FastCGI - Port 9000
Basic info
What is FastCGI?
FastCGI vs CGI
Architecture
PHP-FPM
Default Port
FastCGI Protocol Overview
Protocol Structure
Record Types
FastCGI Parameters
Reconnaissance & Enumeration
Port Scanning
Service Fingerprinting
Check for Exposed FastCGI
Shodan Queries
Remote Code Execution (RCE)
Method 1: Direct FastCGI RCE (Exposed Port)
Method 2: Python FastCGI Exploit
Method 3: SSRF to FastCGI (Gopher Protocol)
Method 4: Nginx Misconfiguration Exploitation
Known Vulnerabilities & CVEs
CVE-2024-xxxx: libfcgi Integer Overflow
CVE-2024-9026: PHP-FPM Log Manipulation
Nginx + cgi.fix_pathinfo Misconfiguration
Defense & Hardening
Secure PHP-FPM Configuration
Secure Nginx Configuration
Network Security
Monitoring & Detection
Regular Security Practices
Tools & Scripts
Essential Tools
Install cgi-fcgi
Complete Exploitation Framework
Cheat Sheet
Quick Reference
Important Files
Key Parameters
Conclusion
Additional Resources
Last updated