目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-40898 PoC — Apache HTTP Server 代码问题漏洞

来源
关联漏洞
标题: Apache HTTP Server 代码问题漏洞 (CVE-2024-40898)
Description:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server 2.4.62之前版本存在代码问题漏洞,该漏洞源于存在服务器端请求伪造问题,可能会将NTML哈希泄露给恶意服务器。
Description
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.  
介绍
CVE-2024-40898 SSL Certificate Validation Bypass Scanner

This repository contains a Python-based proof-of-concept (PoC) script to detect CVE-2024-40898, a vulnerability in Apache HTTP Server that allows attackers to bypass SSL certificate verification.

Overview

CVE-2024-40898 is a security issue in Apache HTTP Server which, under specific conditions, permits clients to bypass certificate validation. This could potentially allow man-in-the-middle (MitM) attacks over TLS.

What This Script Does
	•	Reads a list of host:port pairs from ssl-ports.txt.
	•	For each entry:
	•	Establishes a TLS connection using a custom SSL context that disables certificate validation.
	•	Sends a HEAD / request to the server.
	•	Analyzes the response:
	•	If the response includes 200 OK, the target is marked as potentially vulnerable.
	•	If no such response is returned, the target is marked as safe.
	•	If any exception occurs, it is logged as an error.

Requirements
	•	Python 3.x

How to Use
	1.	Create a file named ssl-ports.txt with one target per line in the format:
                    
		      api.example.com:443
		      
                      www.site.org:443
		      
                      secure.service.net:443
2.	Run the script:

  	      python3 check_cve_40898.py
4.	View the results:
[VULNERABLE] domain.com:443
[SAFE] domain.com:443
[ERROR] domain.com:443 => <error message>
Notes
	•	This is an automated scanner. It will test all domains listed in ssl-ports.txt and print the results.
	•	Make sure your domain list is accurate and within your testing scope.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →