Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-2028 PoC — F5 Nginx 缓冲区错误漏洞

Source
Associated Vulnerability
Title:F5 Nginx 缓冲区错误漏洞 (CVE-2013-2028)
Description:The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Description
this is not stable
Readme
for bypass NX PIE SSP ASLR  

this poc is not stable.    
sometimes http service will down.  
you should fix morecore-offset and chose correct libc-file  
File Snapshot

[4.0K] /data/pocs/8a0b151f5aea8e2a90dd9ca2b2b0ccbb1409e7c0 ├── [8.2K] exploit.py ├── [8.4M] nginx.bin └── [ 155] README.md 0 directories, 3 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →