
Automates sending JSON payloads to multiple IPs via curl to test for CVE-2025-1974 (IngressNightmare), classifying responses and generating XML success/failure reports.
A Python script to automate sending JSON payloads to a list of IPs via curl, capturing responses and splitting them into success and failure XML reports.
Sends HTTPS POST requests with a JSON payload to multiple IP addresses.
Configurable JSON payload file, port, timeout, delay between requests.
Cleans and captures curl stderr (removes progress meter noise).
Classifies requests as success, failed, timeout, or error based on return code and HTTP status.
Generates two XML reports:
Detailed per-request logging to the console.
curl installed on your system and available in PATH.Clone the repository or download the script:
git clone https://github.com/abrewer251/CVE-2025-1974_IngressNightmare_PoC.git
cd autorun
Ensure the script is executable (optional):
chmod +x poc.py
python3 poc.py [OPTIONS] <ip_list_file>
<ip_list_file>: Path to a text file containing one IP address per line.| Option | Description | Default |
|---|---|---|
-h, --help | Show this help message and exit | — |
-j, --json <file> | JSON payload filename to send (with @ syntax) | poc.json |
-p, --port <port> | Target port on each IP | 8443 |
-t, --timeout <seconds> | Timeout in seconds for each curl call | 15 |
-d, --delay <seconds> | Delay in seconds between successive requests | 1.0 |
-s, --success <filename> | Output XML filename for successful requests | 4-3_Success.xml |
-f, --failure <filename> | Output XML filename for failed/timeouted/error requests | 4-3_Failure.xml |
Basic run with defaults:
python3 poc.py ips.txt
Sends poc.json to each IP on port 8443, waits up to 15s, delays 1s between calls, writes 4-3_Success.xml and 4-3_Failure.xml.
Custom payload and port:
python3 poc.py -j payload.json -p 9443 ips.txt
Shorter timeout and faster requests:
python3 poc.py -t 5 -d 0.5 ips.txt
Custom report filenames:
python3 poc.py -s success_report.xml -f error_report.xml ips.txt
This project is licensed under the MIT License. See LICENSE for details.
Generated by Autorun script template.