Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Detections-CVE-2026-23918 — Regras de detecção para CVE-2026-23918 Apache http2 RCE - Crédito: stringa.ai, isec.pl | Kitploit
Ferramentas/GitHubGitHub/insomnisec/detections-cve-2026-23918
Gerenciamento de Indicadores de Comprometimento (IOC)Análise de VulnerabilidadesExploraçãoEvasão de IDS/IPSSegurança WebSegurança de RedeInteligência de AmeaçasDetecção de IntrusãoResposta a Incidentes

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Archived
GitHubinsomnisec/detections-cve-2026-23918

Detections-CVE-2026-23918

Regras de detecção para CVE-2026-23918 Apache http2 RCE - Crédito: stringa.ai, isec.pl

Ver Repositório
há 3 mesesAinda não revisado

MUDANDO PARA: https://github.com/insomnisec/public_cve_detections

PARA UMA MELHOR GESTÃO DE LONGO PRAZO DAS PUBLICAÇÕES DE DETECÇÃO

ESTE REPOSITÓRIO SERÁ REMOVIDO EM JUNHO DE 2026

POR FAVOR, USE O OUTRO REPOSITÓRIO DAQUI EM DIANTE

CVE-2026-23918 "Apache HTTP/2 Double-Free" — Pacote de Detecção e Resposta

Publicado: 2026-05-04
CVSSv3: 8.8 (Alto)
Tipo: Execução Remota de Código / Negação de Serviço (Corrupção de Memória Double-Free)
Componente: Apache HTTP Server mod_http2 (h2_mplx.c caminho de limpeza de stream)
Afetado: Apache HTTP Server 2.4.66 com HTTP/2 ativado e MPM multi-threaded
Referências:

  • Aviso de Segurança do Apache HTTP Server
  • Divulgação oss-security
  • Análise Técnica Hadrian
  • Cobertura insomnisec

Índice

  1. Resumo da Vulnerabilidade
  2. Como o Exploit Funciona
  3. Arquitetura de Detecção — Por Que Este Pacote Difere de Pacotes LPE
  4. Limitações da Detecção
  5. Mitigação Imediata
  6. Regras Suricata
  7. Configuração ModSecurity / Coraza
  8. Regras Auditd
  9. Regras Wazuh
  10. Regras YARA
  11. Modelo de Evento MISP
  12. Correção e Remediação
  13. Principais IoCs de Referência

Resumo da Vulnerabilidade

CVE-2026-23918 é uma vulnerabilidade de corrupção de memória double-free na implementação do protocolo HTTP/2 do Apache HTTP Server 2.4.66, afetando apenas o caminho de limpeza de stream do módulo mod_http2 em h2_mplx.c. Ela permite que um atacante remoto não autenticado derrube processos worker do Apache (Negação de Serviço) com uma única conexão TCP e dois quadros HTTP/2. Sob condições presentes em sistemas derivados do Debian e imagens oficiais do Apache Docker, o double-free pode ser moldado para Execução Remota de Código completa.

A exploração DoS foi confirmada em ambientes reais. Varreduras em larga escala na internet visando endpoints HTTP/2 foram observadas. O exploit RCE foi comprovado viável em ambientes controlados, embora não haja evidências de exploração pública generalizada para RCE neste momento.

O MPM prefork não é afetado — a vulnerabilidade requer uma configuração MPM multi-threaded (worker, event ou similar). CVE-2026-23918 afeta apenas a versão 2.4.66 do Apache HTTP Server.


Como o Exploit Funciona```

Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream

Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup

Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE

c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption

DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption

RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE

root@kitploit:~
> **Assimetria chave:** O caminho DoS não requer habilidade de manipulação de heap e está sendo ativamente explorado. O caminho RCE é tecnicamente exigente, mas foi demonstrado em condições de laboratório e quase certamente será arma no futuro próximo, dada a resistência a ASLR do endereço fixo do scoreboard.

---

## Arquitetura de Deteção

> Esta secção explica porque é que as ferramentas de deteção aqui diferem substancialmente de um pacote típico de escalada de privilégios local.

Copy Fail (CVE-2026-31431) era uma vulnerabilidade **do lado do servidor, pós-acesso**. O atacante precisava de presença existente no sistema. A deteção residia principalmente na camada de syscall (auditd, Wazuh) com análise YARA para o script PoC em disco.

