Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2024-36991 — 重大なSplunkの脆弱性 CVE-2024-36991:任意のファイル読み取りを防ぐため、今すぐパッチを適用 | Kitploit
ツール/GitHubGitHub/jaytiwari05/cve-2024-36991
脆弱性分析エクスプロイトウェブアプリケーション悪用情報収集ペネトレーションテスト学習と教育
GitHubjaytiwari05/cve-2024-36991

CVE-2024-36991

重大なSplunkの脆弱性 CVE-2024-36991:任意のファイル読み取りを防ぐため、今すぐパッチを適用

リポジトリを見る
91年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Splunk パストラバーサル エクスプロイト (CVE-2024-36991)

Screenshot 2025-03-30 at 8 18 32 PM

説明

これは、CVE-2024-36991 に対する Proof-of-Concept (PoC) エクスプロイトスクリプトです。Windows 版 Splunk Enterprise の以下のバージョン未満に影響するパストラバーサル(パス横断)脆弱性です:

  • 9.2.2
  • 9.1.5
  • 9.0.10

この脆弱性により、未認証の攻撃者が Splunk Web インターフェースのパストラバーサル欠陥を悪用して、サーバー上の機密ファイルにアクセスできるようになります。

重大度: Critical
影響: 任意ファイル読み取り


⚠️ 影響を受けるバージョン

  • Splunk Enterprise < 9.2.2
  • Splunk Enterprise < 9.1.5
  • Splunk Enterprise < 9.0.10

💡 使用方法

エクスプロイトを実行するには、以下のコマンドを使用します: Screenshot 2025-03-30 at 8 17 55 PM

root@kitploit:~
# Using Python3
python3 exploit.py -u http://victim.com -s 1

# Running directly
./exploit.py -u http://victim.com -s 1

パラメータ:

  • -u, --url: 対象の Splunk サーバーのベース URL。
  • -s, --section: 列挙するセクションを選択します (1〜5):

セクション:

  1. 認証情報とシークレット:

    • /etc/passwd
    • /etc/auth/splunk.secret
    • /etc/auth/server.pem
    • /var/run/splunk/session
    • /etc/system/local/authentication.conf
  2. 設定ファイル:

    • /etc/system/local/web.conf
    • /etc/system/local/inputs.conf
  3. ログと履歴:

    • /var/log/splunk/splunkd.log
    • /var/log/splunk/audit.log
    • /var/log/splunk/metrics.log
    • /var/log/splunk/searches.log
    • /var/run/splunk/dispatch

🛡️ 緩和策

Splunk サーバーを保護するには:

  • Splunk Enterprise 9.2.2、9.1.5、または 9.0.10 以降にアップグレードしてください。
  • 適切なアクセス制御とファイアウォールルールを適用してください。

⚠️ 免責事項

このエクスプロイトは、教育および許可された侵入テストの目的にのみ使用されます。無断使用は違法かつ非倫理的です。作者は誤用に対する責任を負いません。

ツールをダウンロード
  • システムおよびサービスファイル:

    • /bin/splunk.exe
    • /bin/splunkd.exe
    • /etc/system/default/server.conf
    • /etc/system/default/user-seed.conf
    • /var/lib/splunk/persistentstorage.db
  • アプリとカスタムスクリプト:

    • /etc/apps/Splunk_TA_windows/bin
    • /etc/apps/Splunk_TA_nix/bin
    • /etc/apps/SplunkForwarder/local
    • /etc/apps/Splunk_SA_CIM/local