Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
exim-rce-cve-2018-6789 — 이 저장소는 CVE-2018-6789에 대한 Exim RCE 익스플로잇이 작동하는 방식을 이해하기 위한 학습 환경을 제공합니다. | Kitploit
도구/GitHubGitHub/martinclauss/exim-rce-cve-2018-6789
Vulnerability AnalysisExploitationDebuggersLearning & EducationBinary ExploitationLabs & Practice
GitHubmartinclauss/exim-rce-cve-2018-6789

exim-rce-cve-2018-6789

이 저장소는 CVE-2018-6789에 대한 Exim RCE 익스플로잇이 작동하는 방식을 이해하기 위한 학습 환경을 제공합니다.

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
저장소 보기
117172개월 전아직 검토되지 않음
공유

Exim RCE (CVE-2018-6789) 학습 환경

설명

이것은 Exim RCE(CVE-2018-6789)를 조사하기 위한 환경을 구성하는 파일, 스크립트, 메모, ...의 모음입니다. Exim 디버깅, 익스플로잇 작성, Exim 함수 호출 추적, Exim의 사용자 지정 메모리 관리(storeblocks) 학습, 실제 익스플로잇이 어떻게 동작하는지 알아보는 데 사용할 수 있습니다...

오직 학술 목적으로만 사용해야 합니다!

요구 사항

  • libvirt/KVM을 사용하는 Vagrant(vagrant-libvirt 플러그인)
  • Docker(Vagrant VM 내부가 아닌 호스트에서 Docker를 실행하기로 결정한 경우에만)

설정

Exim 소스 코드를 다운로드하려면 다음을 실행하세요.

$ git submodule update --init

VM

루트 디렉터리에 Vagrantfile이 있습니다. 이 파일은 가상화 제공자로 libvirt를 사용합니다. Vagrant Cloud 다운로드가 현재 중단되었기 때문에(HCP 마이그레이션) 박스는 box_url을 통해 Fedora 미러에서 직접 가져옵니다. Fedora는 해당 사이트에 libvirt 및 VirtualBox 박스만 게시하므로(VMware 없음) 직접 box_url은 제공자별로 다르며, 이 설정은 libvirt만 대상으로 합니다.

# -*- mode: ruby -*-
# vi: set ft=ruby :

memory = 8192 # in MiB
cpus = 4

Vagrant.configure("2") do |config|
  # Vagrant Cloud downloads are broken; pull the box from Fedora's mirror
  config.vm.box = "fedora-44-cloud-base"
  config.vm.box_url = "https://download.fedoraproject.org/pub/fedora/linux/releases/44/Cloud/x86_64/images/Fedora-Cloud-Base-Vagrant-libvirt-44-1.7.x86_64.vagrant.libvirt.box"

  config.vm.provider "libvirt" do |lv|
    lv.memory = memory
    lv.cpus = cpus
  end

  config.vm.provision "shell", inline: <<-SHELL
  	/vagrant/scripts/setup_vm.sh
  SHELL
end

구성은 원하는 대로 변경할 수 있지만, 예를 들어 setup_vm.sh 스크립트는 패키지 설치에 dnf를 사용한다는 점을 명심하세요. Ubuntu를 사용하려면 dnf install 줄을 apt-get install로 바꾸고 패키지 이름도 그에 맞게 조정해야 합니다. 그러나 설정이 올바르게 작동한다는 보장은 없습니다.

구성이 마음에 들면 다음을 실행하기만 하면 됩니다.

$ vagrant up

머신을 설정하고 나서:

$ vagrant ssh

로 접속합니다.

Vagrant 사용법을 모른다면 여기를 참조하세요: https://www.vagrantup.com/intro/getting-started/

Docker 컨테이너

Vagrant는 현재 디렉터리(즉, 방금 클론한 저장소)를 공유 디렉터리로 /vagrant에 매핑합니다. Exim용 Docker 이미지를 생성하고 실행하려면 VM 내부(vagrant ssh)에서 다음 명령을 입력하세요.

[vagrant@localhost ~]$ cd /vagrant
[vagrant@localhost vagrant]$ ./scripts/reset_docker.sh

첫 번째 실행은 Exim을 소스에서 빌드하므로 훨씬 오래 걸립니다. Docker 컨테이너로 복사될 디버깅 스크립트나 다른 파일을 수정한 경우 언제든지 ./scripts/reset_docker.sh를 사용하여 Docker 이미지를 다시 빌드할 수 있습니다. 물론 스크립트에서 필요한 줄만 가져와 단일 명령으로 실행할 수도 있습니다.

모든 작업이 끝나면 루트 콘솔이 표시됩니다:

Successfully tagged exim:latest
787f310ef922a1e519cf8bb47f1c4fed5f510da705e7ceefd48f160c980e969c
root@787f310ef922:/opt#

이상한 문자열은 시스템마다 다를 수 있지만, 지금은 호스트 머신의 Fedora VM 안에서 실행되는 Debian Docker 컨테이너에 있는 것입니다.

VM 및 컨테이너 사용법

먼저 두 개의 터미널 창에서 vagrant ssh로 두 개의 SSH 세션을 만들 수 있습니다. 하나는 익스플로잇을 실행하고 SMTP를 통해 Exim과 상호 작용하는 데 사용할 수 있습니다. 다른 하나는 Docker 컨테이너 내에서 Exim을 시작, 실행, 디버깅, ... 하는 데 사용합니다. VM에서는 ASLR이 비활성화되어 있으므로 디버깅 세션 중에 변경되지 않는 신뢰할 수 있는 중단점을 설정할 수 있습니다.

예제 세션:

첫 번째 터미널:

$ vagrant ssh
[vagrant@localhost vagrant]$

두 번째 터미널:

$ vagrant ssh
[vagrant@localhost vagrant]$ cd /vagrant
[vagrant@localhost vagrant]$ ./scripts/reset_docker.sh
...
# now you are inside the Debian Docker container
root@99296cf63016:/opt# ./run_exim.sh
root@99296cf63016:/opt# ./attach_exim.sh

run_exim.sh 스크립트는 종료되고 Exim은 백그라운드에서 실행됩니다. ./attach_exim.sh 스크립트는 실행 중인 Exim 데몬 프로세스에 gdb를 연결하고 다음과 같은 출력을 표시합니다:

...
pwndbg: loaded 170 commands. Type pwndbg [filter] for a list.
pwndbg: created $rebase, $ida gdb functions (can be used with print/break)

Attaching to process 14
Reading symbols from /usr/exim/bin/exim-4.89_1-1-fc6d6586-XX-1...done.
...
0x00007ffff6b7f5e3 in __select_nocancel () at ../sysdeps/unix/syscall-template.S:84
84	../sysdeps/unix/syscall-template.S: No such file or directory.
Breakpoint 1 at 0x5555555c03d2: file smtp_in.c, line 1762.
Breakpoint 2 at 0x5555555c051d: file smtp_in.c, line 1884.
Breakpoint 3 at 0x55555556a2c8: file base64.c, line 154.
Breakpoint 4 at 0x5555555c6aca: file smtp_in.c, line 3690.

Exim이 실행 중이며 요청을 기다리고 있습니다. 설정된 중단점은 debugging/breakpoints 파일에서 가져온 것입니다. Ctrl+C를 사용하여 프로세스를 중단하고 gdb에 제어권을 넘길 수 있습니다. 또한 제공된 익스플로잇 스크립트 중 하나를 실행하여 모든 것이 예상대로 작동하는지 테스트할 수 있습니다:

첫 번째 터미널:

[vagrant@localhost ~]$ cd /vagrant/sploits/
[vagrant@localhost sploits]$ ./sploit_0.py
[+] Opening connection to localhost on port 25: Done

두 번째 터미널:

Thread 2.1 "exim" hit Breakpoint 2, smtp_reset (reset_point=reset_point@entry=0x555555843078) at smtp_in.c:1884
1884	{
LEGEND: STACK | HEAP | CODE | DATA | RWX | RODATA
──────────────────────────────────────────────[ REGISTERS ]───────────────────────────────────────────────
 RAX  0x555555843078 ◂— 0x0
 RBX  0x0
 RCX  0x555555824b40 (store_last_get) —▸ 0x555555843078 ◂— 0x0
 RDX  0x555555820b30 (yield_length) ◂— 0x15800001c38
 RDI  0x555555843078 ◂— 0x0
 RSI  0x0
 R8   0x3
 R9   0x52
 R10  0x73
 R11  0x246
 R12  0x5555555ec7fa ◂— 'daemon.c'
 R13  0x555555843078 ◂— 0x0
 R14  0x0
 R15  0x0
 RBP  0x5555555ee3db ◂— and    byte ptr [rax], ah /* '  %s\n' */
 RSP  0x7ffffffbe528 —▸ 0x5555555c31d1 (smtp_setup_msg+67) ◂— mov    dword ptr [rip + 0x260b6d], 0
 RIP  0x5555555c051d (smtp_reset) ◂— push   rbp
────────────────────────────────────────────────[ DISASM ]────────────────────────────────────────────────
 ► 0x5555555c051d <smtp_reset>       push   rbp
   0x5555555c051e <smtp_reset+1>     push   rbx
   0x5555555c051f <smtp_reset+2>     sub    rsp, 8
   0x5555555c0523 <smtp_reset+6>     mov    rbp, rdi
   0x5555555c0526 <smtp_reset+9>     mov    qword ptr [rip + 0x263657], 0 <0x555555823b88>
   0x5555555c0531 <smtp_reset+20>    mov    dword ptr [rip + 0x263645], 0 <0x555555823b80>
   0x5555555c053b <smtp_reset+30>    mov    dword ptr [rip + 0x26364f], 0 <0x555555823b94>
   0x5555555c0545 <smtp_reset+40>    mov    dword ptr [rip + 0x263699], 0 <0x555555823be8>
   0x5555555c054f <smtp_reset+50>    mov    dword ptr [rip + 0x263687], 0 <0x555555823be0>
   0x5555555c0559 <smtp_reset+60>    mov    dword ptr [rip + 0x263679], 0 <0x555555823bdc>
   0x5555555c0563 <smtp_reset+70>    mov    dword ptr [rip + 0x263677], 0 <0x555555823be4>
────────────────────────────────────────────[ SOURCE (CODE) ]─────────────────────────────────────────────
In file: /opt/exim/src/src/smtp_in.c
   1879 Returns:    nothing
   1880 */
   1881
   1882 static void
   1883 smtp_reset(void *reset_point)
 ► 1884 {
   1885 recipients_list = NULL;
   1886 rcpt_count = rcpt_defer_count = rcpt_fail_count =
   1887   raw_recipients_count = recipients_count = recipients_list_max = 0;
   1888 cancel_cutthrough_connection("smtp reset");
   1889 message_linecount = 0;
────────────────────────────────────────────────[ STACK ]─────────────────────────────────────────────────
00:0000│ rsp  0x7ffffffbe528 —▸ 0x5555555c31d1 (smtp_setup_msg+67) ◂— mov    dword ptr [rip + 0x260b6d], 0
01:0008│      0x7ffffffbe530 —▸ 0x7ffffffbe600 ◂— 0x0
02:0010│      0x7ffffffbe538 —▸ 0x7ffffffbe540 —▸ 0x555555605f1a ◂— add    byte ptr [rip + 0x25203a73], ah
03:0018│      0x7ffffffbe540 —▸ 0x555555605f1a ◂— add    byte ptr [rip + 0x25203a73], ah
04:0020│      0x7ffffffbe548 —▸ 0x555555843078 ◂— 0x0
05:0028│      0x7ffffffbe550 ◂— 0x0
06:0030│      0x7ffffffbe558 —▸ 0x7ffff6b7f5e3 (__select_nocancel+10) ◂— cmp    rax, -0xfff
07:0038│      0x7ffffffbe560 ◂— 0x7ffffffbe560
──────────────────────────────────────────────[ BACKTRACE ]───────────────────────────────────────────────
 ► f 0     5555555c051d smtp_reset
   f 1     5555555c31d1 smtp_setup_msg+67
   f 2     55555556de43 daemon_go+10909
   f 3     55555556de43 daemon_go+10909
   f 4     555555583ca5 main+21601
   f 5     7ffff6abe2e1 __libc_start_main+241
──────────────────────────────────────────────────────────────────────────────────────────────────────────
Breakpoint smtp_reset
pwndbg>

d로 모든 중단점을 삭제하고 c로 계속 실행하여 sploit_0.py 스크립트가 종료될 때까지 실행되도록 할 수 있습니다:

두 번째 터미널:

Breakpoint smtp_reset
pwndbg> d
pwndbg> c
Continuing.
[Inferior 2 (process 42) exited with code 01]

첫 번째 터미널:

...
220 787f310ef922 ESMTP Exim 4.89_1-1-fc6d6586-XX Mon, 02 Mar 2020 14:47:24 +0000
250-787f310ef922 Hello test.example.org [172.17.0.1]
250-SIZE 52428800
250-8BITMIME
250-PIPELINING
250-AUTH PLAIN
250-CHUNKING
250-PRDR
250 HELP
도구 다운로드