distcc 2.x, including the version bundled with XCode 1.5, does not restrict access to its server port by default. This allows remote attackers to submit compilation jobs that result in arbitrary command execution on the server, as distcc executes received jobs without performing authorization checks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This seven-file Portuguese-language repository is a documented isolated KVM/libvirt penetration-testing lab, not a packaged exploit tool. It contains a README, Nmap and Nikto scan outputs, a libvirt network XML definition, and evidence logs for two manual Netcat-based root-shell demonstrations. No standalone source-code exploit or executable entry point is present. The primary demonstrated exploit is CVE-2011-2523: an FTP USER value ending in `:)` is sent to the Metasploitable2 target's vsFTPd 2.3.4 service on TCP/21, after which the compromised service exposes a root shell on TCP/6200. A second evidence file shows direct unauthenticated root-shell access to the intentionally exposed Metasploitable bindshell on TCP/1524. The repository additionally records unexploited or unconfirmed exposure of UnrealIRCd, distccd, Java RMI, legacy web components, and other services. It explicitly states that testing occurred only against a personal intentionally vulnerable VM on isolated subnet 192.168.100.0/24.
This repository is a small standalone Python proof-of-concept exploit for CVE-2004-2687, targeting the distccd distributed compiler daemon. It contains only two files: a brief README with usage guidance and one Python script implementing the exploit logic. The script is not part of a larger framework such as Metasploit. The main exploit file, distccd_rce_CVE-2004-2687.py, uses Python's socket library to connect directly to a target host and port (default TCP/3632). It crafts a raw DIST protocol request that supplies arguments causing the remote service to execute 'sh -c <command>' instead of a normal compilation workflow. Additional placeholder arguments ('#', '-c', 'main.c', '-o', 'main.o') are included to resemble a compile request. After sending the payload and a DOTI tag with a random alphanumeric token, the script reads back STDERR and STDOUT from the remote service and prints the results. Capabilities: the exploit provides unauthenticated remote command execution against a vulnerable distccd instance. By default it runs 'id', but the operator can pass any shell command with -c. The README demonstrates using netcat to obtain a reverse shell by instructing the target to connect back to an attacker-controlled listener. Repository structure is minimal and purpose-built: README.md documents manual usage, and the Python script is the sole executable entry point. There are no auxiliary modules, persistence features, obfuscation layers, or post-exploitation automation beyond command execution and output retrieval.
This repository contains a Python 3 proof-of-concept exploit for CVE-2004-2687, a remote code execution vulnerability in the distccd daemon (part of the distcc distributed compilation system). The exploit targets distccd instances that are accessible over the network and improperly configured to allow unauthenticated access. The main exploit file, 'distccd_rce.py', connects to the target host and port (default 3632), crafts a payload that abuses the distccd protocol to execute arbitrary shell commands, and sends it to the daemon. The attacker can specify any command to run, with the typical use case being to spawn a reverse shell back to the attacker's machine. The exploit is operational and requires the attacker to provide the target host, port, and command to execute. The README provides usage instructions and context about the vulnerability. No hardcoded IPs or domains are present; the only fingerprintable endpoint is the default distccd TCP port (3632).
This repository contains a single Metasploit module: 'DistCC Daemon Command Execution' (modules/exploits/unix/misc/distcc_exec.rb). The module exploits a documented security weakness in the distccd daemon (CVE-2004-2687), allowing remote attackers to execute arbitrary shell commands on any system running a vulnerable version of distccd. The exploit works by sending a specially crafted TCP request to the distccd service, typically running on port 3632. The module supports a variety of command payloads (cmd, cmd_bash, etc.), enabling the attacker to run arbitrary shell commands, open reverse shells, or perform other post-exploitation actions. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for penetration testers or attackers. The only requirement is that the target system is running distccd and is accessible over the network. No authentication is required. The module includes a check method to verify vulnerability and an exploit method to deliver the payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.