Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
cve-2026-80428-ctf — Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice. | Kitploit
उपकरण/GitHubGitHub/shivammittal2403/cve-2026-80428-ctf
Container SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
GitHub
shivammittal2403/cve-2026-80428-ctf

cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

रिपॉजिटरी देखें
1919 दिन पहलेअभी तक समीक्षित नहीं
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-80428 CTF Training Lab

Educational emulator of the vulnerability mechanics described in CVE-2026-80428 (CWE-502: Deserialization of Untrusted Data).

This is not a real ILIAS installation and not a weaponized exploit package. It is a fully containerized, isolated laboratory for students, interns, and security researchers.

Learning objectives

  1. CWE-502 insecure deserialization
  2. PHP object injection
  3. Serialized PHP objects
  4. Session-data manipulation
  5. Authentication-exempt application endpoints
  6. Object lifecycle and __destruct()
  7. POP / gadget-chain concepts (safe training gadget only)
  8. Web-accessible file-write consequences (sandboxed)
  9. Detection and forensic analysis
  10. Secure remediation
  11. Vulnerability validation
  12. Patch verification

Architecture

                    ┌──────────────────────┐
                    │      CTF HOST        │
                    └──────────┬───────────┘
                               │  127.0.0.1:8080
                         Docker Network (ctfnet)
                               │
       ┌───────────────────────┼────────────────────────┐
       │                       │                        │
       ▼                       ▼                        ▼
┌──────────────┐       ┌──────────────┐        ┌──────────────┐
│   ATTACKER   │       │    TARGET    │        │   OBSERVER   │
│ Python/curl  │       │ PHP/Apache   │        │ Logs/Evidence│
│ PHP CLI      │       │ Vulnerable   │        │              │
└──────────────┘       │ Emulator     │        └──────────────┘
                       └──────────────┘

Optional patched target on 127.0.0.1:8081 via Compose profile patched.

Prerequisites

  • Docker Engine 24+ and Docker Compose v2
  • ~1 GB free disk for images
  • No cloud credentials required; works offline after images are pulled

Quick start

git clone https://github.com/shivammittal2403/cve-2026-80428-ctf.git
cd cve-2026-80428-ctf
cp .env.example .env
docker compose build
docker compose up -d
docker compose ps

Open: http://127.0.0.1:8080/

Attacker shell:

docker exec -it cve80428-attacker bash

Challenge levels (1000 pts)

LevelFocusPoints
1Reconnaissance100
2Session discovery150
3PHP serialization150
4Object lifecycle / destructor200
5Full chain250
6Remediation (patched target)150

Attack flow (educational)

Unauthenticated Request → LTI (/lti.php) → Session Storage
  → Logout (/logout.php) → unserialize() → Object → __destruct()
  → Controlled write (/drop/) → CTF Flag

See docs/ATTACK_FLOW.md.

Safety model

  • Target bound to 127.0.0.1 by default
  • No Docker socket, no privileged mode
  • Gadget writes only under /var/www/html/drop/ using basename()
  • No system() / exec() / reverse shells
  • Nuclei templates are detection-only

Makefile

make build && make up
make attacker
make health && make test
make reset

Documentation

DocumentAudience
docs/STUDENT.mdStudents
docs/INSTRUCTOR.mdInstructors
docs/VULNERABILITY.mdMapping real CVE ↔ lab
docs/ATTACK_FLOW.mdChain diagrams
docs/REMEDIATION.mdPatch patterns
docs/SOLUTIONS.mdInstructors only

License

MIT — educational use only. See SECURITY.md.

टूल डाउनलोड करें