
Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.
Educational emulator of the vulnerability mechanics described in CVE-2026-80428 (CWE-502: Deserialization of Untrusted Data).
This is not a real ILIAS installation and not a weaponized exploit package. It is a fully containerized, isolated laboratory for students, interns, and security researchers.
__destruct() ┌──────────────────────┐
│ CTF HOST │
└──────────┬───────────┘
│ 127.0.0.1:8080
Docker Network (ctfnet)
│
┌───────────────────────┼────────────────────────┐
│ │ │
▼ ▼ ▼
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ ATTACKER │ │ TARGET │ │ OBSERVER │
│ Python/curl │ │ PHP/Apache │ │ Logs/Evidence│
│ PHP CLI │ │ Vulnerable │ │ │
└──────────────┘ │ Emulator │ └──────────────┘
└──────────────┘
Optional patched target on 127.0.0.1:8081 via Compose profile patched.
git clone https://github.com/shivammittal2403/cve-2026-80428-ctf.git
cd cve-2026-80428-ctf
cp .env.example .env
docker compose build
docker compose up -d
docker compose ps
Open: http://127.0.0.1:8080/
Attacker shell:
docker exec -it cve80428-attacker bash
| Level | Focus | Points |
|---|---|---|
| 1 | Reconnaissance | 100 |
| 2 | Session discovery | 150 |
| 3 | PHP serialization | 150 |
| 4 | Object lifecycle / destructor | 200 |
| 5 | Full chain | 250 |
| 6 | Remediation (patched target) | 150 |
Unauthenticated Request → LTI (/lti.php) → Session Storage
→ Logout (/logout.php) → unserialize() → Object → __destruct()
→ Controlled write (/drop/) → CTF Flag
See docs/ATTACK_FLOW.md.
/var/www/html/drop/ using basename()system() / exec() / reverse shellsmake build && make up
make attacker
make health && make test
make reset
| Document | Audience |
|---|---|
docs/STUDENT.md | Students |
docs/INSTRUCTOR.md | Instructors |
docs/VULNERABILITY.md | Mapping real CVE ↔ lab |
docs/ATTACK_FLOW.md | Chain diagrams |
docs/REMEDIATION.md | Patch patterns |
docs/SOLUTIONS.md | Instructors only |
MIT — educational use only. See SECURITY.md.