CVE-2026-23918 é uma vulnerabilidade **do lado da rede, pré-acesso**. O exploit chega como frames de protocolo HTTP/2 através da rede antes de qualquer código de aplicação ser executado. Isto desloca significativamente a pilha de deteção:

| Camada | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **Deteção primária** | Regras de syscall do auditd | Regras de rede do Suricata |
| **WAF (ModSecurity)** | Limitado — não consegue ver o exploit | Relevante — anomalia + pós-exploit |
| **Auditd** | Deteção central | Deteção de resultados (crashes, pós-exploit) |
| **YARA** | Analisa script PoC | Analisa web shells (artefatos pós-exploit) |
| **IDS de rede** | Não aplicável | Camada de deteção de primeira classe |
| **Inspeção TLS** | N/A | Necessário para cobertura total do Suricata |

A regra prática: para RCE a nível de rede, trabalhe de fora para dentro (rede → WAF → servidor). Para escalada de privilégios local, trabalhe a partir do servidor para fora.

---

## Limitações da Deteção

> **Leia isto antes de implementar quaisquer regras.**

**1. TLS termina a visibilidade HTTP/2.**
A maioria das implementações de Apache em produção serve HTTPS. O Suricata não pode inspecionar o conteúdo de frames HTTP/2 encriptados sem que a desencriptação TLS esteja configurada. Se a sua implementação do Suricata não tiver acesso às chaves de sessão TLS ou a um espelho de desencriptação, as regras de nível de rede abaixo apenas detetarão:
- HTTP/2 em texto limpo (h2c) — incomum em produção, mas presente em ambientes internos
- A assinatura de rede do comportamento da conexão TCP (contagem de conexões, padrões RST na camada TCP)

Para implementações HTTPS, ative a desencriptação TLS do Suricata através da definição `tls-decrypt` e do registo de chaves de sessão, ou confie nas camadas WAF (ModSecurity/Coraza) e baseadas no servidor (auditd/Wazuh) em alternativa.

**2. ModSecurity não pode bloquear o gatilho do exploit.**
O double-free ocorre dentro do analisador de frames HTTP/2, antes de um pedido HTTP completo ser montado e passado ao ModSecurity. O WAF vê o pedido apenas após a análise do frame estar concluída — momento em que o dano pode já ter sido feito. O ModSecurity neste pacote é utilizado para deteção de anomalias, limitação de taxa e deteção de pós-exploração, não como bloqueador do gatilho.

**3. MPM prefork não é afetado.**
Se a sua implementação do Apache utilizar `mpm_prefork_module` (single-threaded), esta vulnerabilidade não se aplica. O bug apenas se manifesta em MPMs multi-threaded (`mpm_event_module` ou `mpm_worker_module`). Verifique com `apachectl -V | grep MPM` antes de implementar regras que produziriam falsos positivos em servidores prefork.

**4. RCE requer o alocador mmap.**
O caminho RCE (não o caminho DoS) requer o alocador mmap do APR, que é o padrão em distribuições derivadas do Debian e imagens Docker oficiais do Apache. Implementações baseadas em RHEL/CentOS que utilizam jemalloc ou system malloc têm risco reduzido de RCE, mas ainda são totalmente vulneráveis a DoS.

**5. Ainda não existem IoCs estáveis de pós-exploração.**
Não existem IoCs publicados por fornecedores para atividade de pós-exploração até ao momento. As regras YARA e regras auditd que visam comportamento de pós-exploração baseiam-se em padrões gerais de web shell e escalada de privilégios — capturarão resultados comuns, mas não um payload sofisticado e personalizado.

---

## Mitigação Imediata

Aplicar por ordem de preferência. Cada uma é mais disruptiva que a anterior, mas cada uma é mais completa.```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below

# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
#   Remove or comment out:  Protocols h2 h2c http/1.1
#   Replace with:           Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2

# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2

# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
#   nginx: proxy_http_version 1.1; (already the default for upstream connections)
#   HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly

Verifique sua mitigação: Após desabilitar HTTP/2, confirme com:

root@kitploit:~
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/
# Deve retornar "1.1", não "2"
apachectl -M | grep http2
# Não deve produzir saída

Regras Suricata

Salve como cve-2026-23918.rules e referencie a partir de suricata.yaml.

