Skip to content
KitploitKITPLOIT
OutilsBlog
Log in
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
cve-2026-80428-ctf — Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice. | Kitploit
Outils/GitHubGitHub/shivammittal2403/cve-2026-80428-ctf
Container SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
GitHub
shivammittal2403/cve-2026-80428-ctf

cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

Voir le dépôt
19il y a 19 joursPas encore vérifié
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2026-80428 CTF Training Lab

Educational emulator of the vulnerability mechanics described in CVE-2026-80428 (CWE-502: Deserialization of Untrusted Data).

This is not a real ILIAS installation and not a weaponized exploit package. It is a fully containerized, isolated laboratory for students, interns, and security researchers.

Learning objectives

  1. CWE-502 insecure deserialization
  2. PHP object injection
  3. Serialized PHP objects
  4. Session-data manipulation
  5. Authentication-exempt application endpoints
  6. Object lifecycle and __destruct()
  7. POP / gadget-chain concepts (safe training gadget only)
  8. Web-accessible file-write consequences (sandboxed)
  9. Detection and forensic analysis
  10. Secure remediation
  11. Vulnerability validation
  12. Patch verification

Architecture

                    ┌──────────────────────┐
                    │      CTF HOST        │
                    └──────────┬───────────┘
                               │  127.0.0.1:8080
                         Docker Network (ctfnet)
                               │
       ┌───────────────────────┼────────────────────────┐
       │                       │                        │
       ▼                       ▼                        ▼
┌──────────────┐       ┌──────────────┐        ┌──────────────┐
│   ATTACKER   │       │    TARGET    │        │   OBSERVER   │
│ Python/curl  │       │ PHP/Apache   │        │ Logs/Evidence│
│ PHP CLI      │       │ Vulnerable   │        │              │
└──────────────┘       │ Emulator     │        └──────────────┘
                       └──────────────┘

Optional patched target on 127.0.0.1:8081 via Compose profile patched.

Prerequisites

  • Docker Engine 24+ and Docker Compose v2
  • ~1 GB free disk for images
  • No cloud credentials required; works offline after images are pulled

Quick start

git clone https://github.com/shivammittal2403/cve-2026-80428-ctf.git
cd cve-2026-80428-ctf
cp .env.example .env
docker compose build
docker compose up -d
docker compose ps

Open: http://127.0.0.1:8080/

Attacker shell:

docker exec -it cve80428-attacker bash

Challenge levels (1000 pts)

LevelFocusPoints
1Reconnaissance100
2Session discovery150
3PHP serialization150
4Object lifecycle / destructor200
5Full chain250
6Remediation (patched target)150

Attack flow (educational)

Unauthenticated Request → LTI (/lti.php) → Session Storage
  → Logout (/logout.php) → unserialize() → Object → __destruct()
  → Controlled write (/drop/) → CTF Flag

See docs/ATTACK_FLOW.md.

Safety model

  • Target bound to 127.0.0.1 by default
  • No Docker socket, no privileged mode
  • Gadget writes only under /var/www/html/drop/ using basename()
  • No system() / exec() / reverse shells
  • Nuclei templates are detection-only

Makefile

make build && make up
make attacker
make health && make test
make reset

Documentation

DocumentAudience
docs/STUDENT.mdStudents
docs/INSTRUCTOR.mdInstructors
docs/VULNERABILITY.mdMapping real CVE ↔ lab
docs/ATTACK_FLOW.mdChain diagrams
docs/REMEDIATION.mdPatch patterns
docs/SOLUTIONS.mdInstructors only

License

MIT — educational use only. See SECURITY.md.

Télécharger l’outil