| Soglia di flood RST | >10 errori RST_STREAM/non-zero dalla stessa sorgente in 30s | **Alta** | Coerente con gli strumenti DoS usati negli attacchi reali |
| SIGABRT sul worker Apache | segnale 6 inviato al PID di `httpd`/`apache2` | **Alta** | I worker normali non vanno in abort |
| Esecuzione di shell da parte di www-data | `execve()` di bash/sh da parte di uid 33 o 48 | **Critica** | Indica fortemente una RCE |
| Connessione in uscita da parte dell'utente Apache | `connect()` da parte di uid 33 o 48 verso un IP esterno | **Critica** | Indica fortemente una reverse shell |
| Creazione di file web nella web root | Nuovi file `.php`/`.py`/`.sh` scritti sotto `/var/www` | **Alta** | Può indicare il deploy di una web shell |
| Tipo di MPM | `mpm_prefork` | N/A — **non interessato** | Verificare con `apachectl -V \| grep MPM` |
| Precondizione per RCE | APR mmap allocator | Contestuale | Predefinito su Debian/Ubuntu; non predefinito su RHEL |

---

*Il pacchetto di rilevamento è mantenuto sulla base degli advisory di sicurezza di Apache HTTP Server su [httpd.apache.org/security](https://httpd.apache.org/security/). Se osservi varianti di exploit o pattern post-exploitation non coperti da queste regole, apri una issue.*
Scarica lo strumento