Pré-requisitos:

  • Suricata 6.0+ para suporte às palavras-chave http2.frametype / http2.errorcode (Suricata 7.x recomendado)
  • app-layer.protocols.http2.enabled: yes em suricata.yaml
  • Descriptografia TLS configurada para cobertura HTTPS (veja Limitações de Detecção acima)
  • Variável $HTTP_SERVERS definida para incluir seus hosts Apache
  • SIDs abaixo são exemplos — ajuste para atender sua política local de SIDs```

=============================================================

CVE-2026-23918 Apache HTTP/2 Double-Free — Suricata Rules

=============================================================

Rule overview:

9926231801 — HTTP/2 RST_STREAM with non-zero error code (app layer, high fidelity)

9926231802 — RST_STREAM flood threshold (DoS scanning pattern)

9926231803 — Raw HTTP/2 RST_STREAM frame detection (h2c / non-TLS fallback)

9926231804 — HEADERS+RST rapid sequence targeting HTTP/2 port (behavioral)

9926231805 — Apache worker crash signal (host-network correlation)

9926231806 — Outbound connection from Apache user post-RCE (lateral movement)

=============================================================

--- Rule 1: HTTP/2 RST_STREAM with non-zero error code (app layer) ---

Requires: Suricata HTTP/2 app layer parsing, TLS decryption for HTTPS

This is the highest-fidelity rule — targets the exact protocol condition that

triggers the double-free. RST_STREAM with error code 0 (NO_ERROR) is normal

and common; any non-zero error code in the early-reset context is suspicious.

Expected false positives: legitimate HTTP/2 connection errors (network issues,

client bugs). Tune threshold if noisy in your environment.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)

--- Rule 2: RST_STREAM flood threshold (active DoS/scan pattern) ---

Triggers after 10 RST_STREAM frames with non-zero error code from one source

within 30 seconds. This matches the confirmed in-the-wild DoS scanning behavior.

Lower threshold (e.g., count 5) for higher sensitivity in low-traffic environments.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)

--- Rule 3: Raw RST_STREAM frame detection (h2c cleartext / TLS fallback) ---

Matches the raw HTTP/2 RST_STREAM frame header bytes in cleartext traffic.

HTTP/2 RST_STREAM frame: 3-byte length (0x000004) | type (0x03) | flags (0x00)

This does NOT require app-layer HTTP/2 parsing and catches h2c (non-TLS) traffic.

Higher false positive rate than Rule 1 — use threshold in production.

For h2c on non-standard ports, adjust destination ports accordingly.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)

--- Rule 4: HTTP/2 connection preface followed by rapid RST (behavioral) ---

HTTP/2 client preface begins with "PRI * HTTP/2.0\r\n\r\nSM\r\n\r\n".

Matching this followed by a rapid close is consistent with DoS scanning tooling

that establishes a connection, sends the trigger, and moves to the next target.

Most useful on cleartext h2c; for HTTPS this requires TLS decryption.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)

--- Rule 5: Apache version string exposure (scanner pre-targeting) ---

Attackers actively scanning for vulnerable Apache 2.4.66 servers will often

trigger a version-identifying response. Alert on Apache/2.4.66 in server headers.

Useful for identifying which of your servers are exposed AND being actively scanned.

Note: ServerTokens Prod in Apache config suppresses the version string (recommended).

alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)

--- Rule 6: Suspicious outbound connection from web server process port ---

Post-RCE, an attacker will likely establish a reverse shell or exfiltrate data.

This rule detects NEW outbound TCP connections originating FROM HTTP server ports

to external destinations, which is anomalous for legitimate Apache behavior.

Tune $HOME_NET and $HTTP_SERVERS to avoid false positives on proxy configurations.

This rule pairs with the auditd rule monitoring www-data/apache outbound connects.

alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)

root@kitploit:~
### Notas de Ajuste

Após a implantação em modo `alert` por 24–48 horas, revise os acionamentos nas Regras 3 e 4 — clientes HTTP/2 legítimos podem dispará-las em ambientes de alto tráfego. Se a Regra 1 (camada de aplicação) estiver captando sinal suficiente, as Regras 3 e 4 podem ser rebaixadas para menor severidade ou removidas.

Para implantações Suricata com limites de `stream-depth`, garanta que o padrão de preâmbulo HTTP/2 na Regra 4 esteja dentro da janela de inspeção.

