Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
cve-2026-80428-ctf — Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice. | Kitploit
도구/GitHubGitHub/shivammittal2403/cve-2026-80428-ctf
Container SecurityDynamic Analysis (Sandboxing)Vulnerability AnalysisWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHub
shivammittal2403/cve-2026-80428-ctf

cve-2026-80428-ctf

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

저장소 보기
1919일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-80428 CTF Training Lab

Educational emulator of the vulnerability mechanics described in CVE-2026-80428 (CWE-502: Deserialization of Untrusted Data).

This is not a real ILIAS installation and not a weaponized exploit package. It is a fully containerized, isolated laboratory for students, interns, and security researchers.

Learning objectives

  1. CWE-502 insecure deserialization
  2. PHP object injection
  3. Serialized PHP objects
  4. Session-data manipulation
  5. Authentication-exempt application endpoints
  6. Object lifecycle and __destruct()
  7. POP / gadget-chain concepts (safe training gadget only)
  8. Web-accessible file-write consequences (sandboxed)
  9. Detection and forensic analysis
  10. Secure remediation
  11. Vulnerability validation
  12. Patch verification

Architecture

                    ┌──────────────────────┐
                    │      CTF HOST        │
                    └──────────┬───────────┘
                               │  127.0.0.1:8080
                         Docker Network (ctfnet)
                               │
       ┌───────────────────────┼────────────────────────┐
       │                       │                        │
       ▼                       ▼                        ▼
┌──────────────┐       ┌──────────────┐        ┌──────────────┐
│   ATTACKER   │       │    TARGET    │        │   OBSERVER   │
│ Python/curl  │       │ PHP/Apache   │        │ Logs/Evidence│
│ PHP CLI      │       │ Vulnerable   │        │              │
└──────────────┘       │ Emulator     │        └──────────────┘
                       └──────────────┘

Optional patched target on 127.0.0.1:8081 via Compose profile patched.

Prerequisites

  • Docker Engine 24+ and Docker Compose v2
  • ~1 GB free disk for images
  • No cloud credentials required; works offline after images are pulled

Quick start

git clone https://github.com/shivammittal2403/cve-2026-80428-ctf.git
cd cve-2026-80428-ctf
cp .env.example .env
docker compose build
docker compose up -d
docker compose ps

Open: http://127.0.0.1:8080/

Attacker shell:

docker exec -it cve80428-attacker bash

Challenge levels (1000 pts)

LevelFocusPoints
1Reconnaissance100
2Session discovery150
3PHP serialization150
4Object lifecycle / destructor200
5Full chain250
6Remediation (patched target)150

Attack flow (educational)

Unauthenticated Request → LTI (/lti.php) → Session Storage
  → Logout (/logout.php) → unserialize() → Object → __destruct()
  → Controlled write (/drop/) → CTF Flag

See docs/ATTACK_FLOW.md.

Safety model

  • Target bound to 127.0.0.1 by default
  • No Docker socket, no privileged mode
  • Gadget writes only under /var/www/html/drop/ using basename()
  • No system() / exec() / reverse shells
  • Nuclei templates are detection-only

Makefile

make build && make up
make attacker
make health && make test
make reset

Documentation

DocumentAudience
docs/STUDENT.mdStudents
docs/INSTRUCTOR.mdInstructors
docs/VULNERABILITY.mdMapping real CVE ↔ lab
docs/ATTACK_FLOW.mdChain diagrams
docs/REMEDIATION.mdPatch patterns
docs/SOLUTIONS.mdInstructors only

License

MIT — educational use only. See SECURITY.md.

도구 다운로드