CVE-2013-2028 is a memory corruption vulnerability in nginx 1.3.9 through 1.4.0 in the ngx_http_parse_chunked function within the HTTP request parsing logic. A remote attacker can send a crafted HTTP request using chunked Transfer-Encoding with an excessively large chunk size that triggers an integer signedness error during chunk-size handling. This flaw leads to a stack-based buffer overflow in the chunked request parser, causing worker process crashes and creating conditions for arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This nine-file repository is a Docker-based lab for CVE-2013-2028 in Nginx 1.3.9's ngx_http_parse_chunked parser. Dockerfile builds Nginx release 1.3.9 on Ubuntu 16.04 with rewrite and gzip modules disabled, while docker-compose.yml maps host TCP/8081 to container TCP/80. The primary Python exploit, exploit.py, uses pwntools to send malformed chunked HTTP requests, recover a stack canary byte-by-byte from connection behavior, then deliver a target-specific amd64 ROP chain. The chain makes controlled memory executable with mprotect, writes generated reverse-TCP /bin/sh shellcode at 0x684000, and jumps to it. intermediate_task.py is a separate local Docker validation utility that checks the expected container, Nginx process/version, and nginx -t output; it is not the exploitation path. grader.py appears syntactically malformed in the supplied content (mis-indentation/backticks and incorrect __name__ guard), so it is unlikely to execute as provided.
This repository contains a single Metasploit module (modules/exploits/linux/http/nginx_chunked_size.rb) that exploits a stack buffer overflow vulnerability (CVE-2013-2028) in nginx versions 1.3.9 to 1.4.0. The exploit targets the HTTP service (default port 80) and abuses the chunked transfer encoding parsing logic to trigger an integer overflow, leading to a stack buffer overflow. The module supports exploitation on 32-bit Ubuntu 13.04 and Debian Squeeze systems running the vulnerable nginx version. It includes logic to brute-force or specify the stack canary, construct a ROP chain, and execute arbitrary commands on the target. The exploit is operational and provides remote command execution as the result. The only endpoints referenced are the HTTP service (port 80) and the root path ('/'). The code is written in Ruby and is structured as a typical Metasploit exploit module.
This repository contains a working exploit for CVE-2013-2028, a stack-based buffer overflow in Nginx (versions 1.3.9 to 1.4.0) due to an integer overflow in the ngx_http_parse_chunked function. The exploit is implemented in Python (exploit.py) and automates the process of brute-forcing the stack canary, constructing a ROP chain to call mprotect, copying custom shellcode into executable memory, and finally executing a reverse shell payload. The Dockerfile and docker-compose.yml provide an environment to build and run a vulnerable Nginx instance for testing. The exploit requires the attacker to specify both the target (remote address and port) and the attacker's listener (address and port for the reverse shell). The README.md provides detailed usage instructions and background on the vulnerability. The main attack vector is network-based, targeting the HTTP service running on the vulnerable Nginx instance. The exploit is operational and provides a reverse shell if successful.
This repository contains a single exploit script (exploit.py) and a brief README. The exploit targets a remote HTTP service at 192.168.229.134:80, attempting to bypass modern memory protections (NX, PIE, SSP, ASLR) to achieve remote code execution. The script uses the pwntools library to interact with the target, brute-forces stack canary and code offsets, and crafts a ROP chain to call mmap/mprotect, injects a reverse shell payload, and executes it. The shellcode is a Linux x64 reverse shell generated by msfvenom, configured to connect back to 192.168.229.135:4444. The exploit is unstable and may crash the HTTP service, requiring manual adjustment of offsets and libc versions. The README notes the exploit's instability and the need for further tuning. No specific CVE or product version is mentioned, but the attack is clearly aimed at a Linux HTTP server with strong mitigations enabled.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.