---

## Configuração ModSecurity / Coraza

> **Pré-requisitos:**
> - ModSecurity 2.x (`libapache2-mod-security2`) ou [Coraza](https://coraza.io/) (substituto direto, mantido ativamente)
> - OWASP Core Rule Set (CRS) 4.x recomendado: [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On` (ou `DetectionOnly` para modo somente registro durante o ajuste inicial)

### Por que o ModSecurity é relevante aqui (mas não suficiente)

Conforme observado na seção Limitações de Detecção, o ModSecurity não pode interceptar o gatilho de double-free porque o exploit opera na camada de quadros HTTP/2. No entanto, o ModSecurity fornece três camadas significativas de valor para este CVE:

1. **Limitação de taxa** — retarda a varredura automatizada de DoS e aumenta o custo de forçar o heap spray do RCE
2. **Detecção pós-exploração** — se o RCE for alcançado, o invasor tentará implantar um web shell ou executar comandos; o ModSecurity pode detectar ambos
3. **Pontuação de anomalia OWASP CRS** — cabeçalhos malformados e padrões de conexão associados à exploração podem pontuar anormalmente sob o Nível de Paranoia 2+ do CRS

### Endurecimento da configuração Apache (aplicar junto com ModSecurity)

Adicione ao `httpd.conf` ou a um arquivo de inclusão. Estas são diretivas do Apache, não regras do ModSecurity, mas reduzem a superfície de ataque HTTP/2:```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================

# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100

# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off

# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off

# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535

# If HTTP/2 is not required at all:
# Protocols http/1.1

Regras do ModSecurity

Salve estas no seu arquivo de regras personalizadas do ModSecurity (ex.: /etc/modsecurity/cve-2026-23918.conf):```apache

============================================================

CVE-2026-23918 ModSecurity Detection Rules

============================================================

Rule IDs 9923918xx — adjust range to fit your local policy.

============================================================

Initialize per-IP request counter in the IP collection

SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"

Rule 01: Rate limit — block IPs sending more than 30 requests per minute

Tune the threshold to match your expected legitimate traffic volume.

This catches automated DoS scanning tools that rapidly recycle connections.

SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"

Rule 02: Detect abnormal connection error rates from same IP

Legitimate clients rarely produce rapid sequences of HTTP errors.

Repeated 400-level errors suggest exploit scanning or fuzzing.

SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"

SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"

SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"

============================================================

POST-EXPLOITATION DETECTION

The following rules detect outcomes of successful RCE:

web shell deployment and in-request command execution.

These are NOT specific to CVE-2026-23918 but are the most

likely post-exploitation patterns given the Apache context.

============================================================

Rule 03: Web shell detection in POST body — command execution patterns

Catches PHP web shells that use $_GET/$_POST to pass OS commands.

Note: if you use legitimate PHP applications, tune false positives carefully.

SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 04: Web shell access pattern — direct GET parameter command execution

Catches requests like: GET /shell.php?cmd=id

These are the most common web shell interaction patterns.

SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 05: PHP web shell upload detection

Catches multipart file uploads containing PHP code.

If your application accepts PHP file uploads legitimately, tune carefully.

SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"

Rule 06: Reverse shell patterns in request data

Catches common reverse shell one-liners often placed in web shells.

SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"

root@kitploit:~
### Recomendação de Ajuste do CRS OWASP

Para obter o maior sinal de anomalia sem falsos positivos excessivos, implante o CRS no Nível de Paranóia 2 com a pontuação de anomalia ativada. O comportamento de conexão desencadeador (HTTP/2 malformado levando a erros de fallback para HTTP/1.x, resets repetidos) acumulará pontuação de anomalia sob as regras 920xxx e 921xxx do CRS e pode exceder o limite padrão `inbound_anomaly_score_threshold` de 5, gerando alertas sem regras personalizadas.

