Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
cve-2026-80428-ctf — Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice. | Kitploit
أدوات/GitHubGitHub/shivammittal2403/cve-2026-80428-ctf
Container SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHub
shivammittal2403/cve-2026-80428-ctf

cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

عرض المستودع
19منذ 20 أياملم تتم المراجعة بعد
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2026-80428 CTF Training Lab

Educational emulator of the vulnerability mechanics described in CVE-2026-80428 (CWE-502: Deserialization of Untrusted Data).

This is not a real ILIAS installation and not a weaponized exploit package. It is a fully containerized, isolated laboratory for students, interns, and security researchers.

Learning objectives

  1. CWE-502 insecure deserialization
  2. PHP object injection
  3. Serialized PHP objects
  4. Session-data manipulation
  5. Authentication-exempt application endpoints
  6. Object lifecycle and __destruct()
  7. POP / gadget-chain concepts (safe training gadget only)
  8. Web-accessible file-write consequences (sandboxed)
  9. Detection and forensic analysis
  10. Secure remediation
  11. Vulnerability validation
  12. Patch verification

Architecture

                    ┌──────────────────────┐
                    │      CTF HOST        │
                    └──────────┬───────────┘
                               │  127.0.0.1:8080
                         Docker Network (ctfnet)
                               │
       ┌───────────────────────┼────────────────────────┐
       │                       │                        │
       ▼                       ▼                        ▼
┌──────────────┐       ┌──────────────┐        ┌──────────────┐
│   ATTACKER   │       │    TARGET    │        │   OBSERVER   │
│ Python/curl  │       │ PHP/Apache   │        │ Logs/Evidence│
│ PHP CLI      │       │ Vulnerable   │        │              │
└──────────────┘       │ Emulator     │        └──────────────┘
                       └──────────────┘

Optional patched target on 127.0.0.1:8081 via Compose profile patched.

Prerequisites

  • Docker Engine 24+ and Docker Compose v2
  • ~1 GB free disk for images
  • No cloud credentials required; works offline after images are pulled

Quick start

git clone https://github.com/shivammittal2403/cve-2026-80428-ctf.git
cd cve-2026-80428-ctf
cp .env.example .env
docker compose build
docker compose up -d
docker compose ps

Open: http://127.0.0.1:8080/

Attacker shell:

docker exec -it cve80428-attacker bash

Challenge levels (1000 pts)

LevelFocusPoints
1Reconnaissance100
2Session discovery150
3PHP serialization150
4Object lifecycle / destructor200
5Full chain250
6Remediation (patched target)150

Attack flow (educational)

Unauthenticated Request → LTI (/lti.php) → Session Storage
  → Logout (/logout.php) → unserialize() → Object → __destruct()
  → Controlled write (/drop/) → CTF Flag

See docs/ATTACK_FLOW.md.

Safety model

  • Target bound to 127.0.0.1 by default
  • No Docker socket, no privileged mode
  • Gadget writes only under /var/www/html/drop/ using basename()
  • No system() / exec() / reverse shells
  • Nuclei templates are detection-only

Makefile

make build && make up
make attacker
make health && make test
make reset

Documentation

DocumentAudience
docs/STUDENT.mdStudents
docs/INSTRUCTOR.mdInstructors
docs/VULNERABILITY.mdMapping real CVE ↔ lab
docs/ATTACK_FLOW.mdChain diagrams
docs/REMEDIATION.mdPatch patterns
docs/SOLUTIONS.mdInstructors only

License

MIT — educational use only. See SECURITY.md.

تنزيل الأداة