---

## Regras do Auditd

Salve como `/etc/audit/rules.d/cve-2026-23918.rules`

Recarregue com: `sudo augenrules --load`

> **Princípio de design:** Como o gatilho do exploit reside na camada de parsing HTTP/2 da rede/kernel, o auditd não consegue capturar o próprio gatilho. Estas regras detectam:
> 1. O **resultado** da exploração DoS (sinais de falha do worker do Apache)
> 2. **Atividade pós-exploração** se RCE for alcançada (execução de shell, gravações de arquivos, conexões de saída pelo usuário do Apache)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
##   1. Apache worker process crashes (DoS outcome)
##   2. Shell execution by the web server user (RCE outcome)
##   3. Web root file creation (web shell deployment)
##   4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
##   - Debian/Ubuntu: www-data = uid 33
##   - RHEL/Rocky/CentOS: apache = uid 48
##   Adjust -F uid= values for your distribution. Use `id www-data`
##   or `id apache` to confirm the UID on your systems.
## ============================================================

## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt

## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv

## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb

## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_rhel

## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html     -p wa -k cve_2026_23918_webroot_write
-w /var/www          -p wa -k cve_2026_23918_webroot_write
-w /srv/www          -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write

## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel

## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2      -p wa -k cve_2026_23918_apache_config
-w /etc/httpd        -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods

Correlacionando eventos de crash com atividade de rede

Após a implantação, use este comando de uma linha ausearch para verificar sequências de crash seguido de shell:```bash

Find all CVE-2026-23918 related auditd events from the past 24 hours

sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i

Look for www-data process trees that include shell execution

sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="

root@kitploit:~
---

## Regras do Wazuh

Salve como um arquivo de regras personalizado (ex.: `/var/ossec/etc/rules/local_rules.xml`).

> **Pré-requisitos:**
> - Regras do Auditd implantadas acima e decodificador auditd do Wazuh ativo
> - Log de erros do Apache (`/var/log/apache2/error.log` ou `/var/log/httpd/error_log`) adicionado aos arquivos monitorados do Wazuh
> - Log de acesso do Apache monitorado para padrões de erro de conexão HTTP/2```xml
<!-- ==============================================================
     CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
     Requires:
       - auditd rules from cve-2026-23918.rules deployed
       - Apache error log monitored by Wazuh agent
     ============================================================== -->

<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_sigabrt</field>
    <description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_sigsegv</field>
    <description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
    <if_matched_sid>113001</if_matched_sid>
    <description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
    <group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>

<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
    <description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
    <group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>

<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_webroot_write</field>
    <description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
    <group>cve,rce,webshell,apache,</group>
</rule>

<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
    <description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
    <group>cve,rce,reverse_shell,apache,</group>
</rule>

<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
    <if_matched_sid>113004</if_matched_sid>
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
    <description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
    <group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>

<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
    <if_group>auditd</if_group>
    <field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
    <description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
    <group>cve,rce,persistence,apache,</group>
</rule>

<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
    <decoded_as>apache-errorlog</decoded_as>
    <match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
    <description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
    <group>cve,denial_of_service,apache,http2,</group>
</rule>

<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
    <if_matched_sid>113009</if_matched_sid>
    <if_matched_sid>113001</if_matched_sid>
    <description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
    <group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>

Regras YARA

Salve como cve_2026_23918.yar

Nota importante de escopo: Diferente do Copy Fail (CVE-2026-31431), o YARA não consegue detectar o gatilho de exploração para esta vulnerabilidade. O gatilho são dois quadros HTTP/2 brutos enviados por uma conexão de rede — não há script ou arquivo para verificar. As regras YARA abaixo visam:

  1. Web shells pós-exploração que podem ser implantados após um RCE bem-sucedido
  2. One-liners de reverse shell e payloads codificados em arquivos acessíveis via web
  3. A própria ferramenta de exploração se estiver presente em um host pivô ou servidor de preparação do atacante

Escopo de verificação recomendado: diretórios raiz da web (/var/www/, /srv/www/), diretórios temporários do Apache (/tmp/, /var/tmp/) e arquivos criados recentemente de propriedade de www-data ou apache.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"

root@kitploit:~
strings:
    $php_open       = "<?php" ascii nocase
    $php_short      = "<?" ascii nocase

    // OS command execution functions
    $sys            = "system("       ascii nocase
    $exec           = "exec("         ascii nocase
    $passthru       = "passthru("     ascii nocase
    $shell_exec     = "shell_exec("   ascii nocase
    $popen          = "popen("        ascii nocase
    $proc_open      = "proc_open("    ascii nocase

    // Parameter sourcing — required for command injection
    $get_param      = "$_GET["        ascii
    $post_param     = "$_POST["       ascii
    $req_param      = "$_REQUEST["    ascii
    $cookie_param   = "$_COOKIE["     ascii
    $server_param   = "$_SERVER["     ascii

    // Obfuscation patterns common in web shells
    $b64decode      = "base64_decode(" ascii nocase
    $str_rot13      = "str_rot13("    ascii nocase
    $gzinflate      = "gzinflate("    ascii nocase
    $eval_call      = "eval("         ascii nocase

    // Common web shell capability strings
    $phpinfo        = "phpinfo()"     ascii nocase
    $file_put       = "file_put_contents(" ascii nocase

condition:
    filesize < 512KB and
    (
        // Classic command web shell: PHP + execution function + parameter input
        ($php_open or $php_short) and
        any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
        any of ($get_param, $post_param, $req_param, $cookie_param)
    )
    or
    (
        // Obfuscated web shell: eval + decode chain
        ($php_open or $php_short) and
        $eval_call and
        any of ($b64decode, $str_rot13, $gzinflate)
    )

}

rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"

root@kitploit:~
strings:
    // Bash TCP reverse shell
    $bash_tcp       = "/dev/tcp/"                   ascii
    $bash_rev       = "bash -i >&"                  ascii nocase

    // Netcat reverse shell
    $nc_e           = "nc -e /bin/"                 ascii nocase
    $nc_c           = "nc -c /bin/"                 ascii nocase
    $ncat_e         = "ncat -e /bin/"               ascii nocase

    // Python reverse shell
    $py_socket      = "import socket,subprocess"    ascii
    $py_pty         = "import pty;pty.spawn"        ascii

    // Perl reverse shell
    $perl_rev       = "perl -e 'use Socket"        ascii

    // Common reverse shell via curl/wget pipe to bash
    $curl_bash      = "curl http"                   ascii
    $wget_bash      = "wget -O- http"               ascii
    $bash_pipe      = "|bash"                       ascii

condition:
    filesize < 1MB and
    (
        ($bash_tcp and $bash_rev)
        or ($nc_e or $nc_c or $ncat_e)
        or ($py_socket and $py_pty)
        or $perl_rev
        or ($curl_bash and $bash_pipe)
        or ($wget_bash and $bash_pipe)
    )

}

rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"

root@kitploit:~
strings:
    // h2_mplx.c specific identifier from public PoC analysis
    $mplx_ref       = "h2_mplx_c1_client_rst"      ascii
    $spurge_ref     = "c1_purge_streams"            ascii
    $stream_ref     = "h2_stream_destroy"           ascii

    // CVE reference strings that appear in PoC tools
    $cve_str        = "CVE-2026-23918"              ascii
    $version_target = "Apache/2.4.66"               ascii

    // HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
    // HTTP/2 HEADERS frame header: type=0x01
    $h2_headers_frame  = { 00 00 ?? 01 }
    // HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
    $h2_rst_frame      = { 00 00 04 03 00 }

    // Python h2 library usage (hyper-h2) typical in PoC tools
    $hyper_h2       = "import h2"                   ascii
    $h2_connection  = "H2Connection"                ascii

condition:
    (
        ($mplx_ref or $spurge_ref or $stream_ref)
        or
        ($cve_str and $version_target)
        or
        ($hyper_h2 and $h2_connection and $h2_rst_frame)
    )

}

root@kitploit:~
---

## MISP Event Template

Salve como `misp_cve_2026_23918.json` e importe via MISP → Eventos → Importar.

> Substitua os UUIDs placeholder por UUID4 recém-gerados antes da importação.```json
{
    "Event": {
        "uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
        "info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
        "threat_level_id": "2",
        "analysis": "2",
        "date": "2026-05-04",
        "Attribute": [
            {
                "type": "vulnerability",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
                "comment": "CVE identifier",
                "value": "CVE-2026-23918"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
                "comment": "Vulnerability description",
                "value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
                "comment": "Affected component",
                "value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
                "comment": "RCE precondition",
                "value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
                "comment": "Fix commit — r1930444",
                "value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
                "comment": "Fix commit — r1930796",
                "value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
                "comment": "IoC: HTTP/2 frame trigger sequence",
                "value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
                "comment": "IoC: RST_STREAM frame bytes (raw)",
                "value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
                "comment": "IoC: Server response header (vulnerable version)",
                "value": "Server: Apache/2.4.66"
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": true,
                "uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
                "comment": "Exploitation status",
                "value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
            },
            {
                "type": "text",
                "category": "Other",
                "to_ids": false,
                "uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
                "comment": "Immediate mitigation",
                "value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
            },
            {
                "type": "url",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
                "comment": "Apache official advisory",
                "value": "https://httpd.apache.org/security/vulnerabilities_24.html"
            },
            {
                "type": "url",
                "category": "External analysis",
                "to_ids": false,
                "uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
                "comment": "oss-security disclosure",
                "value": "https://seclists.org/oss-sec/2026/q2/387"
            }
        ],
        "Object": [
            {
                "name": "vulnerability",
                "meta-category": "vulnerability",
                "Attribute": [
                    {
                        "type": "vulnerability",
                        "object_relation": "id",
                        "value": "CVE-2026-23918"
                    },
                    {
                        "type": "cvss-score",
                        "object_relation": "cvss-score",
                        "value": "8.8"
                    },
                    {
                        "type": "text",
                        "object_relation": "summary",
                        "value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
                    }
                ]
            }
        ]
    }
}

Correção e Remediação

Caminho de Atualização

VersãoStatusAção
2.4.67CorrigidoVersão alvo
2.4.66Vulnerável

Comandos de atualização por distribuição:

Após atualizar, verifique:```bash apache2 -v # or httpd -v

Should show: Apache/2.4.67

root@kitploit:~
### Outras CVEs corrigidas no 2.4.67

A versão 2.4.67 aborda cinco CVEs. As duas mais significativas, juntamente com a CVE-2026-23918, são:

- **CVE-2026-24072** — Escalação de privilégio através do tratamento de scripts CGI no Windows (afeta apenas implantações Windows)
- **CVE-2026-24081** — A avaliação de expressões do `mod_rewrite` permite que autores de `.htaccess` leiam arquivos arbitrários como o usuário httpd (afeta 2.4.66 e anteriores, reportado em 2026-01-20)
- **CVE-2026-24088** — Estouro de buffer heap no `mod_proxy_ajp` através de mensagens AJP maliciosas de um backend AJP mal-intencionado (afeta 2.4.66 e anteriores)

Atualizar para o 2.4.67 corrige todas as cinco em uma única ação.

---

## Referência de IoCs Chave

| Indicador | Valor | Confiança | Notas |
|---|---|---|---|
| Versão afetada | `Apache/2.4.66` no cabeçalho Server | **Alta** | A presença por si só indica exposição |
| Tipo de quadro HTTP/2 | RST_STREAM (0x03) com código de erro não nulo | Médio | Erros legítimos de conexão produzem o mesmo |
| Padrão de bytes do quadro | `00 00 04 03 00` (cabeçalho RST_STREAM) | Médio | Combinado com limite = alto |
| Limite de inundação RST | >10 RST_STREAM/erro não nulo da mesma fonte em 30s | **Alto** | Consistente com ferramentas DoS encontradas em campo |
| SIGABRT no worker Apache | sinal 6 enviado para o PID do `httpd`/`apache2` | **Alto** | Workers normais não abortam |
| Execução de shell por www-data | `execve()` de bash/sh pelo uid 33 ou 48 | **Crítico** | Indica fortemente RCE |
| Conexão de saída pelo usuário Apache | `connect()` pelo uid 33 ou 48 para IP externo | **Crítico** | Indica fortemente shell reverso |
| Criação de arquivo web na raiz web | Novos `.php`/`.py`/`.sh` escritos em `/var/www` | **Alta** | Pode indicar implantação de web shell |
| Tipo de MPM | `mpm_prefork` | N/A — **não afetado** | Verifique com `apachectl -V \| grep MPM` |
| Pré-condição RCE | Alocador APR mmap | Contextual | Padrão no Debian/Ubuntu; não padrão no RHEL |

---

*Pacote de detecção mantido com base nos avisos de segurança do Apache HTTP Server em [httpd.apache.org/security](https://httpd.apache.org/security/). Se você observar variantes de exploração ou padrões pós-exploração não cobertos por essas regras, por favor abra uma issue.*
Baixar ferramenta
Atualize imediatamente
2.4.65 e anterioresNão afetado por este bug específicoPode ter outros CVEs conhecidos — revise o aviso
DistribuiçãoComando
Ubuntu / Debiansudo apt-get update && sudo apt-get upgrade apache2
RHEL / Rocky / AlmaLinuxsudo dnf update httpd
Amazon Linuxsudo dnf update httpd
SUSE / openSUSEsudo zypper update apache2
Arch Linuxsudo pacman -Syu